no alarms and no surprises please..
-
Hacker Turns AI Jailbreaks Into Offensive Attack Platform
Hacker Turns AI Jailbreaks Into Offensive Attack Platform A Russian-speaking actor, “Trim,” dismantled publicly available frontier models and integrated them with offensive security tools. Elizabeth Montalbano Go to gbhackers.com
-
Choose Wisely: AI-Generated Coding Risk Varies, A Lot
Choose Wisely: AI-Generated Coding Risk Varies, A Lot AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used. Alexander Culafi Go to gbhackers.com
-
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution Threat actors are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform. This vulnerability allows attackers to escape… Delivered by PolitePaul service Go to gbhackers.com
-
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe… Delivered by PolitePaul service Go to gbhackers.com
-
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma‑associated Node.js backdoor through trusted GitHub Actions–driven release workflows… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell
Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to… Delivered by PolitePaul service Go to gbhackers.com
-
Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials
Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft shares manual fix for WSUS sync delays and timeouts
Microsoft shares manual fix for WSUS sync delays and timeouts Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows LegacyHive zero-day flaw gets free, unofficial patches
Windows LegacyHive zero-day flaw gets free, unofficial patches Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Estée Lauder discloses data breach via Oracle E-Business flaw
Estée Lauder discloses data breach via Oracle E-Business flaw Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. […] Bill Toulas Go to bleepingcomputer
-
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
SonicWall SMA1000 flaws exploited as zero-days to push custom malware Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
Hackers steal $23.7 million in crypto from Ostium in off-chain attack The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. […] Bill Toulas Go to bleepingcomputer
-
The Privilege Paths Attackers See, That You Don’t – A Complete PAM Guide
The Privilege Paths Attackers See, That You Don’t – A Complete PAM Guide Why identity fragmentation is the blind spot behind most breaches—and what a platform approach changes The Identity Problem Hiding in Plain Sight Identity is at the centre of nearly every major breach—yet most organisations still can’t answer one fundamental question: what is the…
-
Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems
Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems A newly uncovered cyberespionage campaign has turned Telegram bots into quiet controllers for backdoors planted inside Middle Eastern government networks. The operation relies on familiar Windows components and legitimate-looking files, allowing attackers to establish access without immediately drawing attention. The infection begins with an…
-
Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware
Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arctic Wolf Labs. The security firm investigated multiple intrusions throughout June 2026, all tracing back to the…
-
Furtex – Linux Toolkit for Post-Exploitation and Evasion for Security Researchers and Red Teamers
Furtex – Linux Toolkit for Post-Exploitation and Evasion for Security Researchers and Red Teamers A new open-source project, Furtex, has emerged as a Linux-focused post-exploitation and evasion research toolkit for authorized security researchers and red-team operators. The project combines raw io_uring system calls, BPF and eBPF tooling, and EDR-evasion research utilities without relying on liburing…
-
Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels
Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. HOLLOWGRAPH is a .NET-compiled malware component that abuses the Microsoft Graph API through a compromised Microsoft 365 account, turning…
-
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. “FakeGit uses…
-
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through…
-
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says…
-
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts,…
-
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of…
-
Sophos Trusted Code
Sophos Trusted Code Recent CVEs across GitHub, Anthropic, Google, dbt, and MISP expose a simple truth: the most trusted code is often the least questioned. As organizations connect AI agents to production systems, those overlooked assumptions can become powerful new attack paths. Categories: Products & Services, Security Operations Tags: AI, MDR, Sophos MDR, Vulnerabilities Go…
-
On Flock License Plate Tracking Cameras
On Flock License Plate Tracking Cameras A recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral. The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM. But when the police report was created and…
-
ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)
ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th) Last week, Searchlight Cyber released details about a vulnerability they are calling “wp2shell”. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in…
-
ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)
ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)
Scans for Hikvision Intelligent Security API, (Sun, Jul 19th) We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans that our honeypot network detects. This weekend, I noticed a new type of recon scans against…
-
‘WP2Shell’ Opens Millions of WordPress Sites to Remote Takeover
‘WP2Shell’ Opens Millions of WordPress Sites to Remote Takeover Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet. Jai Vijayan Go to gbhackers.com
-
Remediating Vulnerabilities With LLMs: Inside Ivanti’s Automation Push
Remediating Vulnerabilities With LLMs: Inside Ivanti’s Automation Push Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open questions. Rob Wright Go to gbhackers.com
-
