A flaw in Atlassian’s enterprise AI assistant has allowed a single crafted link to seed attacker instructions into a victim’s authenticated session, then use the assistant’s own browsing agent to push company data out to the public web. Varonis Threat… Read More "Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant"
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns
OpenAI has flagged its upcoming AI model, Astra, for potentially reaching a ‘critical’ cybersecurity risk threshold, prompting the company to suspend internal development activities that lack newly mandated security controls. Recent internal evaluations of Astra revealed massive leaps in its… Read More "OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns"
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
Swati KhandelwalAug 10, 2026Cyber Espionage / Artificial Intelligence North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running artificial intelligence (AI) offline on its own servers,… Read More "Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development"
One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack
The attack only required one click by the victim on a specially crafted link, which then allowed the attacker to potentially access anything Rovo is privileged. The issue was reported to Atlassian through a bug bounty program hosted on Bugcrowd,… Read More "One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack"
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials
A widespread DNS poisoning campaign is targeting hotels, conference venues and the hospitality sector with credential harvesting attacks designed to steal corporate login credentials from visitors, researchers have warned. Identified by cybersecurity analysts at ReliaQuest, the campaign begins by targeting… Read More "Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials"
Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
Cisco on Friday warned that its Secure Endpoint Connector products on Windows, macOS, and Linux are affected by seven ClamAV vulnerabilities that could lead to denial-of-service (DoS) conditions, including two with public proof-of-concept (PoC) code. ClamAV (Clam AntiVirus) is an… Read More "Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC"
Ransomware Incident Response Plan: 2025-2026 Threat Guide
Ransomware stopped being an isolated incident type in 2025. It became the dominant force behind the modern breach landscape, and the ransomware data breach statistics from Cyble’s own tracking make the shift impossible to ignore. For organizations facing this growing threat,… Read More "Ransomware Incident Response Plan: 2025-2026 Threat Guide"
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed,… Read More "New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA"
OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguards
The company said Astra has not yet been definitively classified at that level, but its early performance is “strong enough” that such a designation cannot be ruled out. Its earlier models, including GPT 5.6 Sol, “have been evaluated for frontier… Read More "OpenAI says Astra could reach ‘critical’ cyber capability, tightens safeguards"
Go-Based macOS Malware Steals Crypto and Secrets
Security researchers have discovered new infostealing macOS malware delivered via ClickFix social engineering attacks. Managed detection and response (MDR) specialist Huntress said that it came across the malware in June 2026. “In a ClickFix attack, the computer’s user is presented… Read More "Go-Based macOS Malware Steals Crypto and Secrets"