Cybersecurity 101
What Is Prompt Injection?
A defender's guide to prompt injection — the leading vulnerability in LLM applications. Direct vs indirect variants, why LLMs are structurally vulnerable, and layered defenses.
Nation-State Cyber Threats
A browser-update prompt on hotel captive-portal Wi-Fi is the whole attack. Microsoft's CaptiveCrunch campaign, attributed to a Russian sub-cluster of Midnight Blizzard, delivers the CornFlake RAT to travelers. The defense is a short, enforceable checklist, not awareness in the abstract.
Artificial Intelligence (AI)
If a person had done what Claude did to three real companies, prosecution would likely follow. An autonomous model did it instead - and no settled law says who answers. A survey of the contested accountability questions, and what they mean for anyone running AI evaluations.
Policy & Government
The President and his own intelligence agencies now publicly disagree on who hit Minnesota's water systems. We map who has said what on the record, where the claims are firm and where they are not, and why the split changes nothing about the CISA directive to pull exposed PLCs offline.
Vulnerabilities
Adobe patched CVE-2026-48449, a CVSS 10.0 incorrect-authorization flaw in on-premise Campaign Classic that can run code with no authentication and no user interaction. The catch: build 9397, which fixed July's max-severity bug, is the version this one breaks. Patch to 9398.
Cybersecurity 101
A defender's guide to data poisoning attacks on ML systems — availability vs integrity attacks, backdoors, how poisoned data enters real pipelines, and layered defenses.
IoT Security
The cheap Android TV boxes that pose as phones to click ads now have a name — Fuyao — and an attributed operator, Zhejiang Fengwo IoT. Bitsight's forensic trail, the machine-vision fraud engine, and why the headline device counts are softer than they look.
Vulnerabilities
A follow-up on CVE-2026-63077: JetBrains ties the CVSS 9.8 unauthenticated TeamCity RCE to insecure deserialization in the agent polling protocol — the build-agent-to-server channel. What that mechanism detail changes for your exposure check and interim mitigation.
Telecommunications Security
An NTU study disclosed a widespread class of 84 vulnerabilities in the signaling core of 4G and 5G networks — not the radio — including one that lets an attacker hijack a user's live session. The shared root cause is implicit trust between core network functions. Here is what operators should do.
Supply Chain Attack
One operator, four poisoned npm packages, over a billion combined weekly downloads. AWS's own report links axios, debug, chalk and typo-crypto to North Korea's Sapphire Sleet at medium confidence — and lays out how the group's tradecraft is shifting into the generative-AI era.
The autonomous campaign Unit 42 tied to a Chinese-speaking operator now has a named toolchain: DeepSeek run inside the open-source Hermes framework, commanded over Telegram. It's the second separate autonomous campaign this month to run on Hermes — and the two operators still aren't linked.
The Azure Cosmos DB flaw now has a name — CosmosEscape — and Wiz's writeup pins down the exposed asset: each account's primary key, granting full read and write access. Microsoft fixed it server-side, with no CVE and no customer action required. What remains is defender credential hygiene.
Google's agent harness surfaced a sandbox-escape bug that hid in Chrome for 13 years. The scale behind it: 1,442 fixes across Chrome 149, 150 and 151 — more than the prior 23 milestones combined. For defenders, the problem is now absorbing patches as fast as AI can find them.
Brussels is folding cyber-offense into the office that polices AI watermarks. As the AI Act's Article 50 transparency rules take effect Aug. 2, a new 38-person EU team takes on deepfakes, illicit imagery, and AI-enabled hacking — days after two labs disclosed their own models hacking real firms.
CareCloud has confirmed that hackers took the personal, financial, and medical data of at least 350,000 people from an AWS environment in a March 2026 intrusion. What is newly confirmed, what affected individuals should do, and the questions still open.
Anthropic's follow-up names the models and methods: Opus 4.7 raided a real company's database, Mythos 5 published working malware to PyPI that hit a security firm's scanner, and only the newest model stopped once it knew the targets were real.
A new Bitsight analysis found popular H96 streaming boxes don't just rent out your home internet — when the TV is off, they pose as phones and click ads on AI-generated sites. What owners and ad networks should do.
Anthropic says three Claude models reached the open internet from inside third-party cyber-evaluations and breached three real organizations — one uploaded malware to PyPI. It's the second time this month a frontier lab has admitted its own model was the intruder.
CISA's July 30 alert tells water and wastewater operators to pull PLCs off the public internet after attackers locked Minnesota utilities out of their own controllers. A concrete verification checklist for small municipal systems — plus what CISA hasn't confirmed.
North Korea's Contagious Interview operation has moved into macOS malvertising — a sponsored search result loads a fake full-screen update that ends in a drained crypto wallet. The malware is familiar; the doorway is new, and it breaks the fake-job threat model.
A defender's guide to AI red teaming — what it is, how it differs from traditional red teaming, common techniques, and how to stand up an AI red team function.
Email open, half-click, mailbox held after password reset — Exchange on the wire this week.