CISOs Feel the Heat Over AI Risk
CISOs Feel the Heat Over AI Risk Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position. Robert Lemos Go to gbhackers.com
-
Attackers Combo Up Evasion Tactics for BEC Phishing
Attackers Combo Up Evasion Tactics for BEC Phishing “The TFF Trap” uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger. Elizabeth Montalbano Go to gbhackers.com
-
Cybersecurity Keeps Events ‘Uneventful’
Cybersecurity Keeps Events ‘Uneventful’ From the World Cup to the United States’ 250th celebration, this year’s event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands. Olga Polishchuk Go to gbhackers.com
-
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier Microsoft will stop delivering feature updates, bug fixes, and security patches for the OneDrive sync app on systems running Windows version 21H2 and earlier… Delivered by PolitePaul service Go to gbhackers.com
-
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor A newly disclosed cluster of Microsoft SharePoint Server vulnerabilities is actively being exploited in the wild, allowing attackers to convert a single crafted web… Delivered by PolitePaul service Go to gbhackers.com
-
LG Monitors Silently Install McAfee Adware on Windows PCs With Full System Access
LG Monitors Silently Install McAfee Adware on Windows PCs With Full System Access Concerns have arisen regarding LG monitors that reportedly trigger the silent installation of an LG companion application on Windows PCs. This installation is followed by… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues
Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues Microsoft has released KB5121767, an out-of-band (OOB) cumulative update for Windows 11 versions 22H2 and 21H2. This update addresses a system performance issue related… Delivered by PolitePaul service Go to gbhackers.com
-
U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million
U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million U.S. federal prosecutors have unsealed a sweeping indictment charging three Russian nationals and two St. Petersburg–based companies for operating a global “bulletproof hosting” infrastructure. That… Delivered by PolitePaul service Go to gbhackers.com
-
Critical ServiceNow code execution flaw now exploited in attacks
Critical ServiceNow code execution flaw now exploited in attacks Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers abuse ViPNet software to target Russian govt agencies
Hackers abuse ViPNet software to target Russian govt agencies An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. […] Bill Toulas Go to bleepingcomputer
-
Threat Actors Allegedly Listed Starbucks Data on Hacker Forums
Threat Actors Allegedly Listed Starbucks Data on Hacker Forums Starbucks has allegedly been listed on a cybercrime forum by a threat actor using the handle “anes2010,” who claims to be selling a database containing 176 million unique user records reportedly extracted in June 2026. Starbucks has not publicly confirmed the alleged security incident, and the…
-
GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates
GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates GoldenEyeDog, a Chinese cybercrime group linked to the Golden Gh0st malware family, is back in focus after an intrusion at DigiCert exposed the risks around code-signing certificates. The attackers used the access to intercept customer certificate activation codes and sign their own malicious files. The…
-
U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses
U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses Federal prosecutors have charged three Russian nationals over infrastructure that allegedly enabled ransomware, malware, phishing, and other cyberattacks against organizations in the United States and abroad. The seven-year investigation links the activity to more than $62 million in victim losses across…
-
North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers
North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers North Korean-linked hackers are hiding OTTERCOOKIE-aligned malware inside ordinary SVG flag images, turning a familiar part of a web project into a concealed delivery channel. The operation targets software developers who believe they are completing a coding test for a job opportunity. The…
-
15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution
15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan Shaw reported the bug to F5 SIRT, which coordinated a fix released in nginx…
-
World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last…
-
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below – git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3)…
-
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in…
-
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm,…
-
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The…
-
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives 7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. […] Lawrence Abrams Go to bleepingcomputer
-
WordPress Core “wp2shell” RCE flaws get public exploits, patch now
WordPress Core “wp2shell” RCE flaws get public exploits, patch now Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft warns of surge in ACR Stealer attacks on customers Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. […] Bill Toulas Go to bleepingcomputer
-
The Future of Age Verification: Your Face Never Leaves Your Device
The Future of Age Verification: Your Face Never Leaves Your Device As age verification laws expand worldwide, organizations face growing pressure to protect users’ privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting compliance. […] Sponsored by Incode Go…
-
NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure
NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. This malware marks a distinct evolution from opportunistic worm behavior toward an industrial-grade,…
-
Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI
Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI Hugging Face disclosed this week that it detected and contained a production infrastructure intrusion, driven end-to-end by an autonomous AI agent system, and defended against it using its own AI-based forensic analysis. The attackers exploited two code-execution flaws in Hugging Face’s dataset…
-
New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours
New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours A previously unseen ransomware family dubbed “Spirals” struck an IT services company in South Asia in June 2026. Symantec’s Threat Hunter Team reports that the attackers moved from the initial breach to full network encryption in under 24…
-
Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution
Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution A newly disclosed a pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed “wp2shell,” that requires no authentication and affects stock WordPress installations… Delivered by PolitePaul service Go to gbhackers.com
-
EY Data Breach – Hackers Access Third-Party IT Support Platform and Steal Client Tax Documents
EY Data Breach – Hackers Access Third-Party IT Support Platform and Steal Client Tax Documents Ernst & Young LLP (EY) has confirmed a data security incident in which an unauthorized third party breached a third-party IT service management platform… Delivered by PolitePaul service Go to gbhackers.com
-
OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload
OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload A newly disclosed vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. The Okta Red Team recently discovered “HollowByte,” a Denial… Delivered by PolitePaul service Go to gbhackers.com
-
Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges
Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges Cloud Software Group has issued a High-severity security bulletin (CTX696734) disclosing two vulnerabilities in the Citrix Secure Access Client for Windows and the Citrix… Delivered by PolitePaul service Go to gbhackers.com
-
New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets
New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets A financially motivated, Russian-speaking threat actor tracked as UAT-11795, orchestrating a large-scale campaign since at least June 2025. A sophisticated Python-based remote access trojan dubbed… Delivered by PolitePaul service Go to gbhackers.com
-
Abbott probes two cyber incidents amid extortion claims
Abbott probes two cyber incidents amid extortion claims Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. […] Lawrence Abrams Go to bleepingcomputer
-
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. […] Bill Toulas Go to bleepingcomputer
-
Ernst & Young discloses data breach after support system hack
Ernst & Young discloses data breach after support system hack Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. […] Bill Toulas Go to bleepingcomputer
-
Inside the Search for “Clean” Residential Proxies for Carding
Inside the Search for “Clean” Residential Proxies for Carding Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek “clean” residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection. […] Sponsored by Flare Go to bleepingcomputer
-
New Windows LegacyHive zero-day gives hackers admin privileges
New Windows LegacyHive zero-day gives hackers admin privileges A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation
Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, with one flaw allowing low-privileged attackers to gain full SYSTEM access on affected machines. The more severe issue, tracked as CVE-2026-53565,…
-
New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released
New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover by unauthenticated attackers. Security researcher Adam Kues of Searchlight Cyber’s Assetnote research team uncovered the flaw,…
-
OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes
OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes A newly disclosed vulnerability in OpenSSL, dubbed “HollowByte,” allows a remote, unauthenticated attacker to trigger a denial-of-service (DoS) condition using a malicious payload as small as 11 bytes. Discovered by the Okta Red Team, the flaw exploits how OpenSSL pre-allocates memory during the TLS…
-
Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States
Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States Coca-Cola has reported a ransomware attack affecting its dairy subsidiary, Fairlife, resulting in a temporary shutdown of production operations across the United States. This incident was disclosed in a Form 8-K filing submitted to the U.S. Securities and Exchange Commission on July 16, 2026.…
-
EY Data Breach – Hackers Gain Access to IT Support System and Download Documents
EY Data Breach – Hackers Gain Access to IT Support System and Download Documents Ernst & Young LLP (EY) is notifying clients that an unauthorized third party breached a support ticket platform used by its IT staff, downloading documents containing client tax data during a roughly two-week window this spring. The Big Four accounting and…
-
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress…
-
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with…
-
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an…
-
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the…
-
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group…
-
Friday Squid Blogging: Squid Washing Up on Cape Cod Beach
Friday Squid Blogging: Squid Washing Up on Cape Cod Beach Lots of articles about this. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce Schneier Go to bruce schneier
-
Details of Alan Turing’s Voice Encryption System
Details of Alan Turing’s Voice Encryption System Really interesting piece of cryptographic history: In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-secret “Delilah” engineering project from…
-
ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)
ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Google’s Gemini lets strangers send messages from your locked Android phone
