Cussins Enterprises LLC

Technology is a paint brush on the canvas of life. 
What can we paint for you?

Cybersecurity News

Awareness of what is happening is the 1st to a secure system.

Threat Post

WP HTTP Error: cURL error 52: Empty reply from server

Beeping Computer

https://www.bleepingcomputer.com/feed/ is invalid XML, likely due to invalid characters. XML error: XML_ERR_NAME_REQUIRED at line 1, column 1342

Motherboard

WP HTTP Error: A valid URL was not provided.

Data Breeches

Developing: AnMed reports phone and internet outage impacting all hospital locations; ERs remain open

On July 26, 2026Source: DataBreaches.NetBy Dissent
Categories: Health Data, U.S.

Media outlets are reporting that all AnMed  hospital locations are experiencing a phone and internetRead more

A-list directors, actors and celebrities exposed in Tribeca film festival data leak

On July 26, 2026Source: DataBreaches.NetBy Dissent
Categories: Exposure

Researcher Jeremiah Fowler provides today’s entry in the “No Need to Hack When It’Read more

US House Votes to Extend Cyber Sharing Law for 10 Years

On July 25, 2026Source: DataBreaches.NetBy Dissent
Categories: Breach Laws, Legislation, Of Note, U.S., CISA

Chris Liotta reports: Lawmakers voted to extend a key cyberthreat sharing law for another decade, atRead more

AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’

On July 25, 2026Source: DataBreaches.NetBy Dissent
Categories: Health Data, Insider, Non-U.S.

Caitlin Powell reports: A male registered nurse from northern Sydney has been charged after allegedlRead more

No Need to Hack When It’s Leaking: Click to Pray edition

On July 25, 2026Source: DataBreaches.NetBy Dissent
Categories: Exposure, Miscellaneous

Jessica Lyons reports on today’s entry in the “No Need to Hack When It’s LeakingRead more

Suspect arrested in investigation into sadistic “764” group

On July 24, 2026Source: DataBreaches.NetBy Dissent
Categories: Miscellaneous, Non-U.S., 764, self-harm, The Com

From the Dutch Police: In an investigation into so-called online sadistic COM networks, a suspect frRead more

Crime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.

On July 24, 2026Source: DataBreaches.NetBy Dissent
Categories: Business Sector, Commentaries and Analyses, Education Sector, Hack, Of Note, U.S., #Transparency, accountability, BlueLeaks 2.0, Crime Stoppers, Navigate360, P3 Campus, P3 Global Intel

Previous reporting about the Navigate360 breach focused on tips submitted by students, teachers, andRead more

Origin silent on settlement as alleged fired employee breach detail emerges

On July 24, 2026Source: DataBreaches.NetBy Dissent
Categories: Non-U.S.

Roxanne Libatique reports: Origin Energy has declined to comment on a public claim that it privatelyRead more

T-Mobile violated WA data breach notification law, judge rules

On July 24, 2026Source: DataBreaches.NetBy Dissent
Categories: Breach Laws, State/Local, U.S.

Mirandah Davis-Powell reports: T-Mobile failed to properly notify customers of a data breach in whicRead more

Furious KPMG boss expels senior partner over confidential documents in locker

On July 24, 2026Source: DataBreaches.NetBy Dissent
Categories: Business Sector, Insider

Colin Kruger provides today’s reminder of the insider threat: The most serious whistleblower cRead more

Cyberscoop

Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks

On July 24, 2026Source: CyberScoopBy Tim Starks
Categories: Government, Policy, Artificial Intelligence (AI), Biden administration, CIRCIA, Congress, critical infrastructure, Cybersecurity and Infrastructure Security Agency (CISA), information sharing, Nick Andersen, regulation, Trump administration

The administration set a target date of September for CISA to finalize the rule, but where the agencRead more

Despite multiple takedowns, botnets continue to grow

On July 24, 2026Source: CyberScoopBy Matt Kapko
Categories: Cybercrime, Cybersecurity, Research, Threats, Black Lotus Labs, botnet, botnets, cybercrime, IPIDEA, Lumen Technologies, ransomware, residential proxy network

Roughly 1 in 4 of those compromised IPs are based in the United States, Lumen’s Black Lotus Labs saiRead more

Microsoft, tech companies throw weight behind spread of open-source AI

On July 24, 2026Source: CyberScoopBy djohnson
Categories: AI, Cybersecurity, Geopolitics, Government, Policy, Technology, AI regulation, AI security, Artificial Intelligence (AI), Dell, Microsoft, Mistral AI, open source AI, Palantir, Perplexity, policy

