no alarms and no surprises please..
-
CISOs Feel the Heat Over AI Risk
CISOs Feel the Heat Over AI Risk Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position. Robert Lemos Go to gbhackers.com
-
Attackers Combo Up Evasion Tactics for BEC Phishing
Attackers Combo Up Evasion Tactics for BEC Phishing “The TFF Trap” uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger. Elizabeth Montalbano Go to gbhackers.com
-
Cybersecurity Keeps Events ‘Uneventful’
Cybersecurity Keeps Events ‘Uneventful’ From the World Cup to the United States’ 250th celebration, this year’s event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands. Olga Polishchuk Go to gbhackers.com
-
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier Microsoft will stop delivering feature updates, bug fixes, and security patches for the OneDrive sync app on systems running Windows version 21H2 and earlier… Delivered by PolitePaul service Go to gbhackers.com
-
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor A newly disclosed cluster of Microsoft SharePoint Server vulnerabilities is actively being exploited in the wild, allowing attackers to convert a single crafted web… Delivered by PolitePaul service Go to gbhackers.com
-
LG Monitors Silently Install McAfee Adware on Windows PCs With Full System Access
LG Monitors Silently Install McAfee Adware on Windows PCs With Full System Access Concerns have arisen regarding LG monitors that reportedly trigger the silent installation of an LG companion application on Windows PCs. This installation is followed by… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues
Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues Microsoft has released KB5121767, an out-of-band (OOB) cumulative update for Windows 11 versions 22H2 and 21H2. This update addresses a system performance issue related… Delivered by PolitePaul service Go to gbhackers.com
-
U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million
U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million U.S. federal prosecutors have unsealed a sweeping indictment charging three Russian nationals and two St. Petersburg–based companies for operating a global “bulletproof hosting” infrastructure. That… Delivered by PolitePaul service Go to gbhackers.com
-
Critical ServiceNow code execution flaw now exploited in attacks
Critical ServiceNow code execution flaw now exploited in attacks Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers abuse ViPNet software to target Russian govt agencies
Hackers abuse ViPNet software to target Russian govt agencies An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. […] Bill Toulas Go to bleepingcomputer
-
Threat Actors Allegedly Listed Starbucks Data on Hacker Forums
Threat Actors Allegedly Listed Starbucks Data on Hacker Forums Starbucks has allegedly been listed on a cybercrime forum by a threat actor using the handle “anes2010,” who claims to be selling a database containing 176 million unique user records reportedly extracted in June 2026. Starbucks has not publicly confirmed the alleged security incident, and the…
-
GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates
GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates GoldenEyeDog, a Chinese cybercrime group linked to the Golden Gh0st malware family, is back in focus after an intrusion at DigiCert exposed the risks around code-signing certificates. The attackers used the access to intercept customer certificate activation codes and sign their own malicious files. The…
-
U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses
U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses Federal prosecutors have charged three Russian nationals over infrastructure that allegedly enabled ransomware, malware, phishing, and other cyberattacks against organizations in the United States and abroad. The seven-year investigation links the activity to more than $62 million in victim losses across…
-
North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers
North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers North Korean-linked hackers are hiding OTTERCOOKIE-aligned malware inside ordinary SVG flag images, turning a familiar part of a web project into a concealed delivery channel. The operation targets software developers who believe they are completing a coding test for a job opportunity. The…
-
15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution
15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan Shaw reported the bug to F5 SIRT, which coordinated a fix released in nginx…
-
World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last…
-
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below – git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3)…
-
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in…
-
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm,…
-
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The…
-
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives 7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. […] Lawrence Abrams Go to bleepingcomputer
-
WordPress Core “wp2shell” RCE flaws get public exploits, patch now
WordPress Core “wp2shell” RCE flaws get public exploits, patch now Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft warns of surge in ACR Stealer attacks on customers Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. […] Bill Toulas Go to bleepingcomputer
-
The Future of Age Verification: Your Face Never Leaves Your Device
The Future of Age Verification: Your Face Never Leaves Your Device As age verification laws expand worldwide, organizations face growing pressure to protect users’ privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting compliance. […] Sponsored by Incode Go…
-
NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure
NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. This malware marks a distinct evolution from opportunistic worm behavior toward an industrial-grade,…
-
Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI
Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI Hugging Face disclosed this week that it detected and contained a production infrastructure intrusion, driven end-to-end by an autonomous AI agent system, and defended against it using its own AI-based forensic analysis. The attackers exploited two code-execution flaws in Hugging Face’s dataset…
-
New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours
New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours A previously unseen ransomware family dubbed “Spirals” struck an IT services company in South Asia in June 2026. Symantec’s Threat Hunter Team reports that the attackers moved from the initial breach to full network encryption in under 24…
-
Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution
Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution A newly disclosed a pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed “wp2shell,” that requires no authentication and affects stock WordPress installations… Delivered by PolitePaul service Go to gbhackers.com
-
EY Data Breach – Hackers Access Third-Party IT Support Platform and Steal Client Tax Documents
EY Data Breach – Hackers Access Third-Party IT Support Platform and Steal Client Tax Documents Ernst & Young LLP (EY) has confirmed a data security incident in which an unauthorized third party breached a third-party IT service management platform… Delivered by PolitePaul service Go to gbhackers.com
-
OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload
OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload A newly disclosed vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. The Okta Red Team recently discovered “HollowByte,” a Denial… Delivered by PolitePaul service Go to gbhackers.com
-
Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges
Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges Cloud Software Group has issued a High-severity security bulletin (CTX696734) disclosing two vulnerabilities in the Citrix Secure Access Client for Windows and the Citrix… Delivered by PolitePaul service Go to gbhackers.com
-
New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets
New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets A financially motivated, Russian-speaking threat actor tracked as UAT-11795, orchestrating a large-scale campaign since at least June 2025. A sophisticated Python-based remote access trojan dubbed… Delivered by PolitePaul service Go to gbhackers.com
-
Abbott probes two cyber incidents amid extortion claims
Abbott probes two cyber incidents amid extortion claims Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. […] Lawrence Abrams Go to bleepingcomputer
-
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. […] Bill Toulas Go to bleepingcomputer
-
Ernst & Young discloses data breach after support system hack
Ernst & Young discloses data breach after support system hack Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. […] Bill Toulas Go to bleepingcomputer
-
Inside the Search for “Clean” Residential Proxies for Carding
Inside the Search for “Clean” Residential Proxies for Carding Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek “clean” residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection. […] Sponsored by Flare Go to bleepingcomputer
-
New Windows LegacyHive zero-day gives hackers admin privileges
New Windows LegacyHive zero-day gives hackers admin privileges A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation
Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, with one flaw allowing low-privileged attackers to gain full SYSTEM access on affected machines. The more severe issue, tracked as CVE-2026-53565,…
-
New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released
New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover by unauthenticated attackers. Security researcher Adam Kues of Searchlight Cyber’s Assetnote research team uncovered the flaw,…
-
OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes
OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes A newly disclosed vulnerability in OpenSSL, dubbed “HollowByte,” allows a remote, unauthenticated attacker to trigger a denial-of-service (DoS) condition using a malicious payload as small as 11 bytes. Discovered by the Okta Red Team, the flaw exploits how OpenSSL pre-allocates memory during the TLS…
-
Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States
Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States Coca-Cola has reported a ransomware attack affecting its dairy subsidiary, Fairlife, resulting in a temporary shutdown of production operations across the United States. This incident was disclosed in a Form 8-K filing submitted to the U.S. Securities and Exchange Commission on July 16, 2026.…
-
EY Data Breach – Hackers Gain Access to IT Support System and Download Documents
EY Data Breach – Hackers Gain Access to IT Support System and Download Documents Ernst & Young LLP (EY) is notifying clients that an unauthorized third party breached a support ticket platform used by its IT staff, downloading documents containing client tax data during a roughly two-week window this spring. The Big Four accounting and…
-
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress…
-
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with…
-
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an…
-
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the…
-
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group…
-
Friday Squid Blogging: Squid Washing Up on Cape Cod Beach
Friday Squid Blogging: Squid Washing Up on Cape Cod Beach Lots of articles about this. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce Schneier Go to bruce schneier
-
Details of Alan Turing’s Voice Encryption System
Details of Alan Turing’s Voice Encryption System Really interesting piece of cryptographic history: In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-secret “Delilah” engineering project from…
-
ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)
ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Google’s Gemini lets strangers send messages from your locked Android phone
Google’s Gemini lets strangers send messages from your locked Android phone Gemini, Google’s AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone. Read more in my article on the Hot for Security…
-
Inc Ransomware Exploits SonicWall SMA Zero-Days
Inc Ransomware Exploits SonicWall SMA Zero-Days When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall’s mobile access appliances. Nate Nelson Go to gbhackers.com
-
The Real AI Threat Is Blind Trust
The Real AI Threat Is Blind Trust AI models left to both interpret and execute commands eliminate critical cybersecurity oversight. R. Justin Martin Go to gbhackers.com
-
Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear
Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it’s being implemented. Alexander Culafi Go to gbhackers.com
-
Google Bets ‘Agentic Defense’ Strategy Can Outpace Attackers
Google Bets ‘Agentic Defense’ Strategy Can Outpace Attackers Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks. Jeffrey Schwartz Go to gbhackers.com
-
New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure
New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure NadMesh is a new, industrial‑grade Go‑based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous… Delivered by PolitePaul service Go to gbhackers.com
-
TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data
TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data TP-Link has revealed several serious vulnerabilities affecting its Kasa EC70 and EC71 smart camera models, which could expose users to credential theft and geolocation… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands
CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities in Fortinet FortiSandbox to its Known Exploited Vulnerabilities (KEV) catalog. These… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Use Paste-and-Run Commands to Deploy ClickLock Stealer Against Mac Users
Hackers Use Paste-and-Run Commands to Deploy ClickLock Stealer Against Mac Users Hackers are actively targeting macOS users with a newly identified infostealer dubbed “ClickLock Stealer,” leveraging paste-and-run social engineering techniques to bypass Apple’s native security… Delivered by PolitePaul service Go to gbhackers.com
-
GPT-5.6 Codex Reportedly Wipes Files From Home Directories
GPT-5.6 Codex Reportedly Wipes Files From Home Directories Recent reports indicate that GPT-5.6 Codex has unintentionally deleted files in users’ home directories under certain configurations, raising concerns about the risks of running… Delivered by PolitePaul service Go to gbhackers.com
-
Windows Server 2022 reach end of mainstream support in 90 days
Windows Server 2022 reach end of mainstream support in 90 days Microsoft announced that Windows Server 2022 will reach the mainstream end date in October 2026, but will switch to extended support and continue receiving security updates for five more years. […] Sergiu Gatlan Go to bleepingcomputer
-
US charges two over laundering $43 million from investment fraud
US charges two over laundering $43 million from investment fraud U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA urges immediate action on actively exploited Fortinet flaws
CISA urges immediate action on actively exploited Fortinet flaws CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform. […] Sergiu Gatlan Go to bleepingcomputer
-
New ClickLock macOS malware traps users into revealing login password
