I added hover over text, it messed up some of the formatting. But whatever, I gotta go write my TPS report.

Krebs on Security

Dark Reading

The Hacker News [ THN ] - Best Security Blog

2026-08-04 - CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
2026-08-04 - 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
2026-08-03 - Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
2026-08-03 - INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
2026-08-03 - ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
2026-08-03 - FOMO in the SOC: Where AI Platforms like Claude Actually Fit
2026-08-03 - Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
2026-08-03 - PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
2026-08-03 - Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
2026-08-03 - N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
2026-08-03 - Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
2026-08-01 - Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
2026-08-01 - Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
2026-08-01 - Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
2026-08-01 - Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
2026-08-01 - Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
2026-07-31 - HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
2026-07-31 - Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
2026-07-31 - Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
2026-07-31 - Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
2026-07-31 - 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
2026-07-31 - Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
2026-07-31 - Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

Schneier on Security

2026-08-03 - published a detailed timeline of the attack. From the summary:

The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or operation of that evaluation environment. As far as we were able to infer, across the course of being evaluated on this benchmark, the agent inferred that Hugging Face may host that benchmark’s models, datasets, and reference solutions. We believe the entire intrusion was, from the agent’s point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own...

">More on the OpenAI Agent’s Attack on Hugging Face
2026-08-03 - Foreign Policy.

Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how good a model is at turning security vulnerabilities into working exploits: basically, offensive cyberattacks.

Since these were internal tests, OpenAI locked those models in a secure sandbox that denied them access to the internet. But it was running the models without any safety filters that would prevent them from offensive cyber-actions. That meant that there was nothing to prevent the models from trying to ...

">The OpenAI Hack Shows the Genie Is Out of the Bottle
2026-07-31 - scientific machine:

One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world of exploring. We could see cells interacting with each other, exchanging material and building skeletons. And we could do that live on the ship, when usually it takes a couple of weeks of staining and mounting to see anything,” Osborn said.

The expedition discovered thirty-one new marine species in two weeks. The article doesn’t say if any of them were new species of squid...

">Friday Squid Blogging: Squid Helps Discover New Marine Species
2026-07-31 - chart is interesting.

On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non-Claude model was Muse Spark at 16.5% within 15 attempts—more than eight times Opus 5’s rate. The most capable GPT 5.6 variant, Sol, was comparable to its predecessor GPT 5.5 (20.0% versus 20.8% within 15 attempts), and was 10 times as likely to be successfully attacked as Claude Opus 5 at 2.0%. The other GPT 5.6 variants are less robust, at 30.4% (Terra) and 43.9% (Luna). A single attempt against GPT 5.6 Sol succeeded 3.1% of the time, higher than the 2.0% an attacker achieved against Opus 5 after fifteen attempts...

">Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
2026-07-31 - broke (alternate link) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition.

Turns out that the system was shut off for Taylor Swift’s wedding.

Evan Greer—one of the people that MSG alerts on—comments:

Ironically, Swift herself has reportedly used facial recognition at her own concerts to identify stalkers. This “privacy for me, surveillance for thee” attitude feels like a perfect encapsulation of the future we’re already living in: one where wealthy elites can afford privacy, while the rest of us are forced to live in a corporate surveillance panopticon...

">Facial Recognition at Madison Square Garden

ThreatPost

Sydney Morning Herald

New York Times

2026-08-03 - SpaceX’s Stock Lockup Is Expiring. Prepare for a Bumpy Ride.
2026-08-03 - What Are Companies Getting for All That A.I. Spending?
2026-08-03 - If You Can’t Beat A.I., Outdress It, Tech Firms and Their Swag Say
2026-07-31 - Open Model Wars + Claire Stapleton’s Dishy Google Memoir + Substack’s Slop Fight
2026-08-03 - Google Earth Disables A.I. Tool After One Day Over Disinformation Concerns
2026-07-31 - Five Takeaways From the Times Investigation Into Larry Ellison’s A.I. Gamble
2026-07-31 - We All Do Errands. Noah Blau Films Them.
2026-08-02 - Larry Ellison Bet It All on the A.I. Boom. Will He Be the Face of the A.I. Bubble?
2026-07-31 - What You Need to Know About Installing Plug-In Solar Panels
2026-08-02 - The German Auto Industry, a Pillar of the National Psyche, Is Trembling
2026-08-03 - Plug-In Solar Panels Are Starting to Sprout in U.S. Backyards
2026-08-01 - How the Pro-Trump Media Ecosystem Is Splintering Ahead of the Midterms
2026-07-31 - Anthropic Says Its A.I. Systems Broke Into Computers at 3 Organizations
2026-07-31 - Big Tech’s A.I. Spending Keeps Rising. So Do the Jitters.
2026-08-03 - When A.I. Invaded ‘Heated Rivalry’ Fan Fiction, the Meltdown Was Epic

