Category: cyber-security-news

  • Threat Actors Allegedly Listed Starbucks Data on Hacker Forums

    Threat Actors Allegedly Listed Starbucks Data on Hacker Forums Starbucks has allegedly been listed on a cybercrime forum by a threat actor using the handle “anes2010,” who claims to be selling a database containing 176 million unique user records reportedly extracted in June 2026. Starbucks has not publicly confirmed the alleged security incident, and the…

  • GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates

    GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates GoldenEyeDog, a Chinese cybercrime group linked to the Golden Gh0st malware family, is back in focus after an intrusion at DigiCert exposed the risks around code-signing certificates. The attackers used the access to intercept customer certificate activation codes and sign their own malicious files. The…

  • U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses

    U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses Federal prosecutors have charged three Russian nationals over infrastructure that allegedly enabled ransomware, malware, phishing, and other cyberattacks against organizations in the United States and abroad. The seven-year investigation links the activity to more than $62 million in victim losses across…

  • North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers

    North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers North Korean-linked hackers are hiding OTTERCOOKIE-aligned malware inside ordinary SVG flag images, turning a familiar part of a web project into a concealed delivery channel. The operation targets software developers who believe they are completing a coding test for a job opportunity. The…

  • 15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution

    15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan Shaw reported the bug to F5 SIRT, which coordinated a fix released in nginx…

  • NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure

    NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. This malware marks a distinct evolution from opportunistic worm behavior toward an industrial-grade,…

  • Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI

    Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI Hugging Face disclosed this week that it detected and contained a production infrastructure intrusion, driven end-to-end by an autonomous AI agent system, and defended against it using its own AI-based forensic analysis. The attackers exploited two code-execution flaws in Hugging Face’s dataset…

  • New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours

    New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours A previously unseen ransomware family dubbed “Spirals” struck an IT services company in South Asia in June 2026. Symantec’s Threat Hunter Team reports that the attackers moved from the initial breach to full network encryption in under 24…

  • Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation

    Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, with one flaw allowing low-privileged attackers to gain full SYSTEM access on affected machines. The more severe issue, tracked as CVE-2026-53565,…

  • New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released

    New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover by unauthenticated attackers. Security researcher Adam Kues of Searchlight Cyber’s Assetnote research team uncovered the flaw,…

  • OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes

    OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes A newly disclosed vulnerability in OpenSSL, dubbed “HollowByte,” allows a remote, unauthenticated attacker to trigger a denial-of-service (DoS) condition using a malicious payload as small as 11 bytes. Discovered by the Okta Red Team, the flaw exploits how OpenSSL pre-allocates memory during the TLS…

  • Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States

    Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States Coca-Cola has reported a ransomware attack affecting its dairy subsidiary, Fairlife, resulting in a temporary shutdown of production operations across the United States. This incident was disclosed in a Form 8-K filing submitted to the U.S. Securities and Exchange Commission on July 16, 2026.…

  • EY Data Breach – Hackers Gain Access to IT Support System and Download Documents

    EY Data Breach – Hackers Gain Access to IT Support System and Download Documents Ernst & Young LLP (EY) is notifying clients that an unauthorized third party breached a support ticket platform used by its IT staff, downloading documents containing client tax data during a roughly two-week window this spring. The Big Four accounting and…

  • New ClickLock macOS Stealer Kills Every App to Force Password Entry

    New ClickLock macOS Stealer Kills Every App to Force Password Entry A newly discovered macOS malware dubbed ClickLock is raising alarms in the cybersecurity community for its aggressive and deceptive credential-harvesting techniques. According to researchers at Group-IB, the stealer employs a highly disruptive tactic that forcibly terminates running applications, effectively locking users out of their…

  • CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks

    CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks CISA has added a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-58644, to its Known Exploited Vulnerabilities (KEV) catalog. This addition comes with a warning that attackers are actively exploiting the flaw in real-world attacks. The vulnerability stems from a weakness in deserializing untrusted data,…

  • Top 10 Best Identity Threat Detection and Response (ITDR) Solutions in 2026

    Top 10 Best Identity Threat Detection and Response (ITDR) Solutions in 2026 Identity has become the primary battleground of enterprise cybersecurity. Attackers increasingly bypass traditional defenses by stealing credentials, hijacking sessions, abusing privileged accounts, and exploiting misconfigurations across Active Directory, cloud platforms, SaaS applications, and non-human identities. Microsoft reported more than 7,000 password attacks per…

  • Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks

    Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks TP-Link has released security updates for two vulnerabilities in its Kasa EC70 v4 and EC71 v4 smart cameras. These flaws, tracked as CVE-2026-9770 and CVE-2026-13230, could allow an attacker on the same local network to obtain sensitive information from vulnerable devices. The most serious issue,…

  • GPT-5.6 Codex is Reportedly Deleting Files From Home Directories

    GPT-5.6 Codex is Reportedly Deleting Files From Home Directories OpenAI is currently investigating a small number of reports indicating that the GPT-5.6 Codex unintentionally deleted files from users’ home directories. These incidents reportedly occurred when Codex was granted full filesystem access without the necessary sandbox protections or automated review controls. According to Tibo Sottiaux, a…