New ClickLock macOS malware traps users into revealing login password A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. […] Bill Toulas Go to bleepingcomputer
-
Coca-Cola says Fairlife ransomware attack halts US dairy production
Coca-Cola says Fairlife ransomware attack halts US dairy production The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. […] Lawrence Abrams Go to bleepingcomputer
-
New ClickLock macOS Stealer Kills Every App to Force Password Entry
New ClickLock macOS Stealer Kills Every App to Force Password Entry A newly discovered macOS malware dubbed ClickLock is raising alarms in the cybersecurity community for its aggressive and deceptive credential-harvesting techniques. According to researchers at Group-IB, the stealer employs a highly disruptive tactic that forcibly terminates running applications, effectively locking users out of their…
-
CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks
CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks CISA has added a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-58644, to its Known Exploited Vulnerabilities (KEV) catalog. This addition comes with a warning that attackers are actively exploiting the flaw in real-world attacks. The vulnerability stems from a weakness in deserializing untrusted data,…
-
Top 10 Best Identity Threat Detection and Response (ITDR) Solutions in 2026
Top 10 Best Identity Threat Detection and Response (ITDR) Solutions in 2026 Identity has become the primary battleground of enterprise cybersecurity. Attackers increasingly bypass traditional defenses by stealing credentials, hijacking sessions, abusing privileged accounts, and exploiting misconfigurations across Active Directory, cloud platforms, SaaS applications, and non-human identities. Microsoft reported more than 7,000 password attacks per…
-
Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks
Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks TP-Link has released security updates for two vulnerabilities in its Kasa EC70 v4 and EC71 v4 smart cameras. These flaws, tracked as CVE-2026-9770 and CVE-2026-13230, could allow an attacker on the same local network to obtain sensitive information from vulnerable devices. The most serious issue,…
-
GPT-5.6 Codex is Reportedly Deleting Files From Home Directories
GPT-5.6 Codex is Reportedly Deleting Files From Home Directories OpenAI is currently investigating a small number of reports indicating that the GPT-5.6 Codex unintentionally deleted files from users’ home directories. These incidents reportedly occurred when Codex was granted full filesystem access without the necessary sandbox protections or automated review controls. According to Tibo Sottiaux, a…
-
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced…
-
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the…
-
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss. A valid token…
-
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that’s been spreading via websites infected with ClickFix lures since late April 2026. “The malware is full-featured, lightweight, and modular,” Elastic Security Labs researcher Cyril François said in a technical report.…
-
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password ClickLock Stealer, a new macOS infostealer, answers a victim’s refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and…
-
Protecting Privacy in an AI Era
Protecting Privacy in an AI Era Daniel Solove argues in the Wall Street Journal (alternate link) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug companies.…
-
Anubis ransomware: what you need to know
Anubis ransomware: what you need to know The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard – but they are not the only ones at risk. Read more in my article on the Fortra blog. Graham Cluley Go to grahamcluley
-
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks – no login, no passwords, no permissions needed. Meanwhile, Geoff – swimming in money and Lamborghinis, as all published authors are – has been on…
-
Agentic AI Is Untamable: Ask the Right Security Questions
Agentic AI Is Untamable: Ask the Right Security Questions Forget about attackers. Agentic artificial intelligence is creating enough risks for organizations and demands a security reframe. Arielle Waldman Go to gbhackers.com
-
1M+ Emails Use Hidden Text to Dupe AI Security Filters
1M+ Emails Use Hidden Text to Dupe AI Security Filters Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox. Nate Nelson Go to gbhackers.com
-
Dutch Police and Europol Disrupt Global Investment Scam Infrastructure and Arrest Key Suspects
Dutch Police and Europol Disrupt Global Investment Scam Infrastructure and Arrest Key Suspects Dutch police, working with international law-enforcement partners including Europol, have disrupted a sprawling investment-fraud operation alleged to have defrauded victims across multiple countries of… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Zoom Workplace Flaw Lets Unauthenticated Attackers Take Over Accounts Remotely
Critical Zoom Workplace Flaw Lets Unauthenticated Attackers Take Over Accounts Remotely Zoom has disclosed a critical vulnerability in its Windows desktop software that could allow unauthenticated attackers to take over user accounts remotely. This issue,… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Warns of Actively Exploited Oracle E-Business Suite Flaw
