Threat Intelligence

Live threat and AI news from CISA, Krebs on Security, Bleeping Computer, SANS ISC, TechCrunch, The Verge, and Simon Willison — cross-referenced to open markets.

15-min cache
SANS ISCHIGHAug 30, 2026

YARA-X 1.20.0 Release, (Sun, Aug 30th)

YARA-X's 1.20.0 release brings 14 improvements and 13 bugfixes.

Simon WillisonMEDIUMAIAug 29, 2026

Introducing Hy4 Preview

Introducing Hy4 Preview New open weight text input (no vision) LLM from Chinese company Tencent today: 770B total parameters, 49B active parameters, 1M token context window, 1.56TB on Hugging Face . This is a big size increase from their previous Hy3 in July, which was 295B, 21B active, 256,000 cont

Bleeping ComputerHIGHAIAug 29, 2026

Anthropic is cutting Claude Code's current weekly limits by 17%

Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. [...]

TechCrunch AIMEDIUMAIAug 29, 2026

Sony Music, Warner sue Anthropic, alleging a “brazen campaign” of intellectual property theft

This latest lawsuit is particularly broad and homes in on accusations of illegal piracy.

The Verge AIMEDIUMAIAug 29, 2026

Sony Music and Warner Chappell are suing Anthropic

Sony Music and Warner Chappell have filed suit against Anthropic in the US District Court for the Northern District of California seeking damages for "tens of thousands" copyrighted works. The companies are asking for up to $150,000 per work, plus up to $25,000 for each instance when identifiable co

TechCrunch AIMEDIUMAIAug 29, 2026

“We’re not doing 30 bets a year”: Vijay Pande on betting small after running $4 billion at a16z

Vijay Pande — who left a16z's roughly $4 billion biotech practice last year to start the much smaller, AI-native VZVC — talks about why biology is finally shifting from a "discovery" science to an "engineering" one, why clinical trials are still brutally expensive, and why he thinks open, shared dat

Bleeping ComputerHIGHAug 29, 2026

Brave browser adds email aliases to help users evade tracking

The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]

TechCrunch AIMEDIUMAIAug 29, 2026

Nvidia’s AI advantage is moving beyond the GPU

The new generation of data center systems is increasing efficiency with smarter traffic control instead of just more processor cycles.

The Verge AIMEDIUMPhishingAIAug 29, 2026

Musicians-turned-detectives are hunting for AI grifters

As audio-focused generative tools and platforms have gotten more sophisticated, the internet has become increasingly filled with AI-generated music whose melodies and vocals are algorithmically derived from the work of human artists. While some of the people pumping out this kind of content immediat

Bleeping ComputerHIGHRansomwareAug 28, 2026

McKesson discloses breach after ShinyHunters claims patient data theft

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]

Simon WillisonMEDIUMVulnerabilityAug 28, 2026

Just a rumour of a bug is enough to find a security exploit these days

Just a rumour of a bug is enough to find a security exploit these days Anil Madhavapeddy is a professor of computer science at Cambridge and a core maintainer of the OCaml compiler. In this somewhat alarming post he reports that security issues in OCaml projects are seeing evidence of attempted expl

TechCrunch AIMEDIUMAIAug 28, 2026

Neocloud Lambda secures $1B in debt to buy more chips

Neocloud Lambda has raised $1B in private debt to buy Nvidia AI chips and lease them to Microsoft. It's the latest in a string of loans, underscoring the high cost of the AI boom.

TechCrunch AIMEDIUMAIAug 28, 2026

An Anthropic researcher just gave us a peek at self-improving AI

Given 10 benchmarks for specific misaligned behaviors, the automated systems were able to improve performance on every single one without degrading overall performance.

Bleeping ComputerHIGHVulnerabilityAug 28, 2026

PaperCut releases second emergency patch for exploited flaws

PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]

TechCrunch AIMEDIUMAIAug 28, 2026

Open-weight AI companies are the Valley’s hottest acquisition targets

There's a lot of capital pouring into the business of giving models away.

Bleeping ComputerHIGHVulnerabilityAug 28, 2026

GiveWP WordPress donation plugin flaw lets hackers execute server commands

A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]

Bleeping ComputerHIGHAug 28, 2026

68-year-old imprisoned after making $1.3 million by pirating IPTV services

A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years. [...]

The Verge AIMEDIUMAug 28, 2026

Trump’s EPA wants to let data centers hide their air pollution

Just as new data centers face growing backlash from neighboring communities, the US Environmental Protection Agency (EPA) is about to make it harder for people to weigh in on any pollution those centers create. The EPA plans to toss out a federal rule requiring public notice and an opportunity to co

SANS ISCHIGHAug 28, 2026

Some Malicious PE Stats, (Thu, Aug 27th)

During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[1]. Can we go a bit further? I (vibe-)coded a Python script based on th

The Verge AIMEDIUMAIAug 28, 2026

Anthropic was illegally blacklisted by the Trump administration, court rules

On Thursday, a judge ruled that the Pentagon's blacklisting of Anthropic earlier this year was unconstitutional, delivering the AI lab a win in a monthslong rollercoaster of a battle with the Trump administration. The lawsuit, filed in March in a California district court, accused the Trump administ

Simon WillisonMEDIUMAIAug 27, 2026

Breaking Claude Code Opus 5 Auto Mode

Breaking Claude Code Opus 5 Auto Mode Anthropic are putting a great deal of faith in Claude Code's auto mode for protecting their coding agent users against prompt injection attacks. They recently made that the default and have made bold claims about its effectiveness. Johann Rehberger is one of the

The Verge AIMEDIUMAIAug 27, 2026

Google’s AI note-taking app now allows you to interact with books

Google's AI note-taking app, Gemini Notebook, can now pull information from the books you've purchased. The new "Expert Intelligence" feature allows you to bring titles from Google Play Books directly into Gemini Notebook, which means you can ask questions about the material, as well as generate pla

The Verge AIMEDIUMAIAug 27, 2026

Jensen Huang says Nvidia achieved AGI, again — not that it matters

On Nvidia's earnings call Wednesday, CEO Jensen Huang casually announced the company had "achieved AGI," one of the tech industry's ultimate goals some of its biggest players have spent years chasing. Almost immediately, Huang dismissed the coveted milestone as "senseless." He's right. For the suppo

CISA AlertsCRITICALVulnerabilityAug 27, 2026

Rockwell Automation OTTO Fleet Manager

View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. The following versions of Rockwell Automation OTTO Fleet Manager are affected: OTTO Fleet Manager <=V2.3

CISA AlertsCRITICALVulnerabilityAug 27, 2026

Xiiaozet LK100W

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The following versions of Xiiaozet LK100W are affected: LK100W <2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943) CVSS Vendor Equipment Vulnerabilities v3 9.8 Xiiaozet X

CISA AlertsCRITICALVulnerabilityAug 27, 2026

Mitsubishi Electric CNC Series (Update A)

View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products. The following versions of Mitsubishi Electric CNC Series (Update A) are affected: Mitsubishi Electric M80

CISA AlertsCRITICALVulnerabilityAug 27, 2026

Mitsubishi Electric Multiple FA Products (Update D)

View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product. The following versions of Mitsubishi Electric Multiple FA Pr

Beta Feedback