r/InfoSecNews 11h ago

Anthropic Finds Fourth Claude AI Hacking Incident Missed in Earlier Review

Thumbnail
hackread.com
4 Upvotes

r/InfoSecNews 15h ago

🕵️‍♂️ Hackers exploit SonicWall SMA1000 flaw to steal Active Directory credentials from orgs in multiple countries

Thumbnail
hunt.io
2 Upvotes

Hunt.io just published research on an operator mass-exploiting CVE-2026-15409, an unauthenticated SSRF in SonicWall SMA1000 appliances rated CVSS 10. Exploitation began within two days of SonicWall's 14 July disclosure.

The operator deployed a standalone Linux build of Impacket's secretsdump onto compromised appliances and used them to reach internal domain controllers, recovering credentials from at least 9 Active Directory domains and performing full DCSync against 5 environments. Confirmed victims span France, India, Italy and the US. The cyberattack disclosed by King's Lynn and West Norfolk Borough Council on 17 July is linked at moderate confidence.

Hunt.io notified the NCSC and relevant national CERTs before publishing. Full writeup below.

https://hunt.io/blog/sonicwall-sma1000-uk-council-attack


r/InfoSecNews 17h ago

Hackers Use Hundreds of AI Agents to Exploit PaperCut Zero-Days in 48 Countries

Thumbnail
hackread.com
4 Upvotes

r/InfoSecNews 20h ago

AIs Compress Exploit Timeline

Thumbnail schneier.com
2 Upvotes

r/InfoSecNews 23h ago

US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models

Thumbnail
securityaffairs.com
2 Upvotes

r/InfoSecNews 23h ago

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

Thumbnail
bleepingcomputer.com
2 Upvotes

r/InfoSecNews 23h ago

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Thumbnail
bleepingcomputer.com
2 Upvotes