Infosecurity News

Six npm Packages Read C2 Addresses From Ethereum Wallet
Six npm packages queried an Ethereum wallet to locate C2 infrastructure

Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification
Cursor fixed a pre-trust code execution path in three days then closed the report as informative

Suisan City, California, Responds to Cyber Incident Amid Wave of US Local Government Attacks
Police and fire response has been impacted by the attack on Suisan City, while two other local authorities have been hit by cyber incidents in the past week also

OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber
Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models

Logistics Giant Ceva Suffers Data Breach Impacting European Clients
Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius

OpenAI Pauses Some Development of Astra Model on Security Concerns
OpenAI is tightening restrictions on testing of its upcoming Astra model due to security concerns

Only Half of UK Manufacturers Have a Cyber Incident Response Plan
Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data

WordPress Plugins Compromised Without a Single File Change
Poisoned JSON feed let attackers backdoor WordPress sites without changing any plugin files

“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls
Tenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reports

Go-Based macOS Malware Steals Crypto and Secrets
A macOS malware variant has been detected stealing crypto, passwords and more

US Sanctions Iranian $6bn Crypto “Exchange” Shelbit
TRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchange

Healthcare and Victim Support Charities Affected by Beacon Cyber Incident
Beacon has informed around 1500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized actor

Google Links Redact Extortion Group to BlackFile Rebrand
BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns

Ransomware Surges in July After Q2 Lull
Finance, technology and healthcare sectors were particularly heavily targeted in July, according to Comparitech

Toolkit Hidden Inside Oracle Database Evades Endpoint Tools
Attackers used SQL injection to compile a post-exploitation toolkit inside an Oracle database

TeamPCP Traced Back to 2020 Cryptojacking Operation
Oligo Security has linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020

Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
One of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI systems

Violent Physical Crypto Thefts Surge to $30m in Losses
So-called “wrench attacks” have resulted in $30m in losses so far in 2026, says Chainalysis

Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign
A Canadian hacker has admitted involvement in the widespread compromise of 165 Snowflake customer accounts used to steal data and extort victims



