August 1, 2026 HackerOne has confirmed that all hackers must now complete identity verification before submitting reports to any bug bounty program (BBP) on its platform, a move the company …
Your Incident Response Plan Has a Dependency You Never Approved
July 31, 2026 During the first publicly documented agent-driven intrusion, the defenders tried to analyze the attack with commercial AI models and were refused. The attacker was operating under no usage …
Keycloak Vulnerability Exposes User Names and Email Addresses Across Admin Boundaries
July 31, 2026 Keycloak has addressed a broken access control vulnerability that could allow restricted administrators to access usernames, email addresses, and other profile information belonging to users outside their …
CyberStrike – AI-Powered Security Platform for Automated Penetration Testing
July 31, 2026 A new open-source project called CyberStrike is positioning itself as the first AI agent built specifically for offensive security, turning any existing Claude, GPT, or LLM subscription …
Critical JetBrains Flaw Allows Attackers to Execute Malicious Code Remotely – Update Now
July 31, 2026 JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows attackers to bypass authentication and execute arbitrary commands remotely. It affects all …
FBI And Allies Warn of North Korean IT Workers Using Stolen Identities
July 31, 2026 The U.S. State Department, FBI, and allied governments including Japan, Canada, Germany, Australia, the United Kingdom, and the Republic of Korea have issued a joint alert warning …
Google Uses AI Agents to Find and Fix 1,072 Chrome Security Vulnerabilities
July 31, 2026 Google is expanding the use of artificial intelligence (AI) agents across the Chrome security lifecycle to identify source code weaknesses, test patches, and accelerate the delivery of …
BlackTech APT Deploys BlueShell Linux Backdoor Against Japanese Organizations
July 31, 2026 BlackTech has been linked to a newly examined Linux backdoor deployment against organizations in Japan, showing how a familiar remote-access tool can be reshaped for cyberespionage. The …
DeepSeek-Powered Hermes Agent Launches Autonomous Cyberattacks Against Exposed Servers
July 31, 2026 A Chinese-speaking threat actor used an AI-driven agent to search for vulnerable internet-facing servers and begin attacks with little direct human input. The campaign shows how automated …
Critical SolarWinds Flaw Lets Attackers Bypass Web Help Desk SAML Login
July 31, 2026 SolarWinds has patched a critical security vulnerability in its Web Help Desk platform that could allow attackers to bypass SAML-based authentication. CVE-2026-28323 affects SolarWinds Web Help Desk …
