
Direct Links | Infosec News Feeds
The San Francisco Beat
SFInfoSec aggregates the latest news, podcasts and books covering Cyber Security, Hacking, Infosec, Online Privacy, Cryptography, Threat Research and Vulnerability Disclosures from all the leading sources.
Threatpost The First Stop For Security News
- Student Loan Breach Exposes 2.5M Recordsby Nate Nelson on August 31, 2022 at 12:57 pm
2.5 million people were affected, in a breach that could spell more trouble […]
- Watering Hole Attacks Push ScanBox Keyloggerby Nate Nelson on August 30, 2022 at 4:00 pm
Researchers uncover a watering hole attack likely carried out by APT TA423, […]
- Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firmsby Nate Nelson on August 29, 2022 at 2:56 pm
Over 130 companies tangled in sprawling phishing campaign that spoofed a […]
Krebs on Security In-depth security news and investigation
- Read This Before You Buy That TV Streaming Stickby BrianKrebs on July 30, 2026 at 4:49 pm
Security experts have been sounding the alarm for years about the risks of […]
- LG to Ban Residential Proxies from Smart TV Appsby BrianKrebs on July 22, 2026 at 1:10 am
The home appliance giant LG Electronics USA said this week it plans to suspend […]
- Microsoft Patches a Record 570 Security Flawsby BrianKrebs on July 14, 2026 at 7:22 pm
Microsoft Corp. today released software updates to plug at least 570 security […]
darkreading Public RSS feed
- Chinese Actor Weaponizes Deepseek AI…by Elizabeth Montalbano on August 3, 2026 at 3:42 pm
Researchers from Jesta intercepted and investigated the model, which was […]
- Is There Really a Fix for CISO Fatigue?by Dirk Schrader on August 3, 2026 at 2:00 pm
Accountability without any real authority is driving CISO burnout, and […]
- CISA Issues Fresh SBOM Guidance. Did…by Nate Nelson on July 31, 2026 at 6:13 pm
A couple dozen changes to SBOM fields will make them more comprehensive, but […]
Blog RSS Feed Fortra Blog
- 3 Years In: How Is AI Doing? SANS Weighs Inby Katrina Thompson on December 15, 2025 at 8:09 am
It’s no secret that AI is “here.” It’s been here for three years now, […]
- What Is Log Management and Why you Need itby Anirudh Chand on November 24, 2025 at 6:00 am
It is arguable that log management forms the basis of modern cybersecurity. […]
- What Did We Learn from the NCSC’s 2025 Annual Review?by Josh Breaker-Rolfe on November 21, 2025 at 11:47 am
Earlier this year, the UK’s National Cyber Security Centre (NCSC) released […]
Security Latest Channel Description
- ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young…by Dhruv Mehrotra on August 3, 2026 at 10:00 am
Internal documents show ICE’s DNA collection has skyrocketed in the second […]
- 8 Best Password Managers (2026), Tested and Reviewedby Scott Gilbertson on August 2, 2026 at 11:30 am
Keep your logins locked down with our favorite password management apps for PC, […]
- 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iranby Matt Burgess, Maddy Varner, Dell Cameron, Andy Greenberg on August 1, 2026 at 10:30 am
Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges […]
- 7MS #733: Tales of Pentest Pwnage – Part 87by Brian Johnson on July 31, 2026 at 4:55 pm
Hey friends! Today’s episode comes to you from a parking lot in the rain, […]
- 7MS #732: Tales of Pentest Pwnage – Part 86by Brian Johnson on July 24, 2026 at 12:07 pm
Hey friends! Welcome back to another Tales of Pentest Pwnage — my favorite […]
- 7MS #731: CARTP – Cloud Red Team Tactics for Attacking and Defending Azure…by Brian Johnson on July 17, 2026 at 12:17 pm
Hey friends! Fair warning: today’s episode is a bit of an emotional […]
- More on the OpenAI Agent’s Attack on Hugging Faceby Bruce Schneier on August 3, 2026 at 5:02 pm
Hugging Face has published a detailed timeline of the attack. From the […]
- The OpenAI Hack Shows the Genie Is Out of the Bottleby Bruce Schneier on August 3, 2026 at 10:47 am
This essay originally appeared in Foreign Policy. Earlier this month, two of […]
- Friday Squid Blogging: Squid Helps Discover New Marine Speciesby Bruce Schneier on July 31, 2026 at 9:06 pm
The Squid is a new scientific machine: One of the technological breakthroughs […]
GRAHAM CLULEY Cybersecurity keynote speaker
- The $5 million threat: AI Is supercharging phishing attacksby Graham Cluley on July 31, 2026 at 11:43 am
According to the newly-published study, phishing and social engineering are […]
- North Korea’s elite hackers turned on their own government – and got caughtby Graham Cluley on July 30, 2026 at 9:17 am
For years, North Korea’s state-trained hackers have been one of the world’s […]
- Smashing Security podcast #478: This job interview could destroy your companyby Graham Cluley on July 29, 2026 at 11:09 pm
You’ve been headhunted for a great job in cryptocurrency. All you have to do is […]
BleepingComputer BleepingComputer – All Stories
- N-able warns of N-central auth bypass flaw exploited in attacksby Bill Toulas on August 3, 2026 at 5:00 pm
N-able is warning customers that hackers are exploiting an authentication […]
- ExfilSquad hackers leak info of over 100,000 UK police officers, staffby Bill Toulas on August 3, 2026 at 3:04 pm