  • New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks

    New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks A newly identified IoT botnet framework, TuxBot v3 Evolution, is targeting internet-connected devices and turning compromised systems into tools for distributed denial-of-service attacks. The malware can run across a wide range of device architectures, creating a broad risk for routers,…

  • Zoom Desktop Client for Windows Flaw Enables Account Takeover via Network Access

    Zoom Desktop Client for Windows Flaw Enables Account Takeover via Network Access Zoom has released updates for a critical Windows desktop client vulnerability, tracked as CVE-2026-53412, that could allow unauthenticated attackers to remotely take over user accounts. This flaw arises from improper input validation and may enable unauthenticated attackers to execute account takeover attacks via…

  • Multiple Splunk Enterprise Vulnerabilities Enable Path Traversal and Information Disclosure Attacks

    Multiple Splunk Enterprise Vulnerabilities Enable Path Traversal and Information Disclosure Attacks Splunk has released security updates addressing multiple vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These flaws could lead to issues such as path traversal, disclosure of stored credential hashes, and arbitrary execution of SPL (Search Processing Language) searches. Three security vulnerabilities affecting both…

  • CISA Warns of Oracle E-Business Suite Vulnerability Actively Exploited in Attacks

    CISA Warns of Oracle E-Business Suite Vulnerability Actively Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in attacks. This flaw impacts Oracle Payments, a component of Oracle E-Business Suite.…

  • Hackers Can Type a Secret Username at the Windows Login Screen to Open a SYSTEM Shell

    Hackers Can Type a Secret Username at the Windows Login Screen to Open a SYSTEM Shell A stealthy Windows backdoor has resurfaced alongside Daxin, a sophisticated espionage tool previously tied to China-linked activity. The newly documented implant lets an intruder type a special username at the Windows sign-in screen and, in some cases, immediately open…

  • Critical SonicWall Firewall 0-Day Vulnerabilities Actively Exploited in Attacks

    Critical SonicWall Firewall 0-Day Vulnerabilities Actively Exploited in Attacks SonicWall has issued an urgent security advisory regarding two vulnerabilities affecting its SMA1000 Series appliances. The company is warning that attackers are actively exploiting these flaws in real-world attacks. The most critical issue, tracked as CVE-2026-15409, carries a maximum CVSS severity score of 10.0 and can…

  • Researcher Claims Bypass of EU Age Verification App Using Chrome Extension

    Researcher Claims Bypass of EU Age Verification App Using Chrome Extension Security researcher Paul Moore has once again exposed critical weaknesses in the EU’s flagship age verification system, this time by bypassing the latest app release (version 2026.07-1) using a Chrome extension powered by ClaudeAI. The proof-of-concept shows that, despite months of “security hardening,” a…

  • Chinese Hackers Embed Claude Code and DeepSeek in AI-Powered Government Cyberattacks

    Chinese Hackers Embed Claude Code and DeepSeek in AI-Powered Government Cyberattacks An active, highly structured intrusion campaign co-opting commercial artificial intelligence platforms as operational engines for state-sponsored operations. Rather than acting as peripheral research tools, Claude Code and DeepSeek-v4-pro were embedded directly into the core execution flows of a China-linked cyber espionage campaign. The operation…

  • Gamers Download Fake Cheats and Hand Attackers a Live Remote Control of Their Windows PCs

    Gamers Download Fake Cheats and Hand Attackers a Live Remote Control of Their Windows PCs New research uncovered 11 malicious NuGet packages disguised as game cheats, bots, and management panels for popular online titles. The campaign targets gaming communities playing titles such as Albion Online, GTA5RP, GrandRP, Majestic RP, and Throne and Liberty. Once installed,…

  • New LegacyHive Windows 0-day Vulnerability Allows Users to Load Another User’s Registry

    New LegacyHive Windows 0-day Vulnerability Allows Users to Load Another User’s Registry A proof-of-concept exploit dubbed LegacyHive has been released, enabling a Windows elevation-of-privilege vulnerability in the Windows User Profile Service that allows a standard user to load another user’s registry hive under their own registry classes root. Registry hives are files that store configuration…

  • Chrome Extension Used by 1.6 Million Users Silently Included Data Exfiltration Capabilities

    Chrome Extension Used by 1.6 Million Users Silently Included Data Exfiltration Capabilities A widely used browser extension, ModHeader, has been removed from the Chrome Web Store after researchers found that its signed release contained a dormant capability to collect, encrypt, and potentially upload users’ browsing-domain data. The extension reportedly had about 1.6 million combined installations…

  • Telegram’s t.me Domain Suspended, ServerHold Status Breaks Links Worldwide

    Telegram’s t.me Domain Suspended, ServerHold Status Breaks Links Worldwide Telegram’s core t[.]me domain has been placed on serverHold at the .me registry, a registry-level status that removes the domain from the global DNS and breaks every t[.]me short link worldwide. WHOIS records confirm the domain now carries eight status flags, including serverHold, clientDeleteProhibited, and serverDeleteProhibited,…

