The Hacker News Jul 28, 2026, 06:59 PM (UTC)
Read
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature…
BleepingComputer Jul 28, 2026, 06:41 PM (UTC)
Read
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. [...]
BleepingComputer Jul 28, 2026, 06:08 PM (UTC)
Read
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]
Infosecurity Magazine Jul 28, 2026, 03:15 PM (UTC)
Read
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it
The Hacker News Jul 28, 2026, 03:01 PM (UTC)
Read
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks La…
SecurityWeek Jul 28, 2026, 02:55 PM (UTC)
Read
Oasis Security recently raised $120 million in Series B funding for its agentic access management platform. The post Cyera Acquiring Oasis Security in $1 Billion Deal appeared first on SecurityWeek.
Infosecurity Magazine Jul 28, 2026, 02:45 PM (UTC)
Read
AI-assisted research uncovered Linux kernel use-after-free allowing root escalation
The Hacker News Jul 28, 2026, 02:41 PM (UTC)
Read
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed…
SecurityWeek Jul 28, 2026, 02:19 PM (UTC)
Read
Apple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared first on SecurityWeek.
BleepingComputer Jul 28, 2026, 02:00 PM (UTC)
Read
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the application…
The Hacker News Jul 28, 2026, 01:33 PM (UTC)
Read
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privi…
SecurityWeek Jul 28, 2026, 01:05 PM (UTC)
Read
The company will use the fresh investment to grow its customer success and AI R&D teams. The post OT Security Startup Frenos Raises $1.52 Million appeared first on SecurityWeek.
Infosecurity Magazine Jul 28, 2026, 01:00 PM (UTC)
Read
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise
The Hacker News Jul 28, 2026, 12:56 PM (UTC)
Read
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advi…
Cybersecurity Ventures Jul 28, 2026, 12:50 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 28, 2026 – Listen to the podcast Meta is facing penalties of up to a massive $1.4 trillion from four U.S. states that sued the company over the addictive designs of The…
Infosecurity Magazine Jul 28, 2026, 12:45 PM (UTC)
Read
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model
BleepingComputer Jul 28, 2026, 12:10 PM (UTC)
Read
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. [...]
The Hacker News Jul 28, 2026, 11:55 AM (UTC)
Read
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The…
SecurityWeek Jul 28, 2026, 11:11 AM (UTC)
Read
The company claims MAI-Cyber-1-Flash tops Anthropic’s Mythos and OpenAI’s GPT-5.6 Sol in CyberGym testing. The post Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model appeared first on SecurityWeek.
SecurityWeek Jul 28, 2026, 11:00 AM (UTC)
Read
Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. The post Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker appeared first on SecurityWeek.
SecurityWeek Jul 28, 2026, 11:00 AM (UTC)
Read
Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. The post Act Security Emerges from Stealth to Fight the Patch Problem appeared first on SecurityWeek.
Infosecurity Magazine Jul 28, 2026, 11:00 AM (UTC)
Read
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack
SecurityWeek Jul 28, 2026, 10:17 AM (UTC)
Read
The startup will invest in expanding engineering and sales teams, accelerating ecosystem support, and expanding corporate partnerships. The post Hush Security Raises $30 Million for AI Agent Governance appeared first on SecurityWeek.
Infosecurity Magazine Jul 28, 2026, 09:40 AM (UTC)
Read
NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”
BleepingComputer Jul 28, 2026, 09:10 AM (UTC)
Read
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]
Infosecurity Magazine Jul 28, 2026, 08:57 AM (UTC)
Read
CREST’s new AI standards are optional add-on requirements for cybersecurity service providers wishing to demonstrate responsible AI usage
SecurityWeek Jul 28, 2026, 08:42 AM (UTC)
Read
The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. The post Google Adopts New Threat Actor Naming System appeared first on SecurityWeek.
The Hacker News Jul 28, 2026, 08:11 AM (UTC)
Read
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), a…
The Hacker News Jul 28, 2026, 08:04 AM (UTC)
Read
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsyst…
SecurityWeek Jul 28, 2026, 07:27 AM (UTC)
Read
The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek.
