Cybersecurity research, threat intelligence & CVE tracking

> Security Feed

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL.

Confiant, which detailed the campaign on July 23, 2026, said it has operat…

#malware #windows

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.

Tracked as CVE-2026-16723,…

#vulnerability #rce #patch #authentication

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose.

That model is changing.

Recent investigations i…

#phishing #authentication

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.

“Attackers chain a pre-authentication information disclosure i…

#ransomware #vulnerability #apt #rce #authentication

OpenAI confirms ChatGPT is down worldwide

ChatGPT, the famous artificial intelligence chatbot that allows users to converse with various personalities and topics, has connectivity issues worldwide. […]

#artificial-intelligence #technology

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server.

An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their diff. The …

#vulnerability #rce #patch

Rockwell Patches Code Execution Flaws in Arena Simulation Software

A researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations. The post Rockwell Patches Code Execution Flaws in Arena Simulation Software appeared first on SecurityWeek.

#icsot #vulnerabilities #ics #rockwell #vulnerability

CISOs vs. Boards: Myth or Misunderstanding?

Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide.

Friday Squid Blogging: Illex Squid Catch in the Falklands

Lower catch this year. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

#uncategorized #squid

Accelerating AWS Network Firewall troubleshooting with AWS DevOps Agent

When an administrator introduces a rule change in AWS Network Firewall and network connectivity is disrupted, pinpointing the cause requires inspecting multiple points in the traffic path. The firewall gives you stateless and stateful rule engines, domain rules, and routing to the firewall endpoint …

#advanced-300 #aws-network-firewall #devops #networking--content-delivery #security

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday’s massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. […]

#microsoft

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware.

“BlueNoroff has …

#malware #phishing #apt #windows

Don’t get fooled by TikTok resin art scams

Scammers are using stolen videos and fake artist profiles to trick people into buying resin art that never arrives. Here’s how to spot the warning signs.

#news #scams #resin-art #scam #tiktok

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws

Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws…

#malware--threats #ransomware #vulnerabilities #in-other-news

Chick-fil-A data breach affects more than 13,000 customers

Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. […]

#security

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malic…

#security

Google wants to store a selfie video of your face

A new selfie video verification feature could make recovering your Google Account easier. But it also creates new security and privacy concerns.

#ai #news #privacy

Europol flags 4,340 URLs for removal in 'The Com' crackdown

Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to “The Com,” a loosely organized network of nihilistic violent extremist groups. […]

#security

Default Azure Automation Setting Enables Cross-Tenant Identity Takeover

Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation which could have let attackers seize another tenant’s identity and access other tenants’ data, credentials, and cloud workloads.

#cloud #authentication #windows

AegisAI Raises $36 Million for AI-Powered Email Security

The company has raised a total of $49 million in funding, including from Battery Ventures, Accel and Foundation Capital. The post AegisAI Raises $36 Million for AI-Powered Email Security appeared first on SecurityWeek.

#cybersecurity-funding #email-security #aegisai #email-security #funding

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim’s organization.

The vulnerability has bee…

#phishing #vulnerability

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet.

XBOW’s testing got the same result on workers across different hosts and network ranges, so the problem sat in …

#windows #linux

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we’ve collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to i…

Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday

Industry professionals debate whether it represents a lab containment failure or an unprecedented agentic capability milestone. The post Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday appeared first on SecurityWeek.

#artificial-intelligence #ai #feedback-friday #hugging-face #openai

Why AI Needs a “Genie Coefficient”

This essay was written with Barath Raghavan, and originally appeared in The Guardian. Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to do it. We propose a new m…

#uncategorized #ai #llm

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand’s Ministry of Finance, which runs the country’s treasury and tax collection.

The agent then worked through the ministry’s netw…

#vulnerability

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.

The malware families in question are: Tin…

#malware #apt

Ransomware Attacks Targeting Universities on the Rise

Comparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher education

#ransomware

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software’s source code.

Every version before 4.14.0 is affected. NodeBB has fixe…

#vulnerability #patch

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.

All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis say…

#zero-day #vulnerability #rce

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems.

The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russ…

#windows

Data Breach Confirmed After Australian Energy Giant Origin Is Hacked

A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it.  The post Data Breach Confirmed After Australian Energy Giant Origin Is Hacked appeared first on SecurityWeek.

#data-breaches #australia #data-breach #energy #origin-energy

New Dolphin X malware uses AI to rank high-value targets

A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. […]

#security

Fake Claude app promoted by Bing ads pushes SectopRAT malware

A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. […]

#security #artificial-intelligence

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client.

The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept for two-factor r…

#zero-day #vulnerability #authentication

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. […]

#security

Hackers abuse Notepad++ plugins to stealthily install malware

Ukraine’s CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. […]

#security

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider appeared first on SecurityWeek.

#artificial-intelligence #chatgpt #vulnerability

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

Most of this week’s trouble came dressed as something useful.

A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic.

The threats change every w…

#injection

Is Patching Dead? Vulnerability Management in the Post-Mythos Era

You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching Dead? Vulnerability Management in the Post-Mythos Era appeared first on SecurityWeek.

#artificial-intelligence #vulnerabilities #ai #patch

Email threat landscape: Q2 2026 trends and insights

In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-st…

#adversary-in-the-middle-aitm #credential-theft #phishing #social-engineering

Chick-fil-A Accounts Get Fried in Credential Stuffing Attack

Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts. The post Chick-fil-A Accounts Get Fried in Credential Stuffing Attack appeared first on SecurityWeek.

#data-breaches #chick-fil-a #credential-stuffing #data-breach

Russian Global Webmail Espionage

Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42.

#cybercrime #threat-research #cl-sta-1114 #javascript #javascript-injection

FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires

FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assurance. […]

#security

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.

Accomplish AI, which shared details of the…

#vulnerability #linux

What Happened Between OpenAI and Hugging Face?

The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry to confront a quest…

#supply-chain-security #artificial-intelligence #incident-response

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek.

#artificial-intelligence #malware--threats #ai #ai-benchmark #benchmark

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.

Group-IB found the s…

#windows

CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild

OverviewOn July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232, an authentication bypass in the SmartConsole login process classified as imprope…

#emergent-threat-response #labs #vulnerability-management

How Synthetic Identity Fraud is Coming for Machine Identities

Most people understand identity theft as an attacker stealing a real person’s sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points wi…

New RefluXFS Linux flaw lets attackers gain root privileges

A nine-year-old race condition vulnerability in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. […]

#linux #security

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances.