Other signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The LiRead more

Rubio restricts visas for sextortionists, cyber scammers

On July 23, 2026Source: CyberScoopBy Tim Starks
Categories: Cybercrime, Geopolitics, Government, Policy, Aspen Institute, Department of Justice (DOJ), Executive order, investment scams, marco rubio, romance scams, scammers, scams, Sextortion, State Department, visas

The move stems from a Trump executive order as the administration continues to pursue cyber-enabledRead more

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

On July 23, 2026Source: CyberScoopBy Matt Kapko
Categories: Cybersecurity, Geopolitics, Government, Research, Threats, APT, Australia, Canada, cyber espionage, Cybersecurity and Infrastructure Security Agency (CISA), Czech Republic, Denmark, espionage, Estonia, Federal Bureau of Investigation (FBI), Finland, France, Italy, Laundry Bear, Moldova, New Zealand, payload, phishing, Poland, Russia, Spain, Sweden, The Netherlands, Ukraine, United Kingdom (U.K.), zero-day, zero-day exploit, Zimbra

Laundry Bear exploited a zero-day vulnerability for five months before it was patched in November 20Read more

ANCHOR-CI could fix 20 years of broken government-industry collaboration

On July 23, 2026Source: CyberScoopBy Greg Otto
Categories: Commentary, Government, ANCHOR-CI, CIPAC, critical infrastructure, Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security (DHS), public private partnerships, Volt Typhoon

The government spent the past two decades learning what private sector partners have always known: cRead more

Most federal cybersecurity reporting rules are duplicative, study finds

On July 22, 2026Source: CyberScoopBy Tim Starks
Categories: Government, Policy, Andrew Garbarino, Biden administration, BreachRx, CIRCIA, cybersecurity harmonization, Department of Homeland Security (DHS), financial sector, Gary Peters, Government Accountability Office, House Homeland Security Committee, Office of the National Cyber Director, regulation, Senate Homeland Security and Governmental Affairs Committee, Trump administration

The Government Accountability Office looked at 117 rules across 37 agencies and found 70% had reportRead more

Malware is targeting AI tools in software development environments

On July 22, 2026Source: CyberScoopBy Matt Kapko
Categories: AI, Cybersecurity, Research, Threats, API, CI/CD, Cloud, code developement, CrowdStrike, hacking, large language models, malware, open source, open source software, Socket, software development

The worm blends in with thousands of other commands occurring daily in any given environment, yet itRead more

White House accuses Chinese company of distilling Anthropic’s Fable

On July 22, 2026Source: CyberScoopBy djohnson
Categories: AI, Cybersecurity, Geopolitics, Government, Policy, Technology, AI cybersecurity, Anthropic, China, model distillation, OSTP, Trump administration

While distillation attacks by foreign governments and companies have real national security implicatRead more

OpenAI says model test was behind Hugging Face hack

On July 21, 2026Source: CyberScoopBy djohnson
Categories: AI, Cybersecurity, Research, Technology, AI hacking, Artificial Intelligence (AI), hugging face, large language models, OpenAI, supply chain attacks

At the time, Hugging Face said it wasn’t clear which LLM was used in the attack. OpenAI confirmed itRead more

Krebs On Security

The Hacker News

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

On July 25, 2026Source: The Hacker NewsBy

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executRead more

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

On July 25, 2026Source: The Hacker NewsBy

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, AlibaRead more

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

On July 25, 2026Source: The Hacker NewsBy

Security researchers at depthfirst published working exploit code on July 24 for a GitLab flawRead more

Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

On July 25, 2026Source: The Hacker NewsBy

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims wRead more

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recent investigations into insurance-focused phishing operations reveal a more immediate approach. Instead of harvesting

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

On July 25, 2026Source: The Hacker NewsBy

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ranRead more

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

On July 25, 2026Source: The Hacker NewsBy

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web plRead more

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis. "The portal combined build generation, finance,

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

On July 24, 2026Source: The Hacker NewsBy

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom andRead more

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. "BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

On July 24, 2026Source: The Hacker NewsBy

Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privilegedRead more

Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

On July 24, 2026Source: The Hacker NewsBy

Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace AgenRead more

Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization. The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of June 8,

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

On July 24, 2026Source: The Hacker NewsBy

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's prRead more

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine. Microsoft issued two critical CVEs, CVE-2026-32194 and

How Can We Help?

2 + 3 =

Share This