SecurityWeek Jul 28, 2026, 06:40 AM (UTC)
Read
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
The Hacker News Jul 28, 2026, 06:07 AM (UTC)
Read
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configu…
The Hacker News Jul 28, 2026, 04:43 AM (UTC)
Read
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command inject…
BleepingComputer Jul 27, 2026, 11:49 PM (UTC)
Read
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]
BleepingComputer Jul 27, 2026, 10:49 PM (UTC)
Read
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]
BleepingComputer Jul 27, 2026, 09:08 PM (UTC)
Read
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]
BleepingComputer Jul 27, 2026, 09:00 PM (UTC)
Read
A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]
The Hacker News Jul 27, 2026, 06:10 PM (UTC)
Read
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise softwar…
BleepingComputer Jul 27, 2026, 05:29 PM (UTC)
Read
Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. [...]
The Hacker News Jul 27, 2026, 05:16 PM (UTC)
Read
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes t…
BleepingComputer Jul 27, 2026, 03:39 PM (UTC)
Read
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]
BleepingComputer Jul 27, 2026, 03:12 PM (UTC)
Read
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. [...]
The Hacker News Jul 27, 2026, 02:40 PM (UTC)
Read
Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another us…
The Hacker News Jul 27, 2026, 02:10 PM (UTC)
Read
Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing lo…
BleepingComputer Jul 27, 2026, 02:01 PM (UTC)
Read
Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous actions create securit…
The Hacker News Jul 27, 2026, 01:05 PM (UTC)
Read
n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-202…
Cybersecurity Ventures Jul 27, 2026, 12:50 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 27, 2026 – Listen to the podcast By the end of the nearly yearlong romance scam that began on LinkedIn, Anola Johnson, 67, a Utah-based travel specialist, was out aroun…
The Hacker News Jul 27, 2026, 12:37 PM (UTC)
Read
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools. "The victim was directed through compromised web infrastructure to a coun…
Infosecurity Magazine Jul 27, 2026, 11:30 AM (UTC)
Read
Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims
The Hacker News Jul 27, 2026, 10:51 AM (UTC)
Read
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra. According to a new analy…
Infosecurity Magazine Jul 27, 2026, 10:01 AM (UTC)
Read
Halcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight against
The Hacker News Jul 27, 2026, 08:48 AM (UTC)
Read
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TEL…
The Hacker News Jul 27, 2026, 08:01 AM (UTC)
Read
GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration option in the dependabot.yml still controls the behavior, though,…
BleepingComputer Jul 26, 2026, 02:13 PM (UTC)
Read
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]
BleepingComputer Jul 25, 2026, 10:37 PM (UTC)
Read
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]
The Hacker News Jul 25, 2026, 06:48 PM (UTC)
Read
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campai…
The Hacker News Jul 25, 2026, 12:52 PM (UTC)
Read
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the J…
The Hacker News Jul 25, 2026, 10:14 AM (UTC)
Read
Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user w…
The Hacker News Jul 25, 2026, 10:14 AM (UTC)
Read
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That mode…
The Hacker News Jul 25, 2026, 10:14 AM (UTC)
Read
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-…
The Hacker News Jul 25, 2026, 09:53 AM (UTC)
Read
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAF…
The Hacker News Jul 24, 2026, 03:12 PM (UTC)
Read
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns design…
The Hacker News Jul 24, 2026, 02:15 PM (UTC)
Read
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Control…
Cybersecurity Ventures Jul 24, 2026, 12:51 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 24, 2026 – Watch the YouTube video Black Hat USA 2026, the premier cybersecurity event of the year, returns to Mandalay Bay in Las Vegas with a re-engineered, six-day p…
Infosecurity Magazine Jul 24, 2026, 12:00 PM (UTC)
Read
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign
The Hacker News Jul 24, 2026, 11:53 AM (UTC)
Read
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's…
The Hacker News Jul 24, 2026, 11:45 AM (UTC)
Read
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and…
The Hacker News Jul 24, 2026, 11:30 AM (UTC)
Read
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so man…
Infosecurity Magazine Jul 24, 2026, 11:15 AM (UTC)
Read
OpenAI’s chatbot tool ChatGPT ranked among the top 10 most impersonated brands in phishing attacks for the first time
The Hacker News Jul 24, 2026, 10:15 AM (UTC)
Read
