Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.
International Press – Newsletter
DentaQuest Data Breach Potentially Impacts Over 23 Million People
Crime: Risk, Responsibility, and Accountability
ShinyHunters Claims Ernst & Young Hack
When AI Becomes the Attacker: Understanding Autonomous Offensive Security Agents
US accuses American of allegedly wiping his phone using a ‘duress’ password during border search
Hacker wipes European country’s entire land registry database, paralyzing real-estate market
Malware
TAG-195 Upgrades MaaS Ecosystem with Modular Tools
SourTrade: Browser-Assembled Malware Delivered Through Malvertising
MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions
Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service
Hacking
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Investigating three real-world incidents in our cybersecurity evaluations
Discovering cryptographic weaknesses with Claude
DNS Poisoning Tactics Expand to Hospitality Wi-Fi
Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities
The hacker who humiliated spyware makers and was never caught
Millions of California-bought cars can be hijacked via Bluetooth
Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker
eBPF Warfare: Subverting Security Solutions Through Kernel-Space Manipulation
Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
What Can an Attacker Find With an LLM?
Intelligence and Information Warfare
Inside a DPRK BlueNoroff ClickFix Kit
Behind the Lithuanian Label: What’s Inside Nicegram and eSIM Plus
Israel’s Palantir Rival Is Selling $1 Million Spy Vans To U.S. Cops
Trump administration bans new Chinese humanoid robots, to protect US AI buildout
ClickFix, EtherHiding & a DPRK Wallet Trail
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
Coordinated “cyberattack” on Minnesota water utilities: What you need to know
Cybersecurity
OpenAI’s rogue agent compromised a customer at a second tech firm, executive says
Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features
Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week
A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach
Stronger with every update: How we’re making Chrome and the web safer in the AI Era
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)