The activity involves malicious Packagist development versions spanning 10 packag…

End-to-End Encryption and “Going Dark”

New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“: Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current…

#uncategorized #academic-papers #backdoors #crypto-wars #encryption

Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses

Hackers recently obtained non-sensitive customer information and other documents from the company. The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses appeared first on SecurityWeek.

#data-breaches #fraud--identity-theft #data-breach #fraud #upbound-group

Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video.

The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone number. The idea is to …

Assaf Keren Appointed New CISO of Meta

He replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek.

#ciso-strategy #management--strategy #assaf-keren #ciso #meta

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild.

The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is …

#vulnerability #patch

ZDI-26-452: Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.4.

#vulnerability

Attackers Are Learning to Live Off the AI Toolchain

Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.

#malware #vulnerability

South Korea discloses data breach impacting diplomats worldwide

South Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. […]

#security #government

Federal agencies broaden alert on Iran-linked OT attacks

The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.

#cybercrime #government #news #news-briefs #technology

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more.

Reports filed before that date, including those alrea…

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment.

The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8),…

#vulnerability #linux

RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)

Executive summary Qualys Threat Research Unit (TRU) identified CVE-2026-64600, a race condition in the Linux kernel’s XFS filesystem copy-on-write path. An attacker with an ordinary local account can exploit this race condition to overwrite protected files on disk and gain host root privileges on af…

#vulnerabilities-and-threat-research #ai-research #anthropic #glasswing #linux

Real world incident response: Microsoft and AXA XL strengthen cyber resilience

Our collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The post Real world incident response: Microsoft and AXA XL strengthen cyber resilience appeared first o…

#windows

How enterprise GenAI can amplify ransomware risk — and how to contain it

Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption. […]

#security

Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

Hackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms.  The post Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts appeared first on SecurityWeek.

#data-breaches #data-breach #paidwork #suno

Palo Alto Networks to Acquire Observability Platform Provider Embrace

Acquisition follows January’s Chronosphere deal, deepening Palo Alto Networks’ push beyond core security into observability. The post Palo Alto Networks to Acquire Observability Platform Provider Embrace appeared first on SecurityWeek.

#fundingma #network-security #acquisition #palo-alto-networks

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek.

#vulnerabilities #adobe #data-leak #vulnerability #whatsapp

The Life of a SOC Analyst: Responsibilities, Challenges, and Strategies for Success

Security Operations Centers (SOCs) serve as a critical line of defense against today’s constantly evolving cybersecurity threats. At the heart of these teams are SOC analysts, who monitor, detect, and respond around the clock to potential attacks. The post The Life of a SOC Analyst: Responsibilities…

#active-soc #blue-team #incident-response #informational #infosec-101

What’s New in Rapid7 Products and Services: Q2 2026 in Review

If Q1 set the pace for Rapid7’s tools, Q2 accelerated it. This quarter brought a steady stream of product enhancements, platform investments, and customer-driven innovation across Rapid7’s portfolio. Each release was designed with a clear goal in mind: helping security teams reduce complexity while …

#managed-detection-and-response-mdr #exposure-command #siem #research

Vibe-Coded Apps Riddled With Exploitable Security Flaws

Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek.

#application-security #artificial-intelligence #vulnerabilities #vibe-coding

StrongestLayer Raises $4.1 Million in Seed Funding Extension

The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek.

#cybersecurity-funding #email-security #email-security #funding #strongestlayer

Chick-fil-A loyalty accounts hijacked using stolen passwords

If you have a Chick-fil-A One account, now is a good time to change your password—and make sure it’s one you don’t use anywhere else.

#data-breaches #news #chick-fil-a #credential-stuffing #passwords

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.

The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint ("/…

#vulnerability #authentication

The Fastest Path to AI Adoption Runs Through Security

Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned.

According to McKinse…

CISA orders urgent action on actively exploited Langflow RCE flaw

The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. […]

#security

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek.

#vulnerabilities #exploited #sharepoint #vulnerability

Why Modern SOCs Need Multi-Layered Detections

The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely.

The CrowdStrike Glob…

#malware

Stop renting storage space — this lifetime 2TB plan is yours for $59

Cloud storage costs tend to creep up over time, since most services charge monthly or annually for as long as you use them. FileJump’s Lifetime Plan skips that model entirely, offering 2TB of cloud storage for a single payment of $59 (MSRP $467). […]

#security

First-Person Identity Theft Story

Harrowing story of an identity theft victim. Yes, the person made a mistake—they gave the scammer a two-factor authentication code that allowed the scammer to take over their email address. But the real story here is how, for many of us, the security of most of our accounts hangs on the security of …

#uncategorized #identity-theft #social-engineering #two-factor-authentication

Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation

Using AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement. The post Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation appeared first on SecurityWeek.

#cybersecurity-funding #endpoint-security #endpoint-security #funding #glow

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates

Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI. The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek.

#vulnerabilities #ai #oracle #oracle-cpu #patches

Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife

The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary. The post Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife appeared first on SecurityWeek.

#data-breaches #ransomware #coca-cola #data-breach #fairlife

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it.

In a joint announcement on Monday, the Frankfu…

#phishing #authentication #windows

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain.

The package, named “Newtonsoftt.Json.Net,” masquerades as the Newtonsoft.Js…

#malware

OpenAI says its AI models hacked Hugging Face during testing

OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. […]

#security

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds.

The flaw is in Microsoft’s official Azure DevOps MCP server, and it works because one of…

#cloud #windows

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available fo…

#a-little-sunshine #internet-of-things-iot #the-coming-storm #bright-data #john-taylor

Police dismantle Kratos phishing platform, arrest developer

Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. […]

#security #legal

Oracle July 2026 Critical Patch Update Addresses 1235 CVEs

Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates.Key TakeawaysThe third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release.261 issues (18% of all patches) were as…

#patch

DNI nominee Clayton wins Senate panel’s approval

By a party-line vote, the Senate Intelligence Committee sent the nomination of Jay Clayton to lead ODNI to the Senate floor.

#people #leadership #government #news #news-briefs

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked, effectively undermining the feature’s privacy guarantees.

404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a yea…

#privacy

Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains

New executive order calls for end-to-end visibility into defense supply chains, including software dependencies, foreign ownership and cyber-related supplier risks. The post Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains appeared first on SecurityWeek.

#government #supply-chain-security #executive-order #sbom

Cisco Launches Low-Cost AI Models for Source Code Security

The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek.

