<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Cyber Digest</title>
  <link>https://cyber.peterjaycox.com/</link>
  <description>A curated, sector-by-sector roundup of global cybersecurity developments with source-reliability indexing and Australian &amp; New Zealand context.</description>
  <language>en-au</language>
  <atom:link href="https://cyber.peterjaycox.com/feed.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Sat, 29 Aug 2026 03:40:07 GMT</lastBuildDate>
<item>
  <title>Cyber Digest — 2026-08-29 · Suspected Chinese-Speaking Operator Exploits Known Flaws to Steal Nuclear and Naval Data From Philippine Targets</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-29.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-29.html</guid>
  <pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-29 — 9 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Suspected Chinese-Speaking Operator Exploits Known Flaws to Steal Nuclear and Naval Data From Philippine Targets&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://hunt.io/blog/chinese-speaking-operator-philippine-nuclear-naval-contractor&quot;&gt;Hunt.io&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;APT28-Linked BlueDelta Targets European Government and Diplomatic Organisations With HOOKEDGE Backdoor&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.recordedfuture.com/research/bluedelta-targets-with-hookedge&quot;&gt;Recorded Future (Insikt Group)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;American Vision Partners Settles 2023 Data Breach Litigation for $1.75 Million&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/class-action-lawsuits-filed-against-american-vision-partners-over-data-breach/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;PaperCut Releases Second Emergency Patch as Exploited Flaws Get CVEs and Chain to Unauthenticated RCE&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/papercut-releases-second-emergency-patch-for-exploited-flaws/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Toy-Making Giant Hasbro Discloses Data Breach Affecting Employee Personal and Financial Information&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Nearly 700 Rogue AI Agents Coordinated the Hugging Face Breach, METR and OpenAI Detail&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/nearly-700-rogue-ai-agents-coordinated-in-the-hugging-face-attack/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and Run SQL&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Socket Identifies 19 Chrome and Edge Extensions Delivering Wallet-Draining and Credential-Stealing Code&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://socket.dev/blog/chrome-edge-extension-wallet-drainer&quot;&gt;Socket&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Boston Scientific Cyberattack Disrupts Global Ordering and Shipping&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.supplychaindive.com/news/boston-scientifics-ordering-shipping-disrupted-in-cyberattack/828933/&quot;&gt;Supply Chain Dive&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-28 · CISA Adds Three Known Exploited Vulnerabilities to the KEV Catalog</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-28.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-28.html</guid>
  <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-28 — 10 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;CISA Adds Three Known Exploited Vulnerabilities to the KEV Catalog&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/08/27/cisa-adds-three-known-exploited-vulnerabilities-catalog&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;PaperCut Warns of NG, MF Flaw Actively Exploited in Zero-Day Attacks&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/&quot;&gt;PaperCut Security Advisory&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Carhartt Breach: ShinyHunters Releases Data of 12.9 Million Accounts&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Manchester Airports Group Says Cyberattack Exposed Data of ~8.7 Million Travellers&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/cyberattack-on-manchester-airports-group-exposes-millions-customer-info&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;White House Bans Foreign-Made Bulk-Power Equipment Over Cyber Backdoor Fears&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/trump-cyber-electricity-parts&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;ATF Confirms &amp;quot;Major Incident&amp;quot; After Qilin Breach Claims&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/atf-confirms-major-incident-after-recent-qilin-breach-claims/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Australia Charges Two Men as TeamPCP&amp;#x27;s &amp;quot;Principal Participants&amp;quot; After Supply-Chain Spree Compromised 1,000+ Organisations&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/australia-teampcp-hackers-arrested&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;OpenAI: &amp;quot;Reward Hacking&amp;quot; Drove AI Agents to Explore Zero-Days and Breach HuggingFace&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/openai-says-reward-hacking-drove-ai.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Chinese Routers Sold Worldwide Found to Contain Backdoors&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.darkreading.com/vulnerabilities-threats/chinese-routers-sold-worldwide-backdoors&quot;&gt;Dark Reading&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Sydney Telco Employee Charged Over Selling Customer Data to Criminal Groups&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.itnews.com.au/news/sydney-based-telco-employee-accused-of-selling-customer-data-628502&quot;&gt;iTnews&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-27 · CISA Adds Six Known Exploited Vulnerabilities to the KEV Catalog</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-27.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-27.html</guid>
  <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-27 — 11 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;CISA Adds Six Known Exploited Vulnerabilities to the KEV Catalog&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;OpenAI Bans Russian ChatGPT Accounts Behind a Covert Influence Operation&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://openai.com/index/disrupting-malicious-uses-of-ai-influence-campaign-russia/&quot;&gt;OpenAI&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;FBI and DOJ Take Down QScan and QTRouter, the Chinese Espionage Proxy Network Behind QTFY&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/qscan-qtrouter-us-takedown-alleged-china-hacking-tools&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Iran-Linked Tortoiseshell Expands Infrastructure Across Europe and the Middle East&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/iran-linked-hackers-expand-infrastructure-europe-middle-east&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Medical-Device Maker Boston Scientific Says Cyberattack Disrupted Operations Globally&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/boston-scientific-says-cyberattack-disrupted-operations-globally/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;ShinyHunters Leaks 7.1 Million Records Claimed from Medical-Device Maker Baxter International&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/shinyhunters-baxter-international-data-breach/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Attackers Chain Microsoft SharePoint RCE Flaws (CVE-2026-55040 + CVE-2026-63520) in Live Attacks&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in West African Cybercrime Crackdown&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.darkreading.com/threat-intelligence/interpols-jackal-iv-west-african-crime-infrastructure&quot;&gt;Dark Reading&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;GTA VI Pre-Release Leaks Prompt Take-Two Subpoenas in High-Profile Data-Extortion Case&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/grand-theft-auto-6-data-theft-extortion-leaks/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;LACMA Data Breach Exposed Social Security and Medical Data&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/lacma-data-breach-last-year-exposed-social-security-and-medical-data/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;First Documented Android Malware Hits Car Head Units, Spreads via Legitimate Updaters&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/android-malware-hijacks-update-system-car-head-units&quot;&gt;Dark Reading&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-26 · CISA Red Team Report: Water Utility Detected Simulated Attack in Minutes, Government Organisation Missed Domain-Wide Compromise</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-26.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-26.html</guid>
  <pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-26 — 9 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;CISA Red Team Report: Water Utility Detected Simulated Attack in Minutes, Government Organisation Missed Domain-Wide Compromise&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Adds Actively Exploited Gitea Code-Injection Flaw (CVE-2026-60004) to KEV Catalog&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/08/25/cisa-adds-one-known-exploited-vulnerability-catalog&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;US Treasury Sanctions Four Alleged MOIS-Directed Iranian Hackers Behind Critical Infrastructure Breaches&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/us-treasury-sanctions-iranian-hackers-economic-dday/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;AnonyMousKIT PhaaS Platform Uses Voice AI Agents to Phish iPhone Passcodes at Scale&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Massive DDoS Disrupts Norway&amp;#x27;s Shared Government Digital Infrastructure for a Second Day&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/massive-ddos-attack-disrupts-norways-government-digital-services/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;UK Seeks Powers to Secretly Block Risky Tech Suppliers Across Critical Sectors&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/uk-technology-national-security&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Akira Ransomware Breach at Benefits Platform Paylogix Exposed SSNs, Health and Financial Data on Tens of Thousands&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/paylogix-cyberattack-akira-ransomware&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hospital Operator Nutex Health Tells SEC Data Was Exfiltrated in Cyberattack Across Its 28-Facility Network&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hospital-operator-nutex-health-says-data-stolen-in-cyberattack/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Tift Regional Health System Pays $1.2 Million to Settle Class Action Over 2022 Hive Ransomware Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/tift-regional-health-system-pays-1-2-million-data-breach-settlement/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-25 · ASD&#x27;s ACSC Alerts on Active Exploitation of TeamCity On-Premises Servers Within Australia</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-25.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-25.html</guid>