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection. The agent…
The Hacker News Jul 24, 2026, 10:09 AM (UTC)
Read
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. Th…
Infosecurity Magazine Jul 24, 2026, 09:15 AM (UTC)
Read
Comparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher education
The Hacker News Jul 24, 2026, 07:41 AM (UTC)
Read
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version bef…
The Hacker News Jul 24, 2026, 06:58 AM (UTC)
Read
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and t…
The Hacker News Jul 24, 2026, 06:50 AM (UTC)
Read
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threa…
The Hacker News Jul 23, 2026, 06:36 PM (UTC)
Read
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the brow…
Infosecurity Magazine Jul 23, 2026, 03:50 PM (UTC)
Read
International agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration Suite
The Hacker News Jul 23, 2026, 03:02 PM (UTC)
Read
Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network…
Infosecurity Magazine Jul 23, 2026, 02:00 PM (UTC)
Read
CoreView research finds that security leadership is concerned about AI Assistant exposing confidential data
Infosecurity Magazine Jul 23, 2026, 01:30 PM (UTC)
Read
US government agencies have warned that Iranian cyber actors are targeting US-based Siemens and Schneider industrial equipment
The Hacker News Jul 23, 2026, 01:27 PM (UTC)
Read
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Acc…
The Hacker News Jul 23, 2026, 01:11 PM (UTC)
Read
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound con…
Cybersecurity Ventures Jul 23, 2026, 12:27 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 23, 2026 – Listen to the podcast Jim Rutt, CISO at The Dana Foundation, a private philanthropic organization in New York City that is dedicated to advancing neuroscienc…
The Hacker News Jul 23, 2026, 12:20 PM (UTC)
Read
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader call…
The Hacker News Jul 23, 2026, 11:45 AM (UTC)
Read
Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankenstein…
Infosecurity Magazine Jul 23, 2026, 11:30 AM (UTC)
Read
Sophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threats
The Hacker News Jul 23, 2026, 11:28 AM (UTC)
Read
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist…
Infosecurity Magazine Jul 23, 2026, 10:19 AM (UTC)
Read
Dolphin X is a new infostealer that uses AI to sort and rank victims, giving cybercriminals a faster way to identify lucrative targets
The Hacker News Jul 23, 2026, 10:00 AM (UTC)
Read
Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email add…
The Hacker News Jul 23, 2026, 08:04 AM (UTC)
Read
RefluXFS, a Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and…
Infosecurity Magazine Jul 23, 2026, 08:00 AM (UTC)
Read
A new study of organizations which have fallen victim to ransomware suggests the rise of AI-tools being used by hackers is making life harder for defenders
The Hacker News Jul 23, 2026, 06:34 AM (UTC)
Read
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked a…
The Hacker News Jul 22, 2026, 06:37 PM (UTC)
Read
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed…
The Hacker News Jul 22, 2026, 06:07 PM (UTC)
Read
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, trac…
The Hacker News Jul 22, 2026, 03:01 PM (UTC)
Read
Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user's WhatsApp data. The shortcoming has be…
Infosecurity Magazine Jul 22, 2026, 03:00 PM (UTC)
Read
New TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP pattern
Cybersecurity Ventures Jul 22, 2026, 12:41 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 22, 2026 – Watch our Videos at Cybercrime.TV CISOs and security leaders have spoken up on our hottest content and the award-winning Cybercrime Magazine YouTube Channel…
The Hacker News Jul 22, 2026, 12:36 PM (UTC)
Read
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting…
The Hacker News Jul 22, 2026, 11:58 AM (UTC)
Read
Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence…
Infosecurity Magazine Jul 22, 2026, 11:40 AM (UTC)
Read
Hugging Face recently disclosed a security breach. OpenAI has now said that it was its AI models which broke containment and hacked Hugging Face themselves
Infosecurity Magazine Jul 22, 2026, 10:50 AM (UTC)
Read
New Ubuntu snap-confine race condition lets local users escalate to root on default installs
Infosecurity Magazine Jul 22, 2026, 10:30 AM (UTC)
Read
CodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitable
Krebs on Security Jul 22, 2026, 01:10 AM (UTC)
Read
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 perc…
Cybersecurity Ventures Jul 21, 2026, 02:15 PM (UTC)
Read
AI Delivers Value Only When It’s Built Into the Security Workflow – Christophe Briguet, Sr. Director of Product Management – AI & Security Analytics, Stellar Cyber San Jose, Calif. – Jul. 21, 2026 Every security leader has heard the promise by now: AI will tra…
