no alarms and no surprises please..
-
Vatican’s Official Prayer App Leaks 700K+ Global Users’ PII
Vatican’s Official Prayer App Leaks 700K+ Global Users’ PII A porous API endpoint exposes, names, email addresses, location, and site status, all of which can be easily gleaned by anyone with a browser. Nate Nelson Go to gbhackers.com
-
Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions
Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser… Delivered by PolitePaul service Go to gbhackers.com
-
SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design
SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade has… Delivered by PolitePaul service Go to gbhackers.com
-
JetBrains Patches Multiple Vulnerabilities Affecting IntelliJ IDEA and TeamCity
JetBrains Patches Multiple Vulnerabilities Affecting IntelliJ IDEA and TeamCity JetBrains has addressed a series of security vulnerabilities affecting IntelliJ IDEA and TeamCity, including several critical flaws that could allow code execution or unauthorized… Delivered by PolitePaul service Go to gbhackers.com
-
Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data
Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data Origin Energy Limited has confirmed a cybersecurity incident involving unauthorized access to and disclosure of customer data, representing a significant data security event for… Delivered by PolitePaul service Go to gbhackers.com
-
Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code
Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code Apache Syncope has released versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to address six security vulnerabilities affecting the 4.1, 4.0, and 3.0 release branches. These vulnerabilities… Delivered by PolitePaul service Go to gbhackers.com
-
Clop ransomware targets Windchill, FlexPLM in data theft attacks
Clop ransomware targets Windchill, FlexPLM in data theft attacks The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. […] Sergiu Gatlan Go to bleepingcomputer
-
New Dolphin X malware uses AI to rank high-value targets
New Dolphin X malware uses AI to rank high-value targets A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. […] Lawrence Abrams Go to bleepingcomputer
-
Australian energy provider Origin says data breach exposes client data
Australian energy provider Origin says data breach exposes client data Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. […] Bill Toulas Go to bleepingcomputer
-
Fake Claude app promoted by Bing ads pushes SectopRAT malware
Fake Claude app promoted by Bing ads pushes SectopRAT malware A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. […] Bill Toulas Go to bleepingcomputer
-
Russian hackers exploit Zimbra zero-click flaw for email theft
Russian hackers exploit Zimbra zero-click flaw for email theft CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. […] Lawrence Abrams Go to bleepingcomputer
-
One Compromised Wi-Fi Gateway Can Redirect Every Hotel Guest to Attacker Controlled Servers
One Compromised Wi-Fi Gateway Can Redirect Every Hotel Guest to Attacker Controlled Servers One compromised hotel Wi-Fi gateway can silently redirect every guest to attacker controlled servers, putting corporate accounts at risk even when users think they are browsing safely. The campaign starts with a simple idea that many travelers overlook. When you connect to…
-
How Infostealer Logs Became the Fuel Behind Massive Cloud Data Breaches
How Infostealer Logs Became the Fuel Behind Massive Cloud Data Breaches Infostealer malware has quietly become the single most important initial-access commodity in the cybercrime economy, replacing traditional phishing and exploit-driven intrusions as the leading precursor to enterprise breaches and ransomware. Rather than breaking into networks, modern threat actors buy their way in by purchasing…
-
Google Rolls Out Emergency Chrome Update for Four High-Severity Security Flaws
Google Rolls Out Emergency Chrome Update for Four High-Severity Security Flaws Google has released an emergency security update for its Chrome browser, addressing four high-severity vulnerabilities that could expose users to serious risks if left unpatched. The update, now rolling out globally, upgrades Chrome to version 150.0.7871.186/.187 for Windows and macOS, and 150.0.7871.186 for Linux…
-
Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails
Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails Hackers are using fake payment receipt emails to deliver a 750MB Lampion remote access trojan to targets in Portugal. The campaign relies on familiar financial language, convincing business details, and oversized files designed to slow down analysis and evade security checks. The attack begins with…
-
Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold
Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold Email phishing remains one of the most common ways attackers gain access to business accounts. During the second quarter of 2026, criminals continued to use fake login pages, malicious attachments, and convincing business messages to steal credentials or deliver malware. The problem…
-
Europe’s Multilingual Reality Exposes AI Security Gaps
Europe’s Multilingual Reality Exposes AI Security Gaps The AI security layer and guardrails for many AI products don’t evenly protect against jailbreaking and unsafe actions in every single language. Alexander Culafi Go to gbhackers.com
-
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks…
-
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client. The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept…
-
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Most of this week’s trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code,…
-
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the…
-
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its…
-
When the attacker is an AI agent
When the attacker is an AI agent Lessons from the OpenAI-Hugging Face breach Categories: Security Operations Tags: AI, OpenAI, Hugging Face Go to sophos