Google’s Gemini lets strangers send messages from your locked Android phone Gemini, Google’s AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone. Read more in my article on the Hot for Security…
-
Inc Ransomware Exploits SonicWall SMA Zero-Days
Inc Ransomware Exploits SonicWall SMA Zero-Days When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall’s mobile access appliances. Nate Nelson Go to gbhackers.com
-
The Real AI Threat Is Blind Trust
The Real AI Threat Is Blind Trust AI models left to both interpret and execute commands eliminate critical cybersecurity oversight. R. Justin Martin Go to gbhackers.com
-
Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear
Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it’s being implemented. Alexander Culafi Go to gbhackers.com
-
Google Bets ‘Agentic Defense’ Strategy Can Outpace Attackers
Google Bets ‘Agentic Defense’ Strategy Can Outpace Attackers Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks. Jeffrey Schwartz Go to gbhackers.com
-
New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure
New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure NadMesh is a new, industrial‑grade Go‑based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous… Delivered by PolitePaul service Go to gbhackers.com
-
TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data
TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data TP-Link has revealed several serious vulnerabilities affecting its Kasa EC70 and EC71 smart camera models, which could expose users to credential theft and geolocation… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands
CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities in Fortinet FortiSandbox to its Known Exploited Vulnerabilities (KEV) catalog. These… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Use Paste-and-Run Commands to Deploy ClickLock Stealer Against Mac Users
Hackers Use Paste-and-Run Commands to Deploy ClickLock Stealer Against Mac Users Hackers are actively targeting macOS users with a newly identified infostealer dubbed “ClickLock Stealer,” leveraging paste-and-run social engineering techniques to bypass Apple’s native security… Delivered by PolitePaul service Go to gbhackers.com
-
GPT-5.6 Codex Reportedly Wipes Files From Home Directories
GPT-5.6 Codex Reportedly Wipes Files From Home Directories Recent reports indicate that GPT-5.6 Codex has unintentionally deleted files in users’ home directories under certain configurations, raising concerns about the risks of running… Delivered by PolitePaul service Go to gbhackers.com
-
Windows Server 2022 reach end of mainstream support in 90 days
Windows Server 2022 reach end of mainstream support in 90 days Microsoft announced that Windows Server 2022 will reach the mainstream end date in October 2026, but will switch to extended support and continue receiving security updates for five more years. […] Sergiu Gatlan Go to bleepingcomputer
-
US charges two over laundering $43 million from investment fraud
US charges two over laundering $43 million from investment fraud U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA urges immediate action on actively exploited Fortinet flaws
CISA urges immediate action on actively exploited Fortinet flaws CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform. […] Sergiu Gatlan Go to bleepingcomputer
-
New ClickLock macOS malware traps users into revealing login password
New ClickLock macOS malware traps users into revealing login password A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. […] Bill Toulas Go to bleepingcomputer
-
Coca-Cola says Fairlife ransomware attack halts US dairy production
Coca-Cola says Fairlife ransomware attack halts US dairy production The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. […] Lawrence Abrams Go to bleepingcomputer
-
New ClickLock macOS Stealer Kills Every App to Force Password Entry
New ClickLock macOS Stealer Kills Every App to Force Password Entry A newly discovered macOS malware dubbed ClickLock is raising alarms in the cybersecurity community for its aggressive and deceptive credential-harvesting techniques. According to researchers at Group-IB, the stealer employs a highly disruptive tactic that forcibly terminates running applications, effectively locking users out of their…
-
CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks
CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks CISA has added a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-58644, to its Known Exploited Vulnerabilities (KEV) catalog. This addition comes with a warning that attackers are actively exploiting the flaw in real-world attacks. The vulnerability stems from a weakness in deserializing untrusted data,…
-
Top 10 Best Identity Threat Detection and Response (ITDR) Solutions in 2026
Top 10 Best Identity Threat Detection and Response (ITDR) Solutions in 2026 Identity has become the primary battleground of enterprise cybersecurity. Attackers increasingly bypass traditional defenses by stealing credentials, hijacking sessions, abusing privileged accounts, and exploiting misconfigurations across Active Directory, cloud platforms, SaaS applications, and non-human identities. Microsoft reported more than 7,000 password attacks per…
-
Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks
Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks TP-Link has released security updates for two vulnerabilities in its Kasa EC70 v4 and EC71 v4 smart cameras. These flaws, tracked as CVE-2026-9770 and CVE-2026-13230, could allow an attacker on the same local network to obtain sensitive information from vulnerable devices. The most serious issue,…
-
GPT-5.6 Codex is Reportedly Deleting Files From Home Directories
GPT-5.6 Codex is Reportedly Deleting Files From Home Directories OpenAI is currently investigating a small number of reports indicating that the GPT-5.6 Codex unintentionally deleted files from users’ home directories. These incidents reportedly occurred when Codex was granted full filesystem access without the necessary sandbox protections or automated review controls. According to Tibo Sottiaux, a…