CISA Warns of Actively Exploited Oracle E-Business Suite Flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting CVE-2026-46817, an improper privilege management vulnerability in Oracle E-Business… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft
Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft A macOS-focused information stealer is combining stolen wallet databases with credentials harvested from the Apple Keychain, browsers, and Apple Notes to conduct offline cryptocurrency… Delivered by PolitePaul service Go to gbhackers.com
-
Splunk Enterprise Flaws Expose Stored Credentials and Allow Arbitrary SPL Searches
Splunk Enterprise Flaws Expose Stored Credentials and Allow Arbitrary SPL Searches Splunk has released security updates for three vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These vulnerabilities could potentially expose stored credential hashes, enable… Delivered by PolitePaul service Go to gbhackers.com
-
Dutch police bust investment fraud ring stealing over €100 million
Dutch police bust investment fraud ring stealing over €100 million The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims. […] Bill Toulas Go to bleepingcomputer
-
Zoom warns of critical account takeover vulnerability
Zoom warns of critical account takeover vulnerability Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. […] Bill Toulas Go to bleepingcomputer
-
Google Gemini CLI abused as a hacking agent, malware botnet operator
Google Gemini CLI abused as a hacking agent, malware botnet operator A Russian-speaking threat actor known as “bandcampro” used Google’s open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. […] Bill Toulas Go to bleepingcomputer
-
AsyncAPI npm packages infected with credential-stealing malware
AsyncAPI npm packages infected with credential-stealing malware Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities. […] Bill Toulas Go to bleepingcomputer
-
We built a vulnerability vending machine: AI tokens in, zero-days out
We built a vulnerability vending machine: AI tokens in, zero-days out Intruder built an AI-powered “vulnerability vending machine” that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already under responsible disclosure. […] Sponsored by…
-
New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks
New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks A newly identified IoT botnet framework, TuxBot v3 Evolution, is targeting internet-connected devices and turning compromised systems into tools for distributed denial-of-service attacks. The malware can run across a wide range of device architectures, creating a broad risk for routers,…
-
Zoom Desktop Client for Windows Flaw Enables Account Takeover via Network Access
Zoom Desktop Client for Windows Flaw Enables Account Takeover via Network Access Zoom has released updates for a critical Windows desktop client vulnerability, tracked as CVE-2026-53412, that could allow unauthenticated attackers to remotely take over user accounts. This flaw arises from improper input validation and may enable unauthenticated attackers to execute account takeover attacks via…
-
Multiple Splunk Enterprise Vulnerabilities Enable Path Traversal and Information Disclosure Attacks
Multiple Splunk Enterprise Vulnerabilities Enable Path Traversal and Information Disclosure Attacks Splunk has released security updates addressing multiple vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These flaws could lead to issues such as path traversal, disclosure of stored credential hashes, and arbitrary execution of SPL (Search Processing Language) searches. Three security vulnerabilities affecting both…
-
CISA Warns of Oracle E-Business Suite Vulnerability Actively Exploited in Attacks
CISA Warns of Oracle E-Business Suite Vulnerability Actively Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in attacks. This flaw impacts Oracle Payments, a component of Oracle E-Business Suite.…
-
Hackers Can Type a Secret Username at the Windows Login Screen to Open a SYSTEM Shell
Hackers Can Type a Secret Username at the Windows Login Screen to Open a SYSTEM Shell A stealthy Windows backdoor has resurfaced alongside Daxin, a sophisticated espionage tool previously tied to China-linked activity. The newly documented implant lets an intruder type a special username at the Windows sign-in screen and, in some cases, immediately open…
-
Forgotten UEFI shims undermining Secure Boot
Forgotten UEFI shims undermining Secure Boot ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities Go to eset
-
Police Disrupt a €140M Cyber Fraud Ring in Spain
Police Disrupt a €140M Cyber Fraud Ring in Spain Iberian hackers carried out a variety of cyberattacks and laundered the winnings through complex financial networks. Nate Nelson Go to gbhackers.com
-
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. “While the AI complied with their request to…
-
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet’s own…
-
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below – CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation in the DOM: Navigation…