  • New macOS Stealer Mimics Apple’s Crash Report Framework to Steal Browser Credentials

    New macOS Stealer Mimics Apple’s Crash Report Framework to Steal Browser Credentials CrashStealer, a native C++ macOS infostealer that disguises itself as Apple’s built-in crash-reporting utility to harvest browser credentials, cryptocurrency wallets, password manager data, and keychain contents before encrypting and exfiltrating everything to a remote command-and-control server. Jamf first spotted a suspicious sample on…

  • Torq and Criminal IP Partner to Deliver Decision-Ready Threat Intelligence for Autonomous SOC Operations

    Torq and Criminal IP Partner to Deliver Decision-Ready Threat Intelligence for Autonomous SOC Operations Torrance, California, USA, July 13th, 2026, CyberNewswire Criminal IP, the cyber threat intelligence search engine and attack surface management platform, today announced a new partnership and integration with Torq, the established agentic security operations leader. The partnership integrates Criminal IP’s decision-ready…

  • Turla Hackers Exploit SharePoint Flaw to Access Thousands of French User Accounts

    Turla Hackers Exploit SharePoint Flaw to Access Thousands of French User Accounts Turla, a long-running cyber espionage operation linked by French authorities to Russia’s Federal Security Service, has again drawn attention after investigators detailed compromises affecting French organizations. The group has been active for more than two decades and is known for quietly stealing sensitive…

  • Hackers Compromised jscrambler With 15,800+ Weekly Downloads to Attack Developers

    Hackers Compromised jscrambler With 15,800+ Weekly Downloads to Attack Developers A supply chain attack on the jscrambler npm package, a JavaScript code-protection tool with over 15,800 weekly downloads, involved malicious versions that silently deployed native malware on Linux, macOS, and Windows systems. Socket Research Team detected the first malicious release, [email protected], on July 11, 2026,…

  • Anthropic Extends Claude Fable 5 Access From July 12 to July 19

    Anthropic Extends Claude Fable 5 Access From July 12 to July 19 Anthropic has extended promotional access to Claude Fable 5 until July 19, 2026, giving eligible paid subscribers more time to use the company’s newest AI model at no additional charge. The offer was previously scheduled to end earlier. However, Anthropic confirmed that access…

  • SpyGlace Attacks Abuse Trusted Developer Services to Evade Network Detection

    SpyGlace Attacks Abuse Trusted Developer Services to Evade Network Detection SpyGlace has returned in a campaign that hides malicious activity behind online services many companies trust. The operation, linked to APT-C-60, uses spear-phishing emails to steer victims toward a booby-trapped archive and then installs malware through a chain of ordinary tools. The latest activity shows…

  • Hackers Weaponize Real Academic Event Materials to Infect Researchers With RokRAT

    Hackers Weaponize Real Academic Event Materials to Infect Researchers With RokRAT A targeted phishing campaign is using genuine academic event details to trick researchers into opening malware. The operation delivers a RokRAT variant through a fake document package that appears connected to a real seminar. The attackers used information from an actual academic event to…

  • One Misconfigured Python HTTP Server Exposed Three Active Campaigns from Attackers

    One Misconfigured Python HTTP Server Exposed Three Active Campaigns from Attackers A forgotten web server can become a window into a criminal operation. In this case, a Python HTTP service left exposed on a virtual private server revealed the working materials of several attackers. The discovery offers a rare look at how phishing operations can…

  • Apple Sues OpenAI and Former Employees for Alleged Theft of Trade Secrets

    Apple Sues OpenAI and Former Employees for Alleged Theft of Trade Secrets Apple has filed a federal lawsuit against OpenAI, accusing the ChatGPT maker of orchestrating a systematic campaign to steal confidential hardware designs, manufacturing processes, and supplier relationships through more than 400 former Apple employees now working at OpenAI. The 41-page complaint, filed July…

  • Microsoft Teams on macOS Screen Sharing Bug Causing Blank Screens

    Microsoft Teams on macOS Screen Sharing Bug Causing Blank Screens Microsoft has confirmed a known issue in Teams on macOS that causes screen sharing to fail, freeze, or show a blank black screen during meetings. The bug affects users running macOS versions older than macOS Tahoe 26.4, and Microsoft has now updated its rollout timeline…

  • New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents

    New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents A novel supply chain attack called “Ghostcommit” that conceals prompt-injection instructions within PNG images to bypass AI code reviewers and trick coding agents into leaking secrets such as .env files. The ASSET Research Group demonstrated that a pull request containing an explicit, plain-text…

  • Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts

    Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts Forg365 is a phishing-as-a-service platform that targets Microsoft accounts, combining AI-powered phishing, session theft, and post-compromise mailbox access in a single operator panel The platform is reportedly distributed through Telegram, where criminals can access a 30-day trial, pay about per month, or choose an annual…

  • CISA Details “Lessons from a Cyber Incident” After AWS GovCloud Credentials Leak

