Latest Cybersecurity News and Articles


Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

31 July 2026
Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,

Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace

31 July 2026
The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase. The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek.

EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels

31 July 2026
When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. The post EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels appeared first on SecurityWeek.

Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations

31 July 2026
A security company’s systems were hacked after it installed a malicious Python package deployed by Claude.  The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek.

Critical Flaw Led to Azure Cosmos DB Pwnage

31 July 2026
Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Led to Azure Cosmos DB Pwnage appeared first on SecurityWeek.

CareCloud Data Breach Impacts Over 350,000

31 July 2026
In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment. The post CareCloud Data Breach Impacts Over 350,000 appeared first on SecurityWeek.

Critical Code Execution Vulnerability Patched in TeamCity 

31 July 2026
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in TeamCity  appeared first on SecurityWeek.

Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

31 July 2026
Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a "

CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

30 July 2026
CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems. The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first on SecurityWeek.

Bank of America to Acquire Cybersecurity Firm MDSec

30 July 2026
The acquisition will add approximately 65 cybersecurity professionals to Bank of America’s operations in the United Kingdom. The post Bank of America to Acquire Cybersecurity Firm MDSec appeared first on SecurityWeek.

Okta to Acquire Identity Threat Detection Firm Permiso

30 July 2026
The deal extends Okta's reach beyond identity management and into the realm of security operations, positioning the company to compete more directly on identity threat detection and response. The post Okta to Acquire Identity Threat Detection Firm Permiso appeared first on SecurityWeek.

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

30 July 2026
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily

Read This Before You Buy That TV Streaming Stick

30 July 2026
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

Timeless Compliance: Why Better Questions Beat Bigger Frameworks

30 July 2026
The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. The post Timeless Compliance: Why Better Questions Beat Bigger Frameworks appeared first on SecurityWeek.

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

30 July 2026
A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway,

DataBahn Raises $40 Million for Agentic Data Pipeline Management

30 July 2026
The company will accelerate investments in R&D and product innovation to expand its agentic data control plane. The post DataBahn Raises $40 Million for Agentic Data Pipeline Management appeared first on SecurityWeek.

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

30 July 2026
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a

Discern Security Raises $13 Million in Series A Funding

30 July 2026
The company will invest in accelerating the development and adoption of its agentic platform. The post Discern Security Raises $13 Million in Series A Funding appeared first on SecurityWeek.

Cantina Emerges From Stealth With $8 Million in Funding

30 July 2026
The startup’s community-powered agentic security platform helps proactively identify, prioritize, and remediate vulnerabilities. The post Cantina Emerges From Stealth With $8 Million in Funding appeared first on SecurityWeek.

Onyx Security Raises $113 Million to Control AI Agents in the Enterprise

30 July 2026
The Series B funding round brings the total raised by Onyx Security to $153 million.  The post Onyx Security Raises $113 Million to Control AI Agents in the Enterprise appeared first on SecurityWeek.