Security Feed Digest (2026-07-30)
Hacker News: Best
- The coolest use for the Vision Pro — Wed, 29 Jul 2026 20:39:40 +0000
- Kimi K3-256k — Wed, 29 Jul 2026 19:25:33 +0000
- Keychron announces first open-source firmware for gaming mice — Wed, 29 Jul 2026 16:36:59 +0000
- Superlogical — Wed, 29 Jul 2026 15:41:33 +0000
- Show HN: Open-source engine running Gemma 4 26B in 2 GB RAM on any M-series Mac — Wed, 29 Jul 2026 15:05:43 +0000
- Handbook.md shows that long policy documents do not reliably govern agents — Wed, 29 Jul 2026 13:01:57 +0000
- Darktable — Wed, 29 Jul 2026 12:33:02 +0000
- French musician Kavinsky found dead — Wed, 29 Jul 2026 11:54:37 +0000
- Document-borne AI worms can self-propagate through Copilot for Word — Wed, 29 Jul 2026 11:44:33 +0000
- KOReader — Wed, 29 Jul 2026 11:05:08 +0000
- More Tailscale tricks for your jailbroken Kindle — Wed, 29 Jul 2026 04:58:46 +0000
- User Interfaces of the Demo Scene — Wed, 29 Jul 2026 04:30:36 +0000
- Show HN: I was tired of opening 2 tabs for every HN link, so I made a userscript — Tue, 28 Jul 2026 22:09:06 +0000
- Half-Life ported to Mac OS 9 — Tue, 28 Jul 2026 20:58:39 +0000
- Codex Security — Tue, 28 Jul 2026 20:52:55 +0000
- Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident — Tue, 28 Jul 2026 20:28:33 +0000
- Steel Bank Common Lisp version 2.6.7 — Tue, 28 Jul 2026 17:11:54 +0000
- Delayed Gratification – Proud to Be ‘Last to Breaking News’ — Tue, 28 Jul 2026 15:50:38 +0000
- Zig’s Incremental Compilation Internals — Tue, 28 Jul 2026 15:46:45 +0000
- Una GPS smart watch – Repairable, USB-C charging, developer-friendly — Tue, 28 Jul 2026 14:48:13 +0000
BleepingComputer
- Russian hackers exploit Exchange OWA zero-day for long-term mailbox access — Wed, 29 Jul 2026 19:44:07 -0400
- Anthropic confirms Claude is down worldwide — Wed, 29 Jul 2026 17:39:29 -0400
- Cisco warns of FMC static credential flaw exploited in zero-day attacks — Wed, 29 Jul 2026 17:35:40 -0400
- Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare — Wed, 29 Jul 2026 13:54:05 -0400
- OpenAI agent used exposed credentials at 4 services in Hugging Face breach — Wed, 29 Jul 2026 12:04:59 -0400
- Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack — Wed, 29 Jul 2026 10:55:57 -0400
- Your AI Agents Are Guessing at Scale: Permissions Decide the Damage — Wed, 29 Jul 2026 10:02:12 -0400
- Windows 11 KB5101684 update released with 42 changes and fixes — Wed, 29 Jul 2026 09:56:22 -0400
- These near-mint ASUS Chromebook refurbs are only $145 — Wed, 29 Jul 2026 07:12:19 -0400
Darkreading
- OpenAI’s Rogue Model Claims More Victims Beyond Hugging Face — Wed, 29 Jul 2026 19:48:12 GMT
- Red Agents vs. Blue Agents: How to Make AI Better At Defense — Wed, 29 Jul 2026 19:46:20 GMT
- Who’s Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions — Wed, 29 Jul 2026 17:43:38 GMT
- Hugging Face Hack Lessons for Cyber Defenders — Wed, 29 Jul 2026 17:35:23 GMT
- When AppSec Scanners Become a Supply Chain Attack Vector — Wed, 29 Jul 2026 17:06:52 GMT
