Latest news as of 8/4/2026, 8:30:10 PM
Bleeping Computer
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. [...]
Bleeping Computer
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. [...]
Dark Reading
The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.
The Hacker News
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. "Greatness supports AiTM [adversary-in-the-middle] credential and
The Register
Claiming 'it's my server' was often enough to persuade models to help
The Register
What to expect as BSides, Black Hat, and DEF CON descend on Las Vegas
The Register
Experts warn hotfix not optional. MSPs warned attacker gains 'full administrative access to an N-central console'
Bleeping Computer
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. [...]
The Register
Broader bounty rules added to a swelling volume of machine-assisted vulnerability reports
Bleeping Computer
AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries. [...]