Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
286 stories published
CISA Urges Water Sector to Secure Exposed PLCs Following Minnesota Cyberattacks
CISA warns water utilities to remove internet-exposed PLCs following attacks on over 30 Minnesota water systems that disrupted automated controls.
Jul 30, 2026South Korea Fines KT $39M Over Rogue Femtocells and Covered-Up BPFDoor Infections
South Korea's PIPC fined KT Corporation $39 million after attackers used stolen femtocell certificates and BPFDoor malware to compromise subscriber data.
Jul 30, 2026Bank of America to Acquire UK Cybersecurity Firm MDSec
Bank of America announced plans to acquire UK cybersecurity consultancy MDSec to expand its cyber threat operations center and internal defense capabilities.
Jul 30, 2026Iran-Backed Actors Target Over 30 Minnesota Water Utilities
A likely Iranian cyber threat group targeted more than 30 Minnesota community water systems, highlighting critical infrastructure vulnerabilities.
Jul 30, 2026Okta Acquires Permiso to Expand Into Identity Threat Detection and SecOps
Okta acquires identity threat detection firm Permiso Security to unify posture management, runtime cloud monitoring, and agentic identity protection.
Jul 30, 2026AI Harness Security: Trust Boundaries Create New Attack Vectors
Complex AI harnesses and framework components suffer from broken trust boundaries, exposing organizations to novel supply chain and privilege escalation risks.
Jul 30, 2026Cheap H96 TV Streaming Sticks Caught Spoofing Phones in $50k-a-Day Ad Fraud Operation
Generic H96 Android TV streaming devices run pre-installed backdoors, spoofing mobile phones to execute automated ad fraud for China's Fengwo Group.
Jul 30, 2026Google Uses AI to Fix Over 1,000 Chrome Security Bugs Across Two Releases
Google reports leveraging AI tools to identify and remediate 1,072 Chrome security vulnerabilities across the browser's last two major releases.
Jul 30, 2026Lazarus Group Shares Infrastructure with Gunra Ransomware Operations
South Korean agencies warn North Korea's Lazarus Group is sharing tools, exploits, and C2 servers with Gunra ransomware operators targeting Korean entities.
Jul 30, 2026Inside a Post-Breach Intrusion: SQL Injection, BadIIS, and Evasion Techniques
Huntress dissects a real-world server compromise where attackers used SQL injection to drop BadIIS malware, create admin backdoors, and mine crypto.
Jul 30, 202618% of Data Center Physical Infrastructure Assets Sit One Hop From Public Internet
Claroty research highlights how dual-homed networks and weak BMS protocols leave 32,000 data center infrastructure devices exposed to lateral attacks.
Jul 30, 2026Critical Ruflo Vulnerability (CVE-2026-59726) Allows AI Swarm Hijacking and RCE
A maximum-severity Ruflo vulnerability tracked as CVE-2026-59726 permits unauthenticated attackers to execute commands and take over AI agent swarms.
Jul 30, 2026No news matches your search.