CYBERSECURITYTRACKER
TRACKING3,629 stories659 vuln stories
The watch floor

Everything moving in security, ranked by what matters now.

One feed of clustered, de-duplicated stories across 43 sources, tagged by category, vendor, and threat actor. Filter to your role, pin your stack, subscribe or point your reader at a feed. No account required.

Presets
Loading feed…
threat intelResearch

Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

On August 4, 2026, Elastic Security Labs discovered a campaign targeting the keyv npm package maintainer, with attackers embedding a self-propagating worm called CHAINDROP that uses stolen npm credentials to backdoor over 400 additional packages. The worm executes via preinstall hooks and additional trigger points in development environments, downloading and running obfuscated malware that harvests credentials from developer machines, AI tools, cloud providers, and code repositories. The compromise affects packages with hundreds of millions of monthly downloads, creating significant downstream exposure across the npm ecosystem.

Why it matters: Developers and organizations relying on affected npm packages face immediate risk of credential theft and supply-chain compromise; security teams must audit dependencies for the malware indicators (Math_Symbol.js, math_init.js filenames and commits authored by 'claude') and rotate all potentially exposed credentials, particularly npm tokens, cloud provider keys, and AI service credentials.

government policy

Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says

A House committee report found that three major Chinese telecommunications companies maintain operational presence within the U.S. internet infrastructure despite their alleged involvement in prior Chinese cyber operations. The committee's findings highlight ongoing concerns about foreign telecommunications entities' access to critical U.S. systems.

Why it matters: Organizations and security teams managing U.S. infrastructure face potential exposure through compromised telecommunications providers; policymakers and practitioners should monitor restrictions on foreign telecom access.

government policy

DHS Wants Protesters’ Signal Group Chats

The Department of Homeland Security is attempting to gain access to encrypted Signal group chats belonging to protesters by leveraging a lawsuit filed against the agency that accuses DHS of violating free speech rights. The agency's legal maneuver seeks to obtain the protesters' private communications as part of the litigation.

Why it matters: Protest organizers and civil liberties advocates should be aware that litigation against government agencies may be used as a legal avenue to compel disclosure of encrypted communications, creating potential risks for activist groups using secure messaging platforms.

breaches incidents

Canadian man pleads guilty to Snowflake hacks that led to 165 breaches

A 26-year-old Ontario resident pleaded guilty to fraud, identity theft, and conspiracy charges stemming from 2024 attacks on Snowflake that compromised 165 organizations. The defendant faces up to 32 years in prison for the coordinated campaign targeting the cloud data platform.

Why it matters: Organizations using Snowflake should review whether they were affected in the campaign and verify account security controls, as this case confirms the severity of the breach and closure of one attack vector.

vulnerabilities

Hackers run khunt post-exploitation toolkit from Oracle database

Attackers exploited a SQL injection vulnerability in an Oracle database to deploy a post-exploitation toolkit directly within the compromised database. This technique allowed them to establish persistence and conduct follow-on attacks within the breached corporate network.

Why it matters: Organizations running Oracle databases are at risk; practitioners should audit SQL injection defenses, database access logs, and implement database activity monitoring to detect suspicious toolkit deployments.

vulnerabilities

CSS: The Hidden Threat Lurking in Your Inbox

Researchers have identified that Cascading Style Sheets (CSS) can be exploited to exfiltrate data from webmail clients, presenting a security risk that some email vendors have not adequately addressed. The discovery highlights an unexpected attack vector using a technology traditionally associated with web design.

Why it matters: Email users and organizations managing webmail infrastructure should understand this CSS-based exfiltration risk and verify that their vendors have implemented mitigations, as this attack could expose sensitive messages and credentials.

ai security

The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop

Security researcher James Kettle investigated the effectiveness of AI in hacking scenarios and found that AI tools are most dangerous when combined with human expertise and oversight. The research highlights how human decision-making and judgment remain critical components in sophisticated attack chains.

Why it matters: Security teams should understand that AI-assisted attacks are particularly effective when humans guide the process, meaning defenders cannot rely on AI's limitations alone and must account for hybrid human-AI threats in their threat models.

vulnerabilities

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

Researchers demonstrated an exploit chain targeting Samsung Members and Samsung Account applications that could weaponize the Bixby voice assistant. The attack was valued at $50,000, suggesting significant technical complexity in chaining multiple vulnerabilities together to achieve unauthorized control.

Why it matters: Samsung phone users face potential unauthorized voice assistant access and account compromise through patched or unpatched vulnerabilities in core Samsung applications; practitioners should track Samsung security updates for these specific apps.

government policy

Tom Cotton prods Treasury for tax code tweaks to modernize OT

Senator Tom Cotton has requested that the Treasury Department consider modifications to the tax code to support modernization of operational technology (OT) systems. The article does not provide specific details about which tax provisions he is targeting or the mechanisms he proposes.

Why it matters: Organizations managing OT infrastructure should monitor legislative efforts that could affect the cost or feasibility of upgrading legacy systems, as tax incentives may influence investment timelines and budgets for critical infrastructure security.

vulnerabilities

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

Researchers highlighted security risks in automated network device provisioning by examining vulnerabilities in a major device manufacturer's systems. The analysis reveals that provisioning workflows may contain exploitable gaps that could undermine network security practices.