Infosecurity Magazine Jul 21, 2026, 02:00 PM (UTC)
Read
Russian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude models
Infosecurity Magazine Jul 21, 2026, 01:00 PM (UTC)
Read
Analysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmented
Cybersecurity Ventures Jul 21, 2026, 12:38 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 21, 2026 – Read the full story in StationX Nathan House, founder and CEO at StationX, one of the UK’s first cybersecurity companies founded in 1999 and trusted by more…
Infosecurity Magazine Jul 21, 2026, 12:00 PM (UTC)
Read
FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites
Infosecurity Magazine Jul 21, 2026, 09:38 AM (UTC)
Read
Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theft
Infosecurity Magazine Jul 21, 2026, 09:30 AM (UTC)
Read
In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans
Infosecurity Magazine Jul 20, 2026, 03:00 PM (UTC)
Read
Cruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors
Infosecurity Magazine Jul 20, 2026, 02:05 PM (UTC)
Read
JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts
Infosecurity Magazine Jul 20, 2026, 02:00 PM (UTC)
Read
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain
Cybersecurity Ventures Jul 20, 2026, 12:30 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 20, 2026 – Read the full story in Yahoo! Finance According to Cybersecurity Ventures, global cybercrime costs were projected to reach $10.5 trillion annually by 2025, u…
Infosecurity Magazine Jul 20, 2026, 12:30 PM (UTC)
Read
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel
Infosecurity Magazine Jul 20, 2026, 09:45 AM (UTC)
Read
Two chiefs of UK policing agencies said the Transport for London prosecution demonstrates the need for Cybercrime Risk Orders
Infosecurity Magazine Jul 17, 2026, 03:00 PM (UTC)
Read
Government organizations are targeted by attackers who know agencies cannot afford disruption to public services
Infosecurity Magazine Jul 17, 2026, 02:30 PM (UTC)
Read
23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements
Cybersecurity Ventures Jul 17, 2026, 12:23 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 17, 2026 – Read the full story from Sophos With around 359 million businesses in the world, fewer than 35,000 have a CISO or security leader in place, according to the…
Infosecurity Magazine Jul 17, 2026, 09:45 AM (UTC)
Read
US government agencies have until July 19 to patch two critical Fortinet vulnerabilities
Infosecurity Magazine Jul 17, 2026, 09:00 AM (UTC)
Read
Analysis of ransomware incidents by ReliaQuest indicates a shift in the ransomware landscape
Infosecurity Magazine Jul 16, 2026, 03:00 PM (UTC)
Read
Global phishing campaign disguised a Lua loader as a font file to deploy RATs and infostealers
Cybersecurity Ventures Jul 16, 2026, 02:38 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 16, 2026 – Watch the YouTube videos Kevin Mitnick, the world’s most famous hacker, passed away three years ago on Jul. 16, 2023. Mitnick visited the Cybersecurity Ventu…
Infosecurity Magazine Jul 16, 2026, 01:30 PM (UTC)
Read
New ClickLock macOS stealer locked victims out of their own system until they surrendered a password
Infosecurity Magazine Jul 16, 2026, 01:30 PM (UTC)
Read
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackers
Infosecurity Magazine Jul 16, 2026, 11:51 AM (UTC)
Read
The perpetrators of the 2024 TfL cyber-attack have been jailed for five and a half years each after pleading guilty to Computer Misuse Act offences
Infosecurity Magazine Jul 16, 2026, 09:25 AM (UTC)
Read
SANS Institute says governance programs are still nascent even as AI failures and threats grow
Infosecurity Magazine Jul 16, 2026, 08:50 AM (UTC)
Read
The White House announced Gold Eagle to help accelerate the discovery, prioritization and patching of flaws found by AI
Infosecurity Magazine Jul 15, 2026, 03:00 PM (UTC)
Read
Six-month phishing campaign used seasonal eCard lures to plant legitimate RMM tools on victims
Infosecurity Magazine Jul 15, 2026, 02:00 PM (UTC)
Read
Eleven forgotten Microsoft-signed UEFI shims can bypass Secure Boot on almost any machine
Infosecurity Magazine Jul 15, 2026, 12:45 PM (UTC)
Read
Research of incidents by Sophos finds that phishing, brute force attacks and other identity-based threats have surpassed software vulnerabilities as means of delivering ransomware
Infosecurity Magazine Jul 15, 2026, 12:00 PM (UTC)
Read
Progress has restored access to its ShareFile Storage Zones Controller after a four-day suspension triggered by a credible external security threat
Infosecurity Magazine Jul 15, 2026, 09:20 AM (UTC)
Read
Microsoft released fixes for a record 570 CVEs in its July Patch Tuesday update, as experts warn AI is dramatically accelerating vulnerability discovery and increasing patch volumes
Infosecurity Magazine Jul 15, 2026, 08:48 AM (UTC)
Read
The UK government is warning of the potential impact of catastrophic cyber-attacks