Key takeaways
OAuth client ID spoofing defeats detections that key off application name or a known application ID, because the field itself is fabricated, rotated or blank.
AADSTS700016 paired with an unrecognized client ID can mean valid credentials, not a broken app r...
Can trauma show up as misconduct? Paul Gullon-Scott explores how cumulative trauma and organisational stress can shape behaviour in policing and digital forensics and why earlier, trauma-informed support could make all the difference.
TRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchange
Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them.
The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek.
AI is having a seismic impact on the cybersecurity market. Record-shattering amounts of venture capital is flowing into a new generation of startups focused on AI cybersecurity.
At the same time, established cybersecurity vendors are racing to integrate AI and agentic AI fe...
Kimi K3 bypassed a UK cybersecurity test by accessing GitHub, cloning the benchmark and reading its solutions instead of solving the challenge Sometimes the smartest move isn’t solving the puzzle, it’s noticing nobody locked the door to the answer key. That’s essentially what happened when Moonshot’...
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer.
The names of the extensions are below -
helper-beeps.solidity-pro
web3devtoolsx.so...
OpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot rule out the model reaching the critical capability level for cybersecurity under its Preparedness Framework. The Preparedness Fra...
GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. GitHub’s Advisory Database now ingests m...
A list of topics we covered in the week of August 3 to August 9 of 2026
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity.
In response to the discovery, the AI upstart said it's imple...
Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a signed in-toto attestati...
Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. Vaults remain on the device or in a cloud storage service selected by the user. Users who work across multiple devices can in...
The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies.
The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek.
Boards want evidence that security controls and architecture reduce business risk, expressed in terms of resilience, consequence, and decision relevance. Translating technical findings into business language remains a major time burden for CISOs, who are calling for simpler data delivery, better fra...
The EU’s fight to regulate AI models entered a new chapter on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. The AI Act is the EU’s law regulating AI, the first broad legal framework of its kind. It creates a common set of rules for AI sy...
PLUS: Hiveminds are emerging to hack the planet, and open-weight models are the new new red scare.
Le district scolaire de Delta a été victime d'un incident de cybersécurité affectant son environnement informatique DeltaLearns.ca. Le district a découvert l'incident le 10 août 2026, lorsque des activités non autorisées ont été détectées, rendant le site indisponible. Bien qu'il n'y ait pas de preu...
Les pirates informatiques du groupe Qilin ont dérobé des données clients chez WEBA et ont partiellement paralysé ses systèmes. Aucune rançon n'a été versée ; les magasins et la boutique en ligne sont à nouveau opérationnels depuis le 12 août. Les clients doivent rester vigilants face aux tentatives...