IT Security Newsletter

IT Security Newsletter - 7/31/2026

Written by Cadre | Fri, Jul 31, 2026

ShinyHunters claims Brinks Home breach, threatens to leak stolen data

Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. ?The company identified the attack on July 20 and immediately activated its incident response procedure to contain the breach. William Niles, CEO at Brinks Home, said that the company's team was working with "leading forensics experts to address this issue." READ MORE...

CareCloud Data Breach Impacts Over 350,000

Healthcare information technology company CareCloud is notifying at least 350,000 people that their information was stolen in a data breach. The incident involved an electronic health record environment within the CareCloud Health division, which was disrupted on March 16, 2026. CareCloud's investigation determined that hackers accessed one of its AWS environments between March 10 and March 16, and likely exfiltrated data from it. READ MORE...

Minnesota Water Utility Attacks Expose Sector's Cyber-Risks

A coordinated cyberattack targeting more than 30 community water systems in Minnesota this week underscored the growing threat to often poorly protected operational technology (OT) from adversaries seeking to disrupt critical infrastructure services across the US. The attacks, which US government officials have reportedly attributed to Iran, disrupted automated systems in some Minnesota communities, forcing them to switch to manual operations for brief periods. READ MORE...

Anthropic says its AI accidentally hacked three companies during safety tests

Anthropic said it found three instances in which its models gained access to the live computer systems of outside organizations, according to a company blog post published Thursday. The company said it began the review after OpenAI disclosed earlier this month that some of its models had exploited an unknown software flaw to escape an isolated test setup and reach production systems at Hugging Face, a platform for AI models and datasets. READ MORE...

Fake Flash Player installs AtlasRAT

Researchers have described a campaign that delivers a remote access Trojan (RAT) called AtlasRAT through a fake Flash Player installer. People still go looking for "Flash player" because a surprising amount of content and software was built around Flash and never properly migrated. Users often just want a quick way to get those old sites, games, or business apps working again. The underlying problem is that Adobe ended support for Flash Player on December 31, 2020. READ MORE...

Krebs on Security: Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks. READ MORE...

Laundry Bear's new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to target US and European government entities and a variety of private sector organizations via email. The warning comes from Proofpoint, who detected emails carrying the concealed exploit hitting inboxes. The exploit, which affects the webmail interface for Exchange, "constructs" a JavaScript loader from payload blobs. READ MORE...

Critical Code Execution Vulnerability Patched in TeamCity

JetBrains this week rolled out patches for a critical-severity vulnerability in TeamCity On-Premises that can be exploited without authentication. Tracked as CVE-2026-63077 (CVSS score of 9.8), the security defect can be exploited via HTTP/S to bypass authentication and achieve remote code execution (RCE). Depending on the available privileges, an attacker could access TeamCity data, configurations, and credentials, could tamper with the server state. READ MORE...

Quantum computers outperform classical ones, with results you can trust

There are many algorithms for which it has been mathematically proven that a quantum computer can generate results that would take a classical computer an unreasonable amount of time to generate. Unfortunately, today's quantum computers either can't run those algorithms or can only run simplified versions that classical computers can also handle. This has left the field facing a challenging question: Can we demonstrate the promise of quantum computers on today's noisy, limited hardware? READ MORE...

  • ...in 1790, the first U.S. patent is issued to inventor Samuel Hopkins for a unique potash production process.
  • ...in 1932, 6'9" actor Ted Cassidy, best known as Lurch from "The Addams Family", is born in Pittsburgh, PA.
  • ...in 1964 Ranger 7, an unmanned U.S. lunar probe, takes the first close-up images of the moon before impacting with the lunar surface.
  • ...in 1990, Nolan Ryan wins the 300th game of his career, throwing 7 2/3 innings with 8 strikeouts to lead his Texas Rangers to an 11-3 victory over the Milwaukee Brewers.