  <pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-25 — 6 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;ASD&amp;#x27;s ACSC Alerts on Active Exploitation of TeamCity On-Premises Servers Within Australia&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/active-exploitation-of-a-software-development-platform-within-australia&quot;&gt;ASD&amp;#x27;s ACSC&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Adds Actively Exploited Oracle HTTP Server Flaw (CVE-2026-21962) to KEV Catalog&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/08/24/cisa-adds-one-known-exploited-vulnerability-catalog&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;South Korean Government Startup Platform Leaked ~5,000 Applicants After Exposing Encryption Key via API&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/south-korean-startup-platform-breach-exposes-key-management-failures/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Critical Keycloak Password-Reset Flaw (CVE-2026-18963) Lets Unauthenticated Attackers Take Over Any Account&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;ReliaQuest Confirms Failed ShinyHunters Data-Theft Attack After Vishing Campaign Turned on the Defender&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Weedhack Malware Spreads Via Fake Minecraft Clients, With One Lookalike Site Built Using Lovable AI&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-24 · Microsoft Defender&#x27;s Own Signed BTR.sys Driver Weaponised for Kernel-Level Attacks</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-24.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-24.html</guid>
  <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-24 — 6 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Microsoft Defender&amp;#x27;s Own Signed BTR.sys Driver Weaponised for Kernel-Level Attacks&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive/&quot;&gt;Check Point Research&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;14 Trojanised npm Packages Deliver RedC2 4.0 Linux Backdoor With AI-Assisted C2&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Leaked Source Code Formally Links Geedge Networks Gateway to China&amp;#x27;s Great Firewall&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://risky.biz/risky-bulletin-academics-find-source-code-overlaps-between-geedge-and-chinas-great-firewall/&quot;&gt;Risky Biz News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Lawmakers Call for Investigation into Impact of CISA Staffing Cuts&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/lawmakers-call-for-investigation-into-impact-of-cisa-cuts&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Senators Press TikTok Over Internal Experiment Withholding Safety Features&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/senators-press-tiktok-over-withholding-safety-features&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;ToxicPanda 2.0 Abuses VPN Permissions to Blind Google Play During Installation&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-23 · First Malware Family Built for Car Head Units Spreads Via Firmware Updaters</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-23.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-23.html</guid>
  <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-23 — 6 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;First Malware Family Built for Car Head Units Spreads Via Firmware Updaters&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://securelist.com/android-head-unit-malware/121106/&quot;&gt;Kaspersky Securelist&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;TikTok Agrees to $400 Million Settlement in US Child Privacy Lawsuit&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/tiktok-agrees-to-400-million-settlement.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/cisco-patches-nine-crosswork-and-secure.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New SynkLoader Malware Delivered Via Fake IT Help Desk in Teams Phishing Campaigns&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;9,300 Leaked AWS Access Keys Still Active, Hundreds Grant Full Corporate Account Control&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/&quot;&gt;BleepingComputer&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Wormable Exploit Chain Jumps From Tesla Wall Connector to Other EV Charger Brands&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.itnews.com.au/news/researchers-chain-tesla-charger-bug-into-a-four-vendor-ev-worm-628346&quot;&gt;iTnews&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-22 · CISA Issues Foundational Logging, Visibility and Operational Guidance for Federal Agencies</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-22.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-22.html</guid>
  <pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-22 — 14 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;CISA Issues Foundational Logging, Visibility and Operational Guidance for Federal Agencies&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/news/cisa-releases-foundational-flexible-guidance-help-federal-agencies-implement-effective-logging&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;U.S. Bank Says Breach Claims Tied to Fourth-Party Incident, Denies Own Systems Hit&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/us-bank-says-breach-claims-related-to-fourth-party-incident&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Apollo Global Discloses Breach From BlackFile Wave Hitting Financial Sector&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Canada&amp;#x27;s Hospital for Sick Children Hit Again, Employee Data Stolen&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/canada-hospital-for-sick-children-attacked-again-employee-data&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;DAP Health Settles Data Breach Lawsuit for $1.3 Million&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/dap-health-data-breach-settlement/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Bitdefender: China&amp;#x27;s &amp;#x27;SilkParasite&amp;#x27; Espionage Operation Targets Central Asia With AI-Assisted Malware&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/china-cyber-espionage-central-asia&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Lawmakers Seek Watchdog Review of Federal Hacking of Americans&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/watchdog-review-federal-government-hacking-americans/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Delta Flight Disrupted by In-Flight Wi-Fi Spoofing and Phishing Page&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.darkreading.com/cyber-risk/delta-flight-disrupted-wi-fi-hack&quot;&gt;Dark Reading&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Rust Registry Supply Chain Attack Plants Build-Time Malware in Crates With 245 Million Downloads&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/rust-supply-chain-attack-puts-build.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Suspected Russian Espionage Clusters Abuse Google OAuth and WhatsApp Linking to Hijack Accounts&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Pro-Ukraine Hackers Claim Breach of Russian Network-Monitoring Firm Microolap&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/russian-network-monitoring-firm-confirms-cyberattack-claimed-by-pro-ukraine-group&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Turner Construction Discloses Breach of Salaries, Bank Accounts and SSNs&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.constructiondive.com/news/turner-construction-data-breach-ssns-bank-accounts/828454/&quot;&gt;Construction Dive&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Origin Energy Restricts Staff Access as It Finalises Review of 900,000-Customer Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.afr.com/technology/origin-restricts-staff-access-after-data-breach-as-it-finalises-review-20260821-p60qda&quot;&gt;Australian Financial Review&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-21 · ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-21.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-21.html</guid>
  <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-21 — 13 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://zimperium.com/blog/the-toxicpanda-never-sleeps-toxicpanda-2.0-prepares-its-next-strike-on-mobile&quot;&gt;Zimperium&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Adds Two TrueConf Server CVEs to Known Exploited Vulnerabilities (CVE-2026-72529/72530)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/08/20/cisa-adds-two-known-exploited-vulnerabilities-catalog&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Advisory: Johnson Controls Simplex Incident Manager Credential Leak&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-26-232-01&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;&amp;quot;Zombie Card&amp;quot; Attack Can Revive Expired Visa Cards for Contactless Payments&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/nasa-ait-gui-flaws-could-let.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Non-profit Urges Designation of AI as Critical Infrastructure&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/ai-critical-infrastructure-designation-cisa-report/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Slovakia&amp;#x27;s Speed Cameras Found With Russian Backdoor&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://risky.biz/risky-bulletin-slovakia-finds-russian-backdoor-in-traffic-speed-cameras/&quot;&gt;Risky.Biz&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cryptographic Context Injection vs Grok — Data Exfiltration Via Encrypted Instructions&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-malicious-instructions-are-encrypted/&quot;&gt;Ars Technica&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Citrix NetScaler: Critical Auth Bypass in Customer-Managed Gateways (CVE-2026-19490)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Talos: Chinese-Speaking UAT-10147 Actor Wires Agentic AI into Post-Compromise Operations&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/&quot;&gt;Talos Intelligence&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;40 Malicious Firefox Extensions Masquerade as Web3 Wallets&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cybersecurity Threat Delays Start of Semester at UT San Antonio&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.insidehighered.com/news/tech-innovation/administrative-tech/2026/08/20/cyber-threat-delays-start-classes-ut-san&quot;&gt;Inside Higher Ed&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-20 · CISA Adds MLflow SSRF Vulnerability to Known Exploited Vulnerabilities Catalog</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-20.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-20.html</guid>
  <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-20 — 9 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;CISA Adds MLflow SSRF Vulnerability to Known Exploited Vulnerabilities Catalog&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/08/19/cisa-adds-one-known-exploited-vulnerability-catalog&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Healthcare Tech Firm CareCloud Says 3.7M People Affected by March EHR Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/electronic-health-record-company-carecloud-data-breach&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Patient &amp;amp; Employee Data Exposed in Baylor Genetics Cybersecurity Incident&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/baylor-genetics-data-breach/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;NSA, FBI, CISA Issue &amp;#x27;Active Threat&amp;#x27; Advisory on AI-Assisted Attacks on Siemens S7 PLCs&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/nsa-fbi-warns-of-hackers-using-ai-generated-tools-critical-infrastructure&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Latvian Officials Resign After Cyberattack Exposes Data on 1.2 Million People&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/latvia-cyberattack-vehicle-data&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;US Charges 17 Iranians Over Decade-Long Academic Hacking Campaign on Universities, Government&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/mabna-institute-iranian-hackers-indictment/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/silkparasite-espionage-campaign-targets.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Microsoft Ties 30+ Rotating Domains to MacSync Stealer Infrastructure&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/microsoft-links-30-rotating-domains-to.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks and P2P&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/hackers-compromised-14500-dahua-devices.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-19 · ACSC Issues High-Rated Alert on Active Exploitation of N-able Slopes — Australia Priority</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-19.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-19.html</guid>
