Kaspersky has analyzed multiple security incidents affecting Brazilian educational institutions and compiled statistics from their incident response cases. The research includes practical security recommendations designed to help schools and universities strengthen their defenses against similar threats.
A malware campaign is distributing a Java stealer malware by posing as an undetected version of the Xeno Roblox script executor, targeting players seeking the legitimate tool. The fake cheats are being promoted through Discord and forum platforms to maximize reach among the gaming community. This attack demonstrates how threat actors continue to exploit gaming tool downloads as a vector for stealing malware delivery.
Executive Summary Frontier AI has turned CVE weaponization timelines to hours, making scan-bound detection a growing compliance and breach-risk challenge. Agent Insta powers InstaScan to deliver scanless detection by transforming existing inventory, telemetry, and threat intelligence into validated exposure findings within minutes of disclosure. Operating 24/7, InstaScan enables AI-speed detection with 90%+ coverage across technologies […]
A newly discovered HollowFrame loader employs a fake Python DLL to conceal Go-based malicious code while evading Windows Defender detection. The threat actor pre-stages Defender exclusions before deploying the loader, enabling it to operate undetected on compromised systems.
Passkey implementations can suffer from critical security gaps when relying parties neglect to validate the User Verified flag, effectively degrading multi-factor authentication to single-factor security. This validation failure creates a novel attack surface in passwordless authentication systems that organizations adopting passkeys should understand and address in their deployments.
Tenable spent 30 days testing Anthropic's Claude Mythos Preview frontier AI model against its own code repositories and found that it fundamentally shifts code security from ranking suspected defects to proving exploitability through reproducible proof-of-concept exploits. The real value lies not in the AI model itself, but in the orchestration harness around it—the system that transforms suspected flaws into proven, actionable findings—along with a senior security researcher who defines threat models and validates findings. Success requires budgeting both for substantial compute costs (Tenable spent roughly $41,718 in one month) and for expert engineering time, as frontier AI makes one senior researcher as productive as five rather than replacing human expertise entirely.
South Korea's largest telecommunications company KT has received a substantial fine following a year-long security breach involving compromised femtocells. The incident resulted in regulatory penalties totaling approximately $38-39 million, highlighting the critical security risks associated with customer-premises equipment in telecom infrastructure.
A hacker exploited a legacy vulnerability in Coldcard Bitcoin wallets to drain approximately $89 million from affected users. The attack highlights ongoing security risks in hardware wallet implementations despite their reputation for robust protection of cryptocurrency assets.
Elastic Security has enhanced its platform with detection rule change tracking that enables one-click rollbacks, providing SOC teams with complete audit trails of rule modifications. The update also makes case data immediately queryable without additional configuration, streamlining reporting and compliance documentation for security operations centers.
Explore eight key ways that AI is reshaping the threat intelligence landscape, from creating speed and stealth advantages for adversaries to helping defenders better prioritize threats and allocate resources.
HackTheBox - Kobold
IppSec·8.8K views · 3 weeks ago
00:00 - Introduciton
01:00 - Start of nmap
02:30 - Finding the bin and mcp subdomain with ffuf
06:00 - Searching for PrivateBin exploits within version 2.0.2, finding an LFI but having trouble getting Code Execution from it
10:28 - Looking at the MCP Subdomain, finding MCPJam 1.4.2, which has an easy RCE Exploit
16:00 - SSH into the box as ben after dropping ssh key. Looking at processes and ports
18:37 - Looking at Arcane, another website discovering the default user of "arcane" still exists based upon timing on login
21:20 - Using find to see what files we have access to because we are in operator, discovering we can edit privateBin which allows us to weaponize the LFI to switch to its user (www-data)
26:30 - Inside of the PrivateBin Docker, looking for sensitive files, getting a password this lets us into Arcane.
30:03 - Logged into Arcane, a docker management website. Starting a container mounting / of the host to /mnt of the container, then accessing the host disk for privesc
33:30 - Showing a really cool unintended vector, which is the gshadow file. Using newgrp to add ourself to the docker group
JHT Course Launch! Home Labs with Proxmox
John Hammond·4.9K views · 3 weeks ago
Just Hacking Training livestream for Joram Stith's new course launch: Home Labs with Proxmox! Friday, July 31 at 1pm ET
Elastic is showcasing its security tools at Black Hat and DEF CON, demonstrating how Attack Discovery converts raw security alerts into confirmed threats while Elastic Defend addresses vulnerable driver vulnerabilities in real time. The company will run live demonstrations against actual attacks at its conference booth.
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been targeting hospitality sign-in portals since May 2026 to deliver malware to travelers and harvest credentials in an operation dubbed CaptiveCrunch. By compromising hotel authentication systems, the threat actor gains access to a high-volume channel for distributing malware and stealing login credentials from a geographically diverse victim pool.
July 2026 saw significant AI-related security developments, including instances of OpenAI models behaving unexpectedly and the emergence of the first documented agentic ransomware operation. A newly identified AI-driven supply chain threat also garnered attention during the month, indicating evolving attack vectors leveraging artificial intelligence capabilities.
Frontier AI models are democratizing attack capabilities while amplifying the effectiveness of sophisticated threat actors, creating a widening security gap. Security leaders from Vista Equity, Cisco, and Bishop Fox discuss the practical implications of this shift, the necessary evolution of defensive technologies, and the timeline for defenders to regain parity against AI-enabled threats.
According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.