Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-29 08:00 PDT
- Hackers target over 30 Minnesota water utilities in coordinated OT attack
BleepingComputer • 2026-07-29 07:55 • www.bleepingcomputer.com
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in “a coordinated cyberattack.” […]
https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack/ - Your AI Agents Are Guessing at Scale: Permissions Decide the Damage
BleepingComputer • 2026-07-29 07:02 • www.bleepingcomputer.com
AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI. […]
https://www.bleepingcomputer.com/news/security/your-ai-agents-are-guessing-at-scale-permissions-decide-the-damage/ - Windows 11 KB5101684 update released with 42 changes and fixes
BleepingComputer • 2026-07-29 06:56 • www.bleepingcomputer.com
Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system. […]
https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5101684-update-released-with-42-changes-and-fixes/ - Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
The Hacker News • 2026-07-29 06:48 • thehackernews.com
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response.Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls.
Braham’s water plant went offline, and the city asked residents to minimize
https://thehackernews.com/2026/07/coordinated-cyberattack-targets-30.html - Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
The Hacker News • 2026-07-29 06:42 • thehackernews.com
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years.According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies
https://thehackernews.com/2026/07/nine-year-fraud-campaign.html - Mythos Asks the Right Question. It Doesn't Answer It.
The Hacker News • 2026-07-29 05:15 • thehackernews.com
AI is compressing exploit timelines. The real question isn’t whether your vulnerability management playbook needs to change, it’s which part of it you’ve been getting wrong all along.The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change?
The honest answer is
https://thehackernews.com/2026/07/mythos-asks-right-question-it-doesnt.html - Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
The Hacker News • 2026-07-29 04:57 • thehackernews.com
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser’s renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update.
“No settings or additional user interaction are required,” Eten Zou,
https://thehackernews.com/2026/07/researchers-show-single-malicious.html - 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
The Hacker News • 2026-07-29 04:13 • thehackernews.com
Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack.According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by Vanson Bourne in January
https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html - These near-mint ASUS Chromebook refurbs are only $145
BleepingComputer • 2026-07-29 04:12 • www.bleepingcomputer.com
Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade “A” rating, but it still only costs $144.97 (reg. $369.99) on sale. […]
https://www.bleepingcomputer.com/news/security/these-near-mint-asus-chromebook-refurbs-are-only-145/ - Long-Lived Vulnerability in Microsoft Secure Boot
Schneier on Security • 2026-07-29 04:01 • www.schneier.comMicrosoft’s Secure Boot has had a serious vulnerability for most of its existence.
An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the softwa…
https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html - Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
The Hacker News • 2026-07-29 04:00 • thehackernews.com
The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law.The principal security agency said the instant messaging platform “failed to remove numerous channels, chats, and bots on the platform that are
https://thehackernews.com/2026/07/russia-charges-telegram-founder-pavel.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