#artificial-intelligence #ai #artificial-inteligence #cisco #cisco-antares

Do more with AWS WAF labels using dynamic label interpolation

AWS WAF classifies web traffic by attaching metadata to each request it evaluates. Managed rule groups such as AWS WAF Bot Control and AWS WAF Fraud Control account takeover prevention (ATP) attach labels that describe what they found. A label can record that a request came from a known bot category…

#aws-waf #security-identity--compliance #technical-how-to #security-blog

VU#762226: Plane contains multi-tenant authorization bypass vulnerability

Overview The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other workspaces. Description Plane is an open-source pr…

#vulnerability

Critical wp2shell WordPress flaws exploited to install webshells

Hackers are exploiting the “wp2shell” critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. […]

#security

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code on a developer’s machine, with no approval step able to stop it.

Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to su…

#cloud

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google’s DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that’s designed to discover, validate, and patch vulnerabilities quickly and efficiently.

According to the tech giant, the model will be exclusively av…

#vulnerability #patch

Manual Patching Can’t Outrun AI. Automated Remediation Can.

Executive Summary AI is rapidly transforming vulnerability discovery, outpacing many security teams’ ability to adapt. Microsoft’s July 2026 Patch Tuesday addressed a record 622 vulnerabilities, an early signal of AI-accelerated discovery at scale compounding an already-large backlog that manual rem…

#product-and-tech #ai #patch-tuesday #trurisk-eliminate

CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine

The Qualys Threat Research Unit (TRU) has identified a Local Privilege Escalation (LPE) vulnerability in snap-confine (CVE-2026-8933). This flaw allows an unprivileged local user to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The issue stems from a secur…

#vulnerabilities-and-threat-research #security #vulnerabilities

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr.

The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint tha…

#vulnerability #rce #patch #windows

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.

Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation o…

#ransomware #vulnerability #apt #patch #authentication

Closing the Identity Gaps in Critical Infrastructure Security

Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. […]

#security

Taiwan to slow mobile data during national resilience drills

The speed of 5G and 4G networks across much of Taiwan will be temporarily reduced to 1 percent of capacity as the island holds annual civilian and military drills.

#government #news #news-briefs #technology

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component.

As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection v…

#vulnerability #patch #xss #injection

Empirical Security Raises $25 Million in Series A Funding

The startup will use the investment to accelerate the development of its threat prediction and discovery products. The post Empirical Security Raises $25 Million in Series A Funding appeared first on SecurityWeek.

#cybersecurity-funding #empirical-security #funding

SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity

Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville The post SecurityWeek Launches Critical Impact …

#icsot #critical-infrastructure #ics #industrial-cybersecurity #ot

Kenya probes hack of president's website after bitcoin ransom demand

The website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information about President William Ruto unless the ransom was paid.

#cybercrime #government #leadership #news #news-briefs

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent.

Researchers demonstrated that chain, plus six o…

#windows

N-day is Becoming N-Hour. Patching Faster Won't Save You.

Every patch is a confession.

The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn’t updated yet. This is N-day exploitation…

#vulnerability #patch

Don’t trust that “FBI agent” in your DMs

The FBI is warning that fraudsters are using fake IC3 accounts and direct messages to target people who’ve already been scammed.

#news #scams #fbi #ic3 #recovery-scam

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in.

That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, …

#vulnerability

MIT to Become Hotbed of AI Video Surveillance

It’s a lot: According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and infrastructure that will supp…

#uncategorized #ai #cameras #privacy #schools

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek.

#vulnerabilities #bug-bounty #data-leak #meta #vulnerability

Ukraine warns fake CAPTCHAs are being used to make you hack yourself

Ukraine’s computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code.

Read more in my article on the Hot for Security blog.

#guest-blog #malware #clickfix #russia #ukraine

Clover Health Investments Discloses Data Breach

Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek.

#data-breaches #clover-health-investments #data-breach #healthcare

Microsoft shares manual fix for WSUS sync delays and timeouts

Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. […]

#microsoft

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.

The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2she…

#vulnerability #rce

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek.

#vulnerabilities #exploited #featured #servicenow #vulnerability

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month.

The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes…

#ransomware #rce

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. […]

#security #cryptocurrency

Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment

The new Amazon GuardDuty investigation agent (now in public preview) investigates security findings across your Amazon Web Services (AWS) environment, reducing investigation time from hours to minutes. GuardDuty is our managed threat detection service that continuously monitors your AWS accounts and…

#amazon-guardduty #intermediate-200 #security-identity--compliance #technical-how-to #security-blog

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. […]

#security

JadePuffer agentic attacks now target AI model data with ransomware

The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. […]

#security #artificial-intelligence

CISOs Feel the Heat Over AI Risk

Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.

Attackers Combo Up Evasion Tactics for BEC Phishing

“The TFF Trap” uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.

#malware #phishing

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit.

“Fa…

#malware

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an …

#malware #phishing #windows

2026 ISO and CSA STAR certificates are now available with two additional services

Amazon Web Services (AWS) successfully completed an onboarding audit with no findings for ISO 9001:2015, 27001:2022, 27017:2015, 27018:2019, 27701:2019, 20000-1:2018, and 22301:2019, and Cloud Security Alliance (CSA) STAR Cloud Controls Matrix (CCM) v4.0. EY Certify Point auditors conducted the audi…

#announcements #foundational-100 #security-identity--compliance #aws-csa-star #aws-csa-star-certificates

Top Five Compliance Audit Software and Tools: Mastering Modern Regulatory Risk

Executive Summary Manual audit preparation no longer scales across hybrid, cloud, endpoint, and application environments. Compliance monitoring software must move from checklist validation to continuous control monitoring. The strongest platforms connect evidence collection with risk prioritization,…

#product-and-tech #compliance #compliance-monitoring #qualys-policy-audit #top5

Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software

Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others. The post Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software appeared first on SecurityWeek.

#artificial-intelligence #cybersecurity-funding #ai #funding #neo

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.

Group-IB, which named the malware HollowGraph, says the approach move…

#malware #windows

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek.

#malware--threats #vulnerabilities #exploited #malware #sonicwall

An AI SOC Evaluation Guide for Security Leaders

Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production rea…

#security

Cybersecurity Keeps Events 'Uneventful'

From the World Cup to the United States’ 250th celebration, this year’s event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands.

From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab

Executive summaryAn MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery pa…

#phishing #malware #labs

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek.

#vulnerabilities #openssl #vulnerability

New Index Tracks Material Breaches — And Refuses to Add Up the Losses

Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek.

#data-breaches #data-breach

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Myt…

Ernst & Young Data Breach Affects Personal, Financial Information

Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek.

#data-breaches #data-breach #ernstyoung #ey #featured

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro’s Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02.

#zero-day #vulnerability

Chrome 150 Update Patches Severe Memory Safety Bugs

The fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek.

