DEF CON 34 – Las Vegas – Security researchers hunting for vulnerabilities could face prison time under a 1990 United Kingdom law that doesn’t distinguish between malicious hackers and those working in good faith. But change may finally be coming.… Read More "Outdated Cybercrime Laws Put Security Researchers at Risk"
WordPress Plugins Compromised Without a Single File Change
Seven WordPress plugins have been used to plant rogue administrator accounts and webshells on live sites without a single plugin file being modified. Instead, attackers poisoned a promotional data feed the plugins load into the admin dashboard. Wordfence was notified… Read More "WordPress Plugins Compromised Without a Single File Change"
Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds
Use of accelerators is growing in line with the growth of AI. These accelerators are specialized chips that are neither CPUs nor GPUs – they specifically offload and speed up the precise workloads required for AI. Primary producers include Tenstorrent,… Read More "Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds"
Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
The Hacker NewsAug 10, 2026Software Supply Chain / DevSecOps AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software… Read More "Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development"
Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
A flaw in Atlassian’s enterprise AI assistant has allowed a single crafted link to seed attacker instructions into a victim’s authenticated session, then use the assistant’s own browsing agent to push company data out to the public web. Varonis Threat… Read More "Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant"
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns
OpenAI has flagged its upcoming AI model, Astra, for potentially reaching a ‘critical’ cybersecurity risk threshold, prompting the company to suspend internal development activities that lack newly mandated security controls. Recent internal evaluations of Astra revealed massive leaps in its… Read More "OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns"
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
Swati KhandelwalAug 10, 2026Cyber Espionage / Artificial Intelligence North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running artificial intelligence (AI) offline on its own servers,… Read More "Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development"
One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack
The attack only required one click by the victim on a specially crafted link, which then allowed the attacker to potentially access anything Rovo is privileged. The issue was reported to Atlassian through a bug bounty program hosted on Bugcrowd,… Read More "One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack"
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials
A widespread DNS poisoning campaign is targeting hotels, conference venues and the hospitality sector with credential harvesting attacks designed to steal corporate login credentials from visitors, researchers have warned. Identified by cybersecurity analysts at ReliaQuest, the campaign begins by targeting… Read More "Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials"
Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
Cisco on Friday warned that its Secure Endpoint Connector products on Windows, macOS, and Linux are affected by seven ClamAV vulnerabilities that could lead to denial-of-service (DoS) conditions, including two with public proof-of-concept (PoC) code. ClamAV (Clam AntiVirus) is an… Read More "Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC"