BleepingComputer Jul 22, 2026, 02:15 PM (UTC)
Read
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. [...]
SecurityWeek Jul 22, 2026, 02:00 PM (UTC)
Read
Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. The post When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover appeared first on SecurityWeek.
BleepingComputer Jul 22, 2026, 01:22 PM (UTC)
Read
The Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication. [...]
SecurityWeek Jul 22, 2026, 01:00 PM (UTC)
Read
The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek.
SecurityWeek Jul 22, 2026, 01:00 PM (UTC)
Read
Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek.
Cybersecurity Ventures Jul 22, 2026, 12:41 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 22, 2026 – Watch our Videos at Cybercrime.TV CISOs and security leaders have spoken up on our hottest content and the award-winning Cybercrime Magazine YouTube Channel…
The Hacker News Jul 22, 2026, 12:36 PM (UTC)
Read
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting…
The Hacker News Jul 22, 2026, 11:58 AM (UTC)
Read
Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence…
BleepingComputer Jul 22, 2026, 11:43 AM (UTC)
Read
The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]
Infosecurity Magazine Jul 22, 2026, 11:40 AM (UTC)
Read
Hugging Face recently disclosed a security breach. OpenAI has now said that it was its AI models which broke containment and hacked Hugging Face themselves
The Hacker News Jul 22, 2026, 11:30 AM (UTC)
Read
OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugging Face's production infrastructure last week. The AI compa…
SecurityWeek Jul 22, 2026, 11:29 AM (UTC)
Read
CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek.
The Hacker News Jul 22, 2026, 11:25 AM (UTC)
Read
The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based d…
BleepingComputer Jul 22, 2026, 11:09 AM (UTC)
Read
Cloud storage costs tend to creep up over time, since most services charge monthly or annually for as long as you use them. FileJump's Lifetime Plan skips that model entirely, offering 2TB of cloud storage for a single payment of $59 (MSRP $467). [...]
Infosecurity Magazine Jul 22, 2026, 10:50 AM (UTC)
Read
New Ubuntu snap-confine race condition lets local users escalate to root on default installs
BleepingComputer Jul 22, 2026, 10:44 AM (UTC)
Read
Microsoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in October. [...]
Infosecurity Magazine Jul 22, 2026, 10:30 AM (UTC)
Read
CodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitable
SecurityWeek Jul 22, 2026, 10:00 AM (UTC)
Read
Using AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement. The post Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation appeared first on SecurityWeek.
SecurityWeek Jul 22, 2026, 09:33 AM (UTC)
Read
Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI. The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek.
SecurityWeek Jul 22, 2026, 08:32 AM (UTC)
Read
The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary. The post Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife appeared first on SecurityWeek.
SecurityWeek Jul 22, 2026, 07:48 AM (UTC)
Read
OpenAI says its AI models went rogue, as CISOS call the incident a watershed moment, warning that autonomous AI threat models have officially crossed into production reality. The post OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face appeared first…
BleepingComputer Jul 22, 2026, 06:40 AM (UTC)
Read
American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. [...]
The Hacker News Jul 22, 2026, 06:38 AM (UTC)
Read
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a jo…
The Hacker News Jul 22, 2026, 06:00 AM (UTC)
Read
Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain. The package, named "Newtonsoftt.Json…
BleepingComputer Jul 22, 2026, 05:19 AM (UTC)
Read
OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. [...]
The Hacker News Jul 22, 2026, 04:57 AM (UTC)
Read
A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft's official Azure DevOps…
Krebs on Security Jul 22, 2026, 01:10 AM (UTC)
Read
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 perc…
BleepingComputer Jul 21, 2026, 11:07 PM (UTC)
Read
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. [...]
BleepingComputer Jul 21, 2026, 10:34 PM (UTC)
Read
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads. [...]
BleepingComputer Jul 21, 2026, 08:06 PM (UTC)
Read
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [...]
BleepingComputer Jul 21, 2026, 06:50 PM (UTC)
Read
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. [...]
The Hacker News Jul 21, 2026, 06:46 PM (UTC)
Read
Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by Apple…
SecurityWeek Jul 21, 2026, 06:16 PM (UTC)
Read
New executive order calls for end-to-end visibility into defense supply chains, including software dependencies, foreign ownership and cyber-related supplier risks. The post Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Cha…
SecurityWeek Jul 21, 2026, 05:44 PM (UTC)
Read
The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek.
BleepingComputer Jul 21, 2026, 04:41 PM (UTC)
Read
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. [...]
The Hacker News Jul 21, 2026, 04:06 PM (UTC)
Read
Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a r…
The Hacker News Jul 21, 2026, 03:09 PM (UTC)
Read
Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech…
The Hacker News Jul 21, 2026, 02:57 PM (UTC)
Read
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted…
Cybersecurity Ventures Jul 21, 2026, 02:15 PM (UTC)
Read
AI Delivers Value Only When It’s Built Into the Security Workflow – Christophe Briguet, Sr. Director of Product Management – AI & Security Analytics, Stellar Cyber San Jose, Calif. – Jul. 21, 2026 Every security leader has heard the promise by now: AI will tra…
The Hacker News Jul 21, 2026, 02:04 PM (UTC)
Read
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June…
BleepingComputer Jul 21, 2026, 02:00 PM (UTC)
Read
Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. [...]
Infosecurity Magazine Jul 21, 2026, 02:00 PM (UTC)
Read
Russian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude models
The Hacker News Jul 21, 2026, 01:18 PM (UTC)
Read
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. To…
Infosecurity Magazine Jul 21, 2026, 01:00 PM (UTC)
Read
Analysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmented
Cybersecurity Ventures Jul 21, 2026, 12:38 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 21, 2026 – Read the full story in StationX Nathan House, founder and CEO at StationX, one of the UK’s first cybersecurity companies founded in 1999 and trusted by more…
Infosecurity Magazine Jul 21, 2026, 12:00 PM (UTC)
Read
FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites
The Hacker News Jul 21, 2026, 11:58 AM (UTC)
Read
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Research…
The Hacker News Jul 21, 2026, 11:42 AM (UTC)
Read
Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't…
The Hacker News Jul 21, 2026, 11:24 AM (UTC)
Read
A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt, described by three Zhejiang University researc…
BleepingComputer Jul 21, 2026, 11:07 AM (UTC)
Read
The U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization. [...]
BleepingComputer Jul 21, 2026, 10:12 AM (UTC)
Read
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]
Infosecurity Magazine Jul 21, 2026, 09:38 AM (UTC)
Read
Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theft
Infosecurity Magazine Jul 21, 2026, 09:30 AM (UTC)
Read
In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans
The Hacker News Jul 21, 2026, 08:59 AM (UTC)
Read
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE…
The Hacker News Jul 21, 2026, 07:34 AM (UTC)
Read
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed t…
The Hacker News Jul 21, 2026, 06:29 AM (UTC)
Read
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS s…
The Hacker News Jul 20, 2026, 06:23 PM (UTC)
Read
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an…
The Hacker News Jul 20, 2026, 05:29 PM (UTC)
Read
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against…
Infosecurity Magazine Jul 20, 2026, 03:00 PM (UTC)
Read
Cruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors
The Hacker News Jul 20, 2026, 02:33 PM (UTC)
Read
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malw…
Infosecurity Magazine Jul 20, 2026, 02:05 PM (UTC)
Read
JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts
Infosecurity Magazine Jul 20, 2026, 02:00 PM (UTC)
Read
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain
The Hacker News Jul 20, 2026, 01:32 PM (UTC)
Read