#vulnerabilities #chrome #memory-safety #patch #vulnerability

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.

The company said it detected and responded to the incident targeting its production infrastructure earlier last week.

“We ident…

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.

The rogue gems are listed below -

git_credential_manager (versions …

#supply-chain #authentication

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.

According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC…

#malware #apt

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.

Cybersecurity company Volexity is tracking the activity under the moni…

#zero-day #vulnerability #apt #privacy #network

Microsoft warns of surge in ACR Stealer attacks on customers

Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. […]

#security

The Future of Age Verification: Your Face Never Leaves Your Device

As age verification laws expand worldwide, organizations face growing pressure to protect users’ privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting c…

#security

Google’s Gemini lets strangers send messages from your locked Android phone

Gemini, Google’s AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone.

Read more in my article on the Hot for Security blog.

#ai #android #google #guest-blog #vulnerability

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable.

Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system.

Adam…

#vulnerability

Abbott Laboratories probes two cyber incidents amid extortion claims

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data….

#security

Inc Ransomware Exploits SonicWall SMA Zero-Days

When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall’s mobile access appliances.

#zero-day #ransomware #vulnerability #apt

Metasploit Wrap Up: An HTTP to SMB relay plus Payload Improvements

Metasploit Wrap Up HousekeepingWhile the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The team is planning to use the additional time between posts to record demos of some …

#metasploit #metasploit-weekly-wrapup

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.

The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an…

#supply-chain

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys.

A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and …

#malware #cloud

The Real AI Threat Is Blind Trust

AI models left to both interpret and execute commands eliminate critical cybersecurity oversight.

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.

Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a…

#apt

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared first on SecurityWeek…

#data-breaches #malware--threats #in-other-news

Inside the Search for 'Clean' Residential Proxies for Carding

Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek “clean” residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection. […]

#security

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges.

“Any user who ran the project ended up with a four-stage payload al…

#malware #apt

Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive

(Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up? The post Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive appeared first on SecurityWeek.

#artificial-intelligence #icsot #uncategorized #ics #ot

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps …

Beacon Security Raises $13 Million for Security Data Platform

The startup helps organizations detect, hunt, and protect their assets across environments at machine speed. The post Beacon Security Raises $13 Million for Security Data Platform appeared first on SecurityWeek.

#cybersecurity-funding #beacon-security #funding

Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday

Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI. The post Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday appeared first on SecurityWeek.

#compliance #government #management--strategy #cmmc #compliance

New Windows LegacyHive zero-day gives hackers admin privileges

A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. […]

#security #microsoft

Details of Alan Turing’s Voice Encryption System

Really interesting piece of cryptographic history: In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-sec…

#uncategorized #encryption #history-of-cryptography

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov.

His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan’s Zvartnots …

#ransomware

How to use GitHub safely

Knowing how to spot a malicious GitHub repository can help you avoid downloading malware disguised as legitimate software.

#how-to

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.

#threat-research #vulnerabilities #command-injection #cve-2025-40947 #cve-2025-40948

Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei

The company disconnected its systems on July 13 and is starting to gradually restore operations. The post Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei appeared first on SecurityWeek.

#cybercrime #cyberattack #disruption #japan #nichirei

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders.

It gets in because someone pasted a command into a Run box and presse…

#malware #windows

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering.

Russian cybersecurity company Kaspersky, which unc…

#malware

Risk Ledger Raises $32 Million in Series B Funding

The British firm has built a collaborative platform to help organizations address supply chain security risks. The post Risk Ledger Raises $32 Million in Series B Funding appeared first on SecurityWeek.

#cybersecurity-funding #supply-chain-security #funding #risk-ledger #supply-chain

Fresh SharePoint Vulnerability Exploited Soon After Disclosure

The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server. The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek.

#vulnerabilities #exploited #sharepoint #vulnerability

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026…

#zero-day #vulnerability #rce #patch #windows

ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments. The…

#clickfix #malware #social-engineering

Anubis ransomware: what you need to know

The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk.

Read more in my article on the Fortra blog.

#guest-blog #malware #ransomware #ransomware

Claude Chrome extension flaw lets malicious extensions trigger AI actions

A flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude’s access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce. […]

#security

New OkoBot framework deploys 20 payloads to steal data, crypto

A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data. […]

#security #cryptocurrency

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.Key TakeawaysCISA confirmed active exploitation of three on-pre…

#vulnerability #patch #windows

Least privilege for AI agents: Identity, access, and tool binding

As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure. The post Least privilege for AI agents: Identity, access, and tool binding appeared first on Microsoft Security Blog.

#windows

Legacy Systems, Real-World Impacts: The Reality of OT Security

Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity’s most challenging balancing acts. The post Legacy Systems, Real-World Impacts: The Reality of OT Security appeared first on SecurityWeek.

#icsot #ics #ot

Protecting Privacy in an AI Era

Daniel Solove argues in the Wall Street Journal (alternate link) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug companies. Measures s…

#uncategorized #academic-papers #ai #privacy

AI Agents Broke the Security Playbook. Here's What Replaces It.

Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own environments. […]

#security

The backlash against Flock cameras is spreading

Privacy concerns have dogged Flock’s automated license plate recognition system for years. Now accuracy and reliability are coming under scrutiny too.

#news #privacy #errors #flock #lapd

Sandworm hackers have a CAPTCHA trick for Ukrainians

Rather than verifying they are human, the CAPTCHA users are instructed to copy and paste a PowerShell command into their Windows computers.

#nation-state #news #technology #malware

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss.

A valid token from issuer A carrying a sub that belongs …

Two Scattered Spider Hackers Sentenced to Jail in UK

Thalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL). The post Two Scattered Spider Hackers Sentenced to Jail in UK appeared first on SecurityWeek.

#cybercrime #tracking--law-enforcement #hacker #scattered-spider #sentenced

Sunsetting the Public AttackerKB Platform

What’s changing, where AttackerKB-style analysis will live, and how users can continue finding Rapid7 vulnerability intelligence.On August 18, Rapid7 will sunset the standalone public AttackerKB website as part of a broader effort to unify our vulnerability intelligence, exploit analysis, and resear…

#research

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that’s been spreading via websites infected with ClickFix lures since late April 2026.

“The malware is full-featured, lightweight, and modular,” Elastic Security Labs researcher Cyril François said in a technica…

#malware

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

ClickLock Stealer, a new macOS infostealer, answers a victim’s refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim cancels, installs two LaunchAgents and …

#malware

20+ Hijacked Government Websites Became
an Attack Channel

More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions.

