-
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private Alibaba package
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on devices.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen. Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Bitcoin business rarely runs a simple website. Payment processors, exchanges, wallet services, blockchain analytics products and Lightning…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Bitsight found Fuyao software on H96 Android TV boxes, letting operators fake ad clicks and route proxy traffic through their owners’ home internet connections.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
·
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
TP-Link has announced a high-severity security vulnerability in its TL-WR940N v6 wireless router that could allow an unauthenticated remote attacker to execute arbitrary code and potentially take full control of the affected device. This vulnerability is tracked as CVE-2026-12935 and has a CVSS v4.0 score of 8.7, categorized as high. TP-Link TL-WR940N Router Flaw According […]
The post TP-Link TL-WR940N Router Flaw Lets Unauthenticated Attackers Execute Code Remotely appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
This week in cybersecurity from the editors at Cybercrime Magazine
Sausalito, Calif. – Aug. 3, 2026– Read the full story in Reddit
The Cybercrime Magazine Podcast stands out as a leading resource for CISOs looking to stay updated on cybersecurity trends in 2026, according to a Reddit post by PWN, a popular community for hackers and cybersecurity enthusiasts.
In 2026, the Cybercrime Magazine Podcast has captured significant attention as the go-to source for chief information security officers (CISOs) and security leaders globally. Recognized by platforms like Million Podcast and the University of San Diego, it is ranked as one of the top cybercrime podcasts thanks to its high listener ratings and expert insights.
Each episode, averaging just 5 minutes, caters to busy professionals who need succinct, relevant information without the lengthy time commitment typical of other podcasts.
The content is not only informative but also varied, mixing short daily news segments with longer interviews featuring CISOs, ex-cybercriminals, and thought leaders. This format balances the entertainment and educational needs of CISOs, who report being inundated with similar content from multiple sources.
According to Steve Morgan, executive producer of the podcast, continuous polling of CISOs reveals a desire for fresh, engaging materials that go beyond traditional cybersecurity news to include trends, new company highlights, and personal stories from the cyber world.
The Cybercrime Magazine Podcast’s reputation for delivering news and insights in bite-sized formats makes it a cherished choice for tech leaders seeking to enhance their knowledge without sacrificing their valuable time.
Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:
- SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
- NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
- HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
- VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
- M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
- BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
- PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
- PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
- RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.
Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.
The post Top Cybercrime And Cybersecurity Podcasts For CISOs In 2026 appeared first on Cybercrime Magazine.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Federal employees and contractors whose sensitive personal data was stolen in the massive Office of Personnel Management breaches disclosed a decade ago would receive identity protection for the rest of their lives under new bicameral legislation.
Senate Intelligence Committee Vice Chair Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., plan to introduce the RECOVER PII Act on Monday, aiming to prevent the federal government’s identity-protection program for victims from expiring Sept. 30, according to bill text first seen by Nextgov/FCW. Sens. Tim Kaine, D-Va.; Angela Alsobrooks, D-Md.; and Chris Van Hollen, D-Md., are also Senate cosponsors.
Just over 10 years after the OPM breaches compromised personal information belonging to roughly 22 million people, the identity-protection services provided to affected federal workers, contractors and their families have begun expiring. People who enrolled in OPM’s MyIDCare program are receiving notices that their complimentary coverage will end 10 years after their individual enrollment date. Some notices began arriving late last year and will continue through September, when OPM plans to conclude the services at the end of the federal fiscal year.
“More than ten years after the OPM data breach exposed the personal information of millions of federal employees, the threat remains,” Warner said in the statement. “The data stolen included workers’ most sensitive and personal information — from Social Security numbers to security clearance records — and once that information is in the hands of a bad actor, you don’t get it back.”
The two breaches compromised information belonging to some 22.1 million current, former and prospective federal employees, contractors and others. One intrusion exposed personnel records for roughly 4.2 million people, while a second compromised 21.5 million background-investigation records. About 3.6 million people were affected in both incidents, according to the Government Accountability Office.
Foreign intelligence services can hold onto these OPM records for years, combine them with information from other cyber intrusions and use the fuller picture to identify or target government personnel and their families.
Those risks can also grow over time. Data stolen from a lower-level employee in 2015 could become far more valuable if that person later moves into a more sensitive national security role. GAO warned last year that adversaries can combine publicly available data to identify military personnel and their families or disrupt Defense Department operations.
Congress responded to the breach in a 2017 appropriations law by requiring OPM to provide victims with at least 10 years of complimentary identity protection and no less than $5 million in identity-theft insurance. The new bill would replace that limit with coverage lasting for the remainder of each affected person’s life while retaining the insurance requirement.
“We have a responsibility to stand by the federal workers who were put at risk through no fault of their own,” Warner said. “This legislation will ensure those affected continue to receive the identity protection they need, while helping better safeguard personal information from future exploitation.”
The bill would also allow agencies to reimburse federal employees and contractors for privacy tools and services, such as those that remove or limit their personal information online. Agencies would decide whether to offer the reimbursements, which would not be limited to OPM breach victims and would come from their salary-and-expense budgets.
Norton has introduced legislation in the past seeking lifetime protection for OPM victims, beginning after the breaches were disclosed. Similar bills introduced over the years have not become law.
“Lifetime identity protection is the only solution that will give the workers whose data was compromised the peace of mind they deserve,” Norton said in a statement. “Because there is no limit on how long personal information can be exploited, Congress must protect these federal employees and contractors in perpetuity. Thank you to Senator Warner for working with me to secure this vital protection for those affected.”
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


