RansomwareWeLiveSecurity·3 weeks ago

This month in security with Tony Anscombe – July 2026 edition

July 2026 saw significant AI-related security developments, including instances of OpenAI models behaving unexpectedly and the emergence of the first documented agentic ransomware operation. A newly identified AI-driven supply chain threat also garnered attention during the month, indicating evolving attack vectors leveraging artificial intelligence capabilities.

OtherBishop Fox·3 weeks ago

What Security Leaders Think About Frontier AI Models: Firsthand of Mythos

Frontier AI models are democratizing attack capabilities while amplifying the effectiveness of sophisticated threat actors, creating a widening security gap. Security leaders from Vista Equity, Cisco, and Bishop Fox discuss the practical implications of this shift, the necessary evolution of defensive technologies, and the timeline for defenders to regain parity against AI-enabled threats.

PhishingGraham Cluley·3 weeks ago

The $5 million threat: AI Is supercharging phishing attacks

According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.

OtherKaspersky Securelist·3 weeks ago

Network Anomaly Detection in KATA

Kaspersky's analysis demonstrates how Network Anomaly Detection rules function within Kaspersky Anti Targeted Attack by examining real-world attack techniques like Kerberoasting and DNS tunneling. The research provides insight into detection mechanisms designed to identify unusual network behavior indicative of targeted threats. Security professionals can leverage this understanding to better recognize and respond to similar attack patterns in their environments.

MalwareUnit 42·3 weeks ago

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

Unit 42 has analyzed XCSSET v40, a macOS malware that specifically targets developers through Xcode, using advanced pattern matching and AI-driven techniques to decode its operational logic. This latest variant represents a continued threat to the Apple developer ecosystem, with the malware leveraging the Xcode development environment as its primary attack vector.

OtherGreyNoise Labs·3 weeks ago

Introducing Tactics: See What Adversaries Do After They’re Inside

GreyNoise Labs has released Tactics, a tool designed to provide visibility into adversary post-compromise behavior by analyzing data from Deception Sensors. The platform automatically maps observed adversary activities to the MITRE ATT&CK framework, enabling security teams to understand tactics and techniques used after initial system compromise.

Data BreachElastic Security Labs·3 weeks ago

Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

Elastic Security Labs analyzes how each phase of the Hugging Face breach—including worker RCE, credential harvesting, self-migrating command and control, and AI-based detection evasion—aligns with existing Elastic Defend protections and SIEM detection rules. The analysis demonstrates that organizations using Elastic's security stack already possess the capabilities to identify and respond to the attack techniques employed in this incident.

OtherElastic Security Labs·3 weeks ago

Alert Zero: AI-driven alert triage and attack investigation for the agentic SOC

Elastic Security 9.5 introduces AI-driven capabilities designed to automate the initial triage and investigation of security alerts, reducing the manual workload on SOC teams. By automating these routine tasks, the update aims to free security analysts from alert queue management so they can focus on higher-value activities like threat hunting and detection engineering.

Policy & LegalTenable·3 weeks ago

What water utilities need to know about cybersecurity compliance

Water and wastewater utilities face accelerating compliance deadlines as federal and state regulators shift cybersecurity from voluntary guidance to enforceable requirements, with community water systems serving 3,301 to 49,999 people required to certify Risk and Resilience Assessments by June 30, 2026 under AWIA 2013. The regulatory landscape is tightening across multiple fronts: the EPA is enforcing existing authority through inspections and updated cyber tools, New York has finalized binding cybersecurity regulations for wastewater facilities expected to serve as a template for other states in 2026-2027, and the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) will require utilities to report significant incidents to CISA within 72 hours and ransom payments within 24 hours once final rules are published. These compliance pressures come amid a documented threat surge, including a coordinated cyberattack affecting 30+ Minnesota water utilities in July 2026 and ongoing targeting by Iranian-affiliated actors, while federal grant programs and information-sharing protections remain dependent on unpredictable budget cycles.

MalwareKrebs on Security·3 weeks ago

Read This Before You Buy That TV Streaming Stick

Generic TV streaming sticks marketed with unlimited content for a one-time fee pose serious security risks beyond their known practice of renting out users' internet connections to third parties. Security researchers have discovered these devices actively spoof mobile phones to click ads on AI-generated websites, enabling fraud schemes targeting online merchants and advertising networks. The analysis reveals a coordinated operation that exploits both user devices and the broader digital advertising ecosystem.

MalwareInfosecurity Magazine·3 weeks ago

Cryptominer Abuses Linux PAM to Hide From SOC Analysts

A cryptomining operation has adopted a novel evasion technique by exploiting Linux PAM (Pluggable Authentication Modules) to masquerade as unprivileged user accounts rather than operating with root privileges. This approach allows the attackers to fly under the radar of security operations center monitoring systems that typically flag suspicious root-level activity. The shift in tactics demonstrates how threat actors are adapting their methods to evade detection rather than seeking elevated system access.

PhishingInfosecurity Magazine·3 weeks ago

AiTM Phishing Becomes Top Initial Access Threat to Law Firms

Adversary-in-the-middle (AiTM) phishing attacks have emerged as the primary initial access vector for threats targeting law firms, accounting for 56% of identified threats. The reliance on identity-based attacks underscores a shift in how threat actors are compromising legal organizations and their sensitive client data.

VulnerabilityZero Day Initiative·3 weeks ago

The July 2026 Apple Security Update Review

Apple's July 2026 security update addresses 210 CVEs, a dramatic spike from 37 in June, with three vulnerabilities standing out as particularly severe: CVE-2026-43818 (ImageIO arbitrary code execution via malicious images across iOS and macOS), CVE-2026-64747 (AVEVideoEncoder kernel-level code execution affecting all platforms), and CVE-2026-64767 (AFP network-reachable kernel memory corruption affecting macOS). Additional critical risks include multiple file-parsing exploits and remote kernel-corruption vulnerabilities across SMB, Model I/O, and SceneKit components that security teams should prioritize for patching.

Load more