no alarms and no surprises please..
-
Agentic AI Challenges Progress in Confidential Computing
Agentic AI Challenges Progress in Confidential Computing Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers. Agam Shah Go to gbhackers.com
-
New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims
New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims A new Windows-focused infostealer and remote access trojan (RAT) dubbed Dolphin X is being advertised on cybercrime forums with a clear pitch: automate the… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication
Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication A critical authentication bypass vulnerability affecting Check Point SmartConsole has been actively exploited in the wild, allowing attackers to gain unauthorized access to security… Delivered by PolitePaul service Go to gbhackers.com
-
Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root
Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root A recently disclosed vulnerability in Ubuntu’s snap ecosystem, identified as CVE-2026-8933, presents a critical local privilege escalation flaw. This vulnerability allows unprivileged users to… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Adds Prompt Injection Protection to Defender for Office 365
Microsoft Adds Prompt Injection Protection to Defender for Office 365 Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats…. Delivered by PolitePaul service Go to gbhackers.com
-
KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars
KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars A critical Bluetooth vulnerability in dealer-installed KARR Security Systems is putting over 2 million vehicles at risk of unauthorized access and immobilization. This situation… Delivered by PolitePaul service Go to gbhackers.com
-
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. […] Bill Toulas Go to bleepingcomputer
-
Microsoft working to fix Exchange Online mailbox quarantine issue
Microsoft working to fix Exchange Online mailbox quarantine issue Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers’ mailboxes since Sunday. […] Sergiu Gatlan Go to bleepingcomputer
-
Check Point warns of SmartConsole zero-day exploited in attacks
Check Point warns of SmartConsole zero-day exploited in attacks Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company’s SmartConsole graphical user interface (GUI) admin panel. […] Sergiu Gatlan Go to bleepingcomputer
-
Upbound says hack caused $13 million in fraudulent Acima leases
Upbound says hack caused $13 million in fraudulent Acima leases The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. […] Bill Toulas Go to bleepingcomputer
-
South Korea discloses data breach impacting diplomats worldwide
South Korea discloses data breach impacting diplomats worldwide South Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. […] Bill Toulas Go to bleepingcomputer
-
Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks
Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks A recently disclosed Bluetooth vulnerability in the aftermarket KARR Security System exposes approximately 2.2 million vehicles to remote attacks that could allow unauthorized door unlocking, alarm control, and vehicle immobilization. This issue, uncovered by researchers at the University of California, San Diego, highlights…
-
July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws
July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws A new infrastructure security review has exposed a busy month for defenders. Fourteen infrastructure vendors issued 61 relevant advisories worldwide during the 30 days ending July 17, including 26 flaws that attackers can reach remotely without logging in. Six advisories carried critical CVSS…
-
Chick-fil-A Urges Customers to Change Chick-fil-A One Passwords After Unauthorized Access
Chick-fil-A Urges Customers to Change Chick-fil-A One Passwords After Unauthorized Access Chick-fil-A has warned customers to update their Chick-fil-A One passwords after detecting unauthorized access to a subset of loyalty accounts during a credential stuffing attack in June 2026. After conducting an internal investigation, the company confirmed that attackers used an automated credential stuffing attack…
-
CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure
CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure Iran-linked hackers are targeting internet-connected industrial controllers used across U.S. critical infrastructure. The campaign has disrupted programmable logic controllers, or PLCs, in government, water, wastewater, and energy facilities. Some victims suffered operational disruption and financial losses after attackers altered the systems that manage…
-
CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild
CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited in the wild, prompting organizations to take immediate defensive action. Tracked as CVE-2026-16232, the flaw affects…
-
Brazilian Banking Trojan Actively Spreading in Portugal
Brazilian Banking Trojan Actively Spreading in Portugal Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets. Nate Nelson Go to gbhackers.com
-
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before…
-
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts…
-
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data. The shortcoming has been codenamed HermeticReader by Guardio Labs.…
-
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”). “The filename parameter is concatenated…
-
The Fastest Path to AI Adoption Runs Through Security
The Fastest Path to AI Adoption Runs Through Security Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned. According to McKinsey’s…
-
July Patch Tuesday only feels endless
