-
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. “These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,” OpenSourceMalware researcher Paul
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU architecture. “
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
This week in cybersecurity from the editors at Cybercrime Magazine
Sausalito, Calif. – Aug. 7, 2026The premier Cybersecurity event of the year, Black Hat USA 2026 in Las Vegas, ended yesterday and the Cybercrime Magazine media team is on their way home.
A quick recap of who we met in Vegas before putting out our post-Black Hat media over the next month or so:
— It was one of the best convos at Black Hat and you’ll have to wait a little while. But we promise something very special is coming. Thanks Joe Levy, CEO at Sophos and Wendy Nather, Senior Research Initiatives Director at 1Password, for spending time with us.
— Keyfactor’s Mission: Securely connect the world—humans, machines, and AI—with cryptographic security. Cybercrime Magazine sat down with Ted Shorter, CTO, Keyfactor and learned why this company is trusted by 40 percent of the Fortune 100.
— Leapfrog software supply chain security, deliver trusted software in the AI era. Paul Davis, Field CISO at JFrog explained it to us. If you want to manage, secure, and govern your AI and software assets from one platform, then it’s possible.
— You read about it in The Wall Street Journal this week. We saw it in person at Black Hat. Horizon3.ai has a message that we all need to wrap our heads around: “Go hack yourself. Before they do. Fight AI with AI.” CEO Snehal Antani and his team showed us what you need to safely and autonomously hack your production environment, fix what matters most, verify instantly, and repeat continuously. It’s security you can prove.
— Cybersecurity is a team sport and Binary Defense is one of the best in our industry. We caught up with Founder & CEO David Kennedy and crew at Black Hat. These are some very serious cyber defenders. Binary Defense pairs U.S.-based operators with NightBeacon — AI that turns raw alerts into evidence-backed investigations you can audit down to the field. Let their experts run it for you, or run it yourself.
— One of the world’s top penetration testing experts was spotted at Black Hat. Seemant Sehgal, founder & CEO at BreachLock, the only offensive security provider combining continuous ASM, autonomous pentesting, CREST-certified pentesting, and closed-loop remediation in a single workflow met with Cybercrime Magazine after we waited behind CISOs who couldn’t get enough of it.
— Cybercrime Magazine met with Levi Gundert, Chief Security & Intelligence Officer at Recorded Future in their Business Hall booth with Mastercard. We explored how AI is reshaping cyber defense, and heard from cybersecurity industry leaders on tackling today’s toughest threat challenges. From AI-powered vulnerability prioritization to machine-speed detection, Recorded Future is bringing actionable insights for security teams on the front lines.
— Laura Stebbing, VP, Content at Black Hat, and Suzy Pallett, President at Black Hat, sat down with Amanda Glassner, Deputy Editor at Cybercrime Magazine. It was exciting for us to be partners with the world’s premier cybersecurity event in the U.S., and we’ll be doing it again later this year at Black Hat Europe in London.
— Call it a lucky day! Clover Security was at Black Hat and we meet them in the Business Hall. Cybercrime Magazine caught up with their founder & CEO Alon Kollmann
. Clover enables both humans and AI to build secure-by-design software, at scale, without slowing down innovation.— Poof! All your cybersecurity problems have vanished! Well, almost all of them. VanishID is on a mission to protect the enterprise from cyberattacks that revolve around using personal information of executives, key employees, and their families. Cybercrime Magazine spoke to Matt Polak, CEO at VanishID at Black Hat and learned about AI that neutralizes the external identity attack surface.
— This company is a keeper! Trusted by millions of individuals and thousands of organizations, Keeper Security, Inc. is the leader for best-in-class password management, secrets management, privileged access, secure remote access and encrypted messaging. Cybercrime Magazine caught up with Craig Lurey, CTO, Co-Founder at Keeper in the Black Hat Business Hall.
— Exaforce is on a mission to 10x improve the productivity and efficacy of security and operations teams using their transformative multi-model AI engine. AI gave attackers machine scale. Now you have the advantage. Marco Rodrigues, Co-Founder, Customer Engineering & Solutions at Exaforce told Cybercrime Magazine their story when we were with him at Black Hat.
— If you don’t know Benny Czarny, Founder & CEO at OPSWAT, then you don’t know cybersecurity. But most CISOs tell us they follow him. Cybercrime Magazine met with Benny at Black Hat. Read his great book “Cybersecurity Upside Down” and you’ll definitely rethink your cybersecurity strategy. We did!
Keep an eye on the award-winning Cybercrime Magazine YouTube Channel for new videos featuring these companies and others.
Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:
- SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
- NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
- HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
- VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
- M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
- BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
- PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
- PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
- RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.
Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.
The post Cybercrime Magazine’s Best Convos At Black Hat USA 2026 appeared first on Cybercrime Magazine.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher has disclosed a technique involving Windows Hello for Business (WHFB) that could allow attackers with access to an active Windows user session to authenticate to Microsoft Entra ID services without needing the victim’s PIN, biometric verification, or password. Mollema’s research demonstrates how attackers can effectively “borrow” the cryptographic key that underlies Windows Hello […]
The post Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral. Then,
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed attack class, NatJack, reveals significant weaknesses in the implementation of Network Address Translation (NAT) across modern network infrastructures. This vulnerability allows attackers to hijack TCP connections, tamper with DNS responses, and disrupt traffic flow. NatJack specifically targets the NAT state table, highlighting that traditional assumptions about cooperative network behavior are no longer […]
The post New NatJack NAT Attack Lets Hackers Hijack TCP Connections and DNS Responses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has released Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update delivers 41 security fixes across various components of the browser, including rendering, graphics, JavaScript, user interface (UI), media, and authentication. The Stable channel update began rolling out on August 6 and will reach users over the next several […]
The post Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