Why it matters: Network administrators and zero-trust practitioners should evaluate their TP-Link device provisioning processes for similar weaknesses, as compromised provisioning can allow attackers to bypass intended security controls during device setup.

vulnerabilities

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

Security researchers discovered a pre-authentication remote code execution vulnerability in Bonita BPM and OFBiz that allows unauthenticated attackers to reach internal APIs and execute code on affected servers. Bonita is widely deployed in financial services, insurance, and government agencies for workflow automation. The vulnerability was presented at Black Hat USA 2026 by researchers at Novee.

Why it matters: Organizations running Bonita or OFBiz in production face immediate risk of complete compromise without authentication or network access controls, and should assess exposure and apply patches urgently.

ai security

Flaws in Google APK for Python Unlock Agent-to-Agent Attack

Google patched flaws in its APK (Application Performance Kit) for Python that enabled agent-to-agent attacks by exploiting trust boundaries between AI agents with different privilege levels. These issues could have been leveraged to compromise supply chain integrity through unauthorized automation.

Why it matters: Python developers and organizations using Google APK for automated workflows need to apply the patch immediately to prevent privilege escalation attacks between integrated agents.

threat intel

AI Sends Global Crime Syndicates Into Fraud Nirvana

Organized crime groups are leveraging generative AI technologies, including voice cloning, deepfake video overlays, and large language models, to conduct fraud and scams at scale. These capabilities enable criminals to automate social engineering, manage fake personas across languages and regions, and generate revenue in the billions of dollars.

Why it matters: Enterprise security teams, fraud investigators, and customer-facing organizations need to implement AI-aware detection and verification methods today, as this threat directly enables account takeovers, wire fraud, and credential compromise at accelerating velocity.

threat intel

Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm

On August 4, 2026, attackers compromised the widely-used keyv and cacheable npm packages and published trojanized versions that execute a credential-stealing worm on install. The malware harvests cloud keys, GitHub tokens, and npm credentials, then uses stolen tokens to automatically inject itself into hundreds of other packages. The payload installs a persistence mechanism that monitors the GitHub token and triggers an attacker-controlled command if the token is revoked, making standard remediation steps potentially dangerous.

Why it matters: Development teams and security responders need to avoid revoking tokens immediately when discovering this compromise, as the dead-man's switch will execute unknown attacker code upon revocation; additionally, repositories checked out for investigation or opened by AI agents can trigger the malware without npm install, expanding the blast radius beyond typical build environments.

threat intel

COLDCARD security audit phishing attack installs remote access tool

A phishing campaign leverages concerns about a recently disclosed COLDCARD wallet vulnerability and a suspected $88.6 million Bitcoin theft to distribute ScreenConnect remote access software to victims. Attackers are using fear and urgency around the vulnerability disclosure to increase click-through and installation rates.

Why it matters: COLDCARD users and other cryptocurrency holders are targeted by this campaign, which aims to establish remote access that could lead to theft of digital assets or credentials; practitioners managing cryptocurrency infrastructure or user awareness should monitor for phishing referencing this vulnerability.

government policy

DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad

The Department of Homeland Security is hiring private investigators to locate and photograph homes of deported individuals abroad, apparently to support debt collection efforts related to fines DHS claims immigrants owe. The agency had previously told departing immigrants that leaving the US would eliminate these financial obligations, creating a discrepancy in its positions on the matter.

Why it matters: Immigration practitioners and deported individuals need to understand that DHS may pursue overseas collection efforts despite prior statements about debt forgiveness, and the hiring of private investigators suggests an escalation in enforcement tactics that could affect privacy and safety.

vulnerabilities

PSA: Apple’s Private Relay can leak your real IP address

Apple's Private Relay feature, designed to mask user IP addresses from websites, contains a bug that can leak users' real IP addresses. The implementation flaw undermines the privacy protection that users expect from this service.

Why it matters: Apple users relying on Private Relay for IP address masking need to understand the current vulnerability affects their browsing privacy; practitioners should assess whether client systems are affected and consider workarounds until Apple patches the issue.

cloud saas

​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

Microsoft has been named a Leader by KuppingerCole across all categories in the Cloud Native Application Protection Platforms (CNAPP) Leadership Compass report, with its Defender for Cloud platform recognized for unifying cloud, data, identity, and AI security. The report reflects the evolution of CNAPP from a consolidation of disparate cloud security tools into a comprehensive foundation for securing AI-native enterprises across multicloud and hybrid environments. Modern CNAPP platforms now prioritize runtime-driven risk detection and attack path analysis to identify genuinely exploitable exposures rather than merely surfacing all potential vulnerabilities.

Why it matters: Cloud and AI security leaders should evaluate whether their current tooling addresses the shift from posture-only visibility to operational risk prioritization across cloud infrastructure, applications, identities, data, and AI workloads in a single platform.

breaches incidents

Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery

Meta's advertising systems hosted more than 50 advertisements containing artificially generated child sexual abuse imagery (CSAM) across its platforms including Facebook, Instagram, Messenger, and Threads. The offending ads were identified through Meta's own ad library, with some having appeared as recently as the current week.

Why it matters: Platform operators and compliance teams must address the technical and moderation gaps that permitted synthetic CSAM to pass advertising filters, as regulators and law enforcement increasingly scrutinize child safety controls.

vulnerabilities

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

The Cybersecurity and Infrastructure Security Agency (CISA) issued a directive requiring federal agencies to remediate three actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days. The flaws are being leveraged by threat actors in ongoing attacks. CISA's Known Exploited Vulnerabilities catalog tracks the issue.

Why it matters: Federal agencies and contractors must patch these three flaws immediately; attackers are exploiting them now, making delay a direct operational risk.

Looking further back? Browse the daily archive, this feed's own history.