A cyberattack on the U.K.’s Police National Legal Database (PNLD) has […]
- Inside the Underground Business of the Android BTMOB RAT malwareby Sponsored by Flare on August 3, 2026 at 2:45 pm
Flare researchers analyzed thousands of underground posts to examine how the […]
TechCrunch Startup and Technology News
- WhatsApp says it is is fixing an issue that disabled several accountsby Ivan Mehta on August 3, 2026 at 5:46 pm
Meta says it’s restoring access to WhatsApp accounts that were mistakenly […]
- Sequoia’s Shaun Maguire leads $1B round for nuclear startup Valar Atomicsby Julie Bort on August 3, 2026 at 5:16 pm
Valar Atomics raised $1 billion at a $6 billion valuation after signing a […]
- Base Power raises another $1B to save the grid using backyard batteriesby Tim De Chant on August 3, 2026 at 4:46 pm
Base Power’s $1 billion round will help the startup ramp production of its […]
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to [email protected]
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected…by [email protected] (The Hacker News) on August 3, 2026 at 4:24 pm
Malware running as an ordinary user on a Windows machine can sign into a […]
- INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flawsby [email protected] (The Hacker News) on August 3, 2026 at 4:15 pm
The INC Ransomware operation has emerged as the “dominant threat actor” […]
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks…by [email protected] (The Hacker News) on August 3, 2026 at 2:03 pm
This week kept coming back to permission. A model crossed a boundary. A wallet […]
The DFIR Report Actionable Cyber Threat Intelligence
- From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akiraby editor on June 29, 2026 at 1:07 pm
Key Takeaways This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same campaign. This report contains data from both intrusions. We plan to release a DFIR Labs The post From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira appeared first on The DFIR Report.
- Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomwareby editor on May 11, 2026 at 2:05 pm
The EtherRAT malware family was first reported by Sysdig back in December 2025. At that time, the initial access vector was exploitation of CVE-2025-55182 (React2Shell) targeting Linux servers. In March 2026, a Windows variant campaign was reported by Atos, with their investigation showing evidence of activity going back to the previous December. In April, we The post Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware appeared first on The DFIR Report.
- Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvestingby editor on April 22, 2026 at 2:51 pm
Key Takeaways We identified an exposed server that provided unusual visibility into a large-scale, multi-victim exploitation and collection operation. Artifacts on the host showed that Claude Code and OpenClaw were embedded in the operator’s day-to-day workflow, supporting troubleshooting, orchestration, and refinement of the collection pipeline. This AI-assisted workflow resulted in the modular platform Bissa scanner The post Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting appeared first on The DFIR Report.
Biz & IT – Ars Technica Serving the Technologist since 1998. News, reviews, and analysis.
- Claude published malicious code to the Internet and attacked 3 real companiesby Dan Goodin on July 31, 2026 at 8:39 pm
Had the hacks used conventional methods, someone would likely go to prison.
- Max-severity Exchange server flaw under active exploitation by Kremlin hackersby Dan Goodin on July 30, 2026 at 8:57 pm
Exploits can give persistent server access that survives credential rotation […]
- Mythos attack on 3rd-round PQC algorithm candidate puts it out of commissionby Dan Goodin on July 29, 2026 at 10:07 pm
HAWK withstood years of testing that had yet to uncover a fatal weakness found […]
Websec Cybersecurity Blog Expert insights, trends, research findings, and best practices from Websec security team to help you strengthen your organization’s security posture.
- A Comparison Between the Real User ID and the Effective User ID is not Enough to Prevent Privilege Escalationby Websec Security Team on October 3, 2023 at 7:39 pm
In Unix-like systems, processes have a real and effective user ID determining their access permissions. While usually identical, they can differ in situations like when the setuid bit is activated in executables.
- Websec DevSecOps Webinarby Websec Security Team on August 29, 2022 at 12:00 am
Roberto Salgado and Kobalt.io’s Miki Fukushima are hosting a free webinar on September 20, 2022 covering why application security matters, the shift to developer-first security, and a practical roadmap for embedding security into DevSecOps.
- CVE-2022-21404: Another story of developers fixing vulnerabilities unknowingly because of CodeQLby Websec Security Team on May 19, 2022 at 6:18 pm
How CodeQL may help reduce false negatives within Open-Source projects. Taking a look into a deserialization vulnerability within Oracle Helidon (CVE-2022-21404).

