  <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-19 — 11 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;ACSC Issues High-Rated Alert on Active Exploitation of N-able Slopes — Australia Priority&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories&quot;&gt;ACSC&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Adds Four Known Exploited Vulnerabilities to Catalog&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Berlin Cuts Two State Ministries Off Government Network After Security Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/berlin-cuts-two-state-ministries-off-government-breach&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Microsoft Copilot Personal Flaws Let One Click Exfiltrate Data From Connected Apps — CoSnitch&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Critical GitLab GraphQL Flaw Lets Unauthenticated Attackers Delete Public Projects&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/one-attacker-has-scraped-both.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Medusa Ransomware Tallying Hundreds of New Victims; CISA Updates Tactics&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/medusa-ransomware-tactics-cisa-advisory/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;American Addiction Centers &amp;amp; Octopus Pathology Disclose Hacking Incidents&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/american-addiction-centers-oculus-pathology-disclose-hacking-incidents/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;ASIC Warns of Deepfake Scam Surge Against Australian Consumers&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.finextra.com/newsarticle/48254/asic-warns-of-surge-in-deepfake-scams?utm_medium=rssfinextra&amp;amp;utm_source=finextrafeed&quot;&gt;Finextra&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;ANZ Warns of Troubling &amp;#x27;Scam-Coaching&amp;#x27; Trend&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.finextra.com/newsarticle/48261/would-i-lie-to-you-anz-warns-of-troubling-scam-coaching-trend?utm_medium=rssfinextra&amp;amp;utm_source=finextrafeed&quot;&gt;Finextra&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Six Arrested as UK Police Target Cargo Theft Costing £70m+ a Year&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.freightwaves.com/news/6-arrested-as-uk-police-target-cargo-theft-costing-88m-a-year&quot;&gt;FreightWaves&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-18 · SafePal Crypto Hardware Wallet Maker Confirms Breach Affecting Nearly 40,000 Customers</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-18.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-18.html</guid>
  <pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-18 — 8 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;SafePal Crypto Hardware Wallet Maker Confirms Breach Affecting Nearly 40,000 Customers&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.safepal.com/en/blog/security-update&quot;&gt;SafePal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Adds Ray-Project Ray Code Injection Flaw to Known Exploited Vulnerabilities&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Poland Probes MyDr Healthcare Software Breach Potentially Affecting 19 Million People&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/poland-probes-mydr-healthcare-software-breach&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Beverly Hills Plastic Surgeon Confirms Data Theft/Extortion Incident&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/data-theft-extortion-incident-beverly-hills-plastic-surgeon/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Vishing Attack Gives Threat Actor Access to Quantum Health Network&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/quantum-health-precision-imaging-centers-heart-america-data-breaches/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Nearly 750,000 Had Financial Info, SSNs Leaked in South Carolina Loan Company Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/financial-info-leak-debt-consolidator&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Ukraine Says Cyberattack Hit Russian E-Commerce Giant Wildberries Amid Drone Strikes&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/russia-wildberries-cyberattack-ukraine&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;EU Publishes Draft Cyber Resilience Act Standards for Product Vendors&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://risky.biz/risky-bulletin-the-eu-publishes-its-upcoming-cybersecurity-standards/&quot;&gt;Risky.Biz&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-17 · ACSC: When AI Agents Take Unexpected Actions</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-17.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-17.html</guid>
  <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-17 — 3 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;ACSC: When AI Agents Take Unexpected Actions&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cyber.gov.au/about-us/view-all-content/news/when-ai-agents-take-unexpected-actions&quot;&gt;ACSC&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;DecryptAds: New Free Service Reveals Who&amp;#x27;s Tracking You — and Ad Networks in Adversarial Nations&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/&quot;&gt;KrebsOnSecurity&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;FBI Seeks Truck Drivers Nationwide Who May Be Victims in 54-Count Tax Fraud Case&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.freightwaves.com/news/fbi-seeks-truck-drivers-nationwide-who-may-be-victims-in-54-count-tax-fraud-case&quot;&gt;FreightWaves&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-16 · Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-16.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-16.html</guid>
  <pubDate>Sun, 16 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-16 — 6 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html&quot;&gt;Infoblox&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Critical SAP Commerce Cloud Vulnerability Targeted in Active Exploitation Attempts Days After Patch&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New Evooo1Bot Mirai Variant Adds Stealth Capabilities to Notorious Botnet Code&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Pentagon Hands Palantir Up to $244M in No-bid Work&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.defenseone.com/business/2026/08/pentagon-palantir-no-bid/415400/&quot;&gt;Defense One&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Tech Contractor for Brightly Software Sentenced to 2 Years in Prison for Insider Attack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/cameron-curry-insider-attack-brightly-software-sentenced/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Investigation of German Banking Hack Leads to Arrests in Germany, Brazil&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/investigation-into-banking-hack-leads-to-arrests-germany-brazil&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-15 · Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-15.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-15.html</guid>
  <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-15 — 11 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/&quot;&gt;Ars Technica&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/ctm360-uncovers-over-3000-recruitment.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;France Investigates Tax Authority Breach After Hacker Claims 600,000 Victims&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/french-tax-authority-dgfip-confirms-data-breach&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/apple-warns-users-in-110-countries-they.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Flock Tightens Privacy Controls Amid Scandals Over Officer Abuse&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/flock-safety-audit-assistance-police-departments&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Boston Healthcare for the Homeless Program Breach Affects at Least 185K State Residents&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/boston-healthcare-homepless-program-mon-general-open-door-illinois-data-breaches/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Texas Hearing Institute Ransomware Attack Affects 30,000 Patients&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/texas-hearing-institute-sportsmed-family-partnerships-florida-data-breaches/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Aesto Health Data Security Incident Affects Multiple Healthcare Provider Clients&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/aesto-health-data-breach/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;ZOLL Medical Pays $3.5 Million to Settle Data Breach Lawsuit&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/zoll-medical-data-breach-settlement/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;WindRelay Android Malware Turns Victims&amp;#x27; Phones Into NFC Relays for Payment Fraud&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-14 · CISA Adds Metabase SQL-Injection Flaw (CVE-2026-72898) to Known Exploited Vulnerabilities</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-14.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-14.html</guid>
  <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-14 — 9 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;CISA Adds Metabase SQL-Injection Flaw (CVE-2026-72898) to Known Exploited Vulnerabilities&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/known-exploited-vulnerabilities-catalog&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Issues Multiple Siemens and Johnson Controls ICS Advisories&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-06&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Attackers Exploit SharePoint Authentication Bypass After Public PoC Release&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New Mirai Variant Adds Stealth Capabilities to Notorious Botnet Code&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;AI&amp;#x27;s &amp;#x27;Middle Class&amp;#x27; Has Gotten Dramatically Better at Hacking&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/mid-tier-ai-models-hacking-threat/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Trump Signs Memo Authorising Private-Sector Offensive Operations Against Foreign Criminals&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/trump-memo-private-sector-offensive-hacking/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Germany Moves to Give Spy Agencies Hacking and Sabotage Powers&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/germany-spy-agency-powers&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Five HIPAA-Regulated Entities Announce Data Breaches; Two Settlements Reached&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/data-breaches-five-hipaa-regulated-entities/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Uber Freight Confirms Cyber Incident After Hackers Claim Nearly 1 Million Files&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.freightwaves.com/news/uber-freight-confirms-cyber-incident-after-hackers-claim-nearly-1-million-files&quot;&gt;FreightWaves&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-13 · CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-13.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-13.html</guid>
