lithos Twitter
Lithos Header
Last Updated
Age in hrs 
1
2
3
5
8
13
21
34
55

 Ransomware Surges in July After Q2 Lull  - Finance, technology and healthcare sectors were particularly heavily targeted in July, according to Comparitech

 ClickFix attack pushes macOS infostealer for crypto theft attacks  - A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials.

 Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident  - One of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI systems

 Canadian Man Pleads Guilty in Snowflake Extortions  - A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake . Connor Riley Moucka , of Kitchener, Ontario,...

 Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency  - Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet. Meanwhile, if you've stayed in a hotel recently, the free Wi-Fi you connected to might have...

 Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People  - Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts . The intrusions reached at least 165 organizations and exposed records belonging to at least...

 Advantech Drives Industrial AI Opportunities with Integrated WISE Solution & Station (IWS) Platform Strategy  - Advantech (TWSE: 2395), hosted an investor conference today (August 5th). For the first half of 2026, the consolidated revenue reached NT$46.512 billion, representing a 32% YoY inc...

 Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses  - Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized...

 Apple fights UK's latest push for encrypted user data access  - The iPhone maker's latest legal fight could shape the future of encrypted data worldwide.

 Secure Agent Harness Execution: Preventing Escape  - At CrowdStrike, we conduct extensive red-team testing of agentic systems using diverse models, tools, and adversarial evaluation harnesses designed to probe for containment failures. To date, none of […]

 Chrome for Android Update  - Hi, everyone! We've just released Chrome 151 (151.0.7922.108) for Android. It'll become available on Google Play over the next few days.

 Meta AI model hacked a company during misconfigured cyber test  - Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face.

 Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits  - Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didn't exist. Read more in my article on the Hot for Security blog.

 Canadian pleads guilty to Snowflake cloud data-theft attacks  - A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims.

 Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt  - Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic's large language models (LLMs),...

 Chrome Beta for Android Update  - Hi everyone! We've just released Chrome Beta 152 (152.0.7977.30) for Android. It's now available on Google Play .

 News alert: Mallory links threat intelligence to governed response as exploit timelines shrink  - Las Vegas, United States, August 4th, 2026, CyberNewswire – Mallory , the AI-native Threat and Exposure Management platform, today introduced a unified context and intelligence layer for security teams.

 Beta Channel Update for ChromeOS / ChromeOS Flex  - The Beta channel is being updated to OS version 16733.40.0 (Browser version 151.0.7922.104) for most ChromeOS devices.

 Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery  - The conversation about AI in cybersecurity has recently centered on capabilities like vulnerability discovery, exploit generation, and automated proof-of-concept development. It’s easy to see why: The[…]

 New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts  - Zapscape , a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and...

 Supermicro's Seventh Annual Open Storage Summit Brings Together 21 Ecosystem Partners to Share Practical Guidance on Deploying Enterprise AI at Scale  - 12-session virtual event explores AI inference, agentic AI, cloud storage, and data management for production AI deployments 38 industry experts from 21 leading technology companies including AMD, DDN, Hammerspace, IBM, Intel, KIOXIA, MinIO, Nutanix, Scality, Solidigm, VAST Data, Western Digital, Crusoe,...

 NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing  - The Open Secure AI Alliance has announced plans for the Shared AI Findings Exchange (SAFE)

 Fake Open VSX Extensions Harvest Private Repo and CI Data  - 77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identity

 Chrome Beta for Desktop Update  - The Beta channel has been updated to 152.0.7977.30 for Windows, Mac and Linux.

 News Alert: Pulse Security AI’s research reveals C-suite, board confidence gap on cyber exposures  - LAS VEGAS, Aug. 5, 2026, CyberNewswire – Boards of directors believe they understand their company’s security posture and what it means for the business. The security leaders presenting to them are far less sure. Only 12.5% of security leaders are very confident their board walks away understanding...

 CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited  - The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows - CVE-2026-9198 (CVSS score: 9.8) - A code injection...

 Massive ChainDrop npm supply-chain attack infects hundreds of packages  - Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.

 Volta Selects Dell Technologies to Help Build Next-Generation AI Factories  - Volta today announced its emergence from stealth as a fully integrated AI infrastructure platform, with a mission it calls The Utility of Compute™, which is making…