2026-07-25
[The Hacker News]
A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL.
Confiant, which detailed the campaign on July 23, 2026, said it has operat…
#malware #windows
2026-07-25
[Bleeping Computer]
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. […]
#security
2026-07-25
[Bleeping Computer]
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. […]
#security
2026-07-25
[The Hacker News]
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.
Tracked as CVE-2026-16723,…
#vulnerability #rce #patch #authentication
2026-07-25
[The Hacker News]
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose.
That model is changing.
Recent investigations i…
#phishing #authentication
2026-07-25
[The Hacker News]
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.
“Attackers chain a pre-authentication information disclosure i…
#ransomware #vulnerability #apt #rce #authentication
2026-07-25
[Bleeping Computer]
ChatGPT, the famous artificial intelligence chatbot that allows users to converse with various personalities and topics, has connectivity issues worldwide. […]
#artificial-intelligence #technology
2026-07-25
[The Hacker News]
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server.
An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their diff. The …
#vulnerability #rce #patch
2026-07-25
[SecurityWeek]
A researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations.
The post Rockwell Patches Code Execution Flaws in Arena Simulation Software appeared first on SecurityWeek.
#icsot #vulnerabilities #ics #rockwell #vulnerability
2026-07-24
[Dark Reading]
Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide.
2026-07-24
[Schneier on Security]
Lower catch this year.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy.
#uncategorized #squid
2026-07-24
[Bleeping Computer]
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. […]
#security
2026-07-24
[AWS Security]
When an administrator introduces a rule change in AWS Network Firewall and network connectivity is disrupted, pinpointing the cause requires inspecting multiple points in the traffic path. The firewall gives you stateless and stateful rule engines, domain rules, and routing to the firewall endpoint …
#advanced-300 #aws-network-firewall #devops #networking--content-delivery #security
2026-07-24
[Dark Reading]
The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best.
2026-07-24
[Bleeping Computer]
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. […]
#security
2026-07-24
[The Record]
The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.
#government #leadership #people #news
2026-07-24
[The Record]
There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.
#cybercrime #news
2026-07-24
[Bleeping Computer]
Microsoft says a bug in its automated network maintenance request system caused Thursday’s massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. […]
#microsoft
2026-07-24
[The Hacker News]
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware.
“BlueNoroff has …
#malware #phishing #apt #windows
2026-07-24
[Malwarebytes Labs]
Scammers are using stolen videos and fake artist profiles to trick people into buying resin art that never arrives. Here’s how to spot the warning signs.
#news #scams #resin-art #scam #tiktok
2026-07-24
[Malwarebytes Labs]
A phishing site posing as a free Call of Duty Points giveaway is stealing Activision logins and two-factor authentication codes.
#scams #threat-intel
2026-07-24
[Malwarebytes Labs]
An OpenAI agent escaped its sandbox, stole credentials, and broke into Hugging Face. Here’s what that actually means.
#ai #news #hugging-face #openai #sandbox
2026-07-24
[SecurityWeek]
Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt.
The post In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws…
#malware--threats #ransomware #vulnerabilities #in-other-news
2026-07-24
[The Hacker News]
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine.
They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replicatio…
#vulnerability
2026-07-24
[Bleeping Computer]
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. […]
#security
2026-07-24
[Bleeping Computer]
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malic…
#security
2026-07-24
[Malwarebytes Labs]
A new selfie video verification feature could make recovering your Google Account easier. But it also creates new security and privacy concerns.
#ai #news #privacy
2026-07-24
[Dark Reading]
A porous API endpoint exposes, names, email addresses, country, and site status, all of which can be easily gleaned by anyone with a browser.
2026-07-24
[Bleeping Computer]
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to “The Com,” a loosely organized network of nihilistic violent extremist groups. […]
#security
2026-07-24
[Dark Reading]
Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation which could have let attackers seize another tenant’s identity and access other tenants’ data, credentials, and cloud workloads.
#cloud #authentication #windows
2026-07-24
[SecurityWeek]
The company has raised a total of $49 million in funding, including from Battery Ventures, Accel and Foundation Capital.
The post AegisAI Raises $36 Million for AI-Powered Email Security appeared first on SecurityWeek.
#cybersecurity-funding #email-security #aegisai #email-security #funding
2026-07-24
[Infosecurity Magazine]
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign
#authentication #network
2026-07-24
[Malwarebytes Labs]
Some threats never pass through the Play Store. Others arrive later in seemingly legitimate updates. Here’s how Malwarebytes detects both.
#inside-malwarebytes #product
2026-07-24
[The Hacker News]
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim’s organization.
The vulnerability has bee…
#phishing #vulnerability
2026-07-24
[The Hacker News]
A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet.
XBOW’s testing got the same result on workers across different hosts and network ranges, so the problem sat in …
#windows #linux
2026-07-24
[The Hacker News]
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we’ve collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to i…
2026-07-24
[SecurityWeek]
Industry professionals debate whether it represents a lab containment failure or an unprecedented agentic capability milestone.
The post Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday appeared first on SecurityWeek.
#artificial-intelligence #ai #feedback-friday #hugging-face #openai
2026-07-24
[Bleeping Computer]
An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos. […]
#security
2026-07-24
[Infosecurity Magazine]
OpenAI’s chatbot tool ChatGPT ranked among the top 10 most impersonated brands in phishing attacks for the first time
#phishing
2026-07-24
[Schneier on Security]
This essay was written with Barath Raghavan, and originally appeared in The Guardian.
Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to do it. We propose a new m…
#uncategorized #ai #llm
2026-07-24
[The Hacker News]
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand’s Ministry of Finance, which runs the country’s treasury and tax collection.
The agent then worked through the ministry’s netw…
#vulnerability
2026-07-24
[The Hacker News]
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.
The malware families in question are: Tin…
#malware #apt
2026-07-24
[Infosecurity Magazine]
Comparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher education
#ransomware
2026-07-24
[The Hacker News]
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software’s source code.
Every version before 4.14.0 is affected. NodeBB has fixe…
#vulnerability #patch
2026-07-24
[Bleeping Computer]
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. […]
#security
2026-07-24
[Dark Reading]
The AI security layer and guardrails for many AI products don’t evenly protect against jailbreaking and unsafe actions in every single language.
2026-07-24
[The Hacker News]
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.
All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis say…
#zero-day #vulnerability #rce
2026-07-24
[The Hacker News]
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems.
The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russ…
#windows
2026-07-24
[SecurityWeek]
A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it.
The post Data Breach Confirmed After Australian Energy Giant Origin Is Hacked appeared first on SecurityWeek.
#data-breaches #australia #data-breach #energy #origin-energy
2026-07-24
[Elastic Security Labs]
We tested two agentic SOC architectures in parallel across 36,822 real Agent Builder conversations. One won by 5.7x: a specialized workflow triaging alerts for $0.69 each, against $3.42 for a single agent juggling 14 Skills. The data and the decision framework are both below.
#security-labs
2026-07-23
[Dark Reading]
A state-sponsored threat group, dubbed “Laundry Bear,” sends “half-click” phishing emails that require a victim only to open or preview the message.
#zero-day #phishing #vulnerability
2026-07-23
[Bleeping Computer]
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. […]
#security
2026-07-23
[Bleeping Computer]
Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. […]
#security
2026-07-23
[Bleeping Computer]
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. […]
#security #artificial-intelligence
2026-07-23
[The Hacker News]
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client.
The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept for two-factor r…
#zero-day #vulnerability #authentication
2026-07-23
[The Record]
A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.
#nation-state #news
2026-07-23
[Bleeping Computer]
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. […]
#security
2026-07-23
[Bleeping Computer]
Ukraine’s CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. […]
#security
2026-07-23
[The Record]
Individuals connected to transnational cyber-scam operations face U.S. visa restrictions under a new policy announced by Secretary of State Marco Rubio.
#cybercrime #government #news #news-briefs
2026-07-23
[Infosecurity Magazine]
International agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration Suite
#vulnerability
2026-07-23
[CERT/CC]
Overview
The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA, replay externally issued SSO responses, or …
#vulnerability #authentication
2026-07-23
[Bleeping Computer]
Microsoft Teams and several Microsoft 365 services are experiencing an ongoing outage, with users reporting problems accessing Teams, SharePoint, Excel and the Microsoft 365 Admin Center. […]
#microsoft #software
2026-07-23
[SecurityWeek]
AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization.
The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider appeared first on SecurityWeek.
#artificial-intelligence #chatgpt #vulnerability
2026-07-23
[The Hacker News]
Most of this week’s trouble came dressed as something useful.
A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic.
The threats change every w…
#injection
2026-07-23
[SecurityWeek]
You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win.
The post Is Patching Dead? Vulnerability Management in the Post-Mythos Era appeared first on SecurityWeek.
#artificial-intelligence #vulnerabilities #ai #patch
2026-07-23
[Microsoft Security]
In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-st…
#adversary-in-the-middle-aitm #credential-theft #phishing #social-engineering
2026-07-23
[SecurityWeek]
Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts.
The post Chick-fil-A Accounts Get Fried in Credential Stuffing Attack appeared first on SecurityWeek.
#data-breaches #chick-fil-a #credential-stuffing #data-breach
2026-07-23
[Palo Alto Unit 42]
Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials.
The post Russian Global Webmail Espionage appeared first on Unit 42.
#cybercrime #threat-research #cl-sta-1114 #javascript #javascript-injection
2026-07-23
[Bleeping Computer]
FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assurance. […]
#security
2026-07-23
[Infosecurity Magazine]
CoreView research finds that security leadership is concerned about AI Assistant exposing confidential data
#windows
2026-07-23
[SecurityWeek]
The latest investment round brings the total raised by Abstract to nearly $50 million.
The post Abstract Raises $25 Million to Expand Composable Security Operations Platform appeared first on SecurityWeek.
#cybersecurity-funding #abstract-security #funding #soc
2026-07-23
[Infosecurity Magazine]
US government agencies have warned that Iranian cyber actors are targeting US-based Siemens and Schneider industrial equipment
2026-07-23
[The Hacker News]
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.
Accomplish AI, which shared details of the…
#vulnerability #linux
2026-07-23
[The Record]
Origin Energy said it was working to figure out how many Australians were affected by a recent data breach.
#news-briefs #news #cybercrime #industry
2026-07-23
[Rapid7 Blog]
The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry to confront a quest…
#supply-chain-security #artificial-intelligence #incident-response
2026-07-23
[SecurityWeek]
SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot.