The investigation revealed previously undocumented backd…

#malware

Oak Emerges From Stealth Mode With $60 Million in Funding

The startup has built an AI-powered Identity Operating System that governs all identities across an organization’s environment. The post Oak Emerges From Stealth Mode With $60 Million in Funding appeared first on SecurityWeek.

#cybersecurity-funding #identity--access #emerge-from-stealth #funding #identity

Splunk, Zoom Patch Critical Vulnerabilities

The flaws could allow attackers to access credentials and data, take over accounts, and escalate their privileges. The post Splunk, Zoom Patch Critical Vulnerabilities appeared first on SecurityWeek.

#vulnerabilities #patches #splunk #vulnerability #zoom

AI Can Find Bugs, But Human Knowledge Still Proves Them

Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive …

Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide

Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people’s Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext.

A researcher publishing under the …

#patch #cloud

F5 Patches Multiple NGINX, BIG-IP Vulnerabilities

Attackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code. The post F5 Patches Multiple NGINX, BIG-IP Vulnerabilities appeared first on SecurityWeek.

#vulnerabilities

Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers

An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed.

Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generate…

#ai #podcast #security-threats #vulnerability #battery

China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans

Chinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures. The post China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans appeared first on SecurityWeek.

#government #management--strategy #china #china-apt #military

OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol

OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely.

“GPT‑Red is a strong red-teamer, and our previous models are highly vulnerable to its prompt injectio…

#vulnerability #injection

Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day

The researcher stripped the proof-of-concept (PoC) exploit to prevent immediate exploitation of the vulnerability. The post Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day  appeared first on SecurityWeek.

#vulnerabilities #chaotic-eclipse #legacyhive #poc #zero-day

Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities

The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products. The post Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities appeared first on SecurityWeek.

#endpoint-security #vulnerabilities #security-product #security-product-vulnerability #vulnerability

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses. The post Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery a…

#npm #supply-chain-attack

The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)

Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.

#high-profile-threats #malware #credential-harvesting #github #npm-packages

Identity Attacks Overtake Exploits as Top Ransomware Cause

Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.

#ransomware #vulnerability #authentication

Zoom warns of critical account takeover vulnerability

Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. […]

#security

Trump’s DNI pick grilled about election security, voter fraud

Senators pressed director of national intelligence nominee Jay Clayton about his stance on the 2020 election and previous statements about voter fraud. Other issues took a back seat.

#people #leadership #government #news

Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)

OverviewOn July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409 (CVSS 10.0) and the high-severity code injection vulnerability CV…

#emergent-threat-response #labs #managed-detection-and-response-mdr

Turning threat intelligence into decisive action with Defender Experts

Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools. The post Turning threat intelligence into decisive action with Defender Experts appeared first on Microsoft …

#windows

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase.

On an infected PC, the request comes from inside the wallet’s own desktop software. Sometimes it waits until you plug …

#malware #phishing #windows

Understanding Claude Tag’s access model in Slack and how to configure it securely

Anthropic’s new AI agent for Slack acts under an admin-configured access bundle rather than each user’s own credentials. Here’s how that model works, what admins should understand and how to securely configure it.Key takeawaysClaude Tag, Anthropic’s newly launched AI agent for Slack, acts on connect…

#authentication

Unpatched Cursor Vulnerability Exposes Users to Code Execution

An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically. The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek.

#artificial-intelligence #vulnerabilities #ai #cursor #vulnerability

Dutch police dismantle global crypto investment scam, arrest alleged mastermind

Authorities said Wednesday that the group operated like a legitimate international business since at least 2021, running about two dozen call centers across several countries and employing more than 700 people who posed as professional financial advisers.

#cybercrime #government #news

We built a vulnerability vending machine: AI tokens in, zero-days out

Intruder built an AI-powered “vulnerability vending machine” that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already un…

#security

KAPE 101: A Kroll Artifact Parser and Extractor Cheatsheet

Spend time performing forensic analysis on the Windows Operating System and you’ll see a host of artifacts that can be used to identify adversary activity. From changes to the registry to the System Resource Utilization Monitor, Windows artifacts run deep. The challenge is locating, extracting, and …

#blue-team #blue-team-tools #dfir #guest-author #how-to

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws

Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published.

The vulnerabilities are listed below -

CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation in the DOM: Navig…

#vulnerability

Windows Bind Link Attacks Can Hide Malware From EDR Tools

Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products. The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek.

#endpoint-security #malware--threats #featured #malware #windows

Investigating Persistence Mechanisms in AWS

OverviewIn the cloud, your infrastructure may be short-lived, but an attacker’s persistence doesn’t have to be. While your environment scales and changes in seconds, adversaries are embedding themselves into your IAM policies, Lambda functions, and federated sessions, creating invisible footholds th…

#aws

5 reasons to bring application security data into your exposure management platform

When you incorporate data from application security scanners into your exposure management platform, you can assess the threat from formerly isolated code flaws using a broader risk context, which illuminates hidden exposures that your security and development teams can eliminate together.Key takeaw…

US Charges Russian Individuals and Firms for Running Cybercrime Services

The suspects and their companies were previously sanctioned by the United States and its allies. The post US Charges Russian Individuals and Firms for Running Cybercrime Services appeared first on SecurityWeek.

#cybercrime #bulletproof-hosting #charged #russia

SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.

For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up.

Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctioned b…

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive.

It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as P…

#zero-day #vulnerability #patch #windows

A Video Screen That Is Also a Camera

Amazing: Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel’s full potential for carrying information by manipu…

#uncategorized #academic-papers #cameras #videos

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow

A critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code. The post Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow appeared first on SecurityWeek.

#vulnerabilities #fortinet #ivanti #servicenow #vulnerability

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute.

Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tok…

#windows

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.

#malware #threat-research #c2 #dga #docker-compose

OkoBot: new sophisticated malware framework targets cryptocurrency users

Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.

#great-research #malware-descriptions #malware-technologies #keyloggers #malware-descriptions

CISA warns admins to patch actively exploited SharePoint flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. […]

#security #microsoft

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell

The industrial giants fixed dozens of vulnerabilities across their ICS products, with advisories also released by CISA and VDE CERT. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell appeared first on SecurityWeek.

#icsot #ics #ics-patch-tuesday #ot #patch-tuesday

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity.

The affected packages are listed below -

@asyncapi/generator-helpers@1.1.1 @asyncapi/generator-compo…

#malware

Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates

Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed. The post Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates appeared first on SecurityWeek.

#vulnerabilities #chrome #firefox #public-poc #vulnerability

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution.

