Accenture Confirms Breach After Threat Actor Offers 35GB of Source Code and Keys for Sale
Summary Global consulting and IT services giant Accenture has confirmed a security breach after a threat actor known as “888” claimed to have stolen 35 GB of data from the…
Japanese Telecom Giant KDDI Confirms Breach Affecting Over 12 Million Customers
Summary Japanese telecommunications giant KDDI, the country’s second-largest mobile carrier with $32.4 billion in annual revenue, has confirmed that a breach of an email platform used by five internet service…
Anthropic’s Claude Code Caught With Hidden Tracker — Company Says Steganographic User Profiling Was an “Experiment”
Summary Independent developer “Thereallo” discovered a hidden steganographic tracking function buried in Anthropic’s Claude Code client (version 2.1.196) that quietly encoded user traffic routing details for Anthropic’s backend. The mechanism…
Illinois Signs First-in-Nation AI Safety Act — Mandatory Annual Audits and 72-Hour Incident Reporting for Frontier Models
Summary Illinois Governor J.B. Pritzker signed the Artificial Intelligence Safety Measures Act (SB 315) into law on July 6, 2026, making Illinois the first state in the nation to mandate…
Avalon Malware Framework Uncovered — Modular Toolkit Bundles Credential Theft, EDR Evasion, and CrownX Ransomware
Summary Blackpoint Cyber’s Adversary Pursuit Group has uncovered “Avalon,” a previously undocumented modular malware framework that bundles credential harvesting, lateral movement, remote access, backup and recovery disruption, and ransomware deployment…
“Exploitarium” Zero-Day Dump: Researcher Publishes 30+ Unpatched Exploits Including Critical libssh2 RCE
Summary A pseudonymous security researcher going by “bikini” has published “Exploitarium,” a GitHub repository containing over 30 proof-of-concept exploits for zero-day vulnerabilities in widely used open-source projects — without performing…
First Fully Autonomous AI Ransomware Attack Identified — JadePuffer Operation Ran End-to-End Without Human Input
Summary Researchers at cloud security company Sysdig have identified what they believe to be the first fully autonomous ransomware attack conducted entirely by an AI agent. Linked to the JadePuffer…
Linux “Bad Epoll” PoC Exploit Published — Unprivileged Users Can Gain Root on Desktops, Servers, and Android
Summary Technical details and a working proof-of-concept exploit for CVE-2026-46242, a Linux kernel privilege escalation vulnerability dubbed “Bad Epoll,” have been publicly released. The vulnerability allows unprivileged local users to…
FBI and Google Dismantle NetNut Residential Proxy Network — Over 2 Million Hijacked Home Devices Cut Off
Summary The FBI, in partnership with Google’s Threat Intelligence Group and other industry partners, has successfully disrupted NetNut, one of the world’s largest commercial residential proxy networks. Also tracked as…
Adobe ColdFusion Max-Severity RCE (CVE-2026-48282) Exploited Within Hours of Disclosure
Summary A maximum-severity remote code execution vulnerability in Adobe ColdFusion, tracked as CVE-2026-48282, is now being actively exploited in the wild — and attackers moved fast. Within just two hours…