The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek.
#artificial-intelligence #malware--threats #ai #ai-benchmark #benchmark
2026-07-23
[Bleeping Computer]
The European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union’s Digital Markets Act (DMA), which ensures fair online competition. […]
#google #technology
2026-07-23
[The Hacker News]
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.
Group-IB found the s…
#windows
2026-07-23
[Rapid7 Blog]
OverviewOn July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232, an authentication bypass in the SmartConsole login process classified as imprope…
#emergent-threat-response #labs #vulnerability-management
2026-07-23
[The Hacker News]
Most people understand identity theft as an attacker stealing a real person’s sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points wi…
2026-07-23
[Bleeping Computer]
A nine-year-old race condition vulnerability in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. […]
#linux #security
2026-07-23
[Infosecurity Magazine]
Sophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threats
2026-07-23
[The Hacker News]
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances.
The activity involves malicious Packagist development versions spanning 10 packag…
2026-07-23
[Malwarebytes Labs]
A hidden flaw in a dealer-installed car alarm could let attackers unlock vehicles and track their locations. Many owners don’t know they have one.
#bugs #news
2026-07-23
[Malwarebytes Labs]
HermeticReader is a now-patched vulnerability in Adobe’s popular Acrobat Chrome extension that could have been used to spy on WhatsApp Web users.
#bugs #news #privacy #adobe #cve-2026-48294
2026-07-23
[Dark Reading]
Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers.
2026-07-23
[Schneier on Security]
New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“:
Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current…
#uncategorized #academic-papers #backdoors #crypto-wars #encryption
2026-07-23
[SecurityWeek]
Hackers recently obtained non-sensitive customer information and other documents from the company.
The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses appeared first on SecurityWeek.
#data-breaches #fraud--identity-theft #data-breach #fraud #upbound-group
2026-07-23
[Infosecurity Magazine]
Dolphin X is a new infostealer that uses AI to sort and rank victims, giving cybercriminals a faster way to identify lucrative targets
#malware
2026-07-23
[Bleeping Computer]
The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. […]
#security
2026-07-23
[The Hacker News]
Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video.
The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone number. The idea is to …
2026-07-23
[SecurityWeek]
He replaces Guy Rosen, who announced his retirement from the company after 13 years.
The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek.
#ciso-strategy #management--strategy #assaf-keren #ciso #meta
2026-07-23
[Bleeping Computer]
Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers’ mailboxes since Sunday. […]
#microsoft
2026-07-23
[CrowdStrike]
#public-sector
2026-07-23
[Bleeping Computer]
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company’s SmartConsole graphical user interface (GUI) admin panel. […]
#security
2026-07-23
[Infosecurity Magazine]
A new study of organizations which have fallen victim to ransomware suggests the rise of AI-tools being used by hackers is making life harder for defenders
#ransomware
2026-07-23
[Dark Reading]
Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets.
#malware
2026-07-23
[The Hacker News]
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild.
The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is …
#vulnerability #patch
2026-07-23
[SecurityWeek]
An updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers.
The post US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices appeared first on SecurityWeek.
#icsot #alert #government #ics #iran
2026-07-23
[Zero Day Initiative]
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.4.
#vulnerability
2026-07-23
[Zero Day Initiative]
This vulnerability allows local attackers to escape the model runner sandbox on affected installations of Docker Desktop for macOS. An attacker must first obtain the ability to execute low-privileged code within the sandbox in order to exploit this vulnerability. The ZDI has assigned a CVSS rating o…
#vulnerability
2026-07-23
[Zero Day Initiative]
This vulnerability allows remote attackers to execute arbitrary code on affected installations of AzeoTech DAQFactory. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The fo…
#vulnerability #rce
2026-07-23
[Dark Reading]
A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken.
#ransomware
2026-07-23
[Elastic Security Labs]
We ran the wp2shell WordPress RCE chain end-to-end with Elastic Defend. Detection rule walkthrough, IOCs, and hunt guidance.
#security-labs
2026-07-23
[Elastic Security Labs]
Elastic InfoSec tested this detection rule pattern on their own cloud fleet, filtering noisy curl and wget events with deterministic logic and LLM triage so only genuine threats reach an analyst.
#security-labs
2026-07-22
[Dark Reading]
Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users.
#vulnerability #windows
2026-07-22
[Graham Cluley]
A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets.
Meanwhile, AI music generator Suno has been hacked - and the stolen data appears to sho…
#ai #data-loss #law--order #podcast #data-breach
2026-07-22
[The Record]
Stadler Rail said it will not make a $12.3 million ransom payment after cybercriminals stole technical data from a supplier’s file-sharing platform.
#news-briefs #cybercrime
2026-07-22
[Bleeping Computer]
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. […]
#security
2026-07-22
[Dark Reading]
Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.
#malware #vulnerability
2026-07-22
[The Record]
A 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House’s fiscal 2027 defense authorization bill.
#government #industry #news
2026-07-22
[Bleeping Computer]
South Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. […]
#security #government
2026-07-22
[Dark Reading]
A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes.
#malware #vulnerability #privacy
2026-07-22
[The Record]
The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says.
#cybercrime #government #news #news-briefs #technology
2026-07-22
[The Hacker News]
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more.
Reports filed before that date, including those alrea…
2026-07-22
[The Hacker News]
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment.
The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8),…
#vulnerability #linux
2026-07-22
[The Record]
Both houses of the French Parliament voted to block social media access for children under 15, making France the first European country to enact a ban amid a broadening global crackdown.
#news
2026-07-22
[CERT/CC]
Overview
Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placing malicious files, …
#vulnerability
2026-07-22
[Bleeping Computer]
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. […]
#security
2026-07-22
[SentinelOne Labs]
A real-world benchmark tests whether powerful AI models can keep an investigation trustworthy when new evidence invalidates their conclusions.
#openai #reverse-engineering
2026-07-22
[The Record]
A North Korean advanced persistent threat (APT) group recently targeted vendors of collaborative-work software, South Korean researchers said.
#nation-state #malware #news
2026-07-22
[Qualys Threat Research]
Executive summary Qualys Threat Research Unit (TRU) identified CVE-2026-64600, a race condition in the Linux kernel’s XFS filesystem copy-on-write path. An attacker with an ordinary local account can exploit this race condition to overwrite protected files on disk and gain host root privileges on af…
#vulnerabilities-and-threat-research #ai-research #anthropic #glasswing #linux
2026-07-22
[Microsoft Security]
Our collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions.
The post Real world incident response: Microsoft and AXA XL strengthen cyber resilience appeared first o…
#windows
2026-07-22
[Dark Reading]
Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective.
2026-07-22
[The Record]
Nichirei Logistics Group said warehouse operations and frozen food shipments are returning to normal. A cybercrime gang said it caused the disruption.
#industry #cybercrime #news
2026-07-22
[Bleeping Computer]
Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption. […]
#security
2026-07-22
[SecurityWeek]
Hackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms.
The post Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts appeared first on SecurityWeek.
#data-breaches #data-breach #paidwork #suno
2026-07-22
[Infosecurity Magazine]
New TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP pattern
#network
2026-07-22
[SecurityWeek]
Acquisition follows January’s Chronosphere deal, deepening Palo Alto Networks’ push beyond core security into observability.
The post Palo Alto Networks to Acquire Observability Platform Provider Embrace appeared first on SecurityWeek.
#fundingma #network-security #acquisition #palo-alto-networks
2026-07-22
[CERT/CC]
Overview
Version 3.5.8 of Analog Way’s Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script.
Description
The Picturall Quad Compact Mark II …
#vulnerability
2026-07-22
[SecurityWeek]
An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts.
The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek.
#vulnerabilities #adobe #data-leak #vulnerability #whatsapp
2026-07-22
[Bleeping Computer]
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. […]
#security
2026-07-22
[Black Hills InfoSec]
Security Operations Centers (SOCs) serve as a critical line of defense against today’s constantly evolving cybersecurity threats. At the heart of these teams are SOC analysts, who monitor, detect, and respond around the clock to potential attacks.
The post The Life of a SOC Analyst: Responsibilities…
#active-soc #blue-team #incident-response #informational #infosec-101
2026-07-22
[Rapid7 Blog]
If Q1 set the pace for Rapid7’s tools, Q2 accelerated it. This quarter brought a steady stream of product enhancements, platform investments, and customer-driven innovation across Rapid7’s portfolio. Each release was designed with a clear goal in mind: helping security teams reduce complexity while …
#managed-detection-and-response-mdr #exposure-command #siem #research
2026-07-22
[Bleeping Computer]
The Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication. […]
#security
2026-07-22
[SecurityWeek]
Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues.
The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek.
#application-security #artificial-intelligence #vulnerabilities #vibe-coding
2026-07-22
[SecurityWeek]
The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform.
The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek.
#cybersecurity-funding #email-security #email-security #funding #strongestlayer
2026-07-22
[Malwarebytes Labs]
If you have a Chick-fil-A One account, now is a good time to change your password—and make sure it’s one you don’t use anywhere else.
#data-breaches #news #chick-fil-a #credential-stuffing #passwords
2026-07-22
[The Hacker News]
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.
The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint ("/…
#vulnerability #authentication
2026-07-22
[The Record]
OpenAI announced that its models were behind a breach of the AI platform Hugging Face, which had earlier detected an attack carried out by “by an autonomous AI agent.”
#news
2026-07-22
[The Hacker News]
Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned.
According to McKinse…
2026-07-22
[Bleeping Computer]
The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. […]
#security
2026-07-22
[Infosecurity Magazine]
Hugging Face recently disclosed a security breach. OpenAI has now said that it was its AI models which broke containment and hacked Hugging Face themselves
2026-07-22
[Malwarebytes Labs]
A reported breach at microtask platform Paidwork exposed personal and financial data of more than 23 million users. Here’s how to check if you’re affected.
#data-breaches #news #data-breach #paidwork #penny-wise
2026-07-22
[Dark Reading]
European banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns.
#privacy
2026-07-22
[SecurityWeek]
CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access.
The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek.
#vulnerabilities #exploited #sharepoint #vulnerability
2026-07-22
[The Hacker News]
The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely.
The CrowdStrike Glob…
#malware
2026-07-22
[Bleeping Computer]
Cloud storage costs tend to creep up over time, since most services charge monthly or annually for as long as you use them. FileJump’s Lifetime Plan skips that model entirely, offering 2TB of cloud storage for a single payment of $59 (MSRP $467). […]
#security
2026-07-22
[Schneier on Security]
Harrowing story of an identity theft victim.