    CISA Details “Lessons from a Cyber Incident” After AWS GovCloud Credentials Leak CISA has published a candid after-action account revealing that a contractor accidentally exposed the agency’s own AWS GovCloud credentials and Infrastructure-as-Code repositories in a personal, public GitHub account, triggering an internal incident response and a rare public “lessons learned” disclosure from the federal…

  • Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds

    Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds A critical flaw in how Dell stores BIOS administrator and user passwords allows full password recovery from a flash dump in milliseconds, with no brute force required. The vulnerability, tracked as CVE-2026-40639 (DSA-2026-197), stems from a broken XOR encryption scheme rather than…

  • 281 Popular VPN Apps from the Google Play Store Leak Sensitive Data, Transfer Data Unencrypted

    281 Popular VPN Apps from the Google Play Store Leak Sensitive Data, Transfer Data Unencrypted A new security study has found serious privacy and security issues in 281 popular Android VPN applications available on the Google Play Store. Researchers discovered that dozens of these apps transfer data without encryption, leak user traffic outside the VPN…

  • Progress Urges ShareFile Admins to Shut Down Servers Over Credible Security Threat

    Progress Urges ShareFile Admins to Shut Down Servers Over Credible Security Threat Progress Software has issued an urgent advisory instructing customers running on-premises ShareFile Storage Zone Controllers to immediately power down the servers hosting these components, citing a “credible external security threat” against the platform. The notice, sent directly to customers’ inboxes, states that Progress…

  • Hackers Turn 50+ Dormant GitHub Accounts Into a Network for Corporate Source Code Recon

    Hackers Turn 50+ Dormant GitHub Accounts Into a Network for Corporate Source Code Recon Research has uncovered coordinated campaigns that use more than dormant GitHub accounts to map corporate organizations, repositories, and developers. The activity relies on GitHub’s API to collect public information. However, some operators have also attempted to access private source code repositories…

  • Ransomware Negotiator Sentenced for BlackCat Ransomware Operators to Attack Victims

    Ransomware Negotiator Sentenced for BlackCat Ransomware Operators to Attack Victims A former Florida ransomware negotiator has been sentenced to 70 months in federal prison after conspiring with BlackCat/ALPHV ransomware operators and helping attack multiple U.S. victims. Angelo Martino, of Land O’Lakes, Florida, worked for a U.S.-based cyber incident response company. His role was to help…

  • GigaWiper Malware Attacking Windows Systems With Data Wipers and Fake Ransomware Notices

    GigaWiper Malware Attacking Windows Systems With Data Wipers and Fake Ransomware Notices GigaWiper is a newly identified Windows threat built to do more than steal information or lock a screen. Once activated, it can erase disks, scramble files beyond recovery, and leave organizations facing sudden outages. Its arrival shows how destructive malware can combine several…

  • Django SQL Injection Vulnerability Actively Exploited in the Wild

    Django SQL Injection Vulnerability Actively Exploited in the Wild A high-severity SQL injection vulnerability in the Django web framework is now being actively exploited in real-world attacks, raising concerns for organizations running geospatial applications on PostGIS-backed deployments. The flaw, tracked as CVE-2026-1207, affects Django’s GIS module and has been confirmed by multiple threat intelligence sources…

  • Braintree NuGet Typosquat Uses XOR-Obfuscated C2 to Hide Environment Secret Theft

    Braintree NuGet Typosquat Uses XOR-Obfuscated C2 to Hide Environment Secret Theft A malicious NuGet package impersonating the Braintree .NET payment library has put production payment systems at risk. The package can collect live card details during transactions, then send the data away without alerting the application or its users. It also seeks credentials that could…

  • Helix Data Extortion Group Uses Vishing and Device Code Phishing to Steal SharePoint Data

    Helix Data Extortion Group Uses Vishing and Device Code Phishing to Steal SharePoint Data Helix has surfaced as a fast-moving data extortion group that targets Microsoft 365 users through phone scams and cloud-focused phishing instead of traditional malware drops. Attackers are after access first, then large volumes of corporate files, with SharePoint libraries becoming a…

  • Microsoft Releases Patches for RoguePlanet Defender Zero-Day Vulnerability

    Microsoft Releases Patches for RoguePlanet Defender Zero-Day Vulnerability Microsoft has released security updates to address a newly disclosed zero-day vulnerability in Microsoft Defender, publicly referred to as “RoguePlanet.” The flaw, tracked as CVE-2026-50656, affects the Microsoft Malware Protection Engine and could allow attackers to gain elevated privileges on vulnerable systems. The vulnerability is classified as…

  • New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents

    New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents A newly disclosed vulnerability pattern dubbed “GhostApproval” has exposed a critical security flaw in six of the most widely used AI coding assistants: Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf, allowing malicious repositories to bypass Human-in-the-Loop safety…

  • Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic

    Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic Palo Alto Networks has disclosed a high-severity vulnerability in PAN-OS that could allow unauthenticated attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition by sending specially crafted network traffic. Tracked as CVE-2026-0288, the flaw carries a CVSS-B score of 9.2 (HIGH,…