-
End-to-End Encryption and “Going Dark”
End-to-End Encryption and “Going Dark” New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“: Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current controversies over end-to-end encryption…
-
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know You can’t have failed to hear the news headlines about “rogue” OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the reports suggest? Find out…
-
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets A state-sponsored threat group, dubbed “Laundry Bear,” sends “half-click” phishing emails that require a victim only to open or preview the message. Rob Wright Go to gbhackers.com
-
Agentic AI Challenges Progress in Confidential Computing
Agentic AI Challenges Progress in Confidential Computing Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers. Agam Shah Go to gbhackers.com
-
New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims
New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims A new Windows-focused infostealer and remote access trojan (RAT) dubbed Dolphin X is being advertised on cybercrime forums with a clear pitch: automate the… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication
Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication A critical authentication bypass vulnerability affecting Check Point SmartConsole has been actively exploited in the wild, allowing attackers to gain unauthorized access to security… Delivered by PolitePaul service Go to gbhackers.com
-
Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root
Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root A recently disclosed vulnerability in Ubuntu’s snap ecosystem, identified as CVE-2026-8933, presents a critical local privilege escalation flaw. This vulnerability allows unprivileged users to… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Adds Prompt Injection Protection to Defender for Office 365
Microsoft Adds Prompt Injection Protection to Defender for Office 365 Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats…. Delivered by PolitePaul service Go to gbhackers.com
-
KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars
KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars A critical Bluetooth vulnerability in dealer-installed KARR Security Systems is putting over 2 million vehicles at risk of unauthorized access and immobilization. This situation… Delivered by PolitePaul service Go to gbhackers.com
-
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. […] Bill Toulas Go to bleepingcomputer
-
Microsoft working to fix Exchange Online mailbox quarantine issue
Microsoft working to fix Exchange Online mailbox quarantine issue Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers’ mailboxes since Sunday. […] Sergiu Gatlan Go to bleepingcomputer
-
Check Point warns of SmartConsole zero-day exploited in attacks
Check Point warns of SmartConsole zero-day exploited in attacks Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company’s SmartConsole graphical user interface (GUI) admin panel. […] Sergiu Gatlan Go to bleepingcomputer
-
Upbound says hack caused $13 million in fraudulent Acima leases
Upbound says hack caused $13 million in fraudulent Acima leases The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. […] Bill Toulas Go to bleepingcomputer
-
South Korea discloses data breach impacting diplomats worldwide
South Korea discloses data breach impacting diplomats worldwide South Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. […] Bill Toulas Go to bleepingcomputer
-
Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks
Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks A recently disclosed Bluetooth vulnerability in the aftermarket KARR Security System exposes approximately 2.2 million vehicles to remote attacks that could allow unauthorized door unlocking, alarm control, and vehicle immobilization. This issue, uncovered by researchers at the University of California, San Diego, highlights…
-
July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws
July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws A new infrastructure security review has exposed a busy month for defenders. Fourteen infrastructure vendors issued 61 relevant advisories worldwide during the 30 days ending July 17, including 26 flaws that attackers can reach remotely without logging in. Six advisories carried critical CVSS…
-
Chick-fil-A Urges Customers to Change Chick-fil-A One Passwords After Unauthorized Access
Chick-fil-A Urges Customers to Change Chick-fil-A One Passwords After Unauthorized Access Chick-fil-A has warned customers to update their Chick-fil-A One passwords after detecting unauthorized access to a subset of loyalty accounts during a credential stuffing attack in June 2026. After conducting an internal investigation, the company confirmed that attackers used an automated credential stuffing attack…
-
CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure
CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure Iran-linked hackers are targeting internet-connected industrial controllers used across U.S. critical infrastructure. The campaign has disrupted programmable logic controllers, or PLCs, in government, water, wastewater, and energy facilities. Some victims suffered operational disruption and financial losses after attackers altered the systems that manage…
-
CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild
CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited in the wild, prompting organizations to take immediate defensive action. Tracked as CVE-2026-16232, the flaw affects…
-
Brazilian Banking Trojan Actively Spreading in Portugal
Brazilian Banking Trojan Actively Spreading in Portugal Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets. Nate Nelson Go to gbhackers.com
-
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before…
-
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts…
-
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data. The shortcoming has been codenamed HermeticReader by Guardio Labs.…