- Patch-Resistant ‘RufRoot’ Flaw Can Unleash Malicious AI Agent Swarms — Wed, 29 Jul 2026 14:40:33 GMT
The Hacker News
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads — Wed, 29 Jul 2026 23:40:00 +0530
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory — Wed, 29 Jul 2026 21:09:30 +0530
- Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape — Wed, 29 Jul 2026 21:01:15 +0530
- Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline — Wed, 29 Jul 2026 19:18:36 +0530
- Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments — Wed, 29 Jul 2026 19:12:57 +0530
- Mythos Asks the Right Question. It Doesn’t Answer It. — Wed, 29 Jul 2026 17:45:00 +0530
- Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser — Wed, 29 Jul 2026 17:27:00 +0530
- 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack — Wed, 29 Jul 2026 16:43:10 +0530
- Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity — Wed, 29 Jul 2026 16:30:00 +0530
- Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass — Wed, 29 Jul 2026 14:28:27 +0530
- OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach — Wed, 29 Jul 2026 13:21:00 +0530
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands — Wed, 29 Jul 2026 13:17:19 +0530
- Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates — Wed, 29 Jul 2026 12:37:23 +0530
- Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js — Wed, 29 Jul 2026 09:50:57 +0530
데일리시큐 - 최근인기기사
- [단독] 딥웹에 해커 “배민 이용자 4,200만명 정보 판매” 주장…우아한형제들 “당사 데이터 아닌 것으로 확인” — 2026-07-29 11:52:05
- 클로드 미토스, 양자내성암호 ‘호크’ 약점 찾아…AES 공격도 최대 800배 단축 — 2026-07-29 13:54:42
- 오픈AI GPT-5.6 솔, 기업망 32단계 끝까지 뚫었다…AI 해킹 능력 ‘충격’ — 2026-07-29 13:13:19
- 마이크로소프트 보안 AI, 취약점 분석 성공률 95.95% 기록…비용 50% 절감 — 2026-07-29 14:07:34
- [보안칼럼] 망분리와 블록체인의 충돌 — 2026-07-29 12:29:53
- 미국 의료비 청구업체 MCBS 해킹…환자 126만 명 개인정보·진료정보 노출 — 2026-07-29 13:25:55
- 하반기 최대 보안 컨퍼런스 ‘KCSCON 2026’ 9월 8일 개최…1,400여 명 참석 예정, 참가기업 모집 및 사전등록 진행 — 2026-07-29 17:09:09
- 에스넷그룹, KAIST 장동인 교수 초청해 특별 강연 개최 — 2026-07-29 16:40:41
- “노로그” 약속한 VPN에서 5,800만 건 접속기록 유출…이용자 개인정보 대거 노출 — 2026-07-29 21:31:16
- 엘앤에프, 미국 코어셸과 LFP 양극재 공급계약…방산·모빌리티 분야 공략 — 2026-07-29 17:35:44
보안뉴스 > SECURITY
- [ISEC 2026 미리보기] 화이트디펜더, AI 시대 랜섬웨어 대응 새로운 기준 — Wed, 29 Jul 2026 16:59:00 +0900
- [ISEC 2026 미리보기] XBOW, 자율 모의해킹으로 보안 검증의 기준 다시 쓰다 — Wed, 29 Jul 2026 16:56:00 +0900
- 허깅페이스 해킹 ‘AI 안전’ 경종… “가드레일 의존말고 ‘기본’ 충실” — Wed, 29 Jul 2026 16:46:00 +0900
- [배종찬의 보안 빅데이터] 빈번한 해킹으로 ‘공유재산’이 되어버린 ‘개인정보’ — Wed, 29 Jul 2026 16:38:00 +0900
- [해킹을 결제하시겠습니까?] #10. 새 체크카드 등록 후 5분, 해킹은 여기서 갈린다 — Wed, 29 Jul 2026 14:43:00 +0900
- “보안사고 83% AI 악용” 기가몬, 2026 보안 보고서 발표 — Wed, 29 Jul 2026 14:07:00 +0900
- 포티넷, 하이브리드 융합 방화벽 ‘포티게이트 1200G’ 공개 — Wed, 29 Jul 2026 13:36:00 +0900
- [ISEC 2026 미리보기] 78리서치랩, 우리 회사 보안 정말 안전할까? 자동화된 실전 공격 시뮬레이션으로 완벽 검증 — Wed, 29 Jul 2026 13:34:00 +0900
- [ISEC 2026 미리보기] 한국마이크로소프트, AI 시대 ‘AI-퍼스트’ 엔드투엔드 보안 전략으로 새로운 보안 패러다임 제 — Wed, 29 Jul 2026 13:32:00 +0900
- 안랩, 올 상반기 영업익 62% 상승… 해외·N2SF 사업 선전 힘입어 — Wed, 29 Jul 2026 11:28:00 +0900