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code…
Cybersecurity Ventures Jul 20, 2026, 12:30 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 20, 2026 – Read the full story in Yahoo! Finance According to Cybersecurity Ventures, global cybercrime costs were projected to reach $10.5 trillion annually by 2025, u…
Infosecurity Magazine Jul 20, 2026, 12:30 PM (UTC)
Read
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel
The Hacker News Jul 20, 2026, 12:13 PM (UTC)
Read
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. Th…
The Hacker News Jul 20, 2026, 11:30 AM (UTC)
Read
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long wo…
Infosecurity Magazine Jul 20, 2026, 09:45 AM (UTC)
Read
Two chiefs of UK policing agencies said the Transport for London prosecution demonstrates the need for Cybercrime Risk Orders
The Hacker News Jul 20, 2026, 09:10 AM (UTC)
Read
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A…
The Hacker News Jul 20, 2026, 09:07 AM (UTC)
Read
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs…
The Hacker News Jul 20, 2026, 05:27 AM (UTC)
Read
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infra…
The Hacker News Jul 20, 2026, 05:15 AM (UTC)
Read
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below…
The Hacker News Jul 19, 2026, 08:42 PM (UTC)
Read
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), a…
The Hacker News Jul 19, 2026, 01:30 PM (UTC)
Read
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA),…
The Hacker News Jul 19, 2026, 01:18 PM (UTC)
Read
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity…
The Hacker News Jul 17, 2026, 09:20 PM (UTC)
Read
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run cod…
The Hacker News Jul 17, 2026, 08:20 PM (UTC)
Read
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no a…
The Hacker News Jul 17, 2026, 06:54 PM (UTC)
Read
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of…
The Hacker News Jul 17, 2026, 05:12 PM (UTC)
Read
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the imag…
The Hacker News Jul 17, 2026, 04:39 PM (UTC)
Read
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-…
Infosecurity Magazine Jul 17, 2026, 03:00 PM (UTC)
Read
Government organizations are targeted by attackers who know agencies cannot afford disruption to public services
Infosecurity Magazine Jul 17, 2026, 02:30 PM (UTC)
Read
23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements
The Hacker News Jul 17, 2026, 01:48 PM (UTC)
Read
North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. "Any user who ran the projec…
Cybersecurity Ventures Jul 17, 2026, 12:23 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 17, 2026 – Read the full story from Sophos With around 359 million businesses in the world, fewer than 35,000 have a CISO or security leader in place, according to the…
The Hacker News Jul 17, 2026, 11:44 AM (UTC)
Read
The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other a…
The Hacker News Jul 17, 2026, 11:30 AM (UTC)
Read
Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivere…
The Hacker News Jul 17, 2026, 10:53 AM (UTC)
Read
Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the…
Infosecurity Magazine Jul 17, 2026, 09:45 AM (UTC)
Read
US government agencies have until July 19 to patch two critical Fortinet vulnerabilities
Infosecurity Magazine Jul 17, 2026, 09:00 AM (UTC)
Read
Analysis of ransomware incidents by ReliaQuest indicates a shift in the ransomware landscape
The Hacker News Jul 17, 2026, 08:56 AM (UTC)
Read
ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pas…
The Hacker News Jul 17, 2026, 08:46 AM (UTC)
Read
Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering. Russian cyb…
The Hacker News Jul 17, 2026, 06:42 AM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agen…
The Hacker News Jul 16, 2026, 05:09 PM (UTC)
Read
Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27,000 of the transpor…
The Hacker News Jul 16, 2026, 03:41 PM (UTC)
Read
A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation. Old b…
Infosecurity Magazine Jul 16, 2026, 03:00 PM (UTC)
Read