The vulnerabilities are listed below -

CVE-2026-15409 (CVSS score: 10.0) - A Server-si…

#zero-day #vulnerability

SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits

SonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution. The post SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits appeared first on SecurityWeek.

#vulnerabilities #exploited #sma1000 #sonicwall #zero-day

ICYMI: June 2026 @AWS Security

Read all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered identity and access…

#announcements #foundational-100 #security-identity--compliance #security-blog

Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review

Microsoft’s July 2026 Patch Tuesday delivers security updates for a broad range of products and services, including several vulnerabilities that pose significant risks to enterprise environments. As attackers continue to target unpatched systems, the timely deployment of these updates remains one of…

#patch-tuesday #vulnerabilities-and-threat-research #microsoft

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning p…

#security-tools #the-coming-storm #time-to-patch #action1 #active-directory-federation-services

Security Hub adds AI workload protection and multicloud support for Microsoft Azure

Security Hub is our foundation for full-stack enterprise security across clouds. It centralizes your security operations and turns raw signals into prioritized insights, so your team spends its time managing real risk instead of stitching tools together. Today that foundation grows in two directions…

#artificial-intelligence #aws-partner-network #aws-security-hub #foundational-100 #news

Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days

Two flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed. The post Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek.

#vulnerabilities #exploited #microsoft #patch-tuesday #zero-day

Microsoft releases Windows 10 KB5099539 extended security update

Microsoft has released the Windows 10 KB5099539 extended security update, which includes the July 2026 Patch Tuesday security updates for 570 vulnerabilities, along with additional security fixes. […]

#microsoft #security

Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)

56Critical510Important3Moderate0LowMicrosoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as imp…

#zero-day #vulnerability #patch #windows

Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims

The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid.  The post Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims appeared first on SecurityWeek.

#cybercrime #data-breaches #bosch #data-breach #fake-hack

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP.

The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows an authenticated a…

#vulnerability #patch

How Qualys ETM Identity Detects Identity-Based Attacks Faster

Key Takeaways Identity-based attacks are among the fastest and most effective intrusion methods because valid credentials let attackers operate as trusted users. Techniques like Pass-the-Hash, Kerberoasting, Domain Controller Synchronization (DCSync), and Authentication Server Response Roasting (AS-…

#product-and-tech #etm-identity #identity-security #identity-threat-detection-and-response #ispm

Manage Vendor Risk in a Few Practical Steps

Risk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance.

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments.

“LabubaRAT creates a reusable foothold for hands-on activity,” Blackpoint Cyber researchers Sam Decker an…

#malware #windows

Upcoming Speaking Engagements

This is a current list of where and when I am scheduled to speak:

I’m speaking (virtually) at the Policy-Relevant Privacy Research Workshop in Calgary, Canada, on Monday, July 20, 2026. I’m speaking at Boston Leadership Exchange in Boston, Massachusetts, USA, on Wednesday, July 22, 2026. I’m speaki…

#uncategorized #schneier-news

Authenticate legitimate AI agent traffic with AWS WAF Bot Control

As AI agents and automated tools increasingly access web applications, distinguishing legitimate bot traffic from malicious attempts has become a critical security challenge. Traditional approaches such as IP-based filtering and reverse DNS lookups fail in multi-tenant systems (such as Amazon Bedroc…

#aws-waf #intermediate-200 #security-identity--compliance #technical-how-to #security-blog

You Don't Have to Run an Exploit to Know If You're Vulnerable

Many vulnerabilities cannot be safely validated with live exploits, either because no exploit exists or the affected systems are too critical to test. Picus explains how TTP chaining helps organizations determine exploitability by validating the attack techniques an exploit depends on, without launc…

#security

7 Severe Vulnerabilities Patched in VMware Avi Load Balancer

The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal. The post 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer appeared first on SecurityWeek.

#vulnerabilities #avi-load-balancer #vmware #vulnerability

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries.

Miggo’s security te…

Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar

A ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions.  The post Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar appeared first on SecurityWeek.

#artificial-intelligence #ai #claude #vulnerability

CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)

OverviewRapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are …

#emerging-threats

11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard.

“An attacker exploiting one of these vulnerable applications can execute untru…

#vulnerability #iot #windows #linux

Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them.

The way these wallets talk to websites and blockchain servers can tie a person’s separate addresses togethe…

#privacy

How Pentera Turns AI Security Workflows into Validation Engines

AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragmented risk signals: scanner output, severity scores, threat intelligence, configuration findings, and e…

SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud

The flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization. The post SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud appeared first on SecurityWeek.

#vulnerabilities #patch #sap #vulnerability

Warning: Scammers are using FaceTime to empty bank accounts

Cybercriminals are combining social engineering through apps like FaceTime with unpatched devices to steal credentials and drain bank accounts.

#news #scams #facetime #social-engineering #unpatched

Vulnerability in FIFA’s Network

FIFA’s network was vulnerable to anyone with even minimal access.

#uncategorized #hacking #sports #vulnerabilities

Valarian Raises $50 Million for Sovereign Infrastructure Control Layer

UK-based cybersecurity firm Valarian has raised a total of $70 million for its ACRA technology. The post Valarian Raises $50 Million for Sovereign Infrastructure Control Layer appeared first on SecurityWeek.

#cybersecurity-funding #funding #valarian

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed.

A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out…

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors’ and other cybercriminals’ malicious activities, including ransomware attacks against Americans.

The VPN, named First VPN Service (1VPNS), …

#ransomware #malware #network

Rapid7 and Mindshare Partner to Accelerate Cyber Resilience Across the Middle East

Gopan Sivasankaran is Regional Director, Middle East & Africa, at Rapid7From AI adoption and cloud-first strategies to smart cities and critical infrastructure modernization, organizations across the United Arab Emirates are embracing innovation at an unprecedented rate. The country truly is setting…

#managed-detection-and-response-mdr #mssp #artificial-intelligence

The ransomware negotiator who was working for the other side

When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help.

Specialist ransomware negotiation firms handle communications with criminal gangs on a victim’s behalf.

What victims don’t expect is that their trusted negotiator might be separately sharing…

#data-loss #guest-blog #law--order #malware #ransomware

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

A campaign of 148 npm packages disguised as student web proxies turned visitors’ browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog.

The packages did not go after the developers who might install them. The operators used the regis…

#malware #ddos

Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity

Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.