Yes, the person made a mistake—they gave the scammer a two-factor authentication code that allowed the scammer to take over their email address. But the real story here is how, for many of us, the security of most of our accounts hangs on the security of …
#uncategorized #identity-theft #social-engineering #two-factor-authentication
2026-07-22
[Infosecurity Magazine]
New Ubuntu snap-confine race condition lets local users escalate to root on default installs
#vulnerability #linux
2026-07-22
[Bleeping Computer]
Microsoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in October. […]
#microsoft #security
2026-07-22
[Infosecurity Magazine]
CodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitable
#vulnerability
2026-07-22
[SecurityWeek]
Using AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement.
The post Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation appeared first on SecurityWeek.
#cybersecurity-funding #endpoint-security #endpoint-security #funding #glow
2026-07-22
[SecurityWeek]
Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI.
The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek.
#vulnerabilities #ai #oracle #oracle-cpu #patches
2026-07-22
[SecurityWeek]
The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary.
The post Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife appeared first on SecurityWeek.
#data-breaches #ransomware #coca-cola #data-breach #fairlife
2026-07-22
[Bleeping Computer]
American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. […]
#security
2026-07-22
[The Hacker News]
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it.
In a joint announcement on Monday, the Frankfu…
#phishing #authentication #windows
2026-07-22
[The Hacker News]
Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain.
The package, named “Newtonsoftt.Json.Net,” masquerades as the Newtonsoft.Js…
#malware
2026-07-22
[Bleeping Computer]
OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. […]
#security
2026-07-22
[The Hacker News]
A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds.
The flaw is in Microsoft’s official Azure DevOps MCP server, and it works because one of…
#cloud #windows
2026-07-22
[Krebs on Security]
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available fo…
#a-little-sunshine #internet-of-things-iot #the-coming-storm #bright-data #john-taylor
2026-07-21
[Bleeping Computer]
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. […]
#security #legal
2026-07-21
[Dark Reading]
Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations.
#ransomware
2026-07-21
[Dark Reading]
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals.
#vulnerability
2026-07-21
[Tenable Research]
Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates.Key TakeawaysThe third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release.261 issues (18% of all patches) were as…
#patch
2026-07-21
[Bleeping Computer]
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. […]
#security
2026-07-21
[CrowdStrike]
#securing-ai
2026-07-21
[The Record]
By a party-line vote, the Senate Intelligence Committee sent the nomination of Jay Clayton to lead ODNI to the Senate floor.
#people #leadership #government #news #news-briefs
2026-07-21
[Bleeping Computer]
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola’s Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. […]
#security
2026-07-21
[The Hacker News]
Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked, effectively undermining the feature’s privacy guarantees.
404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a yea…
#privacy
2026-07-21
[Dark Reading]
A Russian-speaking actor, “Trim,” dismantled publicly available frontier models and integrated them with offensive security tools.
2026-07-21
[SecurityWeek]
New executive order calls for end-to-end visibility into defense supply chains, including software dependencies, foreign ownership and cyber-related supplier risks.
The post Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains appeared first on SecurityWeek.
#government #supply-chain-security #executive-order #sbom
2026-07-21
[SecurityWeek]
The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models.
The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek.
#artificial-intelligence #ai #artificial-inteligence #cisco #cisco-antares
2026-07-21
[The Record]
The Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 million people worldwide.
#cybercrime #news #news-briefs
2026-07-21
[AWS Security]
AWS WAF classifies web traffic by attaching metadata to each request it evaluates. Managed rule groups such as AWS WAF Bot Control and AWS WAF Fraud Control account takeover prevention (ATP) attach labels that describe what they found. A label can record that a request came from a known bot category…
#aws-waf #security-identity--compliance #technical-how-to #security-blog
2026-07-21
[CERT/CC]
Overview
The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other workspaces.
Description
Plane is an open-source pr…
#vulnerability
2026-07-21
[Bleeping Computer]
Hackers are exploiting the “wp2shell” critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. […]
#security
2026-07-21
[The Hacker News]
Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code on a developer’s machine, with no approval step able to stop it.
Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to su…
#cloud
2026-07-21
[The Hacker News]
Google’s DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that’s designed to discover, validate, and patch vulnerabilities quickly and efficiently.
According to the tech giant, the model will be exclusively av…
#vulnerability #patch
2026-07-21
[Qualys Threat Research]
Executive Summary AI is rapidly transforming vulnerability discovery, outpacing many security teams’ ability to adapt. Microsoft’s July 2026 Patch Tuesday addressed a record 622 vulnerabilities, an early signal of AI-accelerated discovery at scale compounding an already-large backlog that manual rem…
#product-and-tech #ai #patch-tuesday #trurisk-eliminate
2026-07-21
[Qualys Threat Research]
The Qualys Threat Research Unit (TRU) has identified a Local Privilege Escalation (LPE) vulnerability in snap-confine (CVE-2026-8933). This flaw allows an unprivileged local user to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The issue stems from a secur…
#vulnerabilities-and-threat-research #security #vulnerabilities
2026-07-21
[The Hacker News]
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr.
The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint tha…
#vulnerability #rce #patch #windows
2026-07-21
[Malwarebytes Labs]
Attackers started exploiting the critical wp2shell vulnerability chain within hours of patches being released, putting sites and their visitors at risk.
#bugs #news #compromised #wordpress #wp2shell
2026-07-21
[The Hacker News]
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.
Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation o…
#ransomware #vulnerability #apt #patch #authentication
2026-07-21
[Bleeping Computer]
Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. […]
#security
2026-07-21
[Infosecurity Magazine]
Russian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude models
2026-07-21
[The Record]
The speed of 5G and 4G networks across much of Taiwan will be temporarily reduced to 1 percent of capacity as the island holds annual civilian and military drills.
#government #news #news-briefs #technology
2026-07-21
[The Hacker News]
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component.
As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection v…
#vulnerability #patch #xss #injection
2026-07-21
[Kaspersky Securelist]
We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.
#incidents #microsoft-windows #ransomware #powershell #rdp
2026-07-21
[SentinelOne Labs]
In April, SentinelLABS’ Tom Hegel published an initial assessment of the first five weeks of the conflict. Three months later, the evidence supports refinement.
#iran #us
2026-07-21
[Tenable Research]
Attackers have shifted from hiding from AI tools to running inside them. By poisoning the config files that govern AI coding assistants, a new worm class achieves silent persistence, evades AI-based scanners, and spreads across an organization’s repositories through developers’ own tools.Key takeawa…
2026-07-21
[Dark Reading]
AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.
#vulnerability
2026-07-21
[Infosecurity Magazine]
Analysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmented
#ransomware #apt
2026-07-21
[SecurityWeek]
The startup will use the investment to accelerate the development of its threat prediction and discovery products.
The post Empirical Security Raises $25 Million in Series A Funding appeared first on SecurityWeek.
#cybersecurity-funding #empirical-security #funding
2026-07-21
[SecurityWeek]
Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville
The post SecurityWeek Launches Critical Impact …
#icsot #critical-infrastructure #ics #industrial-cybersecurity #ot
2026-07-21
[The Record]
The website was hacked on Saturday, when its homepage was replaced with a message displaying a cryptocurrency wallet address and threatening to publish unspecified information about President William Ruto unless the ransom was paid.
#cybercrime #government #leadership #news #news-briefs
2026-07-21
[Infosecurity Magazine]
FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites
2026-07-21
[Malwarebytes Labs]
A new macOS infostealer tricks victims into revealing their system password and installs a persistent backdoor for future access.
#news #threat-intel #clicklock #kill-loop #system-password
2026-07-21
[The Hacker News]
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent.
Researchers demonstrated that chain, plus six o…
#windows
2026-07-21
[SecurityWeek]
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.
The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek.
#malware--threats #hollowgraph #malware
2026-07-21
[The Hacker News]
Every patch is a confession.
The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn’t updated yet. This is N-day exploitation…
#vulnerability #patch
2026-07-21
[Malwarebytes Labs]
The FBI is warning that fraudsters are using fake IC3 accounts and direct messages to target people who’ve already been scammed.
#news #scams #fbi #ic3 #recovery-scam
2026-07-21
[The Hacker News]
A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in.
That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, …
#vulnerability
2026-07-21
[Schneier on Security]
It’s a lot:
According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and infrastructure that will supp…
#uncategorized #ai #cameras #privacy #schools
2026-07-21
[Bleeping Computer]
The U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization. […]
#security
2026-07-21
[SecurityWeek]
A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure.
The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek.
#vulnerabilities #bug-bounty #data-leak #meta #vulnerability
2026-07-21
[Bleeping Computer]
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecurity company Arctic Wolf. […]
#security
2026-07-21
[Graham Cluley]
Ukraine’s computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code.
Read more in my article on the Hot for Security blog.
#guest-blog #malware #clickfix #russia #ukraine
2026-07-21
[Malwarebytes Labs]
Instead of fighting over what app stores host, the San Francisco City Attorney is targeting how they make money from AI nudify apps.
#news #privacy
2026-07-21
[Infosecurity Magazine]
Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theft
2026-07-21
[SecurityWeek]
Using social engineering, hackers compromised employee accounts with access to personal and health information.
The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek.
#data-breaches #clover-health-investments #data-breach #healthcare
2026-07-21
[Infosecurity Magazine]
In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans
#malware #windows
2026-07-21
[Bleeping Computer]
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. […]
#microsoft
2026-07-21
[The Hacker News]
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.
The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2she…
#vulnerability #rce
2026-07-21
[SecurityWeek]
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution.
The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek.
#vulnerabilities #exploited #featured #servicenow #vulnerability
2026-07-21
[Kaspersky Securelist]
Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.
#great-research #malware-descriptions #malware-technologies #microsoft #microsoft-windows
2026-07-21
[CrowdStrike]
#executive-viewpoint
2026-07-21
[Bleeping Computer]
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. […]
#security #microsoft
2026-07-21
[The Hacker News]
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month.