Global phishing campaign disguised a Lua loader as a font file to deploy RATs and infostealers
Cybersecurity Ventures Jul 16, 2026, 02:38 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 16, 2026 – Watch the YouTube videos Kevin Mitnick, the world’s most famous hacker, passed away three years ago on Jul. 16, 2023. Mitnick visited the Cybersecurity Ventu…
The Hacker News Jul 16, 2026, 01:33 PM (UTC)
Read
n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss. A valid token fro…
Infosecurity Magazine Jul 16, 2026, 01:30 PM (UTC)
Read
New ClickLock macOS stealer locked victims out of their own system until they surrendered a password
Infosecurity Magazine Jul 16, 2026, 01:30 PM (UTC)
Read
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackers
The Hacker News Jul 16, 2026, 12:50 PM (UTC)
Read
Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026. "The malware is full-featured, lightweight, and modular," Elastic Security Labs resea…
The Hacker News Jul 16, 2026, 12:33 PM (UTC)
Read
ClickLock Stealer, a new macOS infostealer, answers a victim's refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim…
The Hacker News Jul 16, 2026, 11:58 AM (UTC)
Read
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation…
Infosecurity Magazine Jul 16, 2026, 11:51 AM (UTC)
Read
The perpetrators of the 2024 TfL cyber-attack have been jailed for five and a half years each after pleading guilty to Computer Misuse Act offences
Infosecurity Magazine Jul 16, 2026, 09:25 AM (UTC)
Read
SANS Institute says governance programs are still nascent even as AI failures and threats grow
Infosecurity Magazine Jul 16, 2026, 08:50 AM (UTC)
Read
The White House announced Gold Eagle to help accelerate the discovery, prioritization and patching of flaws found by AI
Infosecurity Magazine Jul 15, 2026, 03:00 PM (UTC)
Read
Six-month phishing campaign used seasonal eCard lures to plant legitimate RMM tools on victims
Infosecurity Magazine Jul 15, 2026, 02:00 PM (UTC)
Read
Eleven forgotten Microsoft-signed UEFI shims can bypass Secure Boot on almost any machine
Cybersecurity Ventures Jul 15, 2026, 12:51 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 15, 2026 – Listen to the podcast Hunting Warhead is an award-winning investigative true-crime podcast from CBC Podcasts and the Norwegian newspaper VG. Hosted by Daemon…
Infosecurity Magazine Jul 15, 2026, 12:45 PM (UTC)
Read
Research of incidents by Sophos finds that phishing, brute force attacks and other identity-based threats have surpassed software vulnerabilities as means of delivering ransomware
Infosecurity Magazine Jul 15, 2026, 12:00 PM (UTC)
Read
Progress has restored access to its ShareFile Storage Zones Controller after a four-day suspension triggered by a credible external security threat
Infosecurity Magazine Jul 15, 2026, 09:20 AM (UTC)
Read
Microsoft released fixes for a record 570 CVEs in its July Patch Tuesday update, as experts warn AI is dramatically accelerating vulnerability discovery and increasing patch volumes
Infosecurity Magazine Jul 15, 2026, 08:48 AM (UTC)
Read
The UK government is warning of the potential impact of catastrophic cyber-attacks
Krebs on Security Jul 14, 2026, 07:22 PM (UTC)
Read
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last mont…
Infosecurity Magazine Jul 14, 2026, 03:28 PM (UTC)
Read
The US Department of Defense announced the immediate suspension of the CMMC Phase II requirements until further review
Cybersecurity Ventures Jul 14, 2026, 12:51 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 14, 2026 – Watch the YouTube video “When high-trust individuals are compromised, the blast radius reaches well beyond them to their companies, partners, and networks,”…
Infosecurity Magazine Jul 14, 2026, 12:00 PM (UTC)
Read
Researchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and more
Infosecurity Magazine Jul 14, 2026, 09:43 AM (UTC)
Read
Supermarket giant Lidl has revealed details of a supplier breach impacting customer data
Infosecurity Magazine Jul 14, 2026, 08:21 AM (UTC)
Read
Five UK residents have been charged in relation to supplying Russian Coms fraud devices and apps
