STAY INFORMED
STAY SECURED
Cyber incidents continue to increase in frequency, scale, and business impact, driven by financially motivated threat actors targeting high-value data assets. Despite advancements in security technologies, many organizations remain underprepared to effectively prevent, detect, and respond to evolving threats.
Metrics
Key trends highlight escalating financial impact, expanding attack surfaces, and growing third-party risk exposure, reinforcing the need for enhanced investment, modernized controls, and mature incident response capabilities.
- Global average breach cost: ~US $4.44M / U.S. average breach cost: ~US $10.22M
- Multi-environment breaches (cloud + on-prem): ~US $5.05M average cost
- PII involved in ~53% of breaches
- AI-related risks emerging: ~16% attacker use; ~20% shadow AI exposure
- Average dwell time: ~241 days
- Third-party involvement in ~30% of breaches
ThreatScape
Cyber threat activity remains persistent and diverse, with widespread website compromise, insider involvement, financially driven attacks, ransomware prevalence, concentrated industry impact, and strong links to organized cybercrime groups.
- 4,800 websites/month are compromised with formjacking.
- 34% of breaches involve internal actors.
- 71% of breaches are financially motivated.
- 24% of malware incidents involve ransomware.
- 95% of breached records** come from government, retail, and technology.
- 36% of external actors** are linked to organized crime.
CyberPulse
Corporate cyberattacks are on the rise. How should you protect yourself if you fall victim to a breach? ... data stored in cloud servers, it said in a filing Friday, the latest large healthcare company to suffer a data breach. The drugmaker is still ... GB News' Tom Harwood explains the latest AI security breach. AI firm Anthropic said its Claude model gained unauthorized access to the systems of ... Data and Modeling Requirements. . Actuarial-grade claims data: Insurance industry claims history and multi-source loss data anchor the model to real ... Paidwork data breach reportedly exposed 23 million accounts, including bank account numbers and passwords. Have I Been Pwned confirmed the leak, ... We've treated security awareness and secure coding as two separate worlds. One for the workforce, one for the technical teams. Attackers have never ... This helps covered entities and business associates configure, implement, and evidence compliance with the HIPAA Security Rule Technical Safeguard ... Elsewhere, senior investigative reporter Sian Norris uncovers a data breach at the UK's General Medical Council, and openDemocracy columnist Paul ... Data breaches are no longer rare anomalies. They happen every single week. Between retail hacks, credit bureau slips, and app leaks, your email, old ... The FBI said Thursday that “some of that activity has degraded water operations,” which the U.S. Cybersecurity and Infrastructure Security Agency ( ... Sumner County Schools' network restored after data breach delays start of school year. @WSMV43 likes51 views12 hours ago “Adobe has released a security update for Adobe Campaign Classic. This update addresses critical vulnerabilities that could result in arbitrary code ... Tracked as CVE-2026-66066 (CVSS score of 9.5), the critical security defect is described as an arbitrary file read that potentially exposes secrets, ... On the Moroccan side of the border, thousands of migrants streamed into the town of Fnideq overnight despite a reinforced deployment of security that ... The man who uncovered a major celebrity data leak has a bleak warning about the 'super scary' capabilities of AI, and it has nothing to do with losing ... University of St. Thomas data breach settlement could pay student, employee victims up to $4,500. By Samantha Ketterer, Staff Writer Aug 1, 2026. This week's enterprise technology news showed that the AI security story keeps getting more complicated. Organizations need to defend against new ... Cybersecurity experts are faulting Anthropic PBC and OpenAI for sloppy safeguards after their models broke into outside organizations — breaches ... Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple ... If you were notified about the 2023 Comcast Xfinity data breach, you may be eligible for a cash payment. But you'll need to file a claim before ...
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in […] Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.
Adform detected the incident […] Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code […] A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft […] A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, […] Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.
According to Blackpoint […] Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same […] Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones […] An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and […] Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. […] Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously.
After an initial Telegram instruction, […] Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three […] Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent […] A lot of security still comes down to trusting the wrong screen.
This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. […] A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, […] Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on […] Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network […] South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed […] The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial […] The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access […] The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving […] Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a […] The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known […] Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. […] Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated […] Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.
The […] A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response.
Braham, Plymouth, South […] Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international […] AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along.
The […] Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.
Tracked as CVE-2026-10702, the bug provides […]
A couple-dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements. The most valuable move any security team can make is building a certificate and key inventory. When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out. Hundreds of thousands of California residents have already registered for the Delete Request and Opt-out Platform (DROP), which launches Aug. 1. Other states could follow if the process goes smoothly. The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the […] A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure. A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors. In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it? The organized crime groups have moved from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone. A premium-grade malware-as-a-service offering takes flight with multiple threat groups, building infostealers that drain victims' bank accounts. OpenAI's goal-seeking agent compromised a Modal customer environment and others during its sandbox escape. The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts. Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware […] Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face. New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks. The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching. Dormant nonhuman identities can create security blind spots, says security researcher Aleksandr Krasnov, who plans to release an open source tool next week at Black Hat USA 2026 that sniffs out trust […] A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note. OpenAI's recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log everything. Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action. Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment. The cybersecurity pioneer discusses the evolution of the CISO role, AI's impact on careers, and why operational resilience is the profession's next frontier. Attackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance. PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin requests. This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls. An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time. As attackers shift from password theft to session and token theft to bypass multifactor authentication controls, organizations must move beyond login security and protect authenticated sessions. Confidence in autonomous security tools is declining, and here's why. Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide. The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best. A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned by anyone with a browser. Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant's identity and access others' data, credentials, […] The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language. A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message. Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers. Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets. A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken. Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users. Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity. A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes. Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective. European and US banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns. Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations. The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. A Russian-speaking actor, "Trim," dismantled publicly available frontier models and integrated them with offensive security tools. AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used. Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet. Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages, but cost and human-in-the-loop viability remain open questions. Marc Maiffret reflects on Code Red's legacy and the security lessons helping organizations navigate AI risk today. Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.