  <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-13 — 14 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/news/cisa-unveils-new-cybersecurity-resources-k-12-schools-and-districts&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;First &amp;#x27;Near-Autonomous&amp;#x27; AI Attack Documented on Taiwanese Government Target&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/near-autonomous-ai-attack-government-target-taiwan/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;737 Chrome VPN Extensions Caught Routing Traffic Through Single Proxy Infrastructure&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organisations&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html&quot;&gt;Ars Technica&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Zoom Screen-Share Hijack Flaws Found by AI Tool in Under 20 Prompts&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://arstechnica.com/security/2026/08/researchers-found-a-way-to-hijack-devices-through-zoom-screen-sharing/&quot;&gt;Ars Technica&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;OpenAI, Anthropic, Google API Flaw Lets Weaker Models Decode Stronger Models&amp;#x27; Reasoning&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Long-Running Data Theft Campaign Targeting Salesforce and ServiceNow&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenow&quot;&gt;Dark Reading&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;UK Criminal Records Office Reprimanded After Three Undetected Intrusions Over Two Years&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/uk-criminal-records-office-acro-data-breaches&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.darkreading.com/cyberattacks-data-breaches/ransomware-hits-colombian-justice-ministry-presidential-transition&quot;&gt;Dark Reading&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;FBI Warns of Social-Engineering Attacks to Steal Accounts and Explicit Content&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/social-engineering-hackers-explicit-photos-fbi-alert&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/strict-rules-change-healthcare-data-use-multidistrict-litigation/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Critical Vulnerabilities Identified in Popular Consumer Fertility and Wellness Devices&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/vulnerabilities-mira-hormone-monitor-pulsetto-vagus-nerve-stimulator/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Data Breaches Announced by Five Small Healthcare Organisations&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/data-breaches-five-small-healthcare-organizations/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-12 · CISA Adds Three Known Exploited Vulnerabilities to Catalog</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-12.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-12.html</guid>
  <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-12 — 12 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;CISA Adds Three Known Exploited Vulnerabilities to Catalog&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html&quot;&gt;Unit 42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/openai-launches-gpt-56-cyber-with.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Local Governments in Four States Dealing with Cyberattacks That Have Shut Down Services&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/cyberattacks-ransomware-local-governments&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;NIST Wants to Overhaul Its Vulnerability Database for the AI Age&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/nist-national-vulnerability-database-ai-overhaul/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Data Breaches Reported by Sunshine Health; Health Payment Systems&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/data-breaches-sunshine-health-health-payment-systems/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Ransomware Group Hijacks Hospital System&amp;#x27;s Facebook Page Amid Ongoing Cyberattack Fallout&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/ransomware-group-hijacks-hospital-facebook-amid-cyberattack-response&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cyberattack on Logistics Giant Ceva Hits Retailers and Steam Customers Across Europe&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/ceva-logistics-cyberattack-bol-steam-debijenkorf-ace-tate&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Delta Investigates In-Flight Wi-Fi Spoofing on Post-DEF CON Flight from Las Vegas&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/delta-flight-rogue-wifi-investigation-def-con-las-vegas/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-11 · FBI, CISA and International Partners Warn of Gunra Ransomware Targeting Critical Infrastructure</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-11.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-11.html</guid>
  <pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-11 — 8 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;FBI, CISA and International Partners Warn of Gunra Ransomware Targeting Critical Infrastructure&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New Zealand Sanctions Russian Hackers, Propaganda Groups Over Ukraine War&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/new-zealand-russian-hackers-sanctions&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Senate Democrats Introduce Bill Distributing $300 Million Annually for Water System Cybersecurity&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/senate-water-cybersecurity-legislation&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Poland Uncovers Second Heat Plant Cyberattack That Went Hidden for Months&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/poland-uncovers-critical-infrastructure-attack-hidden&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Data Breaches Announced by Loma Linda University Health &amp;amp; UCLA Health&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/data-breaches-loma-linda-university-health-ucla-health/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-10 · N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-10.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-10.html</guid>
  <pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-10 — 3 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;More Than Half of AI-Generated Security Patches Are Broken, Study Finds&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://cyberscoop.com/ai-code-patching-security-risks/&quot;&gt;CyberScoop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Levi Strauss Says Hackers Breached Employee Computers, Accessed Corporate Data&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/levis-data-breach-social-engineering&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-09 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication (CVSS 10.0)</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-09.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-09.html</guid>
  <pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-09 — 11 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication (CVSS 10.0)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Atlassian Rovo AI Assistant Can Be Tricked Into Exfiltrating Jira and Confluence Data&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/atlassian-rovo-can-be-tricked-into.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds-novel.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Levi Strauss Says Hackers Breached Employee Computers, Accessed Corporate Data&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/levi-strauss-hackers-breached-employee-computers&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;French Rugby Club Stade Français Restores Systems After Cyberattack, Probes Data Leak&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/french-rugby-club-restores-systems-after-cyberattack&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Military Device Manufacturer Discloses Cyber Incident to SEC&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/military-device-manufacturer-discloses-cyber-incident&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Irregular, Firm Behind AI Hacking Incidents, Won&amp;#x27;t Say If There Were More&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/irregular-ai-security-company-incidents&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;IAPP Analysis: New Mexico Decree Treats Social Media as a &amp;#x27;Digital Superfund Site&amp;#x27;&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://iapp.org/news/a/a-view-from-dc-new-mexico-decree-treats-social-media-as-a-digital-superfund-site&quot;&gt;IAPP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;US Senate Commerce Committee Approves KOSA and Children&amp;#x27;s AI Safety Bills&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://iapp.org/news/a/us-senate-committee-approves-kosa-children-s-ai-safety-bills&quot;&gt;IAPP&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-08 · CISA Adds Progress LoadMaster RCE (CVE-2026-8037) to Known Exploited Vulnerabilities Catalogue</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-08.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-08.html</guid>
  <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-08 — 11 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;CISA Adds Progress LoadMaster RCE (CVE-2026-8037) to Known Exploited Vulnerabilities Catalogue&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Issues ICS Advisory on CPDLC over ATN-B1 Vulnerabilities (Five CVEs)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/ics-advisories/icsa-26-219-01&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;UK AI Security Institute Discloses Incidents as Anthropic, OpenAI and Meta Models Attack Real-World Targets&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://risky.biz/newsletters/&quot;&gt;Risky.Biz&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;US Cyber Ambassador Nominee Cassady Confirmed in Senate&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/adam-cassady-confirmed-senate-cyber-ambassador&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New Mexico Judge Orders Meta to Pay $567 Million in Kids Online Safety Case&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/new-mexico-judge-orders-meta-567-million-kids-safety&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Unlimited Technology Systems Data Breach Affects 3.8 Million Patients — Largest US Healthcare Breach of 2026&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/patient-data-exposed-ohio-revenue-cycle-management-company/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Five Healthcare Providers Settle Pixel Class Action Lawsuits&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/five-healthcare-providers-pixel-class-action-settlements/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cyberattack on North Carolina Ports &amp;#x27;Contained&amp;#x27; as Coast Guard, State Officials Investigate&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/cyberattack-north-carolina-ports&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-06 · CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-06.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-06.html</guid>
  <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-06 — 12 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/aws-google-and-vercel-patch-agent-flaws.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Attackers Compile &amp;quot;khunt&amp;quot; Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Trojaniased npm Packages Use &amp;quot;NullReceiver&amp;quot; to Conceal C2 IP in Blockchain&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Anthropic AI Agent Faked Identities and Phished Real Developers in UK Government Hacking Test&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/snowflake-hacker-pleads-guilty-over.html&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Chinese Telcos Maintain Deep US Presence Despite Salt Typhoon Links, House Committee Says&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/chinese-hackers-telecoms-house&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cyberattacks on Water Systems Expand to 12 States as South Dakota and Georgia Announce Incidents&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/iran-cyberattacks-water-treatment&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Dutch Retailer De Bijenkorf Warns Customer Data May Be Exposed After Cyber Incident&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/de-bijenkorf-luxury-retailer-third-party-cyber-incident&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Data Breach Lawsuits Settled by Omni Healthcare &amp;amp; Western Montana Clinic&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/omni-healthcare-western-montana-clinic-data-breach-settlements/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;FTC, Utah, California Sue Him &amp;amp; Hers Over Business and Data Sharing Practices&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells (ENDLESSDOORS)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-05 · ACSC Publishes New AI Frontier Cyber Threat Guidance for Boards of Directors</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-05.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-05.html</guid>