The way in has been the trust the organization had already extended, usually through the OAuth connect…

#vulnerability #windows

AI Security Report 2026

For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from Check Point Research documents a transition that goes further. AI has c…

#check-point-research-publications

Hackers steal Lidl customer data from external service provider

The retailer said the incident did not affect its online shopping platform itself but involved a separately stored customer database maintained by a third-party provider. According to notifications sent to Lidl’s German, Belgian and Dutch customers on Friday, the attackers briefly accessed the file …

#cybercrime

Defending SaaS-based applications against ShinyHunters OAuth abuse

Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications. The post Defending SaaS-based applications …

#social-engineering #supply-chain-attack #vishing

EU leaders eye social media ban for children under age 13

“While ultimately it is up to parents to decide when children get their first smartphones, what we already have is a consensus that there needs to be a start date for the age children can join social media,” says European Commission President Ursula van der Leyen.

#technology #government #news #news-briefs

VPN service favored by ransomware groups is sanctioned by US

The U.S. Treasury Department announced sanctions against First VPN Service (1VPNS) and its Ukrainian administrator for aiding ransomware groups. Separately, a Belarusian man was sanctioned for malware “cryptors.”

#cybercrime #government #news #technology #people

CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that’s capable of harvesting sensitive data from compromised systems.

Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is implemented in nat…

#malware

⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More

Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That’s supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don’t file tickets.

That’s the shape of this week. Trusted code turns on the peo…

#ransomware

Lessons Learned from CISA’s Recent GitHub Leak

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials – including AWS Govcloud keys – in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Exper…

#a-little-sunshine #data-breaches #latest-warnings #brad-libbey #cybersecurity-and-infrastructure-security-agency

Breach at the Beach: Play the Ultimate Entra ID CTF

Learn how attackers abuse Entra ID through a free hands-on Capture the Flag. Varonis created the Breach at the Beach CTF to teach defenders how to investigate Entra ID attack techniques using realistic scenarios. […]

#security

Why cloud security is mission-critical for federal civilian and defense agencies

Beyond IT compliance, cloud security is now the backbone of civilian agency resilience, national defense, and warfighter safety, as cloud environments become increasingly complex.Key takeawaysFor the Department of War (DoW), cloud security is an IT concern and a requirement for operational readiness…

#cloud

New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email

Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false “fact” about the user, hide the change, and quietly steer its answers in later sessions.

When it works, the pe…

New compliance guidance available: HITRUST i1 on AWS

We are pleased to announce the publication of a new AWS compliance implementation guidance: HITRUST i1 Compliance on AWS: Customer Implementation Guidance with an Illustrative Healthcare Platform. Healthcare organizations seeking HITRUST i1 certification increasingly rely on Amazon Web Services (AWS…

#announcements #compliance #intermediate-200 #security-identity--compliance #aws-compliance

13th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employee and used compromi…

#global-cyber-attack-reports

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts.

Distrib…

#phishing #windows

Introducing Precursor: detecting agentic behavior with continuous client-side signals

Precursor, our new continuous behavioral validation engine for bot management, offers visibility into how humans and bots actually interact across the full user journey. By turning session-level behavior into bot detection signals, it identifies advanced automation with higher precision — while redu…

#bot-management #security #turnstile #javascript #ai

Cybersecurity M&A Roundup: 37 Deals Announced in June 2026

Significant cybersecurity M&A deals announced by 1Password, Accenture, Cisco, F5, Rubrik, and SailPoint. The post Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 appeared first on SecurityWeek.

#ma-tracker #acquisitions #ma

RabbitMQ Vulnerability Threatens Enterprise Systems

Unauthenticated attackers could obtain the broker’s confidential OAuth client secret, allowing them to take control of the broker. The post RabbitMQ Vulnerability Threatens Enterprise Systems appeared first on SecurityWeek.

#vulnerabilities #featured #rabbitmq #vulnerability

Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling

Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read.

Each read gets pinned to the moment it happened: the time, your location, what you were doing, even…

EU sanctions Russian GRU military hackers over cyberattacks

The European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Europe. […]

#security

Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration.

“The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting …

#apt

AI Data Centers and the Concentration of Wealth

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian. Opposition to AI data centers has emerged as a primary theme in US politics, one that—surprisingly—doesn’t fall along party lines. We applaud people coming together for constructive debate on any issue, and agree…

#uncategorized #ai #laws #llm #regulation

Zimbra Patches Critical Code Execution Vulnerability

The flaw results in malicious code embedded in crafted emails being executed when the emails are opened. The post Zimbra Patches Critical Code Execution Vulnerability appeared first on SecurityWeek.

#email-security #vulnerabilities #patch #remote-code-execution #vulnerability

EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign

The move targeted people and entities accused of links to an online spying network that the EU claims targeted governments and carried out sabotage operations against critical infrastructure. The post EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign appea…

#cyberwarfare #nation-state #eu #russia

US and allies warn of Russian critical infrastructure attacks

Cybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks. […]

#security

Organizations Warned of Exploited Joomla Extension Vulnerabilities

Threat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution. The post Organizations Warned of Exploited Joomla Extension Vulnerabilities appeared first on SecurityWeek.

#vulnerabilities #cisa-kev #exploited #joomla

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history.

From that one lapse, French security firm Lexfo …

#phishing #windows

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild.

The vulnerabilities, both…

#zero-day #vulnerability

OpenAI temporarily relaxes GPT-5.6 Sol usage limits

OpenAI is temporarily relaxing GPT-5.6 Sol usage after demand for the company’s most powerful model surged over the past 48 hours. […]

#artificial-intelligence #technology

RedHook Android malware now uses Wireless ADB for shell access

A new version of the RedHook Android malware abuses the Android Wireless Debugging (Wireless ADB) mechanism in a novel way to gain shell-level privileges without requiring a computer connection. […]

#security #mobile

Why we cannot wait for better post-quantum signature algorithms

NIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and argue that while they are in the works and show great potential, we should use ML-DSA for now — the best currently available.

#cryptography #post-quantum #research #security

Finding the “Goldilocks” Zone: A Practical Approach to Alert Triage

We’re all petrified about missing a critical event or misclassifying an alert, but when we’re talking about incident response (IR), there are often hundreds if not thousands of alerts to parse through. It’s easy to get caught up with one alert because it feels “too hot” or maybe not spend enough tim…

#active-soc #blue-team #dfir #hayden-covington #incident-response

ESET Threat Report H1 2026

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

#eset-research

Unmasking the crawls with Attribution Business Insights

Cloudflare’s new Attribution Business Insights dashboard helps website owners understand crawler behavior, appetite, and potential value, fueling business-level conversations around crawl compensation.

#ai #bot-management #bots #content-independence-day #security

Unlocking the Cloudflare app ecosystem with OAuth for all

Self-Managed OAuth is now available to all developers on Cloudflare. Here’s how we executed a zero-downtime migration of our core OAuth engine to make it happen.