The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes…
#ransomware #rce
2026-07-21
[Zero Day Initiative]
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The follow…
#vulnerability #windows
2026-07-20
[Bleeping Computer]
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. […]
#security
2026-07-20
[Bleeping Computer]
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. […]
#security #cryptocurrency
2026-07-20
[AWS Security]
The new Amazon GuardDuty investigation agent (now in public preview) investigates security findings across your Amazon Web Services (AWS) environment, reducing investigation time from hours to minutes. GuardDuty is our managed threat detection service that continuously monitors your AWS accounts and…
#amazon-guardduty #intermediate-200 #security-identity--compliance #technical-how-to #security-blog
2026-07-20
[Dark Reading]
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
#vulnerability
2026-07-20
[Bleeping Computer]
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. […]
#security
2026-07-20
[Bleeping Computer]
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. […]
#security #artificial-intelligence
2026-07-20
[Dark Reading]
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open questions.
#vulnerability
2026-07-20
[The Record]
“Community consultation” is one of the reasons automated license plate reader (ALPR) company Flock Safety cited in its decision to drop voice-oriented tech from a gunshot detection system.
#technology #news #news-briefs #privacy
2026-07-20
[Dark Reading]
Marc Maiffret reflects on Code Red’s legacy and the security lessons helping organizations navigate AI risk today.
2026-07-20
[Dark Reading]
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.
2026-07-20
[Dark Reading]
“The TFF Trap” uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.
#malware #phishing
2026-07-20
[The Hacker News]
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit.
“Fa…
#malware
2026-07-20
[The Record]
Documents that the World Leaks cybercrime group claimed to leak from the Kudankulam Nuclear Power Plant do not contain information pertaining to safety or security, Indian officials said.
#industry #cybercrime #news
2026-07-20
[Bleeping Computer]
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. […]
#security
2026-07-20
[The Hacker News]
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an …
#malware #phishing #windows
2026-07-20
[The Record]
Over the course of the World Cup tournament, the Department of Justice seized more than 1,000 domains for illegally streaming games.
#news #cybercrime
2026-07-20
[AWS Security]
Amazon Web Services (AWS) successfully completed an onboarding audit with no findings for ISO 9001:2015, 27001:2022, 27017:2015, 27018:2019, 27701:2019, 20000-1:2018, and 22301:2019, and Cloud Security Alliance (CSA) STAR Cloud Controls Matrix (CCM) v4.0. EY Certify Point auditors conducted the audi…
#announcements #foundational-100 #security-identity--compliance #aws-csa-star #aws-csa-star-certificates
2026-07-20
[Qualys Threat Research]
Executive Summary Manual audit preparation no longer scales across hybrid, cloud, endpoint, and application environments. Compliance monitoring software must move from checklist validation to continuous control monitoring. The strongest platforms connect evidence collection with risk prioritization,…
#product-and-tech #compliance #compliance-monitoring #qualys-policy-audit #top5
2026-07-20
[Malwarebytes Labs]
The release of The Odyssey has already sparked a wave of piracy scams, from fake browser errors to malware masquerading as movie files.
#scams #threat-intel
2026-07-20
[The Record]
Unidentified hackers compromised an online education system used by South Korea’s diplomatic academy, stealing personal information belonging to former and current employees of the country’s Ministry of Foreign Affairs.
#news #government
2026-07-20
[Infosecurity Magazine]
Cruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors
2026-07-20
[SecurityWeek]
Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others.
The post Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software appeared first on SecurityWeek.
#artificial-intelligence #cybersecurity-funding #ai #funding #neo
2026-07-20
[The Record]
Romania’s land registry agency is still recovering from a cyberattack it called “the most serious technical incident in the institution’s history.”
#news #cybercrime
2026-07-20
[The Hacker News]
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.
Group-IB, which named the malware HollowGraph, says the approach move…
#malware #windows
2026-07-20
[SecurityWeek]
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.
The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek.
#malware--threats #vulnerabilities #exploited #malware #sonicwall
2026-07-20
[Infosecurity Magazine]
JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts
#ransomware
2026-07-20
[Bleeping Computer]
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production rea…
#security
2026-07-20
[Infosecurity Magazine]
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain
#vulnerability
2026-07-20
[Dark Reading]
From the World Cup to the United States’ 250th celebration, this year’s event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands.
2026-07-20
[Tenable Research]
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public …
#vulnerability #rce
2026-07-20
[The Hacker News]
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs w…
#zero-day #malware #rce
2026-07-20
[Rapid7 Blog]
Executive summaryAn MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery pa…
#phishing #malware #labs
2026-07-20
[SecurityWeek]
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory.
The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek.
#vulnerabilities #openssl #vulnerability
2026-07-20
[Infosecurity Magazine]
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel
#malware #windows
2026-07-20
[The Hacker News]
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops.
That is the finding of a cybersecurity ad…
2026-07-20
[SecurityWeek]
Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens.
The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek.
#data-breaches #data-breach
2026-07-20
[The Hacker News]
The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Myt…
2026-07-20
[SecurityWeek]
Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform.
The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek.
#data-breaches #data-breach #ernstyoung #ey #featured
2026-07-20
[The Record]
Craneware, which is headquartered in Edinburgh and listed on London’s AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since brought in outside forensic investigators.
#cybercrime #news #news-briefs
2026-07-20
[Malwarebytes Labs]
We look into how attackers are using the legitimate Ren’Py game engine to spread a malware loader that ultimately delivers Amatera Stealer.
#threat-intel
2026-07-20
[Bleeping Computer]
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. […]
#microsoft
2026-07-20
[Bleeping Computer]
Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. […]
#microsoft
2026-07-20
[Infosecurity Magazine]
Two chiefs of UK policing agencies said the Transport for London prosecution demonstrates the need for Cybercrime Risk Orders
2026-07-20
[Bleeping Computer]
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. […]
#security
2026-07-20
[The Hacker News]
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro’s Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02.
…
#zero-day #vulnerability
2026-07-20
[The Hacker News]
A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.
The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, wh…
#malware #apt
2026-07-20
[SecurityWeek]
The fresh security update resolves six critical and high-severity use-after-free vulnerabilities.
The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek.
#vulnerabilities #chrome #memory-safety #patch #vulnerability
2026-07-20
[Malwarebytes Labs]
A list of topics we covered in the week of July 13 to July 19 of 2026
#news #flock #github #updates
2026-07-20
[The Hacker News]
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.
The company said it detected and responded to the incident targeting its production infrastructure earlier last week.
“We ident…
2026-07-20
[The Hacker News]
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
The rogue gems are listed below -
git_credential_manager (versions …
#supply-chain #authentication
2026-07-19
[Bleeping Computer]
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. […]
#security #government
2026-07-19
[The Hacker News]
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.
According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC…
#malware #apt
2026-07-19
[The Hacker News]
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.
Cybersecurity company Volexity is tracking the activity under the moni…
#zero-day #vulnerability #apt #privacy #network
2026-07-18
[Bleeping Computer]
7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. […]
#security
2026-07-18
[Bleeping Computer]
Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. […]
#security
2026-07-18
[Bleeping Computer]
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. […]
#security
2026-07-18
[Bleeping Computer]
As age verification laws expand worldwide, organizations face growing pressure to protect users’ privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting c…
#security
2026-07-18
[Elastic Security Labs]
DPRK-aligned hackers hid malware inside SVG flag images to backdoor developer job interview coding tests. Not one antivirus vendor caught it.
#security-labs
2026-07-17
[Graham Cluley]
Gemini, Google’s AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone.
Read more in my article on the Hot for Security blog.
#ai #android #google #guest-blog #vulnerability
2026-07-17
[The Hacker News]
An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable.
Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system.
Adam…
#vulnerability
2026-07-17
[Bleeping Computer]
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data….
#security
2026-07-17
[Dark Reading]
When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall’s mobile access appliances.
#zero-day #ransomware #vulnerability #apt
2026-07-17
[Rapid7 Blog]
Metasploit Wrap Up HousekeepingWhile the Metasploit Framework will be continuing its weekly release cadence, bringing you dear reader our latest content, the Weekly Wrap Up is being shifted to a bi-weekly cadence. The team is planning to use the additional time between posts to record demos of some …
#metasploit #metasploit-weekly-wrapup
2026-07-17
[The Hacker News]
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.
The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an…
#supply-chain
2026-07-17
[Rapid7 Blog]
OverviewOn July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644, a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical), results from the dese…
#emergent-threat-response
2026-07-17
[Bleeping Computer]
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. […]
#security
2026-07-17
[The Hacker News]
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys.
A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and …
#malware #cloud
2026-07-17
[Dark Reading]
AI models left to both interpret and execute commands eliminate critical cybersecurity oversight.
2026-07-17
[The Hacker News]
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.
Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a…
#apt
2026-07-17
[Infosecurity Magazine]
Government organizations are targeted by attackers who know agencies cannot afford disruption to public services
#ransomware
2026-07-17
[Bleeping Computer]
Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. […]
#security
2026-07-17
[Infosecurity Magazine]
23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements
#data-breach
2026-07-17
[SecurityWeek]
Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach.
The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared first on SecurityWeek…
#data-breaches #malware--threats #in-other-news
2026-07-17
[Bleeping Computer]
Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek “clean” residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection. […]
#security
2026-07-17
[The Hacker News]
North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges.
“Any user who ran the project ended up with a four-stage payload al…
#malware #apt
2026-07-17
[The Record]
Fairlife’s U.S. operation includes plants in Michigan, New York and Arizona, and the company’s retail sales passed $1 billion in 2022.
#cybercrime #news #news-briefs
2026-07-17
[Dark Reading]
The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it’s being implemented.
#vulnerability
2026-07-17
[The Record]
Yevhenii Khmara, a major general with deep experience in intelligence, counterterrorism and long-range strikes against Russia, is Ukraine’s new acting defense minister.
#people #leadership #government #news
2026-07-17
[Malwarebytes Labs]
One compromised Shark robot vacuum could unlock remote access to many others.
#bugs #news #privacy #certificate #remote-control
2026-07-17
[SecurityWeek]
(Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up?
The post Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive appeared first on SecurityWeek.
#artificial-intelligence #icsot #uncategorized #ics #ot
2026-07-17
[Dark Reading]
Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks.
2026-07-17
[The Hacker News]
The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps …
2026-07-17
[SecurityWeek]
The startup helps organizations detect, hunt, and protect their assets across environments at machine speed.
The post Beacon Security Raises $13 Million for Security Data Platform appeared first on SecurityWeek.
#cybersecurity-funding #beacon-security #funding
2026-07-17
[The Hacker News]
Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move from…
2026-07-17
[SecurityWeek]
Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI.
The post Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday appeared first on SecurityWeek.