  <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-05 — 13 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;ACSC Publishes New AI Frontier Cyber Threat Guidance for Boards of Directors&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cyber.gov.au/business-government/protecting-business-leaders/cyber-security-for-business-leaders/frontier-ai-cyber-threat-considerations-for-boards-of-directors&quot;&gt;ACSC&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;UK NCSC Statement on Recent Incidents Resulting from Frontier AI Evaluations&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.ncsc.gov.uk/news/ncsc-statement-in-response-to-recent-incidents-resulting-from-frontier-ai-evaluations&quot;&gt;UK NCSC&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/privacy-concerns-government-demand-hospital-emergency-room-data/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Brown Health Medical Group-MA Data Breach Affects 312,000 Individuals&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/brown-health-medical-group-ma-data-breach/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Apple Launches New Legal Challenge Against UK Over iCloud Access&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/apple-uk-tcn-icloud-new-legal-challenge&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Britain&amp;#x27;s Next War Won&amp;#x27;t Be an Away Game: Q&amp;amp;A with Former Head of Defence Intelligence&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/interview-jim-hockenhull-uk-defence-intelligence-russia-ukraine&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Swiss IT Agency Hacked, 200 Accounts Compromised, SharePoint Vulnerabilities Suspected&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/swiss-bit-foitt-hacked-possibly-sharepoint-vulnerabilities&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Polish Convenience Store Chain Żabka Hacked Through Third-Party Account&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/poland-convenience-store-chain-zabka-cyberattack&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Bitcoin Hardware Wallet Maker Destroys Some Inventory After More Than $88 Million Stolen&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/coincard-hardware-wallet-bitcoin-theft-inventory-destroyed&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/keyv-linked-npm-worm-poisons-hundreds.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access (SMOKE#SCREEN)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/google-deletes-3-adk-ai-workflows-after.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-04 · Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-04.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-04.html</guid>
  <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-04 — 18 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/health-isac-warning-shinyhunters-healthcare/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Biotech Giant Amgen Says Patient Data Stolen from Third-Party Cloud Systems&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/amgen-hackers-cyberattack-sec&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CareCloud Notifies More Than 345,000 Patients About Cyberattack Data Theft&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/carecloud-data-breach/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Patients Warned About AnMed Communications After Cyberattack Closes 83 Facilities&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/anmed-closes-almost-80-facilities-while-it-grapples-with-cyberattack/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;EDPB Requests Review of EU-US Data Privacy Framework Following Trump v. Slaughter&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://iapp.org/news/a/edpb-requests-review-of-eu-us-data-privacy-framework-following-trump-v-slaughter&quot;&gt;IAPP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;China Proposes Significant Amendments to National Standard on Personal Information Protection&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://iapp.org/news/a/china-proposes-significant-amendments-to-the-national-standard-on-personal-information-protection&quot;&gt;IAPP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hackers Steal 31,000 Records Identifying People Behind Liechtenstein Companies&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/hackers-steal-records-liechtenstein-companies-foundations&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;PNLD Breach Exposes UK Police and Government Contact Details on Dark Web&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Singapore Launches AI Training Data Guidelines, Expands PETs Resources&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://iapp.org/news/a/singapore-launches-ai-training-data-guidelines-expands-pets-resources&quot;&gt;IAPP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/google-password-manager-attacks-could.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hugging Face Diffusers Flaws (FaceHugger) Could Let Model Repositories Execute Arbitrary Code&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;University of Tennessee Sues Anthropic Over AI Research Patent Infringement&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.insidehighered.com/news/tech-innovation&quot;&gt;Inside Higher Ed&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-03 · CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-03.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-03.html</guid>
  <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-03 — 18 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Researchers Report 84 Flaws in 4G and 5G Cores, Including Session Hijacking&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/researchers-report-84-flaws-in-4g-and.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Mythos Attack on 3rd-Round PQC Algorithm Candidate Puts HAWK Out of Commission&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://arstechnica.com/security/&quot;&gt;Ars Technica&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Max-Severity Exchange Server Flaw Under Active Exploitation by Kremlin Hackers&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/&quot;&gt;Ars Technica&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Claude Published Malicious Code to the Internet and Attacked 3 Real Companies — Detailed Account&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://arstechnica.com/security/2026/08/claude-published-malicious-code-to-the-internet-and-attacked-3-real-companies/&quot;&gt;Ars Technica&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;We Now Have a Better Understanding How OpenAI Hacked Into Hugging Face&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://arstechnica.com/security/&quot;&gt;Ars Technica&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Anthropic Is Finding Bugs Faster Than Microsoft Can Fix Them&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://arstechnica.com/security/&quot;&gt;Ars Technica&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver CornFlake Surveillance Malware (CaptiveCrunch)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/hijacked-hotel-wi-fi-pushes-fake.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Finland to Disconnect Fibre-Optic Link to Russia as Lease Expires&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/finland-russia-fiber-optic-disconnection&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/hollowframe-loader-deploys-matryoshka.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;AI Scammers Outperform Humans When It Comes to Building Trust&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://arstechnica.com/security/2026/07/ai-scammers-outperform-humans-when-it-comes-to-building-trust/&quot;&gt;Ars Technica&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cheap Android TV Boxes Pose as Phones and Turn Owners&amp;#x27; Broadband Into Proxies (Fuyao)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;European Commission Issues Guidance on the Cyber Resilience Act&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;France Becomes First EU Member State to Approve Children&amp;#x27;s Social Media Ban&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.iapp.org/news/&quot;&gt;IAPP&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-08-01 · Fuyao Operation: Cheap Android TV Boxes Pose as Phones and Turn Broadband Into Proxies</title>
  <link>https://cyber.peterjaycox.com/daily/2026-08-01.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-08-01.html</guid>
  <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-08-01 — 6 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Fuyao Operation: Cheap Android TV Boxes Pose as Phones and Turn Broadband Into Proxies&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks Against 460+ Targets&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Finland to Disconnect Fiber-Optic Link to Russia as Lease Expires&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/finland-russia-fiber-optic-disconnection&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;US Cyber Command Plans Silicon Valley Office to Drive Innovation&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/cyber-command-plans-silicon-valley-office-to-drive-innovation&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Three Recent Chrome Releases Fix 1,442 Flaws — More Than Prior 23 Updates Combined&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/health-isac-warning-shinyhunters-healthcare/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-07-31 · ACSC Publishes Guidance on Secure Adoption of Agentic AI in Defence</title>
  <link>https://cyber.peterjaycox.com/daily/2026-07-31.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-07-31.html</guid>
  <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-07-31 — 15 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;ACSC Publishes Guidance on Secure Adoption of Agentic AI in Defence&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cyber.gov.au/&quot;&gt;ACSC&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Adds One New Known Exploited Vulnerability to KEV Catalogue&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/07/01/cisa-adds-one-known-exploited-vulnerability-catalog&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Publishes Open Source Software Security Principles and Practices&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/resources-tools/resources/open-source-software-security-principles-and-practices&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Urges Water and Wastewater Systems to Protect OT Against Activity Targeting PLCs&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Anthropic Reveals Claude Models Breached Three Organisations After Mistaking Internet for CTF&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Azure Cosmos DB &amp;#x27;CosmosEscape&amp;#x27; Flaw Exposed Platform-Wide Key Across All Tenants&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;North Korea&amp;#x27;s Lazarus Group Sharing Tools with Ransomware Hackers, South Korean Agencies Warn&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hackers Exploit AnySign4PC via Compromised Korean Websites to Install Backdoors&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cyber Extortionists Steal Data from UK Department for Education&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/alabama-education-department-data-breach&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Semiconductor Titan Analog Devices Reports Data Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/analog-devices-semiconductor-company-data-breach&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Global Data Breach Cost Rises 12% to Almost $5 Million — IBM 2026 Study&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-07-30 · Cisco FMC Zero-Day Actively Exploited via Static Credentials (CVE-2026-20316)</title>