-
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”). “The filename parameter is concatenated…
-
The Fastest Path to AI Adoption Runs Through Security
The Fastest Path to AI Adoption Runs Through Security Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned. According to McKinsey’s…
-
July Patch Tuesday only feels endless
July Patch Tuesday only feels endless <p>AI deluge brings 575 CVEs, 479 advisories, reset to blog-post format</p> Categories: Threat Research Tags: x-ops, Patch Tuesday, MICROSOFT PATCH TUESDAY Go to sophos
-
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday – and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has…
-
Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain
Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken. Robert Lemos Go to gbhackers.com
-
Attackers Are Learning to Live Off the AI Toolchain
Attackers Are Learning to Live Off the AI Toolchain Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity. Jai Vijayan Go to gbhackers.com
-
Fake Bahrain Alert App Deploys Android Surveillance Malware
Fake Bahrain Alert App Deploys Android Surveillance Malware A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes. Alexander Culafi Go to gbhackers.com
-
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective. Elizabeth Montalbano Go to gbhackers.com
-
EU Financial Institutions Leak Data Through Cookie Trackers
EU Financial Institutions Leak Data Through Cookie Trackers European banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns. Alexander Culafi Go to gbhackers.com
-
Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws
Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws Zimbra has released version 10.1.20 of its Collaboration Suite (ZCS) to address multiple high-severity security vulnerabilities. This release includes a critical command injection flaw… Delivered by PolitePaul service Go to gbhackers.com
-
FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims
FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims The Federal Bureau of Investigation (FBI) has issued a new Public Service Announcement (Alert Number I-072026-PSA) regarding an evolving fraud campaign. Cybercriminals are increasingly… Delivered by PolitePaul service Go to gbhackers.com
-
Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands
Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands ASUS has announced a significant security vulnerability in its router firmware that could enable remote attackers to execute arbitrary commands through a man-in-the-middle (MITM)… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time
Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time An active adversary-in-the-middle (AiTM) phishing campaign that clones Microsoft authentication pages to intercept credentials, Multi-Factor Authentication (MFA) codes, and session tokens in real time. Rather… Delivered by PolitePaul service Go to gbhackers.com
-
North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs
North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs North Korea’s Famous Chollima threat group, also tracked as Wagemole, is actively running a sophisticated cyberespionage campaign dubbed ClickFake Interview. The operation targets cryptocurrency and… Delivered by PolitePaul service Go to gbhackers.com
-
Chick-fil-A discloses data breach after credential stuffing attacks
Chick-fil-A discloses data breach after credential stuffing attacks American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI says its AI models hacked Hugging Face during testing
OpenAI says its AI models hacked Hugging Face during testing OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. […] Sergiu Gatlan Go to bleepingcomputer
-
Police dismantle Kratos phishing platform, arrest developer
Police dismantle Kratos phishing platform, arrest developer Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. […] Bill Toulas Go to bleepingcomputer
-
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware A large-scale operation dubbed ‘FakeGit’ is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. […] Bill Toulas Go to bleepingcomputer
-
Critical SharePoint RCE flaw exploited to steal machine keys
Critical SharePoint RCE flaw exploited to steal machine keys Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. […] Bill Toulas Go to bleepingcomputer
-
Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them
Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them An anonymous GitHub user has quietly assembled one of the most disruptive exploit collections of the year, dropping 204 zero‑day proof‑of‑concept files for dozens of open‑source projects before vendors had a chance to patch them. The archive, hosted under the name “exploitarium” by…
-
Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data
Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding assistant and turn it into a data-exfiltration tool. Security researchers at Manifold Security found…
-
Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach
Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach Spain’s data protection authority has fined the genetic testing company 23andMe €2.4 million due to security failures linked to a data breach in 2023. This incident exposed highly sensitive information such as genetic, health, ethnicity, and family-related data belonging to over 2,600 individuals…
-
Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions
Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions Attackers are quietly turning trusted Microsoft Outlook mailboxes into launchpads for stealing multi factor authenticated Microsoft 365 sessions, even when users think they are protected. Adversary in the middle phishing has evolved into a reliable tool for hijacking live cloud sessions that organizations depend…
-
Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform
Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform A Russian-speaking threat actor known as “Trim” has reportedly transformed jailbroken frontier AI models into an automated penetration testing platform called AI Pentest Checker. This activity highlights how criminals can misuse legitimate AI services and common security tools to accelerate reconnaissance, validate vulnerabilities,…
-
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain. The package, named “Newtonsoftt.Json.Net,” masquerades as the Newtonsoft.Json library and is a trojanized fork. Seven versions of…
-
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft’s…
-
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an “even more capable pre-release model,” was behind the security incident that targeted Hugging Face’s production infrastructure last week. The AI company said the models were…
-
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked, effectively undermining the feature’s privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by…
-
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code on a developer’s machine, with no approval step able to stop it. Intezer, in research with…
-
MIT to Become Hotbed of AI Video Surveillance
MIT to Become Hotbed of AI Video Surveillance It’s a lot: According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and infrastructure that will…
-
ISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd)
ISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Captive Portal Detection, (Tue, Jul 21st)
Captive Portal Detection, (Tue, Jul 21st) Not everything our honeypots detect is an attack. Sometimes it is just “odd traffic”, and this is one example: Our “First Seen” list currently includes “http://detectportal.firefox.co m/success.txt” as one of the new URLs detected by our honeypots. The hostname “detectportal” kind of gives away what is happening here. If you have…
-
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent…
-
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine’s computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code. Read more in my article on the Hot for Security blog. Graham Cluley Go…
-
177: National Public Data
177: National Public Data This is the story of the hacker known as “USDoD”. When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far. Sponsors Support…
-
Weekly Update 513: Clauding The Home Network
Weekly Update 513: Clauding The Home Network I reckon this week’s video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is – if ever there was an actual value proposition for AI it’s taking lots of noise and converting it…
-
Ransomware Is Accelerating, But It’s Not Because of AI
Ransomware Is Accelerating, But It’s Not Because of AI Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations. Jai Vijayan Go to gbhackers.com
-
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. Robert Lemos Go to gbhackers.com
-
Hacker Turns AI Jailbreaks Into Offensive Attack Platform
Hacker Turns AI Jailbreaks Into Offensive Attack Platform A Russian-speaking actor, “Trim,” dismantled publicly available frontier models and integrated them with offensive security tools. Elizabeth Montalbano Go to gbhackers.com
-
Choose Wisely: AI-Generated Coding Risk Varies, A Lot
Choose Wisely: AI-Generated Coding Risk Varies, A Lot AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used. Alexander Culafi Go to gbhackers.com
-
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution Threat actors are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform. This vulnerability allows attackers to escape… Delivered by PolitePaul service Go to gbhackers.com
-
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe… Delivered by PolitePaul service Go to gbhackers.com
-
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma‑associated Node.js backdoor through trusted GitHub Actions–driven release workflows… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell
Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to… Delivered by PolitePaul service Go to gbhackers.com
-
Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials
Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft shares manual fix for WSUS sync delays and timeouts
Microsoft shares manual fix for WSUS sync delays and timeouts Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows LegacyHive zero-day flaw gets free, unofficial patches
Windows LegacyHive zero-day flaw gets free, unofficial patches Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Estée Lauder discloses data breach via Oracle E-Business flaw
Estée Lauder discloses data breach via Oracle E-Business flaw Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. […] Bill Toulas Go to bleepingcomputer
-
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
SonicWall SMA1000 flaws exploited as zero-days to push custom malware Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
Hackers steal $23.7 million in crypto from Ostium in off-chain attack The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. […] Bill Toulas Go to bleepingcomputer
-
The Privilege Paths Attackers See, That You Don’t – A Complete PAM Guide
The Privilege Paths Attackers See, That You Don’t – A Complete PAM Guide Why identity fragmentation is the blind spot behind most breaches—and what a platform approach changes The Identity Problem Hiding in Plain Sight Identity is at the centre of nearly every major breach—yet most organisations still can’t answer one fundamental question: what is the…
-
Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems
Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems A newly uncovered cyberespionage campaign has turned Telegram bots into quiet controllers for backdoors planted inside Middle Eastern government networks. The operation relies on familiar Windows components and legitimate-looking files, allowing attackers to establish access without immediately drawing attention. The infection begins with an…
-
Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware
Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arctic Wolf Labs. The security firm investigated multiple intrusions throughout June 2026, all tracing back to the…