#compliance #government #management--strategy #cmmc #compliance
2026-07-17
[Bleeping Computer]
A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. […]
#security #microsoft
2026-07-17
[Schneier on Security]
Really interesting piece of cryptographic history:
In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-sec…
#uncategorized #encryption #history-of-cryptography
2026-07-17
[The Hacker News]
Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov.
His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan’s Zvartnots …
#ransomware
2026-07-17
[Malwarebytes Labs]
Knowing how to spot a malicious GitHub repository can help you avoid downloading malware disguised as legitimate software.
#how-to
2026-07-17
[Palo Alto Unit 42]
A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access.
The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.
#threat-research #vulnerabilities #command-injection #cve-2025-40947 #cve-2025-40948
2026-07-17
[SecurityWeek]
The company disconnected its systems on July 13 and is starting to gradually restore operations.
The post Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei appeared first on SecurityWeek.
#cybercrime #cyberattack #disruption #japan #nichirei
2026-07-17
[Infosecurity Magazine]
Analysis of ransomware incidents by ReliaQuest indicates a shift in the ransomware landscape
#ransomware
2026-07-17
[The Hacker News]
ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders.
It gets in because someone pasted a command into a Run box and presse…
#malware #windows
2026-07-17
[The Hacker News]
Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering.
Russian cybersecurity company Kaspersky, which unc…
#malware
2026-07-17
[SecurityWeek]
The British firm has built a collaborative platform to help organizations address supply chain security risks.
The post Risk Ledger Raises $32 Million in Series B Funding appeared first on SecurityWeek.
#cybersecurity-funding #supply-chain-security #funding #risk-ledger #supply-chain
2026-07-17
[Bleeping Computer]
U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams. […]
#security #cryptocurrency
2026-07-17
[SecurityWeek]
The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server.
The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek.
#vulnerabilities #exploited #sharepoint #vulnerability
2026-07-17
[The Hacker News]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026…
#zero-day #vulnerability #rce #patch #windows
2026-07-16
[Microsoft Security]
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments.
The…
#clickfix #malware #social-engineering
2026-07-16
[Bleeping Computer]
A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. […]
#security
2026-07-16
[Bleeping Computer]
The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. […]
#security
2026-07-16
[Graham Cluley]
The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk.
Read more in my article on the Fortra blog.
#guest-blog #malware #ransomware #ransomware
2026-07-16
[The Record]
Democratic Sen. Ron Wyden says the Trump administration should pressure Canada not to enact a proposal that would “weaponize American technology infrastructure” for surveillance purposes.
#government #privacy #news
2026-07-16
[Dark Reading]
Agentic artificial intelligence is creating enough risks for organizations to demand a security reframe.
2026-07-16
[Dark Reading]
Forget about attackers. Agentic artificial intelligence is creating enough risks for organizations and demands a security reframe.
2026-07-16
[Dark Reading]
Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.
#phishing
2026-07-16
[Bleeping Computer]
A flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude’s access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce. […]
#security
2026-07-16
[Bleeping Computer]
A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data. […]
#security #cryptocurrency
2026-07-16
[CERT/CC]
Overview
A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion and service interrupti…
#vulnerability #ddos
2026-07-16
[The Record]
“Age checks are a cornerstone of the UK’s online safety laws,” said Ofcom’s Chief Executive, Melanie Dawes. “Too many services have no or inadequate age checks in place, which is not good enough.”
#government #news #technology
2026-07-16
[Tenable Research]
Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.Key TakeawaysCISA confirmed active exploitation of three on-pre…
#vulnerability #patch #windows
2026-07-16
[The Record]
Ukraine President Volodymyr Zelensky dismissed Defense Minister Mykhailo Fedorov, who championed the push to integrate drone technology and digital innovation into the military.
#news
2026-07-16
[Microsoft Security]
As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure.
The post Least privilege for AI agents: Identity, access, and tool binding appeared first on Microsoft Security Blog.
#windows
2026-07-16
[The Hacker News]
A lot of this week’s trouble starts with something that looks close enough.
A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation.
Old bugs are back, weak defaults are earnin…
#ransomware
2026-07-16
[SecurityWeek]
Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity’s most challenging balancing acts.
The post Legacy Systems, Real-World Impacts: The Reality of OT Security appeared first on SecurityWeek.
#icsot #ics #ot
2026-07-16
[Infosecurity Magazine]
Global phishing campaign disguised a Lua loader as a font file to deploy RATs and infostealers
#malware #phishing
2026-07-16
[CERT/CC]
Overview
A Pickle deserialization vulnerability has been discovered within the SGLang project, enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsystem must be enabled, an…
#vulnerability #rce
2026-07-16
[Schneier on Security]
Daniel Solove argues in the Wall Street Journal (alternate link) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug companies. Measures s…
#uncategorized #academic-papers #ai #privacy
2026-07-16
[Bleeping Computer]
Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own environments. […]
#security
2026-07-16
[Malwarebytes Labs]
Privacy concerns have dogged Flock’s automated license plate recognition system for years. Now accuracy and reliability are coming under scrutiny too.
#news #privacy #errors #flock #lapd
2026-07-16
[The Record]
Rather than verifying they are human, the CAPTCHA users are instructed to copy and paste a PowerShell command into their Windows computers.
#nation-state #news #technology #malware
2026-07-16
[The Hacker News]
n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss.
A valid token from issuer A carrying a sub that belongs …
2026-07-16
[Infosecurity Magazine]
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackers
2026-07-16
[Infosecurity Magazine]
New ClickLock macOS stealer locked victims out of their own system until they surrendered a password
#malware
2026-07-16
[SecurityWeek]
Thalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL).
The post Two Scattered Spider Hackers Sentenced to Jail in UK appeared first on SecurityWeek.
#cybercrime #tracking--law-enforcement #hacker #scattered-spider #sentenced
2026-07-16
[Kaspersky Securelist]
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
#malware-technologies #targeted-attacks #apt #vpn #full
2026-07-16
[Rapid7 Blog]
What’s changing, where AttackerKB-style analysis will live, and how users can continue finding Rapid7 vulnerability intelligence.On August 18, Rapid7 will sunset the standalone public AttackerKB website as part of a broader effort to unify our vulnerability intelligence, exploit analysis, and resear…
#research
2026-07-16
[The Hacker News]
Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that’s been spreading via websites infected with ClickFix lures since late April 2026.
“The malware is full-featured, lightweight, and modular,” Elastic Security Labs researcher Cyril François said in a technica…
#malware
2026-07-16
[SecurityWeek]
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.
The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek.
#malware--threats #clickfix #clicklock-stealer #infostealer #macos-malware
2026-07-16
[The Hacker News]
ClickLock Stealer, a new macOS infostealer, answers a victim’s refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim cancels, installs two LaunchAgents and …
#malware
2026-07-16
[Bleeping Computer]
Two leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024. […]
#security
2026-07-16
[Kaspersky Securelist]
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.
#great-research #malware-descriptions #malware-technologies #malware-descriptions #malware
2026-07-16
[The Record]
Two leading members of the Scattered Spider cybercrime collective have been sentenced to more than five years in prison for carrying out the 2024 cyberattack against Transport for London (TfL).
#news #cybercrime
2026-07-16
[Bleeping Computer]
Microsoft announced on Wednesday that systems running Windows 10 Enterprise LTSB 2016 and Home and Pro editions of Windows 11 24H2 will stop receiving updates in three months. […]
#microsoft
2026-07-16
[The Hacker News]
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions.
The investigation revealed previously undocumented backd…
#malware
2026-07-16
[Infosecurity Magazine]
The perpetrators of the 2024 TfL cyber-attack have been jailed for five and a half years each after pleading guilty to Computer Misuse Act offences
2026-07-16
[SecurityWeek]
The startup has built an AI-powered Identity Operating System that governs all identities across an organization’s environment.
The post Oak Emerges From Stealth Mode With $60 Million in Funding appeared first on SecurityWeek.
#cybersecurity-funding #identity--access #emerge-from-stealth #funding #identity
2026-07-16
[Bleeping Computer]
CISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application. […]
#security
2026-07-16
[SecurityWeek]
The flaws could allow attackers to access credentials and data, take over accounts, and escalate their privileges.
The post Splunk, Zoom Patch Critical Vulnerabilities appeared first on SecurityWeek.
#vulnerabilities #patches #splunk #vulnerability #zoom
2026-07-16
[Bleeping Computer]
A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT. […]
#security
2026-07-16
[The Hacker News]
Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive …
2026-07-16
[Bleeping Computer]
A new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours. […]
#security
2026-07-16
[Malwarebytes Labs]
Samsung threatened to delete users’ health data if they refused AI training. After a backlash, it quickly backed down.
#ai #news #privacy
2026-07-16
[Infosecurity Magazine]
SANS Institute says governance programs are still nascent even as AI failures and threats grow
2026-07-16
[The Hacker News]
Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people’s Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext.
A researcher publishing under the …
#patch #cloud
2026-07-16
[SecurityWeek]
Attackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code.
The post F5 Patches Multiple NGINX, BIG-IP Vulnerabilities appeared first on SecurityWeek.
#vulnerabilities
2026-07-16
[Graham Cluley]
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed.
Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generate…
#ai #podcast #security-threats #vulnerability #battery
2026-07-16
[SecurityWeek]
Chinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures.
The post China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans appeared first on SecurityWeek.
#government #management--strategy #china #china-apt #military
2026-07-16
[The Hacker News]
OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely.
“GPT‑Red is a strong red-teamer, and our previous models are highly vulnerable to its prompt injectio…
#vulnerability #injection
2026-07-16
[Dark Reading]
Iberian hackers carried out a variety of cyberattacks and laundered the winnings through complex financial networks.
2026-07-16
[SecurityWeek]
The researcher stripped the proof-of-concept (PoC) exploit to prevent immediate exploitation of the vulnerability.
The post Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day appeared first on SecurityWeek.
#vulnerabilities #chaotic-eclipse #legacyhive #poc #zero-day
2026-07-16
[SecurityWeek]
The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products.
The post Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities appeared first on SecurityWeek.
#endpoint-security #vulnerabilities #security-product #security-product-vulnerability #vulnerability
2026-07-16
[Microsoft Security]
Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses.
The post Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery a…
#npm #supply-chain-attack
2026-07-16
[Elastic Security Labs]
TELEPUZ is a modular malware that emerged through CLICKFIX-VIDAR attacks in April. We reverse-engineered it to show you the infrastructure and evasion techniques that matter.
