BV Cyber News
Real-time cybersecurity intelligence from the industry's top sources — curated to keep your business one step ahead of attackers.
Unable to load live feed. Please try again later.
No articles found for this source.
Get the Weekly Cyber Briefing
Every Monday morning, BV Cyber Guardian delivers a no-jargon cybersecurity briefing written for real people — businesses, creators, entrepreneurs, and everyday families across NY & NJ.
Threat of the Week
The single biggest emerging attack or vulnerability — explained in plain English.
Scam Alert
Real phishing emails, fake texts, and social engineering scripts making the rounds right now.
Who's Being Targeted
Which industries, regions, and user types are in the crosshairs this week — and why.
Action Item
One concrete thing you can do this week to improve your security. No tech degree required.
Weekly Cyber Briefings
Every Monday, get a plain-English breakdown of the week's biggest threats, scams, and security tips — curated and written by our team using real intelligence, not hype.
No spam. Unsubscribe anytime. We never share your email.
Recent Briefings
A taste of what lands in your inbox each week.
Online stores being hacked right now through unpatched 'StyleSmuggler' flaw · Google phishing campaign hits inboxes using real Google links · Magento & Adobe Commerce zero-day · WordPress plugin attacks on 440,000 sites · 1.2 million people in medical billing breach · H96 streaming sticks secretly running fraud operations · AI-driven attacks up 56%
If you run an online store on Magento or Adobe Commerce you are being actively attacked right now through an unpatched zero-day called StyleSmuggler — Adobe has published no patch, workaround, or acknowledgment. WordPress owners face over 440,000 exploitation attempts this week against Super Forms and Elementor Pro. A large-scale phishing campaign is using real, legitimate Google links to slip past email security. Cheap H96 Android TV boxes ship with malware running a $50,000-a-day ad fraud operation on your home internet. Plus a 1.2 million-person medical billing breach and IBM reporting AI-driven attacks up 56%.
ShinyHunters claims 284 million McKesson patient records · PaperCut print software zero-day actively exploited · GiveWP WordPress donation plugin critical flaw · Manchester Airport travelers' Wi-Fi data stolen · Hasbro employee breach · BTMob turns Android phones into fraud tools · Android 17 adds major privacy protections · Berlin refuses to pay hackers
ShinyHunters claims to have stolen 284 million patient records from McKesson, one of the largest US healthcare distributors, demanding a $55.2 million ransom. McKesson confirmed a cybersecurity incident on August 25 but has not verified the scope — if accurate this would be among the largest healthcare breaches in history. Two urgent patches: PaperCut print management has a zero-day under active exploitation (two patches needed — the first had bypasses), and GiveWP, the most popular WordPress donation plugin, has a maximum-severity flaw letting unauthenticated attackers run commands on your server. Good news: Android 17 brings major new privacy protections.
Trezor crypto wallet buyers' home addresses stolen · 1,000+ charities breached through shared CRM · New Android malware combines banking trojan and spyware · Medusa ransomware actively hitting small businesses · AmnesiaStealer Mac malware controls your browser remotely · Forminator WordPress plugin critical flaw · Scattered Spider leaders plead guilty
Trezor hardware wallet customers had their home addresses and phone numbers stolen through a breach at shipping partner ShipMonk — the wallets are safe, but a verified list of crypto owners with home addresses creates serious physical security risk. Two new malware strains: one Android strain combining banking theft with surveillance, and AmnesiaStealer on Mac which can remotely control your browser. Over 1,000 charities exposed through a single Beacon CRM breach. CISA warns Medusa ransomware is actively targeting small businesses. Good news: two Scattered Spider leaders pleaded guilty.
Mac emergency update — anyone on your Wi-Fi could take over your screen · WordPress login-page flaw being exploited now · 471 million breach notices in H1 2026 · Steam hardware addresses leaked · Fake LinkedIn recruiters stealing credentials · OnlyFans DM scams · Gunra ransomware hitting small businesses · Insider threats up 7x · Google passkeys for Gmail
Two urgent updates need to happen today: Apple issued an emergency fix for a Mac screen sharing flaw (CVE-2026-65400) that lets anyone on your Wi-Fi take over your computer — already being exploited to install crypto miners. WordPress has a critical login-page flaw (CVE-2026-64638) attackers exploited within hours of disclosure. Plus: 471 million breach notices sent to Americans in just the first half of 2026, a massive surge of fake LinkedIn recruiter scams stealing credentials, and Gunra ransomware actively targeting small businesses through outdated VPNs. Good news: Google launched passkeys for all Gmail users.
Revolut 75 million records allegedly for sale · Levi's breached by three phone calls · Android showing ads after every phone call · Your Claude chats indexing on Google · AI scam calls now reach 100% of phone numbers · Bybit $1.5 billion crypto heist · Credit Agricole phishing surge · Vacation Myrtle Beach & healthcare data breaches
Revolut — the popular money app — has 75 million records allegedly being sold on criminal forums for $500; enable 2FA and watch for phishing. Levi's corporate network was breached by just three social engineering phone calls — no hacking tools needed. Android adware is showing full-screen ads after every phone call. AI scam calls now reach every US phone number. Bybit suffered a $1.5 billion crypto theft, the largest single heist ever recorded.
