GitHub’s malware detection has broadened beyond npm, adding coverage for PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. It does this by ingesting malware reports from OpenSSF’s malicious-packages repository in OSV format, surfacing warnings earlier in development and CI/CD workflows.
For defenders, this is a practical signal that supply-chain hygiene is moving from “advisories when it’s too late” toward “continuous detection across package managers.” Teams should review how alerts are routed and make sure dependency update pipelines block or flag newly reported malicious packages.
Source: Help Net Security
CISA urges immediate patching of exploited Progress LoadMaster vulnerability
CISA is calling for urgent remediation of a critical-severity Progress LoadMaster flaw that enables unauthenticated, remote attackers to execute arbitrary commands. The emphasis on “exploited” indicates active targeting in the wild rather than a purely theoretical risk.
Organizations using LoadMaster should prioritize patching and compensating controls (e.g., restricting management interfaces, isolating exposed systems) immediately, then validate with vulnerability scans and configuration review. The key takeaway: treat this as an incident-class update, not a routine maintenance item.
Source: SecurityWeek
Critical flaws found in Belgian eID software used by ~2 million people
Researchers discovered multiple critical vulnerabilities in Belgian electronic ID (eID) software deployed across major banks and government agencies. The impacted ecosystem includes software used by some of the largest organizations in the country, raising the potential blast radius for credential theft or system compromise.
Even when public-facing services are well defended, identity platforms become high-value targets. Stakeholders should focus on rapid patch deployment, hardening of verification flows, and monitoring for suspicious authentication and session activity.
Source: SecurityWeek
OpenAI pauses Astra activities after internal review flags “critical cybersecurity” potential
OpenAI says it has paused some internal activities related to its upcoming Astra model after evaluation indicated significant progress in agentic coding and cybersecurity. The company concluded it cannot rule out reaching a “critical capability” level for cybersecurity under its Preparedness Framework, and will implement additional controls.
This matters for security teams because frontier AI progress is increasingly measured by operational misuse potential, not just general capability. Expect more product and governance changes that directly affect how agents are tested, deployed, and sandboxed—alongside continued attention on “AI hacking” scenarios.
Source: Help Net Security
Anthropic to make AI-driven Claude Code action review the default (auto mode)
Anthropic will enable auto mode by default for new Claude Code sessions on Pro, Max, and Team plans starting August 14, shifting routine action review to AI. Internal testing cited in the report suggests auto mode catches a much higher percentage of dangerous commands compared with human review in the described experiment.
While this could improve safety at the product level, it also highlights a growing trend: security decisions are being delegated to model behavior and agent workflows. Enterprises using AI coding assistants should revisit policy for tool access, approval gates, and logging of high-risk actions.
Source: Help Net Security
Webmail CSS attacks demonstrate a new risk for AI-powered email tools
PortSwigger research shows that “plain CSS,” typically used only for styling, can be weaponized to steal credentials, hijack sessions, and manipulate how users’ inboxes interact with AI tools. The concern is amplified for AI-assisted workflows that interpret or react to email content.
Defenders should treat email rendering and client-side behaviors as part of the attack surface—not merely spam and phishing delivery. Add controls such as strict content security policies, safe rendering modes, and careful review of any AI features that summarize or trigger actions from email text.
Source: Security Affairs
You May Also Be Interested In...
Corporate Data Stolen in Levi Strauss Cyberattack
How to report an AI Act violation in the EU
ISC Stormcast For Monday, August 10th, 2026