Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware

Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like hotels and conference centers, according to new findings from Microsoft Threa… Continue reading Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware

EU begins enforcing AI Act, putting AI models under the microscope

Europe’s fight to regulate AI models moved from paper to practice on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. On the same date, new transparency rules took effect, requirin… Continue reading EU begins enforcing AI Act, putting AI models under the microscope

Fake IRS letters direct crypto holders to bogus compliance portal

Scammers are sending physical letters to cryptocurrency holders that copy the look of official IRS notices. The letters tell recipients they must enroll in something called a Digital Asset Compliance Portal before a deadline, or risk penalties. “If you… Continue reading Fake IRS letters direct crypto holders to bogus compliance portal

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers

A Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention. Researchers at Palo Alto Networks’ Unit… Continue reading Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers

Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire

A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao apps ecosystem (Source: Bitsight) According to Bitsight, the operation, named Fuyao, uses preinstal… Continue reading Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire

Anthropic’s Claude breached three companies during security tests

Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s July 21 announcement that some of its models had escaped… Continue reading Anthropic’s Claude breached three companies during security tests

Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks

Attackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past the warning signs employees are trained to spot, according to Check Point. Between June 25 a… Continue reading Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks

Coordinated cyberattack hits more than 30 Minnesota water utilities

A coordinated cyberattack on July 26 and 27 hit operational technology (OT) systems at more than 30 community water utilities across Minnesota, prompting an immediate response from Minnesota IT Services (MNIT) to contain the threat. MNIT confirmed the … Continue reading Coordinated cyberattack hits more than 30 Minnesota water utilities

Tengu botnet reboots Linux devices to survive removal

A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered… Continue reading Tengu botnet reboots Linux devices to survive removal