#security-labs
2026-07-15
[Palo Alto Unit 42]
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more.
The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.
#high-profile-threats #malware #credential-harvesting #github #npm-packages
2026-07-15
[The Record]
Kentucky Fried Chicken restaurants have been left short on ingredients and major restaurant chains struggling to keep up with deliveries following a cyberattack on Nichirei Logistics Group.
#news #cybercrime
2026-07-15
[Bleeping Computer]
The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims. […]
#security
2026-07-15
[Dark Reading]
Nearly a dozen vulnerable and now revoked UEFI shim bootloaders remained trusted for years, giving attackers a path to bypass Secure Boot.
2026-07-15
[Dark Reading]
Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.
#ransomware #vulnerability #authentication
2026-07-15
[Bleeping Computer]
Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. […]
#security
2026-07-15
[CrowdStrike]
#securing-ai
2026-07-15
[The Record]
The Gold Eagle program will allowe industry, critical infrastructure operators and the government to use artificial intelligence to rapidly detect, prioritize and patch cybersecurity vulnerabilities, officials said.
#government #technology #news
2026-07-15
[Bleeping Computer]
A Russian-speaking threat actor known as “bandcampro” used Google’s open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. […]
#security #artificial-intelligence
2026-07-15
[Dark Reading]
We’re thrilled to unveil the latest evolution of Dark Reading’s DR Global section — your go-to source for region-specific cybersecurity intelligence beyond North America.
2026-07-15
[The Record]
Senators pressed director of national intelligence nominee Jay Clayton about his stance on the 2020 election and previous statements about voter fraud. Other issues took a back seat.
#people #leadership #government #news
2026-07-15
[The Record]
A coalition of 42 state attorneys general reached an $18 million settlement with 23andMe for cybersecurity failings that led to a data breach.
#news #privacy
2026-07-15
[Tenable Research]
SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.Key takeawaysCVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been cha…
#zero-day #vulnerability #rce #patch
2026-07-15
[CERT/CC]
Overview
A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL dispatch routines [RM…
#vulnerability #patch
2026-07-15
[Dark Reading]
The US government’s restrictions on Anthropic and OpenAI frontier models have intensified calls in the UK and other countries to reduce their reliance on US tech companies, with significant cyber implications.
2026-07-15
[Rapid7 Blog]
OverviewOn July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409 (CVSS 10.0) and the high-severity code injection vulnerability CV…
#emergent-threat-response #labs #managed-detection-and-response-mdr
2026-07-15
[CERT/CC]
Overview
Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attackers to forge RSA (PKCS#1 v1.5) and Ed25519 sig…
#vulnerability
2026-07-15
[Microsoft Security]
Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools.
The post Turning threat intelligence into decisive action with Defender Experts appeared first on Microsoft …
#windows
2026-07-15
[The Hacker News]
A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase.
On an infected PC, the request comes from inside the wallet’s own desktop software. Sometimes it waits until you plug …
#malware #phishing #windows
2026-07-15
[Dark Reading]
When combined with another exploit, the “PromptFiction” vulnerability, which has been fixed, could have enabled an end-to-end attack on a targeted system.
#vulnerability
2026-07-15
[Tenable Research]
Anthropic’s new AI agent for Slack acts under an admin-configured access bundle rather than each user’s own credentials. Here’s how that model works, what admins should understand and how to securely configure it.Key takeawaysClaude Tag, Anthropic’s newly launched AI agent for Slack, acts on connect…
#authentication
2026-07-15
[Infosecurity Magazine]
Six-month phishing campaign used seasonal eCard lures to plant legitimate RMM tools on victims
#phishing
2026-07-15
[SecurityWeek]
An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically.
The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek.
#artificial-intelligence #vulnerabilities #ai #cursor #vulnerability
2026-07-15
[Malwarebytes Labs]
The ClaudeBleed vulnerability still lets malicious Chrome extensions abuse Claude for Chrome’s permissions.
#ai #bugs #news #claude-for-chrome #claudebleed
2026-07-15
[The Record]
Authorities said Wednesday that the group operated like a legitimate international business since at least 2021, running about two dozen call centers across several countries and employing more than 700 people who posed as professional financial advisers.
#cybercrime #government #news
2026-07-15
[Bleeping Computer]
Intruder built an AI-powered “vulnerability vending machine” that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already un…
#security
2026-07-15
[Black Hills InfoSec]
Spend time performing forensic analysis on the Windows Operating System and you’ll see a host of artifacts that can be used to identify adversary activity. From changes to the registry to the System Resource Utilization Monitor, Windows artifacts run deep. The challenge is locating, extracting, and …
#blue-team #blue-team-tools #dfir #guest-author #how-to
2026-07-15
[The Hacker News]
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published.
The vulnerabilities are listed below -
CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component
CVE-2026-15719, a site isolation in the DOM: Navig…
#vulnerability
2026-07-15
[SecurityWeek]
Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products.
The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek.
#endpoint-security #malware--threats #featured #malware #windows
2026-07-15
[The Record]
The Los Angeles Police Department is the latest U.S. municipal agency to rethink its relationship to ALPR company Flock Safety.
#privacy #news #news-briefs #technology
2026-07-15
[Rapid7 Blog]
OverviewIn the cloud, your infrastructure may be short-lived, but an attacker’s persistence doesn’t have to be. While your environment scales and changes in seconds, adversaries are embedding themselves into your IAM policies, Lambda functions, and federated sessions, creating invisible footholds th…
#aws
2026-07-15
[Dark Reading]
Simple age-old bugs give bad actors access to developers’ secrets and source code-rich environments.
#vulnerability
2026-07-15
[Infosecurity Magazine]
Research of incidents by Sophos finds that phishing, brute force attacks and other identity-based threats have surpassed software vulnerabilities as means of delivering ransomware
#ransomware #phishing #vulnerability
2026-07-15
[Tenable Research]
When you incorporate data from application security scanners into your exposure management platform, you can assess the threat from formerly isolated code flaws using a broader risk context, which illuminates hidden exposures that your security and development teams can eliminate together.Key takeaw…
2026-07-15
[The Record]
Vulnerability counts have been surging this year, and Microsoft’s mammoth disclosure this week of 622 bugs is larger than the three previous months combined.
#news
2026-07-15
[Infosecurity Magazine]
Progress has restored access to its ShareFile Storage Zones Controller after a four-day suspension triggered by a credible external security threat
#vulnerability
2026-07-15
[SecurityWeek]
The suspects and their companies were previously sanctioned by the United States and its allies.
The post US Charges Russian Individuals and Firms for Running Cybercrime Services appeared first on SecurityWeek.
#cybercrime #bulletproof-hosting #charged #russia
2026-07-15
[The Hacker News]
For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up.
Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctioned b…
2026-07-15
[The Hacker News]
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive.
It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as P…
#zero-day #vulnerability #patch #windows
2026-07-15
[Schneier on Security]
Amazing:
Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel’s full potential for carrying information by manipu…
#uncategorized #academic-papers #cameras #videos
2026-07-15
[SecurityWeek]
A critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code.
The post Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow appeared first on SecurityWeek.
#vulnerabilities #fortinet #ivanti #servicenow #vulnerability
2026-07-15
[The Hacker News]
Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute.
Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tok…
#windows
2026-07-15
[SecurityWeek]
The new program stems from an AI-focused Executive Order signed by President Trump on June 2.
The post White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative appeared first on SecurityWeek.
#artificial-intelligence #government #ai #critical-infrastructure #featured
2026-07-15
[Palo Alto Unit 42]
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs.
The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.
#malware #threat-research #c2 #dga #docker-compose
2026-07-15
[Kaspersky Securelist]
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.
#great-research #malware-descriptions #malware-technologies #keyloggers #malware-descriptions
2026-07-15
[Bleeping Computer]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. […]
#security #microsoft
2026-07-15
[SecurityWeek]
The industrial giants fixed dozens of vulnerabilities across their ICS products, with advisories also released by CISA and VDE CERT.
The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell appeared first on SecurityWeek.
#icsot #ics #ics-patch-tuesday #ot #patch-tuesday
2026-07-15
[The Hacker News]
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity.
The affected packages are listed below -
@asyncapi/generator-helpers@1.1.1
@asyncapi/generator-compo…
#malware
2026-07-15
[Infosecurity Magazine]
The UK government is warning of the potential impact of catastrophic cyber-attacks
2026-07-15
[Malwarebytes Labs]
Disguised as Apple’s CrashReporter, CrashStealer steals passwords, browser data, crypto wallets, and other sensitive information.
#news #threat-intel #crashreporter #crashstealer #werkbit
2026-07-15
[Bleeping Computer]
Microsoft is blocking this month’s Windows 11 security updates on some Dell devices because they are causing shutdowns and performance issues. […]
#microsoft
2026-07-15
[Dark Reading]
The West African country advanced rules to force organizations to disclose cyberattacks, joining other nations in a shift to mandated transparency.
2026-07-15
[SecurityWeek]
Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed.
The post Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates appeared first on SecurityWeek.
#vulnerabilities #chrome #firefox #public-poc #vulnerability
2026-07-15
[The Hacker News]
SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution.
The vulnerabilities are listed below -
CVE-2026-15409 (CVSS score: 10.0) - A Server-si…
#zero-day #vulnerability
2026-07-15
[SecurityWeek]
SonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution.
The post SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits appeared first on SecurityWeek.
#vulnerabilities #exploited #sma1000 #sonicwall #zero-day
2026-07-15
[Zero Day Initiative]
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.
#vulnerability #linux
2026-07-15
[Zero Day Initiative]
This vulnerability allows remote attackers to execute arbitrary code on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-2291.
#vulnerability #rce #authentication #network
2026-07-15
[Zero Day Initiative]
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DTM Soft. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8….
#vulnerability #rce
2026-07-15
[AWS Security]
Read all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered identity and access…
#announcements #foundational-100 #security-identity--compliance #security-blog
2026-07-15
[Dark Reading]
CardinalOps will give Cribl customers the ability to map detection rules and security controls to the MITRE ATT&CK framework. SecOps teams can identify coverage gaps and operationalize threat intelligence.
2026-07-14
[Dark Reading]
Three of the 622 CVEs for which Microsoft issued patches this week are zero-days; there are more than 60 critical vulnerabilities.
