Cloud and SaaS Environments Now Top Targets for Attackers
Cloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity attacks
Cloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity attacks
Interpol claims AI is driving a surge in cybercrime in Africa, with related losses doubling
Scammers are impersonating the IRS by sending fraudulent letters to cryptocurrency holders claiming they must register with a "Digital Asset Compliance Portal." This social engineering attack exploits taxpayers' concerns about regulatory compliance to trick victims into disclosing sensitive information or visiting malicious sites. Security professionals should be aware of this scheme and alert clients who hold digital assets to verify any such communications directly with official IRS channels.
The UK’s Police National Legal Database and Ask the Police service have been breached
Snyk has launched Evo Continuous Offensive Security, an AI-powered solution that performs autonomous pentesting during the gaps between traditional security assessments. The tool aims to identify exploitable vulnerabilities throughout the year rather than only during scheduled testing windows, reducing the window of exposure to attacks that discover flaws first.
AI model risk depends on how a model is deployed. Learn how Evo combines adversarial testing, attack impact, and deployment context to help teams compare models and enforce policy.
Snyk has introduced its first Agentic AppSec capabilities, featuring an autonomous Remediation Agent designed to automatically fix vulnerabilities and a Malicious Code Defense system that prevents risky packages from reaching production. These new tools aim to streamline vulnerability management and supply chain security by automating detection and remediation workflows within the development pipeline.
The keyv npm package and ten related releases were compromised with malware that executed during installation, exploiting trusted package provenance to evade detection. Snyk provides details on affected versions, file hashes, and detection methods to help security teams identify compromised installations and safely remediate the supply chain attack.
Snyk has launched Snyk Secrets as a generally available feature, offering contextual machine learning detection and secure-at-commit prevention capabilities. The offering integrates into the Snyk AI Security Platform to provide unified secrets governance across development workflows.
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects IBM Langflow.
Elastic Security Labs developed an AI triage agent using large language models to process bug bounty submissions at a fraction of traditional costs, achieving 85% alignment with human security expert decisions. The system was calibrated and validated against a dataset of 3,300 real HackerOne reports, addressing the challenge of LLM-driven spam flooding vulnerability disclosure platforms. The research details the agent's architecture and threat model, offering insights into automating security triage workflows at scale.
Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
Executive Summary In the Frontier AI era, the number of CISA-known exploited vulnerabilities has increased by 6.5x over the past four years, and time-to-exploitation has collapsed to -7 days. Traditional monthly patch cycles cannot keep up. Organizations need a new operating model that detects at AI speed, hyper-prioritizes truly exploitable exposures, and remediates immediately. TruRisk […]
Powered by TruConfirm — Exploit Validation That Now Runs on the Network and the Host Executive Summary Qualys TruConfirm now validates exploitability across the entire attack surface, not just the network. Cloud Agent-Based TruConfirm brings the same proof-based validation model to the endpoint, closing the gap on local, kernel, browser, and post-authentication CVEs that network […]
China-linked threat actors demonstrated rapid exploitation capabilities by weaponizing the critical React2Shell vulnerability within 24 hours of discovery. The finding aligns with broader H1 2026 trends showing that 88% of exploited vulnerabilities were compromised within 48 hours of disclosure, underscoring the compressed window security teams face for patching critical issues.
Russian-nexus threat actor Storm-2945, operating under the Midnight Blizzard banner, has been hijacking hotel captive portals to distribute fake software updates and harvest authentication tokens from travelers. The campaign leverages the trust users place in hotel network login systems to deliver malicious payloads in a hospitality-focused targeting strategy.
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported […] The post 3rd August – Threat Intelligence Report appeared first on Check Point Research.