  <link>https://cyber.peterjaycox.com/daily/2026-07-30.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-07-30.html</guid>
  <pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-07-30 — 18 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Cisco FMC Zero-Day Actively Exploited via Static Credentials (CVE-2026-20316)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/cybersecurity-advisories&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;ACSC Urges Organisations to Isolate Vital OT and Critical Enabling Systems&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cyber.gov.au/&quot;&gt;ACSC&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA and ACSC Update Joint Guidance on 2026 Minimum Elements for SBOM&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cyber.gov.au/&quot;&gt;ACSC&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Two Critical VMware vCenter Flaws Allow Authentication Bypass and RCE (CVE-2026-59309 / CVE-2026-59310)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Critical Rails Flaw Exposes Process Secrets via Crafted Image Uploads (CVE-2026-66066)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Public PoC Released for Check Point SmartConsole Authentication Bypass (CVE-2026-16232)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Russian Laundry Bear Exploits Microsoft OWA Flaw to Retain Mailbox Access (CVE-2026-42897)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Amazon Attributes Historic npm Package Hijacks to North Korea’s Sapphire Sleet&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;FSB Charges Telegram Founder Pavel Durov with Aiding Terrorist Activity&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Coordinated Cyberattack Disables Operational Technology at 30+ Minnesota Water Systems&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;FTC Sues Hims &amp;amp; Hers Over Unlawful Sharing of Patient Data with Ad Platforms&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Soniva Dental Care Data Breach Affects Over 30,000 Patient Records&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Banner Health and LifeStance Health Settle Website Tracking Pixel Lawsuits&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Maximum-Severity &amp;quot;RufRoot&amp;quot; MCP Flaw Threatens Claude Code and Codex (CVE-2026-59726)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;OpenAI Identifies Rogue AI Agent Breaching Secondary Services Post-Hugging Face Hack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/openai-says-rogue-agent-behind-hugging-face-hack-broke-into-additional-services&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;European Commission Issues Technical Guidance on Cyber Resilience Act Compliance&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Privacy Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;EU Digital Omnibus on Artificial Intelligence Enters Into Force&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Privacy Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;FCC Places Connected Robots and Power Inverters on National Security Covered List&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-07-28 · CISA Adds Two Known Exploited Vulnerabilities to KEV Catalogue</title>
  <link>https://cyber.peterjaycox.com/daily/2026-07-28.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-07-28.html</guid>
  <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-07-28 — 12 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;CISA Adds Two Known Exploited Vulnerabilities to KEV Catalogue&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalog&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;AnMed Closes Almost 80 Facilities Amid Cyberattack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;MCBS Announces Cybersecurity Incident Impacting 1.26 Million Individuals&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Data Breaches Announced by Four Hospitals and Surgery Centres&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/four-hospitals-surgery-centers-data-breaches/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw (CVE-2026-61511)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/public-exploit-released-for-patched.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;n8n Sandbox Escape Lets Workflow Editors Run OS Commands (CVSS 8.7)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Dysphoria IoT Botnet Adopts Blockchain C2 and Victim Relays After JackSkid Disruption&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html?m=1&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Telegram Phishing Campaign Targets Exiled Belarusian Activists, Russians, and Kazakhs&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;UK Court Rejects Bahrain Immunity Claim in Spyware Case&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/uk-court-rejects-bahrain-immunity-claim-spyware-case&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hackers Used Autonomous AI Agent to Spy on Thailand&amp;#x27;s Finance Ministry&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/thailand-hackers-ai-finance-ministry&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;NVIDIA Forms 37-Member Open Secure AI Alliance, Open-Sources NOOA Framework&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/nvidia-forms-37-member-open-secure-ai.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;US Senator Calls for Purging Outdated VPNs from Federal Agencies&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/federal-purge-outdated-vpns-wyden-letter&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-07-27 · ACSC/CISA Joint Advisory: Russian State-Sponsored Zimbra Phishing Campaign</title>
  <link>https://cyber.peterjaycox.com/daily/2026-07-27.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-07-27.html</guid>
  <pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-07-27 — 10 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;ACSC/CISA Joint Advisory: Russian State-Sponsored Zimbra Phishing Campaign&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cyber.gov.au/&quot;&gt;ACSC&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;UK Information Commission Takes Shape with Non-Executive Board Appointments&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.iapp.org/news/&quot;&gt;IAPP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Clover Health Assessing Impact of Social Engineering Incident&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;TriWest Healthcare Alliance Announces Breach Affecting ~12,000 Tricare Beneficiaries&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;MEPs Question Anthropic&amp;#x27;s EU Standing, Discuss Digital Sovereignty&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.iapp.org/news/&quot;&gt;IAPP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Congressional Stalemates Take Wind Out of US Digital Policy Sails&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://iapp.org/news/a/congressional-stalemates-take-wind-out-of-us-digital-policy-sails&quot;&gt;IAPP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management Company&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Singapore Launches AI Training Data Guidelines, Expands PETs Resources&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://iapp.org/news/a/singapore-launches-ai-training-data-guidelines-expands-pets-resources&quot;&gt;IAPP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;China&amp;#x27;s Regulation on AI Companions Takes Force&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://iapp.org/news/a/chinas-regulation-on-ai-companions-takes-force&quot;&gt;IAPP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;DevMan RaaS Portal Centralises Payload Builds, Victim Management, and Affiliate Payouts&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-07-26 · Connecticut AG Leads 42-State Settlement With 23andMe Over 2023 Data Breach</title>
  <link>https://cyber.peterjaycox.com/daily/2026-07-26.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-07-26.html</guid>
  <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-07-26 — 35 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Connecticut AG Leads 42-State Settlement With 23andMe Over 2023 Data Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Plans to Finalise Cyber Incident Reporting Regulations in September 2026&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA/FBI Joint Advisory: Russian State-Sponsored Zimbra Phishing Campaign (AA26-204A)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/news/cisa-nsa-fbi-and-partners-warn-zimbra-collaboration-suite-users-ongoing-russian-state-supported&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Advisory: Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting (AA26-194A)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2018/04/16/russian-state-sponsored-cyber-actors-targeting-network-infrastructure-devices&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Illinois Governor Signs Frontier AI Model Law&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;US State Department Imposes Visa Restrictions on Foreign Cyber Scammers&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/visa-restrictions-cyber-scammers&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Extension of CISA 2015 Info-Sharing Protections Passes as Part of House Defence Bill&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/cisa-2015-extension-passes-house-ndaa&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;UK Signals Continuity on Cyber Policy — Minister Reappointed Despite Ministry Scrapping&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;BlueNoroff (North Korea) Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New Kimsuky Campaign Compromises South Korean Software Vendors&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM With Unauthenticated RCE (CVE-2026-12569)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Report Shows Surge in Malicious Insider Incidents and Mega Data Breaches&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Fastjson 1.x RCE Vulnerability Under Active Attack — No Patch Available (CVE-2026-16723, CVSS 9.0)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/05/ivanti-epmm-cve-2026-6973-rce-under.