  • Accenture Confirms Data Breach – Hacker Claims Theft of Internal Source Code

    Accenture Confirms Data Breach – Hacker Claims Theft of Internal Source Code IT services and consulting giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other sensitive data from the company. A threat actor operating under the alias “888” posted a…

  • China-Nexus Hackers Exploit Ruckus Routers to Build Operational Relay Box Networks

    China-Nexus Hackers Exploit Ruckus Routers to Build Operational Relay Box Networks UAT-7810, a China-nexus hacking group, is expanding a global network of hijacked internet devices by exploiting security flaws in Ruckus wireless routers and rolling out new custom malware. This activity feeds into what researchers call an Operational Relay Box network, a chain of compromised…

  • Discord’s Security Systems Mistakenly Banned 8,000+ Accounts Since May 2026

    Discord’s Security Systems Mistakenly Banned 8,000+ Accounts Since May 2026 Discord has confirmed that a bug in its automated security systems led to the wrongful suspension of more than 8,000 user accounts between May 2026 and early July 2026. The company disclosed the issue via its official support account on X, clarifying both the root…

  • 15-year-old GhostLock Kernel Flaw Enables Privilege Escalation in Major Linux Distributions

    15-year-old GhostLock Kernel Flaw Enables Privilege Escalation in Major Linux Distributions A critical Linux kernel vulnerability, tracked as CVE-2026-43499 and dubbed “GhostLock,” has been disclosed by security researchers at VEGA, exposing a privilege escalation flaw that has silently affected major Linux distributions for over a decade. GhostLock originates from a logic error in the kernel’s…

  • OpenAI Reportedly Secures US Government Clearance to Launch GPT-5.6 Model

    OpenAI Reportedly Secures US Government Clearance to Launch GPT-5.6 Model OpenAI has reportedly received approval from the U.S. Department of Commerce for a broad public launch of its advanced GPT-5.6 model, marking a significant moment in how Washington regulates access to frontier AI systems. A source familiar with the matter confirmed the development to Axios…

  • Anthropic Extends Free Access to Claude Fable 5 on All Paid Plans

    Anthropic Extends Free Access to Claude Fable 5 on All Paid Plans Anthropic has extended promotional access to its newest AI model, Claude Fable 5, allowing subscribers on paid plans to use it at no additional cost through July 12, 2026, at 11:59:59 PM PT. The company confirmed the extension in an official announcement, stating…

  • Cavern Manticore Abuses SysAid RMM and WinDirStat DLL Sideloading to Deploy C2 Framework

    Cavern Manticore Abuses SysAid RMM and WinDirStat DLL Sideloading to Deploy C2 Framework A new Iranian-linked hacking group has been caught abusing everyday IT tools to slip malware onto Israeli networks. Researchers have named the group Cavern Manticore, and its latest campaign shows how creative attackers have become at hiding in plain sight. Instead of…

  • Tenda Authentication Backdoor Grants Attackers Full Administrative Access

    Tenda Authentication Backdoor Grants Attackers Full Administrative Access A newly disclosed vulnerability in Tenda network devices exposes a critical authentication backdoor that allows attackers to gain full administrative access without valid credentials. The flaw affects multiple firmware versions across several Tenda router models, including the FH1201, W15E, AC10, AC5, and AC6 series. The issue, tracked…

  • 16-Year-Old Linux KVM Vulnerability Allows Malicious Guest to Corrupt Host Kernel Memory

    16-Year-Old Linux KVM Vulnerability Allows Malicious Guest to Corrupt Host Kernel Memory A newly disclosed Linux Kernel-based Virtual Machine (KVM) vulnerability, tracked as CVE-2026-53359 and dubbed “Januscape,” exposes a critical flaw that allows a malicious guest to corrupt host kernel memory, breaking the fundamental isolation guarantees of virtualization. The issue, which remained unnoticed for nearly…

  • Critical BeyondTrust Flaws Let Attackers Bypass Access Controls and Gain Unauthorized Access

    Critical BeyondTrust Flaws Let Attackers Bypass Access Controls and Gain Unauthorized Access BeyondTrust has disclosed multiple critical and high-severity vulnerabilities affecting its Remote Support (RS) and Privileged Remote Access (PRA) solutions, potentially allowing attackers to bypass access controls and gain unauthorized access to sensitive systems. The issues are tracked under Advisory ID BT26-03 and carry…

  • Windows Device Identifier Feature Leads to Arrest of Scattered Spider Hacking Group Member

    Windows Device Identifier Feature Leads to Arrest of Scattered Spider Hacking Group Member A persistent Microsoft device identifier was used to unravel the anonymity of an alleged Scattered Spider operator, according to a federal superseding complaint filed in the Northern District of Illinois. Peter Stokes, 19, a dual U.S.–Estonian citizen who allegedly used the handles…

  • Opera GX 0-Click Vulnerability Lets Attackers Exfiltrate User Data via Malicious Website