Wall Street Journal

BBC

2026-08-03 - Tokenomics: Why making AI pay is tricky
2026-08-03 - Xbox Series X price hiked by £170 due to rising memory chip costs
2026-07-31 - Snapchat joins other popular platforms in fight against 'AI slop'
2026-07-31 - AI firms must answer for rogue bots, says boss of hacked company
2026-07-31 - Amazon and Apple just told us more about their AI plans - here are three things we learned
2026-07-31 - How police are trying to divert teen hackers away from crime
2026-08-01 - Tech Now

SecurityBrief AU

ITNews AU

2026-08-04 - Russia-linked "Midnight Blizzard" group hijacks hotel wi-fi with CaptiveCrunch
2026-08-04 - Visa snaps up BioCatch
2026-08-03 - Arch Linux halts package adoptions after malware hijacking wave
2026-07-31 - Microsoft can't kill dogged researcher's Copilot for Word worm
2026-07-31 - In Pictures: Security in the age of shadow AI Security Centric roundtable

BleepingComputer

2026-08-03 - Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
2026-08-03 - New Pass-ta-key attacks let malware hijack Google-synced passkeys
2026-08-03 - New DOUBLECUP ClickFix service hides malware in browser cache images
2026-08-03 - Fake Roblox Xeno script launcher pushes infostealer, RAT malware
2026-08-03 - N-able warns of N-central auth bypass flaw exploited in attacks
2026-08-03 - ExfilSquad hackers leak info of over 100,000 UK police officers, staff
2026-08-03 - Inside the Underground Business of the Android BTMOB RAT malware
2026-08-02 - OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems
2026-08-02 - COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
2026-08-02 - Google Chrome may soon block New Tab hijacker extensions by default
2026-08-01 - Rails patches critical Active Storage flaw with RCE potential
2026-07-31 - Amgen says cloud data breach exposed patient health, proprietary info
2026-07-31 - Arch Linux disables AUR package adoption to stop malware flood
2026-07-31 - Online ad firm Adform’s script compromised to steal cryptocurrency
2026-07-31 - OpenAI says its new GPT 5.6 models are becoming more cost-efficient

/r/NetSec

2026-08-01 -

Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.

Rules & Guidelines

As always, the content & discussion guidelines should also be observed on r/netsec.

Feedback

Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.

submitted by /u/albinowax
[link] [comments]">r/netsec monthly discussion & tool thread
2026-08-03 - /u/callmejackfrost1
[link] [comments]">Jackpot: a browser lab of 10 deliberately vulnerable LLM apps, one per OWASP LLM Top 10 category
2026-08-03 - /u/si9int
[link] [comments]">SQLite Critical CVEs or LLM Slop?
2026-08-03 - /u/AnimalStrange
[link] [comments]">Cruising for Shells in Flowise - elttam
2026-08-02 - /u/S3cur3Th1sSh1t
[link] [comments]">The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog
2026-07-31 -

In three incidents across six runs, the agents treated real systems as simulated targets and tried weak passwords or unauthenticated endpoints.

submitted by
/u/luckokkkk
[link] [comments]">Investigating three real-world incidents in Anthropic's evaluations
2026-07-31 - /u/hakluke
[link] [comments]">Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack
2026-07-31 - /u/_vavkamil_
[link] [comments]">Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware

/r/InfoSecNews