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft&amp;#x27;s Servers (CVE-2026-32194/32191, CVSS 9.8)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;GitLab RCE PoC Published — Authenticated Users Can Run Commands as Git&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Certighost Exploit: Low-Privileged AD Users Can Impersonate a Domain Controller (CVE-2026-54121, CVSS 8.8)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Single Phishing Link&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;SourTrade Malvertising: Browser Builds Windows Executable Using Bun Runtime&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;DevMan RaaS Portal Centralises Payload Builds, Victim Management, and Affiliate Payouts&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html?utm_campaign=CTI%20Newsletter&amp;amp;utm_medium=email&amp;amp;_hsenc=p2ANqtz-9WdBDsAFUJygLCOqLFm5pTuxI6BCAX6Cq6Eh8klwaHYGCdcp_TIvmRwPnCQE5DdN-x0Hl5lfZL2SDKzChlDgC9HwEPlQ&amp;amp;_hsmi=430902293&amp;amp;utm_content=430831637&amp;amp;utm_source=hs_email&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Insurance Phishing Evolves Into Real-Time Account Hijacking&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hermes AI Agent Used Unattended for Post-Exploitation at Thailand&amp;#x27;s Ministry of Finance&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html?m=1&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Spain Fines 23andMe Nearly $3 Million for Cybersecurity Failings Enabling 2023 Hack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/spain-fines-23andme-3-million-cyber-failings-data-breach&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;French Parliament Greenlights Social Media Ban for Under-15s&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/france-social-media-ban-parliament&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Federal Agencies Broaden Alert on Iran-Linked OT Attacks&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Swiss Train Maker Stadler Refuses Everest $12 Million Ransomware Demand&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/stadler-refuses-everest-ransom-demand&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Major Australian Energy Supplier Confirms Customer Data Compromised&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Tennessee Pathology Group Announces 170K-Record Data Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Colorado Behavioral Healthcare Provider Discovers Insider Data Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Golden Chickens Resurfaces With Four New Malware Families&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;&amp;#x27;Wrench&amp;#x27; Attacks Against Crypto Holders Appear to Be on the Rise&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/wrench-attacks-against-cryptocurrency-holders&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Japanese Food Logistics Giant Nichirei Recovers as Extortion Group Claims Cyberattack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/nichirei-japan-food-logistics-cyberattack-recovery&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-07-25 · Certighost Exploit Lets Low-Privileged AD Users Impersonate a Domain Controller</title>
  <link>https://cyber.peterjaycox.com/daily/2026-07-25.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-07-25.html</guid>
  <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-07-25 — 20 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Certighost Exploit Lets Low-Privileged AD Users Impersonate a Domain Controller&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft&amp;#x27;s Servers&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Golden Chickens Resurfaces With Four New Malware Families&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;State Department imposes visa restrictions on foreign cyber scammers&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/visa-restrictions-cyber-scammers&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;&amp;#x27;Wrench&amp;#x27; attacks against crypto holders appear to be on the rise&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/wrench-attacks-against-cryptocurrency-holders&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Tennessee Pathology Group Announces 170K-record Data Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Colorado Behavioral Healthcare Provider Discovers Insider Data Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Patient Data Exposed in Cybersecurity Incident at Ohio Revenue Cycle Management Company&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Singapore launches AI training data guidelines, expands PETs resources&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://iapp.org/news/a/singapore-launches-ai-training-data-guidelines-expands-pets-resources&quot;&gt;IAPP News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Congressional stalemates take wind out of US digital policy sails&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://iapp.org/news/a/congressional-stalemates-take-wind-out-of-us-digital-policy-sails&quot;&gt;IAPP News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;China&amp;#x27;s regulation on AI companions takes force&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://iapp.org/news/a/chinas-regulation-on-ai-companions-takes-force&quot;&gt;IAPP News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Major Australian energy supplier confirms customer data compromised&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-07-24 · Russian State-Sponsored Zimbra Zero-Day Campaign (AA26-204A / CVE-2025-66376)</title>
  <link>https://cyber.peterjaycox.com/daily/2026-07-24.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-07-24.html</guid>
  <pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-07-24 — 17 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Russian State-Sponsored Zimbra Zero-Day Campaign (AA26-204A / CVE-2025-66376)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/cybersecurity-advisories&quot;&gt;CISA Cybersecurity Advisory AA26-204A&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;China-Nexus JadeProx Uses TriBack Loader in Government and Healthcare Attacks&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Kimsuky Campaign Compromised South Korean Software Vendors&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/north-korean-hackers-target-employees-of-news-outlets-software-vendors-and-more-through-chrome-vulnerability&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Claude Cowork Sandbox Escape (SharedRoot) — ~500K macOS Users Affected&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Chaos Ransomware Uses msaRAT to Route C2 Through Headless Chrome&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Check Point SmartConsole Authentication Bypass (CVE-2026-16232, CVSS 9.3) Under Active Exploitation&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;OpenAI Models Behind Hugging Face Breach — Escaped Containment&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/openai-says-rogue-agent-behind-hugging-face-hack-broke-into-additional-services&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Adobe Acrobat Extension Flaw (HermeticReader / CVE-2026-48294) — 314M Users at Risk&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;DentaQuest Starts Notifying 15+ Million Individuals About May 2026 Cyber Incident&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Swiss Train Maker Stadler Refuses Everest $12 Million Ransomware Demand&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/stadler-refuses-everest-ransom-demand&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Major Australian Energy Supplier Confirms Customer Data Compromised&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Japanese Food Logistics Giant Nichirei Recovers as Extortion Group Claims Cyberattack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/nichirei-japan-food-logistics-cyberattack-recovery&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Federal Agencies Broaden Alert on Iran-Linked OT Attacks&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Canvas Pauses Data Delivery Due to Potential &amp;#x27;Security Threat&amp;#x27;&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.insidehighered.com/news/tech-innovation&quot;&gt;Inside Higher Ed&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;French Parliament Greenlights Social Media Ban for Under-15s&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/france-social-media-ban-parliament&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-07-23 · Federal Agencies Broaden Alert on Iran-Linked OT Attacks</title>
  <link>https://cyber.peterjaycox.com/daily/2026-07-23.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-07-23.html</guid>
  <pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-07-23 — 13 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Federal Agencies Broaden Alert on Iran-Linked OT Attacks&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Extension of CISA 2015 Info-Sharing Protections Passes as Part of House Defense Bill&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/cisa-2015-extension-passes-house-ndaa&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New Kimsuky Campaign Compromised South Korean Software Vendors&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/github-cuts-public-bug-bounty-payouts.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Adobe Acrobat Extension Flaw (HermeticReader) Lets Malicious Sites Read WhatsApp Web Data — CVE-2026-48294&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html?m=1&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;OpenAI Models Behind Breach of Hugging Face Systems, Companies Say&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/openai-cyberattack-hugging-face&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;TriWest Healthcare Alliance Breach Affects Almost 12,000 Tricare Beneficiaries&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Clover Health Assessing Impact of Social Engineering Incident&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Craneware — Major Healthcare Software Vendor Investigating Cyberattack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;French Parliament Greenlights Social Media Ban for Under-15s&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/france-social-media-ban-parliament&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New Jersey Enacts Data Broker Registration Regime and Sensitive Data Sales Restrictions&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.wilmerhale.com/insights/blogs/wilmerhale-privacy-and-cybersecurity-law&quot;&gt;WilmerHale Privacy and Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Japanese Food Logistics Giant Nichirei Recovers as Extortion Group Claims Cyberattack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/nichirei-japan-food-logistics-cyberattack-recovery&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-07-22 · AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code</title>
  <link>https://cyber.peterjaycox.com/daily/2026-07-22.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-07-22.html</guid>
  <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-07-22 — 20 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html?utm_campaign=CTI%20Newsletter&amp;amp;utm_medium=email&amp;amp;_hsenc=p2ANqtz-8cAY8VDxCTz4LCsMXUXOnLbcH_CUoVA383IskEC_c1xeNh_FGA_C7kRrGXWv6e6bNs9XKqnCKsOMjLSPe9TtGHd3yihw&amp;amp;_hsmi=429834389&amp;amp;utm_content=429748423&amp;amp;utm_source=hs_email&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/google-launches-gemini-35-flash-cyber.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/zimbra-patches-critical-snmp-command.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Major Healthcare Software Vendor Craneware Investigating Cyberattack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Kenya Probes Hack of President&amp;#x27;s Website After Bitcoin Ransom Demand&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/kenya-probes-hack-of-presidents-website-after-ransom-demand&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;DNI Nominee Clayton Wins Senate Panel&amp;#x27;s Approval&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/jay-clayton-dni-nomination-senate-committee-approval&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Taiwan to Slow Mobile Data During National Resilience Drills&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New Jersey Enacts Data Broker Registration Regime With Sensitive Data Sale Restrictions&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.wilmerhale.com/insights/blogs/wilmerhale-privacy-and-cybersecurity-law&quot;&gt;WilmerHale Privacy and Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Spain Fines 23andMe Nearly $3 Million for Cybersecurity Failings Enabling 2023 Hack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/spain-fines-23andme-3-million-cyber-failings-data-breach&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Abbott Investigating Cyberattack Claims From Two Threat Actors&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Illinois Governor Signs Frontier AI Model Law&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Apps Marketed to US Troops Are Shipping Chinese and Russian Code&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.wired.com/story/apps-marketed-to-us-troops-are-shipping-chinese-and-russian-code/&quot;&gt;Wired&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-07-21 · WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning</title>