July Patch Tuesday only feels endless <p>AI deluge brings 575 CVEs, 479 advisories, reset to blog-post format</p> Categories: Threat Research Tags: x-ops, Patch Tuesday, MICROSOFT PATCH TUESDAY Go to sophos
-
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday – and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has…
-
Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain
Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken. Robert Lemos Go to gbhackers.com
-
Attackers Are Learning to Live Off the AI Toolchain
Attackers Are Learning to Live Off the AI Toolchain Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity. Jai Vijayan Go to gbhackers.com
-
Fake Bahrain Alert App Deploys Android Surveillance Malware
Fake Bahrain Alert App Deploys Android Surveillance Malware A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes. Alexander Culafi Go to gbhackers.com
-
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective. Elizabeth Montalbano Go to gbhackers.com
-
EU Financial Institutions Leak Data Through Cookie Trackers
EU Financial Institutions Leak Data Through Cookie Trackers European banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns. Alexander Culafi Go to gbhackers.com
-
Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws
Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws Zimbra has released version 10.1.20 of its Collaboration Suite (ZCS) to address multiple high-severity security vulnerabilities. This release includes a critical command injection flaw… Delivered by PolitePaul service Go to gbhackers.com
-
FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims
FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims The Federal Bureau of Investigation (FBI) has issued a new Public Service Announcement (Alert Number I-072026-PSA) regarding an evolving fraud campaign. Cybercriminals are increasingly… Delivered by PolitePaul service Go to gbhackers.com
-
Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands
Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands ASUS has announced a significant security vulnerability in its router firmware that could enable remote attackers to execute arbitrary commands through a man-in-the-middle (MITM)… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time
Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time An active adversary-in-the-middle (AiTM) phishing campaign that clones Microsoft authentication pages to intercept credentials, Multi-Factor Authentication (MFA) codes, and session tokens in real time. Rather… Delivered by PolitePaul service Go to gbhackers.com
-
North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs
North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs North Korea’s Famous Chollima threat group, also tracked as Wagemole, is actively running a sophisticated cyberespionage campaign dubbed ClickFake Interview. The operation targets cryptocurrency and… Delivered by PolitePaul service Go to gbhackers.com
-
Chick-fil-A discloses data breach after credential stuffing attacks
Chick-fil-A discloses data breach after credential stuffing attacks American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI says its AI models hacked Hugging Face during testing
OpenAI says its AI models hacked Hugging Face during testing OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. […] Sergiu Gatlan Go to bleepingcomputer
-
Police dismantle Kratos phishing platform, arrest developer
Police dismantle Kratos phishing platform, arrest developer Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. […] Bill Toulas Go to bleepingcomputer
-
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware A large-scale operation dubbed ‘FakeGit’ is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. […] Bill Toulas Go to bleepingcomputer
-
Critical SharePoint RCE flaw exploited to steal machine keys
Critical SharePoint RCE flaw exploited to steal machine keys Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. […] Bill Toulas Go to bleepingcomputer
-
Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them
Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them An anonymous GitHub user has quietly assembled one of the most disruptive exploit collections of the year, dropping 204 zero‑day proof‑of‑concept files for dozens of open‑source projects before vendors had a chance to patch them. The archive, hosted under the name “exploitarium” by…
-
Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data
Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding assistant and turn it into a data-exfiltration tool. Security researchers at Manifold Security found…
-
Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach
Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach Spain’s data protection authority has fined the genetic testing company 23andMe €2.4 million due to security failures linked to a data breach in 2023. This incident exposed highly sensitive information such as genetic, health, ethnicity, and family-related data belonging to over 2,600 individuals…
-
Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions
Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions Attackers are quietly turning trusted Microsoft Outlook mailboxes into launchpads for stealing multi factor authenticated Microsoft 365 sessions, even when users think they are protected. Adversary in the middle phishing has evolved into a reliable tool for hijacking live cloud sessions that organizations depend…
-
Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform
Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform A Russian-speaking threat actor known as “Trim” has reportedly transformed jailbroken frontier AI models into an automated penetration testing platform called AI Pentest Checker. This activity highlights how criminals can misuse legitimate AI services and common security tools to accelerate reconnaissance, validate vulnerabilities,…