    Opera GX 0-Click Vulnerability Lets Attackers Exfiltrate User Data via Malicious Website A newly disclosed vulnerability in Opera GX allowed attackers to silently exfiltrate sensitive user data with no interaction required, simply by luring victims to a malicious website. The issue, documented in recent research titled “One trigram at a time: XSLeak via Universal CSS…

  • New TrojPix Attack Lets Attackers Access Air-gapped Computers From 208 Meters

    New TrojPix Attack Lets Attackers Access Air-gapped Computers From 208 Meters A novel electromagnetic (EM) covert-channel attack, dubbed TrojPix, can steal sensitive data from already-compromised air-gapped computers over distances of up to 208 meters, even through concrete walls, by exploiting only the pixels displayed on a victim’s screen. The technique was developed by a team…

  • Hackers Abuse OpenAI Org Invites to Harvest Sensitive Prompts and API Activity

    Hackers Abuse OpenAI Org Invites to Harvest Sensitive Prompts and API Activity Hackers are actively abusing OpenAI’s organization invitation feature to launch a new form of “poisoned tenant” attack, allowing them to harvest sensitive prompts, API activity, and potentially corporate data from unsuspecting users. According to research disclosed by Push Security, attackers created a fake…

  • SSH Honeypots Miss Most Post-Login Attacks by Focusing on Interactive Shells

    SSH Honeypots Miss Most Post-Login Attacks by Focusing on Interactive Shells SSH honeypots, widely used in cyber defense, may miss most real-world post-login attacker activity, according to new research that challenges long-standing assumptions in deception technology. A recent study titled “Ghost Without Shell: Measuring Non-Interactive SSH Attacks on Honeypots” by researchers from the Czech Technical…

  • Parrot 7.3 Released With Optimized Packages and Updated Tools

    Parrot 7.3 Released With Optimized Packages and Updated Tools Parrot Security has released Parrot OS 7.3, introducing significant system-level optimizations, updated security tools, and a redesigned application management experience to improve performance and usability for security professionals. The update arrives just months after the previous release, with developers focusing less on expanding the toolset and…

  • Microsoft Releases OOBE Cumulative Update for Windows 11, Versions 24H2 and 25H2

    Microsoft Releases OOBE Cumulative Update for Windows 11, Versions 24H2 and 25H2 Microsoft has rolled out KB5095189, a new cumulative update targeting the Out-of-Box Experience (OOBE) for Windows 11, versions 24H2 and 25H2. Released on June 23, 2026, this update refines the initial setup flow that users encounter when configuring a new or freshly reset…

  • PamStealer Mimics Maccy Clipboard Manager Silently Harvests Data and Clipboard Contents

    PamStealer Mimics Maccy Clipboard Manager Silently Harvests Data and Clipboard Contents PamStealer is a newly identified macOS infostealer that disguises itself as the popular open-source clipboard manager “Maccy” while silently harvesting sensitive user data. Discovered by Jamf Threat Labs, the malware uses a stealthy two-stage infection chain designed to evade detection and blend into normal…

  • Multiple FatFs Vulnerabilities Expose Millions of Embedded Devices to Cyber Risks

    Multiple FatFs Vulnerabilities Expose Millions of Embedded Devices to Cyber Risks Security researchers at runZero have disclosed seven new CVEs affecting FatFs, the ubiquitous lightweight FAT/exFAT filesystem driver used across embedded and IoT ecosystems. The vulnerabilities range from CVSS Medium to High, with no Critical-rated findings, but their reach is significant: FatFs underpins platforms including…

  • New “Bad Epoll” 0-Day Vulnerability Allows Root Access on Linux Servers and Android Devices

    New “Bad Epoll” 0-Day Vulnerability Allows Root Access on Linux Servers and Android Devices A newly disclosed Linux kernel flaw dubbed “Bad Epoll” (CVE-2026-46242) allows an unprivileged local user to escalate to root on Linux servers, desktops, and Android devices by exploiting a race condition and a use-after-free (UAF) in the kernel’s epoll subsystem. Bad…

  • Indian Govt Bans Apps Being Misused to Stop E-Rickshaws Remotely

    Indian Govt Bans Apps Being Misused to Stop E-Rickshaws Remotely The Indian government has directed Google and Apple to take down three mobile applications, BAT-BMS, Lossigy, and Epoch-i-ion, after they were allegedly misused to remotely disable e-rickshaws and other battery-operated three-wheelers mid-journey, putting passenger safety at risk. Authorities have also warned that any additional apps…

  • Top 10 Best Post-Quantum Cryptographic Solutions in 2026

    Top 10 Best Post-Quantum Cryptographic Solutions in 2026 Quantum computing has crossed the line from research curiosity to board-level risk. Once a cryptographically relevant quantum computer arrives — an event security planners call “Q-Day” — the public-key cryptography that protects banking, government, healthcare, and the entire internet (RSA, ECC, Diffie-Hellman) collapses in hours. Worse, the…

  • Multiple WatchGuard Firebox OS Vulnerabilities Enable Arbitrary Code Execution Attacks