#zero-day #vulnerability #patch #windows
2026-07-14
[Bleeping Computer]
SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. […]
#security
2026-07-14
[Qualys Threat Research]
Microsoft’s July 2026 Patch Tuesday delivers security updates for a broad range of products and services, including several vulnerabilities that pose significant risks to enterprise environments. As attackers continue to target unpatched systems, the timely deployment of these updates remains one of…
#patch-tuesday #vulnerabilities-and-threat-research #microsoft
2026-07-14
[Bleeping Computer]
The Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. […]
#security #legal
2026-07-14
[Dark Reading]
Automated Frequency Coordination systems by default trust client-side data, which could lead to location spoofing and other attacks that disrupt traffic.
2026-07-14
[The Record]
The Russians face multiple charges for allegedly providing cybercriminals with infrastructure and tech support through the St. Petersburg-based business Media Land and a sister company, ML Cloud.
#cybercrime #news
2026-07-14
[Krebs on Security]
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning p…
#security-tools #the-coming-storm #time-to-patch #action1 #active-directory-federation-services
2026-07-14
[AWS Security]
Security Hub is our foundation for full-stack enterprise security across clouds. It centralizes your security operations and turns raw signals into prioritized insights, so your team spends its time managing real risk instead of stitching tools together. Today that foundation grows in two directions…
#artificial-intelligence #aws-partner-network #aws-security-hub #foundational-100 #news
2026-07-14
[Bleeping Computer]
A threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to distribute infostealer malware. […]
#security
2026-07-14
[SecurityWeek]
Two flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed.
The post Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek.
#vulnerabilities #exploited #microsoft #patch-tuesday #zero-day
2026-07-14
[Bleeping Computer]
Microsoft has released the Windows 10 KB5099539 extended security update, which includes the July 2026 Patch Tuesday security updates for 570 vulnerabilities, along with additional security fixes. […]
#microsoft #security
2026-07-14
[Tenable Research]
56Critical510Important3Moderate0LowMicrosoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as imp…
#zero-day #vulnerability #patch #windows
2026-07-14
[SecurityWeek]
The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid.
The post Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims appeared first on SecurityWeek.
#cybercrime #data-breaches #bosch #data-breach #fake-hack
2026-07-14
[The Hacker News]
SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP.
The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows an authenticated a…
#vulnerability #patch
2026-07-14
[Bleeping Computer]
Today is Microsoft’s July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. […]
#microsoft #security
2026-07-14
[Qualys Threat Research]
Key Takeaways Identity-based attacks are among the fastest and most effective intrusion methods because valid credentials let attackers operate as trusted users. Techniques like Pass-the-Hash, Kerberoasting, Domain Controller Synchronization (DCSync), and Authentication Server Response Roasting (AS-…
#product-and-tech #etm-identity #identity-security #identity-threat-detection-and-response #ispm
2026-07-14
[Dark Reading]
Risk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance.
2026-07-14
[The Record]
The defendant’s lawyer told Finnish media that he does not know where his client is but believes Kivimäki is outside Finland.
#cybercrime #government #news
2026-07-14
[The Hacker News]
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments.
“LabubaRAT creates a reusable foothold for hands-on activity,” Blackpoint Cyber researchers Sam Decker an…
#malware #windows
2026-07-14
[Bleeping Computer]
Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. […]
#security
2026-07-14
[Schneier on Security]
This is a current list of where and when I am scheduled to speak:
I’m speaking (virtually) at the Policy-Relevant Privacy Research Workshop in Calgary, Canada, on Monday, July 20, 2026.
I’m speaking at Boston Leadership Exchange in Boston, Massachusetts, USA, on Wednesday, July 22, 2026.
I’m speaki…
#uncategorized #schneier-news
2026-07-14
[Dark Reading]
Cutting-edge artificial intelligence models are deploying with more independence and less human oversight. Several state governments are trying to legislate transparency in their use.
2026-07-14
[Dark Reading]
The attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option.
2026-07-14
[Bleeping Computer]
LastPass is warning users about an ongoing phishing campaign that is using fake security notices to direct them to fraudulent websites. […]
#security
2026-07-14
[Infosecurity Magazine]
The US Department of Defense announced the immediate suspension of the CMMC Phase II requirements until further review
2026-07-14
[AWS Security]
As AI agents and automated tools increasingly access web applications, distinguishing legitimate bot traffic from malicious attempts has become a critical security challenge. Traditional approaches such as IP-based filtering and reverse DNS lookups fail in multi-tenant systems (such as Amazon Bedroc…
#aws-waf #intermediate-200 #security-identity--compliance #technical-how-to #security-blog
2026-07-14
[Bleeping Computer]
Many vulnerabilities cannot be safely validated with live exploits, either because no exploit exists or the affected systems are too critical to test. Picus explains how TTP chaining helps organizations determine exploitability by validating the attack techniques an exploit depends on, without launc…
#security
2026-07-14
[SecurityWeek]
The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal.
The post 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer appeared first on SecurityWeek.
#vulnerabilities #avi-load-balancer #vmware #vulnerability
2026-07-14
[The Record]
Dutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel.
#nation-state #news #technology
2026-07-14
[The Hacker News]
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries.
Miggo’s security te…
2026-07-14
[SecurityWeek]
A ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions.
The post Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar appeared first on SecurityWeek.
#artificial-intelligence #ai #claude #vulnerability
2026-07-14
[Rapid7 Blog]
OverviewRapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are …
#emerging-threats
2026-07-14
[Dark Reading]
Researchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks.
#vulnerability
2026-07-14
[The Hacker News]
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard.
“An attacker exploiting one of these vulnerable applications can execute untru…
#vulnerability #iot #windows #linux
2026-07-14
[Infosecurity Magazine]
Researchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and more
#malware #vulnerability
2026-07-14
[The Hacker News]
Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them.
The way these wallets talk to websites and blockchain servers can tie a person’s separate addresses togethe…
#privacy
2026-07-14
[The Hacker News]
AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragmented risk signals: scanner output, severity scores, threat intelligence, configuration findings, and e…
2026-07-14
[SecurityWeek]
The flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization.
The post SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud appeared first on SecurityWeek.
#vulnerabilities #patch #sap #vulnerability
2026-07-14
[Malwarebytes Labs]
Cybercriminals are combining social engineering through apps like FaceTime with unpatched devices to steal credentials and drain bank accounts.
#news #scams #facetime #social-engineering #unpatched
2026-07-14
[Schneier on Security]
FIFA’s network was vulnerable to anyone with even minimal access.
#uncategorized #hacking #sports #vulnerabilities
2026-07-14
[Bleeping Computer]
Microsoft is now testing a cleaner and faster version of Windows Search that should prioritize relevant results over ads and promotional content. […]
#microsoft
2026-07-14
[SecurityWeek]
UK-based cybersecurity firm Valarian has raised a total of $70 million for its ACRA technology.
The post Valarian Raises $50 Million for Sovereign Infrastructure Control Layer appeared first on SecurityWeek.
#cybersecurity-funding #funding #valarian
2026-07-14
[Malwarebytes Labs]
Instead of helping victims negotiate with BlackCat, a trusted ransomware negotiator secretly helped the gang extort them.
#news
2026-07-14
[The Hacker News]
xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed.
A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out…
2026-07-14
[Infosecurity Magazine]
Five UK residents have been charged in relation to supplying Russian Coms fraud devices and apps
2026-07-14
[The Hacker News]
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors’ and other cybercriminals’ malicious activities, including ransomware attacks against Americans.
The VPN, named First VPN Service (1VPNS), …
#ransomware #malware #network
2026-07-14
[Rapid7 Blog]
Gopan Sivasankaran is Regional Director, Middle East & Africa, at Rapid7From AI adoption and cloud-first strategies to smart cities and critical infrastructure modernization, organizations across the United Arab Emirates are embracing innovation at an unprecedented rate. The country truly is setting…
#managed-detection-and-response-mdr #mssp #artificial-intelligence
2026-07-14
[Graham Cluley]
When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help.
Specialist ransomware negotiation firms handle communications with criminal gangs on a victim’s behalf.
What victims don’t expect is that their trusted negotiator might be separately sharing…
#data-loss #guest-blog #law--order #malware #ransomware
2026-07-14
[The Hacker News]
A campaign of 148 npm packages disguised as student web proxies turned visitors’ browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog.
The packages did not go after the developers who might install them. The operators used the regis…
#malware #ddos
2026-07-14
[SecurityWeek]
A new CMMC review and reform task force will conduct a comprehensive review of the program.
The post Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules appeared first on SecurityWeek.
#compliance #government #cmmc #compliance
2026-07-14
[The Hacker News]
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform.
The way in has been the trust the organization had already extended, usually through the OAuth connect…
#vulnerability #windows
2026-07-14
[Check Point Research]
For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from Check Point Research documents a transition that goes further. AI has c…
#check-point-research-publications
2026-07-13
[The Record]
The retailer said the incident did not affect its online shopping platform itself but involved a separately stored customer database maintained by a third-party provider. According to notifications sent to Lidl’s German, Belgian and Dutch customers on Friday, the attackers briefly accessed the file …
#cybercrime
2026-07-13
[Microsoft Security]
Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications.
The post Defending SaaS-based applications …
#social-engineering #supply-chain-attack #vishing
2026-07-13
[Dark Reading]
In a first, the UK and the EU jointly impose sanctions on Russian individuals and entities for cyberattacks and disinformation campaigns in the region.
2026-07-13
[The Record]
“While ultimately it is up to parents to decide when children get their first smartphones, what we already have is a consensus that there needs to be a start date for the age children can join social media,” says European Commission President Ursula van der Leyen.
#technology #government #news #news-briefs
2026-07-13
[Bleeping Computer]
Japan’s largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. […]
#security
2026-07-13
[Bleeping Computer]
The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. […]
#security
2026-07-13
[Bleeping Computer]
A new macOS information-stealing malware called CrashStealer pretends to be Apple’s crash-reporting tool to steal credentials, keychain data, and crypto wallets. […]
#security #apple
2026-07-13
[The Record]
The U.S. Treasury Department announced sanctions against First VPN Service (1VPNS) and its Ukrainian administrator for aiding ransomware groups. Separately, a Belarusian man was sanctioned for malware “cryptors.”
#cybercrime #government #news #technology #people
2026-07-13
[Dark Reading]
In some companies, engineers are building defense and attack tools to test the potential of artificial intelligence for cybersecurity — and its threat.