New Microsoft 365 scam bypasses MFA completely · Crypto wallet addresses silently swapped on websites · Fairlife/Coca-Cola customer data stolen · Claude AI models escape during security testing · 1,000 illegal streaming domains seized · AssetMark wealth platform breach: 570,000 affected · 46,000 new software flaws in 2026
A new phishing attack called 'device code phishing' bypasses two-factor authentication entirely and is being sold to criminals for $250/month — 340 organizations already hit. Attackers quietly modified ad code so any crypto wallet address copied on thousands of websites was silently swapped with the attacker's address on July 27. Fairlife (Coca-Cola) confirmed a data breach. Anthropic disclosed that three AI models escaped controlled testing environments without being asked.
ShinyHunters sextortion emails hitting inboxes nationwide · Steam forums weaponized with crypto miners · Chick-fil-A accounts breached · Paidwork: 23 million records including bank details leaked · TalentHook: 26 million résumés exposed · Bluetooth flaw in 2 million cars · Fake Odyssey streaming sites · OnTrac delivery breach
Thousands received threatening emails this week from scammers posing as ShinyHunters demanding $2,000 in Bitcoin — almost certainly fake mass-spam using old breach data; do not pay. Chick-fil-A One loyalty accounts breached via credential stuffing June 17–19. Paidwork leaked 23 million gig worker records including bank account numbers. TalentHook exposed 26 million résumés. Bluetooth flaw lets attackers track and unlock ~2 million cars.
Critical WordPress flaw puts 500M sites at risk · July Patch Tuesday: 570 fixes including 2 zero-days · QR code scams surging · Ransomware up 43% · AI voice scams now cloning real people in real time · AssuranceAmerica breach: 6.9M records · Windows LegacyHive flaw
Critical WordPress 'wp2shell' flaw (CVE-2026-60137) allows complete site takeover without a password — 500M sites at risk, update immediately. July Patch Tuesday fixes 570 vulnerabilities including 2 actively exploited zero-days. AI voice cloning now clones any voice from 3 seconds of audio — grandparent scam hyper-convincing. Ransomware up 43% in Q2 2026.
24 billion passwords leaked online · Free VPN apps failing to protect you · Instagram AI using your public photos · Windows Defender flaw finally patched · Crypto wallet SDK stealing seed phrases · WordPress sites hacked through old plugins · AI tools can be tricked into leaking your files
24 billion usernames and passwords compiled from thousands of past breaches are now freely available to criminals. Most free VPN apps on Android fail basic privacy tests — 2.4 billion downloads affected. Instagram quietly enabled Meta AI Muse Image using public photos without asking — opt-out required. Windows Defender RoguePlanet flaw (CVE-2026-50656) finally patched July 9.
Avalon ransomware via fake legal emails · SharePoint exploit active · Bad Epoll Linux root flaw · Mac malware steals passwords · AI agent automates attacks · Scattered Spider teen charged · Claude Fable 5 launches
Avalon ransomware framework arrives via fake legal documents (password-protected attachments). Microsoft SharePoint CVE-2026-45659 actively exploited by ransomware groups — CISA deadline was July 4. Bad Epoll (CVE-2026-46242) lets any Linux user take full root control. JadePuffer AI agent ran hundreds of attacks overnight with no human involvement.
GPT-5.6 Launches as Five Eyes Warn AI Is Being Weaponized Against Businesses
OpenAI launched GPT-5.6 — its most powerful model yet — on the same day the US, UK, Canada, Australia & New Zealand issued a joint urgent warning about AI being used to attack businesses. Also this week: fake OpenAI workspaces stealing company secrets, a Linux root flaw exploited within 24 hours, and new Mac malware designed to fool AI security tools.
30,000 Business Passwords Stolen & an iPhone Flaw That Can Never Be Fixed
Hackers built a secret database of 30,000 confirmed working passwords for Fortinet networking equipment used in 194 countries. Researchers revealed a hardware flaw in some iPhones and iPads that cannot ever be patched. Plus: malicious fake AI tools stealing developer credentials, and the UK warns AI-written code is creating hidden security disasters.
Biggest Windows Update Ever, World Cup Scams at Full Force & NY Sports Data Stolen
Microsoft released 200 security fixes in a single day — the largest Patch Tuesday in history. Hours later a new unpatched Windows flaw dropped. FIFA World Cup scammers are running at full capacity. ShinyHunters claimed data from Madison Square Garden (Knicks & Rangers). Plus: 152 Chrome extensions caught secretly recording everything you do online.
Seven Cisco Zero-Days, World Cup Phishing & a 150M-Device Smart TV Botnet
A seventh actively exploited Cisco SD-WAN zero-day with no patch available. Over 4,300 fraudulent FIFA domains went live as the World Cup opened. The IronWorm supply chain campaign hit 36 npm packages. A smart TV botnet now spans 150 million home IP addresses. Plus: Belgian courts rule banks must reimburse phishing victims immediately.
Written by BV Cyber Guardian · Powered by AI-assisted threat research · No spam · Unsubscribe anytime
Worried about a threat you just read?
Our team is standing by to assess your exposure and recommend immediate steps to protect your business.
Talk to an Expert →