#agents #api #cloudflare-media-platform #developer-platform #developers

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible to go from a zero-click context to root on Android in just two exploits. The Dolby 0-click vulnerability existed across all of Android, until it was patched in January 2026. While we had an exploit chain …

#vulnerability #patch

AI threats in the wild: The current state of prompt injections on the web

Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the secur…

#injection

Bringing Rust to the Pixel Baseband

Posted by Jiacheng Lu, Software Engineer, Google Pixel Team

Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with m…

#android #android-security #pixel

Protecting Cookies with Device Bound Session Credentials

Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team

Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upco…

#authentication #windows

On the Effectiveness of Mutational Grammar Fuzzing

Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar that describes the structure of the samples. When a sample gets mutated, the mutations happen in such a way that any resulting samples still adhere to the grammar rules, thus the structure of the samples …

A Deep Dive into the GetProcessHandleFromHwnd API

In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I thought I should take a closer look. I typically start by reading …

Top 10 web hacking techniques of 2025

Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year

The Fragile Lock: Novel Bypasses For SAML Authentication

TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi

#vulnerability #authentication

> Vulnerability Research

Announcing the External Penetration Testing Program Pack

This release contains everything you need to scope your first pentest, work with a vendor, execute, and get the types of reports you need from an external tester. This will enable you to perform your …

PE OopsSec: Mind your PE, guard your OPSEC

This article helps identify Operational Security (OPSEC) vulnerabilities and structural discrepancies inside compiled Windows Portable Executable (PE) files.

AI Agent for reconaissasion

Hey everyone, I’ve been experimenting with building an AI-powered reconnaissance agent, and I’m excited to finally share it with the community! It’s now publicly available with limited free credits so…

When LLMs do more than they have to

I wanted to build an HTML file with Claude. And it started a Node server to open it. And there was a Directory Traversal as well there. Always review what agents / LLMs do

Enhancing IIoT Security Using Digital Twins in Industry

The AI research centre at Torrens University Australia has helped produce a review of 110 studies on digital twins and IIoT security. What were the main takeaways? They have found that DTs are shiftin…

On the Effectiveness of Mutational Grammar Fuzzing

Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar that describes the structure of the samples. When a sample gets mutated, the mutations happen in such a …

A Deep Dive into the GetProcessHandleFromHwnd API

In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application….

Bypassing Administrator Protection by Abusing UI Access

In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didn’t exist. I described one of the ways I was able …

Top 10 web hacking techniques of 2025

Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year

Introducing HTTP Anomaly Rank

HTTP Anomaly Rank If you’ve ever used Burp Intruder or Turbo Intruder, you’ll be familiar with the ritual of manually digging through thousands of responses by repeatedly sorting the table via length,

Leaking File Contents with a Blind File Oracle in Flarum

Introduction

Flarum is a free, open source PHP-based forum software used for everything from gaming hobbyist sites to cryptocurrency discussion. A quick survey on Shodan suggests there are over 1200 …

Advisory: Flarum LFI - CVE-2023-40033

Summary

An attacker with a basic user forum account can specify a malicious avatar URL that discloses the contents of arbitrary local files on the file system.

Impact

An attacker can read the conte…

> This Month's Exploited CVEs

CVE-2026-48282 Critical CVSS: 10.0

EPSS: 3.2% probability of exploitation in the next 30 days.

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

2026-06-30 Affected: adobe coldfusion
#actively-exploited #critical #path-traversal
CVE-2026-48558 Critical CVSS: 10.0

EPSS: 1.2% probability of exploitation in the next 30 days.

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

2026-06-12 Affected: simple-help simplehelp
#actively-exploited #critical #auth-bypass
CVE-2026-10520 Critical CVSS: 10.0

EPSS: 99.0% probability of exploitation in the next 30 days.

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.

2026-06-09 Affected: ivanti standalone_sentry
#actively-exploited #critical #rce #injection
CVE-2026-56290 Critical CVSS: 9.8

EPSS: 0.7% probability of exploitation in the next 30 days.

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

References

2026-06-29 Affected: joomlack page_builder_ck
#actively-exploited #critical #rce
CVE-2026-48908 Critical CVSS: 9.8

EPSS: 1.4% probability of exploitation in the next 30 days.

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

References

2026-06-20 Affected: ollyo sp_page_builder
#actively-exploited #critical
CVE-2026-12569 Critical CVSS: 9.8

EPSS: 1.1% probability of exploitation in the next 30 days.

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions

  • The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

2026-06-18 Affected: ptc flexplm
#actively-exploited #critical #rce #deserialization
CVE-2026-35273 Critical CVSS: 9.8

Known ransomware campaign usage.

EPSS: 92.3% probability of exploitation in the next 30 days.

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

2026-06-11 Affected: oracle peoplesoft_enterprise_peopletools
#actively-exploited #critical #ransomware
CVE-2026-20253 Critical CVSS: 9.8

EPSS: 88.2% probability of exploitation in the next 30 days.

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.

2026-06-10 Affected: splunk splunk
#actively-exploited #critical #auth-bypass
CVE-2026-11645 High CVSS: 8.8

EPSS: 1.7% probability of exploitation in the next 30 days.

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

2026-06-09 Affected: google chrome
#actively-exploited #high
CVE-2026-54420 High CVSS: 8.5

EPSS: 1.3% probability of exploitation in the next 30 days.

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.

2026-06-14 Affected: litespeedtech litespeed_cpanel_plugin
#actively-exploited #high
CVE-2026-55255 High CVSS: 8.4

EPSS: 0.4% probability of exploitation in the next 30 days.

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim’s flow ID in the request. This vulnerability is fixed in 1.9.1.

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim’s flow ID in the request.

2026-06-23 Affected: langflow langflow
#actively-exploited #high
CVE-2026-20262 Medium CVSS: 6.5

EPSS: 7.7% probability of exploitation in the next 30 days.

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.

This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This

2026-06-15 Affected: cisco catalyst_sd-wan_manager
#actively-exploited #privilege-escalation

> whoami

root@s3c.zip:~# cat /etc/hacker.conf
[identity]
name      = Andrii Lyho
role      = Penetration Testing Lead
location  = Warsaw, PL
motto     = Hacking for Fun and Profit
 
[focus]
areas     = AppSec, Cloud Security, Offensive Research
tools     = Burp Suite, AWS, Kubernetes, Python
 
[certs]
offensive = OSCP, OSWE
cloud     = ARTE
web       = BSCP
root@s3c.zip:~# ls -la ./links
-r--r-----  LinkedIn