    Multiple WatchGuard Firebox OS Vulnerabilities Enable Arbitrary Code Execution Attacks Multiple high‑severity vulnerabilities in WatchGuard Firebox devices running Fireware OS could let authenticated attackers execute arbitrary code and take full control of affected appliances. WatchGuard has disclosed three high‑impact vulnerabilities in Fireware OS affecting Firebox firewall appliances, all scored 8.6 under CVSS v4.0 and already…

  • North Korea-Linked Hackers Hide JavaScript Loaders in Open Source Repositories

    North Korea-Linked Hackers Hide JavaScript Loaders in Open Source Repositories A new wave of supply chain attacks is spreading across the open source world, and this time the target is developers themselves. Security researchers have uncovered a campaign called PolinRider that hides malicious JavaScript loaders inside trusted code repositories, waiting for unsuspecting developers to run…

  • Microsoft Exchange SSRF Vulnerability Details Released Along With Public PoC Exploit

    Microsoft Exchange SSRF Vulnerability Details Released Along With Public PoC Exploit Security researchers from HawkTrace have disclosed technical details of a high-severity server-side request forgery (SSRF) vulnerability in Microsoft Exchange, tracked as CVE-2026-45504. The flaw, which carries a CVSS score of 8.8, allows authenticated, low-privileged users to read arbitrary files from vulnerable Exchange servers, raising…

  • Hacker Used Claude AI to Score Free Tickets to Nearly Every US Music Show

    Hacker Used Claude AI to Score Free Tickets to Nearly Every US Music Show A critical unauthenticated SQL injection vulnerability in Front Gate Tickets (FGT), a Live Nation/Ticketmaster subsidiary that powers ticketing for major US festivals including EDC, Bonnaroo, and Outside Lands, allowed full administrative takeover of the platform with help from Anthropic’s Claude AI…

  • Anthropic Details Claude Fable 5 Cybersecurity Safeguards and Jailbreak Framework

    Anthropic Details Claude Fable 5 Cybersecurity Safeguards and Jailbreak Framework Anthropic has published detailed technical documentation on the cybersecurity safeguards protecting Claude Fable 5, following the model’s global redeployment. The disclosure covers both the AI’s safety classifier system and a draft framework for grading jailbreak severity, developed in partnership with Glasswing. Fable 5’s safety classifiers…

  • CISA Warns of Microsoft SharePoint Server Code Execution Vulnerability Exploited in Attacks

    CISA Warns of Microsoft SharePoint Server Code Execution Vulnerability Exploited in Attacks CISA has added a newly disclosed Microsoft SharePoint Server vulnerability, tracked as CVE-2026-45659, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is actively being exploited in real-world attacks. The vulnerability is a deserialization of untrusted data issue (CWE-502) that allows…

  • Browser-Only Ransomware Abuses Chrome File System Access API to Encrypt Android Photos

    Browser-Only Ransomware Abuses Chrome File System Access API to Encrypt Android Photos A new ransomware technique can now run entirely inside a web browser, with no app installation or root access required. It targets Android photo directories by abusing a legitimate Chrome feature meant for photo editing. The attack begins with something as simple as…

  • Multiple ClamAV Vulnerabilities Allow Remote Attacker to Cause a DoS Condition

    Multiple ClamAV Vulnerabilities Allow Remote Attacker to Cause a DoS Condition Multiple high-severity vulnerabilities in Cisco’s ClamAV engine allow remote attackers to crash the antivirus scanning process, causing a denial-of-service (DoS) on affected Cisco Secure Endpoint Connector deployments. The flaws affect Windows, Linux, and macOS, with the highest impact on Windows, where they are rated…

  • Medtronic Confirms Data Breach – Hackers Gained Access to Corporate IT Systems

    Medtronic Confirms Data Breach – Hackers Gained Access to Corporate IT Systems Medical technology giant Medtronic Inc. has disclosed a cybersecurity incident involving unauthorized access to its corporate IT systems, potentially affecting sensitive personal and health-related information of patients using Medtronic medical devices. Medtronic detected unusual activity in certain corporate IT systems on April 15,…

  • WinRAR 7.23 Fixes Heap Overflow Vulnerability that Leads to Application Crashes

    WinRAR 7.23 Fixes Heap Overflow Vulnerability that Leads to Application Crashes WinRAR 7.23 addresses a newly disclosed heap overflow vulnerability in the RAR5 recovery volume processing code, tracked as CVE-2026-14191. Closing a memory-corruption flaw that could be triggered by malicious recovery volume (.rev) data and potentially lead to application crashes or further exploitation. WinRAR 7.23…

  • Chrome Update Fixes 382 Vulnerabilities, Including 15 Critical Ones – Update Now!