  <link>https://cyber.peterjaycox.com/daily/2026-07-21.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-07-21.html</guid>
  <pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-07-21 — 14 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Software Provider to More Than 2,000 US Hospitals Says Hackers Stole Employee and Customer Data&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/software-provider-for-us-hospitals-customer-data-breach&quot;&gt;The Record from Recorded Future News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;ApolloMD Agrees to Pay $4.02M to Settle Data Breach Lawsuit&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Abbott Investigating Cyberattack Claims From Two Threat Actors&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Centers Laboratory Discloses Data Breach Affecting 542,000 Individuals&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Romania Races to Restore Land Registry After Cyberattack Disrupts Property Market&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/romania-cyberattack-land-registry&quot;&gt;The Record from Recorded Future News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;More Than 1,000 Domains Illegally Streaming World Cup Games Seized, DOJ Says&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record from Recorded Future News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Flock Safety Kills Acoustic System Designed to Detect &amp;#x27;Human Distress&amp;#x27;&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/flock-safety-kills-audio-detection-system-human-distress&quot;&gt;The Record from Recorded Future News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Illinois Governor Signs Frontier AI Model Law&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Blog&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-07-20 · Critical NGINX Vulnerability (CVE-2026-42533) — Heap Buffer Overflow, DoS/RCE</title>
  <link>https://cyber.peterjaycox.com/daily/2026-07-20.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-07-20.html</guid>
  <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-07-20 — 12 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Critical NGINX Vulnerability (CVE-2026-42533) — Heap Buffer Overflow, DoS/RCE&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2012/09/critical-buffer-overflow-vulnerability.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410) — Exploited Before Disclosure&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;wp2shell WordPress Core Flaw — Unauthenticated RCE, PoC Public&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;UAC-0145 (Sandworm) Uses ClickFix CAPTCHAs to Infect Ukrainian Devices&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;EU Orders Google to Open Android to Rival AI Assistants Under DMA&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/eu-orders-google-to-open-android-mic.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Illinois Governor Signs Frontier AI Model Law (SB 315)&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Plans to Finalise Cyber Incident Reporting Regulations by September 2026&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;23andMe Reaches $18 Million Settlement with States for 2023 Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/bankruptcy-admin-approves-settlement-for-23andme-breach-victims&quot;&gt;The Record from Recorded Future News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Dairy Company Fairlife Suspends US Production After Cyber Incident&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/dairy-company-fairlife-suspends-production-us-cyber-incident&quot;&gt;The Record from Recorded Future News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Scattered Spider Hackers Sentenced to 5.5 Years Over £29M Transport for London Hack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/transport-for-london-hack-scattered-spider-suspects-plead-not-guilty&quot;&gt;The Record from Recorded Future News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;OpenSSL &amp;quot;HollowByte&amp;quot; Flaw — Memory DoS via 11-Byte TLS Request&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html&quot;&gt;OpenSSL &amp;quot;HollowByte&amp;quot; Flaw — Memory DoS via 11-Byte TLS Request&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Trump Administration Unveils AI-Supported Clearinghouse for Cyber Vulnerabilities&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record from Recorded Future News&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-07-19 · Joint Advisory: Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting</title>
  <link>https://cyber.peterjaycox.com/daily/2026-07-19.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-07-19.html</guid>
  <pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-07-19 — 23 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Joint Advisory: Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/cybersecurity-advisories&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale Restrictions&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Trump Administration Unveils AI-Supported Clearinghouse for Cyber Vulnerabilities&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New GoSerpent Malware Targets Southeast Asian Governments and Diplomats&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/new-goserpent-malware-targets-southeast.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cyberattack on Japan&amp;#x27;s Largest Cold-Chain Operator Disrupts KFC and Supermarket Supplies&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Two Scattered Spider Hackers Sentenced to 5.5 Years for £29 Million TfL Hack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/scattered-spider-hackers-tfl-sentenced&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;EU Commission Unveils Cybersecurity and AI Action Plan&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Microsoft Patches a Record 570 Security Flaws&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/&quot;&gt;Krebs on Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;All About Women&amp;#x27;s Care Data Breach Affects Up to 12,000 Patients&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Atrium Health Pays Up to $1.8M to Resolve Pixel Lawsuit&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Illinois Governor Signs Frontier AI Model Law&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;23andMe Reaches $18 Million Settlement with States for Massive Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cash App Owner to Pay $45 Million to Settle Allegations of Lax Security&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/cash-app-owner-to-pay-45-million-security-allegations&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Lessons Learned from CISA&amp;#x27;s Recent GitHub Leak&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/&quot;&gt;Krebs on Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Dairy Company Fairlife Suspends Production in US After Cyber Incident&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/dairy-company-fairlife-suspends-production-us-cyber-incident&quot;&gt;The Record&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Madison Square Garden Kept a List of Gay Celebrities&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.wired.com/tag/security/&quot;&gt;Wired Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hackers Claim to Leak Stolen Madison Square Garden Data&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.wired.com/tag/security/&quot;&gt;Wired Security&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
<item>
  <title>Cyber Digest — 2026-07-18 · Joint Advisory: Russian State-Sponsored Cyber Actors Target Network Devices</title>
  <link>https://cyber.peterjaycox.com/daily/2026-07-18.html</link>
  <guid isPermaLink="true">https://cyber.peterjaycox.com/daily/2026-07-18.html</guid>
  <pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate>
  <description>&lt;p&gt;2026-07-18 — 24 stories.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Joint Advisory: Russian State-Sponsored Cyber Actors Target Network Devices&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.cisa.gov/news-events/alerts/2018/04/16/russian-state-sponsored-cyber-actors-targeting-network-infrastructure-devices&quot;&gt;CISA&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Microsoft Patches a Record 570 Security Flaws&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/&quot;&gt;Krebs on Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Sandworm Hackers Have a CAPTCHA Trick for Ukrainians&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record by Recorded Future&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;EU Orders Google to Open Android Mic, Camera, and Screen to Rival AI Assistants&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/eu-orders-google-to-open-android-mic.html&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Illinois Governor Signs Frontier AI Model Law&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hunton.com/privacy-and-cybersecurity-law-blog/&quot;&gt;Hunton Andrews Kurth Privacy &amp;amp; Cybersecurity Law Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Lessons Learned from CISA&amp;#x27;s Recent GitHub Leak&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/&quot;&gt;Krebs on Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;All About Women&amp;#x27;s Care Data Breach Affects Up to 12,000 Patients&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Atrium Health Pays Up to $1.8M to Resolve Pixel Lawsuit&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;May 2026 Healthcare Data Breach Report: 61 Breaches Reported&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.hipaajournal.com/&quot;&gt;HIPAA Journal&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Cash App Owner to Pay $45 Million to Settle Allegations of Lax Security&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/cash-app-owner-to-pay-45-million-security-allegations&quot;&gt;The Record by Recorded Future&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;23andMe Reaches $18 Million Settlement with States for Massive Breach&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/&quot;&gt;The Record by Recorded Future&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Dairy Company Fairlife Suspends Production in US After Cyber Incident&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/dairy-company-fairlife-suspends-production-us-cyber-incident&quot;&gt;The Record by Recorded Future&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;A Guide to OT Security Best Practices&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.sans.org/webcasts/best-practices-lessons-learned-starting-osint-teams&quot;&gt;SANS Institute Blog&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Scattered Spider Hackers Sentenced to 5.5 Years for £29 Million Transport for London Hack&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://therecord.media/scattered-spider-hackers-tfl-sentenced&quot;&gt;The Record by Recorded Future&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;FBI Seizes NetNut Proxy Platform, Popa Botnet&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/&quot;&gt;Krebs on Security&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html?utm_source=infosec-mashup.santolaria.net&amp;amp;utm_medium=newsletter&amp;amp;utm_campaign=infosec-mashup-29-2026-they-didn-t-hack-the-military-they-hacked-the-phone-network&quot;&gt;The Hacker News&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.wired.com/tag/security/&quot;&gt;Wired&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Madison Square Garden Kept a List of Gay Celebrities&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.wired.com/tag/security/&quot;&gt;Wired&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Hackers Claim to Leak Stolen Madison Square Garden Data&lt;/strong&gt; &amp;mdash; &lt;a href=&quot;https://www.wired.com/tag/security/&quot;&gt;Wired&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</description>
</item>
</channel>
</rss>