2026-07-13
[The Hacker News]
Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that’s capable of harvesting sensitive data from compromised systems.
Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is implemented in nat…
#malware
2026-07-13
[The Hacker News]
Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version.
The collector was dormant. An empty allow-list kept it switched…
#windows
2026-07-13
[The Record]
Following the breach of several of her Telegram channels, controversial Russian journalist Ksenia Sobchak claimed published screenshots of her correspondence with political figures were fake.
#news #cybercrime
2026-07-13
[Microsoft Security]
Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare.
The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID appeared first on Microsoft Security Blog.
#patch #authentication #windows
2026-07-13
[Dark Reading]
A modular implant borrows from various malware families to combine both backdoor and wiper activities to maximize impact and minimize operational output.
#malware #apt
2026-07-13
[Infosecurity Magazine]
Misconfigured server exposed three phishing operators running Evilginx forks to bypass MFA
#phishing #authentication
2026-07-13
[The Hacker News]
Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That’s supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don’t file tickets.
That’s the shape of this week. Trusted code turns on the peo…
#ransomware
2026-07-13
[Krebs on Security]
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials – including AWS Govcloud keys – in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Exper…
#a-little-sunshine #data-breaches #latest-warnings #brad-libbey #cybersecurity-and-infrastructure-security-agency
2026-07-13
[Infosecurity Magazine]
Chinese and Indian spies converged on the same Balochistan police force, SentinelLabs found
2026-07-13
[Malwarebytes Labs]
This week on the Lock and Code podcast, we speak with Anna Brading about what actually works in keeping her kids safe online.
#family-and-parenting #podcast #child-privacy #child-safety #children-online
2026-07-13
[SecurityWeek]
Once a notorious blackhat hacker, McGraw shares his journey from high school hacking and prison to redemption as a cybersecurity advocate.
The post Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption appeared first on SecurityWeek.
#hacker-conversations
2026-07-13
[Bleeping Computer]
German discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole their personal information in a breach at a service provider. […]
#security
2026-07-13
[Bleeping Computer]
Learn how attackers abuse Entra ID through a free hands-on Capture the Flag. Varonis created the Breach at the Beach CTF to teach defenders how to investigate Entra ID attack techniques using realistic scenarios. […]
#security
2026-07-13
[Tenable Research]
Beyond IT compliance, cloud security is now the backbone of civilian agency resilience, national defense, and warfighter safety, as cloud environments become increasingly complex.Key takeawaysFor the Department of War (DoW), cloud security is an IT concern and a requirement for operational readiness…
#cloud
2026-07-13
[The Hacker News]
Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false “fact” about the user, hide the change, and quietly steer its answers in later sessions.
When it works, the pe…
2026-07-13
[AWS Security]
We are pleased to announce the publication of a new AWS compliance implementation guidance: HITRUST i1 Compliance on AWS: Customer Implementation Guidance with an Illustrative Healthcare Platform. Healthcare organizations seeking HITRUST i1 certification increasingly rely on Amazon Web Services (AWS…
#announcements #compliance #intermediate-200 #security-identity--compliance #aws-compliance
2026-07-13
[Malwarebytes Labs]
A proof-of-concept attack hides prompt injection in a PNG file, turning routine code reviews into a path for secret theft.
#ai #news #ghostcommit #harness #model
2026-07-13
[Check Point Research]
For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employee and used compromi…
#global-cyber-attack-reports
2026-07-13
[The Hacker News]
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts.
Distrib…
#phishing #windows
2026-07-13
[Infosecurity Magazine]
New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments
#windows
2026-07-13
[Cloudflare Security]
Precursor, our new continuous behavioral validation engine for bot management, offers visibility into how humans and bots actually interact across the full user journey. By turning session-level behavior into bot detection signals, it identifies advanced automation with higher precision — while redu…
#bot-management #security #turnstile #javascript #ai
2026-07-13
[SecurityWeek]
Significant cybersecurity M&A deals announced by 1Password, Accenture, Cisco, F5, Rubrik, and SailPoint.
The post Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 appeared first on SecurityWeek.
#ma-tracker #acquisitions #ma
2026-07-13
[Infosecurity Magazine]
Progress Software, the provider of the popular file-sharing and data storage solutions, has urged customers to shut down the server hosting their Storage Zone Controller
2026-07-13
[SecurityWeek]
Unauthenticated attackers could obtain the broker’s confidential OAuth client secret, allowing them to take control of the broker.
The post RabbitMQ Vulnerability Threatens Enterprise Systems appeared first on SecurityWeek.
#vulnerabilities #featured #rabbitmq #vulnerability
2026-07-13
[The Hacker News]
Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read.
Each read gets pinned to the moment it happened: the time, your location, what you were doing, even…
2026-07-13
[The Hacker News]
A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as we…
2026-07-13
[Bleeping Computer]
The European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Europe. […]
#security
2026-07-13
[Malwarebytes Labs]
Scam crypto gift card stores look almost identical to the real thing. One wrong click can leave you with no card and no way to get your money back.
#scams #threat-intel
2026-07-13
[The Hacker News]
Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration.
“The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting …
#apt
2026-07-13
[Schneier on Security]
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.
Opposition to AI data centers has emerged as a primary theme in US politics, one that—surprisingly—doesn’t fall along party lines. We applaud people coming together for constructive debate on any issue, and agree…
#uncategorized #ai #laws #llm #regulation
2026-07-13
[Infosecurity Magazine]
Cybersecurity agencies from 12 countries have warned that Russian state-backed hackers are actively targeting vulnerable routers using weak SNMP credentials
#authentication #network
2026-07-13
[SecurityWeek]
The flaw results in malicious code embedded in crafted emails being executed when the emails are opened.
The post Zimbra Patches Critical Code Execution Vulnerability appeared first on SecurityWeek.
#email-security #vulnerabilities #patch #remote-code-execution #vulnerability
2026-07-13
[SecurityWeek]
The move targeted people and entities accused of links to an online spying network that the EU claims targeted governments and carried out sabotage operations against critical infrastructure.
The post EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign appea…
#cyberwarfare #nation-state #eu #russia
2026-07-13
[Bleeping Computer]
Cybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks. […]
#security
2026-07-13
[Infosecurity Magazine]
An Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operation
#ransomware
2026-07-13
[SecurityWeek]
Threat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution.
The post Organizations Warned of Exploited Joomla Extension Vulnerabilities appeared first on SecurityWeek.
#vulnerabilities #cisa-kev #exploited #joomla
2026-07-13
[Infosecurity Magazine]
Australian Cyber Security Centre warns CMS users of mass scanning and exploitation campaign
#vulnerability
2026-07-13
[The Hacker News]
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history.
From that one lapse, French security firm Lexfo …
#phishing #windows
2026-07-13
[The Hacker News]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild.
The vulnerabilities, both…
#zero-day #vulnerability
2026-07-13
[Bleeping Computer]
OpenAI is temporarily relaxing GPT-5.6 Sol usage after demand for the company’s most powerful model surged over the past 48 hours. […]
#artificial-intelligence #technology
2026-07-12
[The Record]
The allies blamed Center 16, the FSB’s signals intelligence arm, for acts of attempted cyber sabotage targeting Poland’s energy sector and water treatment facilities, alongside “a wide range of malicious cyber activities with growing severity.”
#government
2026-07-12
[Bleeping Computer]
Anthropic has just extended access to Claude Fable 5 for paid subscribers until July 19, giving you another week to keep using the most powerful model. […]
#artificial-intelligence #technology
2026-07-12
[Bleeping Computer]
A new version of the RedHook Android malware abuses the Android Wireless Debugging (Wireless ADB) mechanism in a novel way to gain shell-level privileges without requiring a computer connection. […]
#security #mobile
2026-07-09
[Cloudflare Security]
NIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and argue that while they are in the works and show great potential, we should use ML-DSA for now — the best currently available.
#cryptography #post-quantum #research #security
2026-07-09
[SentinelOne Labs]
China and India ran separate espionage operations against the same Pakistani police force, each drawn by different stakes in Pakistan’s internal security.
#china #india #pakistan
2026-07-08
[Black Hills InfoSec]
We’re all petrified about missing a critical event or misclassifying an alert, but when we’re talking about incident response (IR), there are often hundreds if not thousands of alerts to parse through. It’s easy to get caught up with one alert because it feels “too hot” or maybe not spend enough tim…
#active-soc #blue-team #dfir #hayden-covington #incident-response
2026-07-08
[ESET WeLiveSecurity]
A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.
#eset-research
2026-07-03
[ESET WeLiveSecurity]
AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
#business-security
2026-07-01
[Cloudflare Security]
Cloudflare’s new Attribution Business Insights dashboard helps website owners understand crawler behavior, appetite, and potential value, fueling business-level conversations around crawl compensation.
#ai #bot-management #bots #content-independence-day #security
2026-06-24
[Cloudflare Security]
Self-Managed OAuth is now available to all developers on Cloudflare. Here’s how we executed a zero-downtime migration of our core OAuth engine to make it happen.
#agents #api #cloudflare-media-platform #developer-platform #developers
2026-05-13
[Google Project Zero]
We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible to go from a zero-click context to root on Android in just two exploits. The Dolby 0-click vulnerability existed across all of Android, until it was patched in January 2026. While we had an exploit chain …
#vulnerability #patch
2026-04-23
[Google Security Blog]
Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the secur…
#injection
2026-04-10
[Google Security Blog]
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team
Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with m…
#android #android-security #pixel
2026-04-09
[Google Security Blog]
Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team
Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upco…
#authentication #windows
2026-03-05
[Google Project Zero]
Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar that describes the structure of the samples. When a sample gets mutated, the mutations happen in such a way that any resulting samples still adhere to the grammar rules, thus the structure of the samples …
2026-02-26
[Google Project Zero]
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I thought I should take a closer look. I typically start by reading …
2026-02-05
[PortSwigger Research]
Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
2025-12-10
[PortSwigger Research]
TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: including attribute pollution, namespace confusi
#vulnerability #authentication
2025-05-07
[NCSC UK]
An NCSC assessment highlighting the impacts on cyber threat from AI developments between now and 2027.
2025-01-28
[NCSC UK]
Research from the NCSC designed to eradicate vulnerability classes and make the top-level mitigations easier to implement.
#vulnerability
2024-01-18
[Assetnote]
#vulnerability #rce #authentication
2023-10-23
[Assetnote]
#vulnerability
2023-10-03
[Assetnote]
#vulnerability #rce