    Chrome Update Fixes 382 Vulnerabilities, Including 15 Critical Ones – Update Now! Chrome 151’s latest stable-channel update delivers patches for 382 security vulnerabilities, including 15 critical bugs that can be weaponized for remote code execution and full browser compromise if left unpatched. Google is rolling this update out for Windows, macOS, Linux, and Chrome for…

  • Multiple Apache Tomcat Vulnerabilities Allow Attackers to Bypass Authentication

    Multiple Apache Tomcat Vulnerabilities Allow Attackers to Bypass Authentication The Apache Software Foundation has disclosed two vulnerabilities affecting Apache Tomcat that could allow attackers to bypass authentication and security constraints protecting web applications. The flaws, tracked as CVE-2026-55957 and CVE-2026-55956, impact multiple major versions of the widely deployed servlet container, prompting urgent upgrade recommendations across…

  • U.S. Lifts Export Controls on Claude Fable 5 and Mythos 5

    U.S. Lifts Export Controls on Claude Fable 5 and Mythos 5 The U.S. Department of Commerce has formally withdrawn export control restrictions on Anthropic’s Claude Fable 5 and Mythos 5 AI models, ending an 18-day standoff that had blocked global access to the company’s most advanced systems. In a letter dated June 30, 2026, Commerce…

  • Anthropic’s Claude Code Reportedly Uses Hidden Code to Detect Chinese Users

    Anthropic’s Claude Code Reportedly Uses Hidden Code to Detect Chinese Users A Reddit disclosure has ignited a serious debate about developer trust and covert surveillance, alleging that Anthropic embedded undisclosed detection logic inside its Claude Code CLI tool, specifically targeting users in China or those routing traffic through Chinese AI lab proxies. A Reddit user…

  • Microsoft Teams’ New Feature Blocks Bots from Joining Meetings

    Microsoft Teams’ New Feature Blocks Bots from Joining Meetings Microsoft has rolled out a new bot protection capability in Microsoft Teams that gives IT administrators and meeting organizers greater control over external bots attempting to join meetings, a move designed to address growing privacy and security concerns around AI-powered meeting tools. As AI note-taking bots…

  • Kali Linux 2026.2 Released With 9 New Tools and VM Boot Tweaking

    Kali Linux 2026.2 Released With 9 New Tools and VM Boot Tweaking Kali Linux team officially released Kali Linux 2026.2 right on schedule at the close of Q2 2026, delivering a compelling mix of desktop environment upgrades, infrastructure modernization, VM performance enhancements, and nine brand-new tools for penetration testers and security researchers. This release bumps…

  • Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks

    Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks Nissan Americas has officially confirmed a data breach affecting current and former employees across four countries after threat actors exploited a critical zero-day vulnerability in Oracle PeopleSoft software, a campaign attributed to the ShinyHunters extortion group. The attack stems from CVE-2026-35273, a CVSS 9.8-rated unauthenticated Server-Side…

  • WhatsApp Launches New Username Feature to Communicate Without Exposing Phone Numbers

    WhatsApp Launches New Username Feature to Communicate Without Exposing Phone Numbers WhatsApp introduces a new privacy update that lets users connect using unique handles, eliminating the need to share phone numbers with strangers or new group members. Earlier, we detailed that WhatsApp is preparing to roll out a long-anticipated username feature. Now WhatsApp has officially…

  • EvilTokens Phishing Breaches Finance Firms Using “Ghost” Code Across U.S. and European Businesses

    EvilTokens Phishing Breaches Finance Firms Using “Ghost” Code Across U.S. and European Businesses EvilTokens can keep serious account-takeover activity out of your SOC’s view by relying on “ghost” code that only surfaces after the browser decrypts it. Because of this, analysis that looks only at the static URL can overlook the part of the attack that…

  • New Claude Code Attack Allows Attackers to Take Full Control of Developers’ Systems

    New Claude Code Attack Allows Attackers to Take Full Control of Developers’ Systems Researchers at Mozilla’s Zero Day Investigative Network (0DIN) have demonstrated a proof-of-concept attack that shows how a completely clean-looking GitHub repository can trick AI-powered coding agents like Claude Code into silently opening a reverse shell on a developer’s machine, without a single…

  • China’s New Zhipu AI Reportedly Matches Claude Mythos in Vulnerability Detection

    China’s New Zhipu AI Reportedly Matches Claude Mythos in Vulnerability Detection Zhipu AI’s open-weight GLM-5.2 model is reportedly performing on par with Anthropic’s restricted Claude Mythos in specific cybersecurity and software vulnerability detection tasks, a development that is intensifying concerns inside the U.S. government about the effectiveness of its AI export control strategy. Zhipu AI…

  • RedAmon AI Tool that Chains Reconnaissance, Exploitation, and Post-exploitation

    RedAmon AI Tool that Chains Reconnaissance, Exploitation, and Post-exploitation A new open-source offensive security platform called RedAmon is redefining automated penetration testing by chaining reconnaissance, exploitation, post-exploitation, AI-driven triage, and automated code remediation all into a single end-to-end pipeline that culminates in a GitHub pull request with the fix already written. RedAmon is a modular,…

  • OpenAI Released GPT-5.6 Sol With Limited Access and Strong Cyberattack Protections

    OpenAI Released GPT-5.6 Sol With Limited Access and Strong Cyberattack Protections OpenAI has officially begun a limited preview of the GPT‑5.6 model series Sol, Terra, and Luna, positioning its flagship Sol as the company’s most capable and security-hardened AI model to date, available initially only to a small group of trusted partners at the formal…