Breaking News – Cyber Threats – 2026-08-04 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-08-04 13:00 PDT
- New XCSSET variant targets macOS devs via compromised Xcode projects
BleepingComputer • 2026-08-04 12:03 • www.bleepingcomputer.com
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. […]
https://www.bleepingcomputer.com/news/security/new-xcsset-variant-targets-macos-devs-via-compromised-xcode-projects/ - Iran Cyberattacks Against Minnesota Water Systems
Schneier on Security • 2026-08-04 12:00 • www.schneier.comAttribution is preliminary, and so far it seems no real damage.
And it seems like this is a campaign that has targeted at least https://www.schneier.com/blog/archives/2026/08/iran-cyberattacks-against-minnesota-water-systems.html
- 77 Open VSX extensions found harvesting developer info
BleepingComputer • 2026-08-04 11:50 • www.bleepingcomputer.com
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. […]
https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/ - Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Hacker News • 2026-08-04 10:27 • thehackernews.com
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.“Greatness supports AiTM [adversary-in-the-middle] credential and
https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html - Massive ChainDrop npm supply-chain attack infects hundreds of packages
BleepingComputer • 2026-08-04 08:24 • www.bleepingcomputer.com
Self-propagating malware named ‘ChainDrop’ has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. […]
https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/ - Varonis Agent IBAC keeps AI agents within their intended boundaries
BleepingComputer • 2026-08-04 07:00 • www.bleepingcomputer.com
AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user’s intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries. […]
https://www.bleepingcomputer.com/news/security/varonis-agent-ibac-keeps-ai-agents-within-their-intended-boundaries/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.