Infosecurity Magazine Jul 13, 2026, 03:30 PM (UTC)
Read
Misconfigured server exposed three phishing operators running Evilginx forks to bypass MFA
Krebs on Security Jul 13, 2026, 03:03 PM (UTC)
Read
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before…
Infosecurity Magazine Jul 13, 2026, 02:45 PM (UTC)
Read
Chinese and Indian spies converged on the same Balochistan police force, SentinelLabs found
Infosecurity Magazine Jul 13, 2026, 01:00 PM (UTC)
Read
New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments
Cybersecurity Ventures Jul 13, 2026, 12:41 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 13, 2026 – Listen to the podcast Larry Clinton is the President and CEO of the Internet Security Alliance. Since 2001, ISA strives to promote the recognition of cyberse…
Infosecurity Magazine Jul 13, 2026, 12:05 PM (UTC)
Read
Progress Software, the provider of the popular file-sharing and data storage solutions, has urged customers to shut down the server hosting their Storage Zone Controller
Infosecurity Magazine Jul 13, 2026, 10:40 AM (UTC)
Read
Cybersecurity agencies from 12 countries have warned that Russian state-backed hackers are actively targeting vulnerable routers using weak SNMP credentials
Infosecurity Magazine Jul 13, 2026, 09:30 AM (UTC)
Read
An Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operation
Infosecurity Magazine Jul 13, 2026, 08:30 AM (UTC)
Read
Australian Cyber Security Centre warns CMS users of mass scanning and exploitation campaign
Infosecurity Magazine Jul 10, 2026, 04:00 PM (UTC)
Read
CISA reveals how it responded after sensitive AWS GovCloud credentials and internal data were exposed in a public GitHub repository
Infosecurity Magazine Jul 10, 2026, 03:30 PM (UTC)
Read
A new multi-purpose backdoor allows cyber threat actors to conduct both quiet espionage activity and destructive wiping operations
Infosecurity Magazine Jul 10, 2026, 01:45 PM (UTC)
Read
Researchers at the AI Now Institute developed a proof-of-concept exploit showing common AI tools used for security could backfire
Infosecurity Magazine Jul 10, 2026, 01:00 PM (UTC)
Read
GodDamn ransomware uses remote desktop application to secretly move around networks and drop the malicious PoisonX kernel driver
Cybersecurity Ventures Jul 10, 2026, 12:18 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 10, 2026 – Watch the video The Cybercrime Magazine media team will step into the Business Hall at Black Hat USA in Las Vegas Aug. 2-4 and experience the future of cyber…
Infosecurity Magazine Jul 10, 2026, 09:33 AM (UTC)
Read
Microsoft has said the volume of Windows security updates is set to grow as it uses AI to find new bugs
Infosecurity Magazine Jul 10, 2026, 09:00 AM (UTC)
Read
NHS tells staff they could face prison for “inappropriate” access to patients’ medical records
Infosecurity Magazine Jul 9, 2026, 02:00 PM (UTC)
Read
Huntress found a threat actor using vibe-coded PowerShell to map an Active Directory network
Infosecurity Magazine Jul 9, 2026, 12:00 PM (UTC)
Read
Survey of cybersecurity leaders by MetaCompliance finds that many feel boards are uninterested in ever-evolving cyber risks
Infosecurity Magazine Jul 9, 2026, 11:45 AM (UTC)
Read
Operation First Light 2026, coordinated by Interpol and funded by the Chinese government, has led to 5,811 arrests
Infosecurity Magazine Jul 9, 2026, 11:00 AM (UTC)
Read
Wiz discovered GhostApproval, a symlink flaw in six major AI coding assistants that bypasses approval
Infosecurity Magazine Jul 9, 2026, 09:30 AM (UTC)
Read
Over 70 cybersecurity organizations have signed the CREST AI Charter detailing responsible use of AI for security
Infosecurity Magazine Jul 9, 2026, 07:30 AM (UTC)
Read
Cybersecurity researchers at ESET identify big rise in suspicious and malicious toolsets which put users at risk from cyber-attacks
Infosecurity Magazine Jul 8, 2026, 03:30 PM (UTC)
Read
Zimperium found RedWing, an Android spyware sold as a service via Telegram to target banking apps
Infosecurity Magazine Jul 8, 2026, 02:30 PM (UTC)
Read
Cisco Talos said China-linked APT UAT-7810 is growing its proxy relay network with new malware