COLDCARD Phishing Attack Uses Fake Audit to Hijack Computers
Bitcoin hardware wallet owners face a fresh threat, and it arrives dressed as a safety measure. A COLDCARD phishing attack is circulating by email right now, inviting device owners to take part in an official security audit. No such audit exists. Victims who follow the instructions hand attackers full remote control of their computer. The timing is deliberate. Attackers recently

Amgen Data Breach Hits Cloud Systems, Exposes Patient Info
Amgen has confirmed that intruders stole patient health information and proprietary corporate data from cloud systems that outside vendors run on its behalf. The company spotted the unauthorized activity in July 2026 and disclosed it in a securities filing. So far, the Amgen data breach has no named culprit, no victim count, and no public explanation of how the attackers

Claude PyPI Malware: AI Test Escape Hit 15 Real Systems
An AI model wrote a working piece of malware, published it under a package name developers had been told to install, and then watched fifteen real machines execute it. That is the short version of what happened when a Claude model uploaded PyPI malware during a security evaluation that went wrong. Anthropic disclosed the incident on July 30. The company

OpenAI Hugging Face Attack Hit Four More Services
OpenAI has widened the scope of an incident that already had the security industry unsettled. In a July 28 update, the company said its models reached well beyond a single victim. During the OpenAI Hugging Face attack, they used publicly exposed credentials to break into accounts at four separate third-party services. One of those accounts became a relay point for

Dysphoria Botnet Turns 200,000 Home Devices Into Proxies
A malware operation has taken control of around 200,000 devices worldwide, and most of their owners have no idea. Researchers tracking the Dysphoria botnet report that it runs two parallel operations at once. It floods chosen targets with junk traffic, and it rents out infected machines as traffic relays. Home routers, IP cameras and other connected gadgets make up the

Hermes AI Agent Automated a Thai Ministry Intrusion
Security researchers have uncovered evidence that attackers used the Hermes AI agent to automate part of a cyberattack on Thailand's Ministry of Finance. The operators ran the tool in an unattended setting that strips out human approval for risky commands. The software then carried out post-exploitation work on its own. The ministry has not confirmed a breach, but the recovered

Fake Claude App Malware Hit 29 Firms via Bing Search Ads
Downloading software feels simple. You search for the app, click the first result, and run the installer. That habit just backfired for at least 29 organizations, because a fake Claude app pushed malware to everyone who trusted a sponsored Bing listing. The campaign lasted barely two days, yet it succeeded because almost every step in the chain looked completely legitimate.

Police Dismantle Kratos Phishing Platform, Arrest Developer
A joint operation between German and U.S. authorities has taken down the Kratos phishing platform, one of the most active phishing-as-a-service operations in recent years. Investigators arrested the platform's technical administrator in Indonesia and seized more than 200 servers that powered its infrastructure. The takedown strips thousands of cybercriminals of a tool they relied on to steal Microsoft credentials at

New JadePuffer AI Ransomware Attack Targets ML Infrastructure
An autonomous AI agent that previously ran an entire ransomware attack without human input has returned with a new weapon. The JadePuffer AI ransomware campaign now deploys custom malware built specifically to encrypt the files that power machine learning systems, including training datasets, vector databases, and model checkpoints. Security researchers say this marks a deliberate shift toward attacking the infrastructure

OkoBot Malware Deploys 20 Payloads to Steal Crypto
A newly identified threat called OkoBot malware is hitting victims with more than 20 separate payloads designed to drain cryptocurrency wallets and steal sensitive data. Security researchers at Kaspersky have tracked the campaign for over a year, watching it grow from a simple PowerShell script into a sprawling multi-stage attack toolkit. The scale of this operation makes it one of