-
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain. The package, named “Newtonsoftt.Json.Net,” masquerades as the Newtonsoft.Json library and is a trojanized fork. Seven versions of…
-
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft’s…
-
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an “even more capable pre-release model,” was behind the security incident that targeted Hugging Face’s production infrastructure last week. The AI company said the models were…
-
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked, effectively undermining the feature’s privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by…
-
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code on a developer’s machine, with no approval step able to stop it. Intezer, in research with…
-
MIT to Become Hotbed of AI Video Surveillance
MIT to Become Hotbed of AI Video Surveillance It’s a lot: According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and infrastructure that will…
-
ISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd)
ISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Captive Portal Detection, (Tue, Jul 21st)
Captive Portal Detection, (Tue, Jul 21st) Not everything our honeypots detect is an attack. Sometimes it is just “odd traffic”, and this is one example: Our “First Seen” list currently includes “http://detectportal.firefox.co m/success.txt” as one of the new URLs detected by our honeypots. The hostname “detectportal” kind of gives away what is happening here. If you have…
-
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent…
-
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine’s computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code. Read more in my article on the Hot for Security blog. Graham Cluley Go…
-
177: National Public Data
177: National Public Data This is the story of the hacker known as “USDoD”. When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far. Sponsors Support…
-
Weekly Update 513: Clauding The Home Network
Weekly Update 513: Clauding The Home Network I reckon this week’s video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is – if ever there was an actual value proposition for AI it’s taking lots of noise and converting it…
-
Ransomware Is Accelerating, But It’s Not Because of AI
Ransomware Is Accelerating, But It’s Not Because of AI Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations. Jai Vijayan Go to gbhackers.com
-
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. Robert Lemos Go to gbhackers.com
-
Hacker Turns AI Jailbreaks Into Offensive Attack Platform
Hacker Turns AI Jailbreaks Into Offensive Attack Platform A Russian-speaking actor, “Trim,” dismantled publicly available frontier models and integrated them with offensive security tools. Elizabeth Montalbano Go to gbhackers.com
-
Choose Wisely: AI-Generated Coding Risk Varies, A Lot
Choose Wisely: AI-Generated Coding Risk Varies, A Lot AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used. Alexander Culafi Go to gbhackers.com
-
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution Threat actors are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform. This vulnerability allows attackers to escape… Delivered by PolitePaul service Go to gbhackers.com
-
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe… Delivered by PolitePaul service Go to gbhackers.com
-
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma‑associated Node.js backdoor through trusted GitHub Actions–driven release workflows… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell
Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to… Delivered by PolitePaul service Go to gbhackers.com
-
Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials
Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft shares manual fix for WSUS sync delays and timeouts
Microsoft shares manual fix for WSUS sync delays and timeouts Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows LegacyHive zero-day flaw gets free, unofficial patches
Windows LegacyHive zero-day flaw gets free, unofficial patches Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Estée Lauder discloses data breach via Oracle E-Business flaw
Estée Lauder discloses data breach via Oracle E-Business flaw Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. […] Bill Toulas Go to bleepingcomputer
-
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
SonicWall SMA1000 flaws exploited as zero-days to push custom malware Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
Hackers steal $23.7 million in crypto from Ostium in off-chain attack The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. […] Bill Toulas Go to bleepingcomputer
-
The Privilege Paths Attackers See, That You Don’t – A Complete PAM Guide
The Privilege Paths Attackers See, That You Don’t – A Complete PAM Guide Why identity fragmentation is the blind spot behind most breaches—and what a platform approach changes The Identity Problem Hiding in Plain Sight Identity is at the centre of nearly every major breach—yet most organisations still can’t answer one fundamental question: what is the…
-
Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems
Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems A newly uncovered cyberespionage campaign has turned Telegram bots into quiet controllers for backdoors planted inside Middle Eastern government networks. The operation relies on familiar Windows components and legitimate-looking files, allowing attackers to establish access without immediately drawing attention. The infection begins with an…
-
Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware
Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arctic Wolf Labs. The security firm investigated multiple intrusions throughout June 2026, all tracing back to the…
-
Furtex – Linux Toolkit for Post-Exploitation and Evasion for Security Researchers and Red Teamers
Furtex – Linux Toolkit for Post-Exploitation and Evasion for Security Researchers and Red Teamers A new open-source project, Furtex, has emerged as a Linux-focused post-exploitation and evasion research toolkit for authorized security researchers and red-team operators. The project combines raw io_uring system calls, BPF and eBPF tooling, and EDR-evasion research utilities without relying on liburing…
-
Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels
Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. HOLLOWGRAPH is a .NET-compiled malware component that abuses the Microsoft Graph API through a compromised Microsoft 365 account, turning…
-
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. “FakeGit uses…
-
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through…
-
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says…
-
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts,…
-
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of…
-
Sophos Trusted Code
Sophos Trusted Code Recent CVEs across GitHub, Anthropic, Google, dbt, and MISP expose a simple truth: the most trusted code is often the least questioned. As organizations connect AI agents to production systems, those overlooked assumptions can become powerful new attack paths. Categories: Products & Services, Security Operations Tags: AI, MDR, Sophos MDR, Vulnerabilities Go…
-
On Flock License Plate Tracking Cameras
On Flock License Plate Tracking Cameras A recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral. The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM. But when the police report was created and…
-
ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)
ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th) Last week, Searchlight Cyber released details about a vulnerability they are calling “wp2shell”. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in…
-
ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)
ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)
Scans for Hikvision Intelligent Security API, (Sun, Jul 19th) We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans that our honeypot network detects. This weekend, I noticed a new type of recon scans against…
-
‘WP2Shell’ Opens Millions of WordPress Sites to Remote Takeover
‘WP2Shell’ Opens Millions of WordPress Sites to Remote Takeover Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet. Jai Vijayan Go to gbhackers.com
-
Remediating Vulnerabilities With LLMs: Inside Ivanti’s Automation Push
Remediating Vulnerabilities With LLMs: Inside Ivanti’s Automation Push Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open questions. Rob Wright Go to gbhackers.com
-
CISOs Feel the Heat Over AI Risk
CISOs Feel the Heat Over AI Risk Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position. Robert Lemos Go to gbhackers.com
-
Attackers Combo Up Evasion Tactics for BEC Phishing
Attackers Combo Up Evasion Tactics for BEC Phishing “The TFF Trap” uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger. Elizabeth Montalbano Go to gbhackers.com
-
Cybersecurity Keeps Events ‘Uneventful’
Cybersecurity Keeps Events ‘Uneventful’ From the World Cup to the United States’ 250th celebration, this year’s event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands. Olga Polishchuk Go to gbhackers.com
-
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier Microsoft will stop delivering feature updates, bug fixes, and security patches for the OneDrive sync app on systems running Windows version 21H2 and earlier… Delivered by PolitePaul service Go to gbhackers.com
-
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor A newly disclosed cluster of Microsoft SharePoint Server vulnerabilities is actively being exploited in the wild, allowing attackers to convert a single crafted web… Delivered by PolitePaul service Go to gbhackers.com
-
LG Monitors Silently Install McAfee Adware on Windows PCs With Full System Access
LG Monitors Silently Install McAfee Adware on Windows PCs With Full System Access Concerns have arisen regarding LG monitors that reportedly trigger the silent installation of an LG companion application on Windows PCs. This installation is followed by… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues
Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues Microsoft has released KB5121767, an out-of-band (OOB) cumulative update for Windows 11 versions 22H2 and 21H2. This update addresses a system performance issue related… Delivered by PolitePaul service Go to gbhackers.com
-
U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million
U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million U.S. federal prosecutors have unsealed a sweeping indictment charging three Russian nationals and two St. Petersburg–based companies for operating a global “bulletproof hosting” infrastructure. That… Delivered by PolitePaul service Go to gbhackers.com
-
Critical ServiceNow code execution flaw now exploited in attacks
Critical ServiceNow code execution flaw now exploited in attacks Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers abuse ViPNet software to target Russian govt agencies
Hackers abuse ViPNet software to target Russian govt agencies An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. […] Bill Toulas Go to bleepingcomputer
-
Threat Actors Allegedly Listed Starbucks Data on Hacker Forums
Threat Actors Allegedly Listed Starbucks Data on Hacker Forums Starbucks has allegedly been listed on a cybercrime forum by a threat actor using the handle “anes2010,” who claims to be selling a database containing 176 million unique user records reportedly extracted in June 2026. Starbucks has not publicly confirmed the alleged security incident, and the…