BleepingComputer Jul 31, 2026, 05:35 PM (UTC)
Read
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]
BleepingComputer Jul 31, 2026, 04:49 PM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...]
The Hacker News Jul 31, 2026, 04:39 PM (UTC)
Read
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing messag…
SecurityWeek Jul 31, 2026, 03:47 PM (UTC)
Read
Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto…
SecurityWeek Jul 31, 2026, 03:17 PM (UTC)
Read
Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek.
The Hacker News Jul 31, 2026, 02:45 PM (UTC)
Read
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed i…
BleepingComputer Jul 31, 2026, 02:01 PM (UTC)
Read
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware…
Cybersecurity Ventures Jul 31, 2026, 01:11 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 31, 2026 – Listen to the podcast “The exploit lands before the fix even ships,” says John Vecchi, CMO at Mitiga, a leader in zero-impact breach prevention for cloud, Sa…
The Hacker News Jul 31, 2026, 12:51 PM (UTC)
Read
Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patc…
The Hacker News Jul 31, 2026, 11:55 AM (UTC)
Read
An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control…
The Hacker News Jul 31, 2026, 11:24 AM (UTC)
Read
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers…
The Hacker News Jul 31, 2026, 11:21 AM (UTC)
Read
Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exp…
SecurityWeek Jul 31, 2026, 10:28 AM (UTC)
Read
The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase. The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek.
SecurityWeek Jul 31, 2026, 10:00 AM (UTC)
Read
When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. The post EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in…
Infosecurity Magazine Jul 31, 2026, 09:50 AM (UTC)
Read
AWS has linked North Korea to the axios campaign to other attacks on npm libraries
SecurityWeek Jul 31, 2026, 09:39 AM (UTC)
Read
A security company’s systems were hacked after it installed a malicious Python package deployed by Claude. The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek.
SecurityWeek Jul 31, 2026, 09:04 AM (UTC)
Read
Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Allowed to Azure Cosmos DB Pwnage appeared first on SecurityWeek.
Infosecurity Magazine Jul 31, 2026, 08:35 AM (UTC)
Read
Anthropic has revealed that Claude AI models compromised third-party organizations
SecurityWeek Jul 31, 2026, 07:51 AM (UTC)
Read
In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment. The post CareCloud Data Breach Impacts Over 350,000 appeared first on SecurityWeek.
SecurityWeek Jul 31, 2026, 06:50 AM (UTC)
Read
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in TeamCity appeared first on SecurityWeek.
The Hacker News Jul 31, 2026, 06:41 AM (UTC)
Read
Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without i…
BleepingComputer Jul 31, 2026, 12:57 AM (UTC)
Read
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. […
BleepingComputer Jul 30, 2026, 10:28 PM (UTC)
Read
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. [...]
SecurityWeek Jul 30, 2026, 10:18 PM (UTC)
Read
CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems. The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first on SecurityWeek.
BleepingComputer Jul 30, 2026, 10:01 PM (UTC)
Read
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...]
SecurityWeek Jul 30, 2026, 09:02 PM (UTC)
Read
The acquisition will add approximately 65 cybersecurity professionals to Bank of America’s operations in the United Kingdom. The post Bank of America to Acquire Cybersecurity Firm MDSec appeared first on SecurityWeek.
The Hacker News Jul 30, 2026, 06:18 PM (UTC)
Read
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of…
BleepingComputer Jul 30, 2026, 06:13 PM (UTC)
Read
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. [...]
BleepingComputer Jul 30, 2026, 06:00 PM (UTC)
Read
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the ho…
BleepingComputer Jul 30, 2026, 05:00 PM (UTC)
Read
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI. [...]
Krebs on Security Jul 30, 2026, 04:49 PM (UTC)
Read
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking…
BleepingComputer Jul 30, 2026, 04:46 PM (UTC)
Read
Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. [...]
BleepingComputer Jul 30, 2026, 03:56 PM (UTC)
Read
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]
The Hacker News Jul 30, 2026, 03:25 PM (UTC)
Read
A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abu…
BleepingComputer Jul 30, 2026, 03:12 PM (UTC)
Read
American semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. [...]
Infosecurity Magazine Jul 30, 2026, 02:30 PM (UTC)
Read
Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts
BleepingComputer Jul 30, 2026, 02:01 PM (UTC)
Read
Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather…
Infosecurity Magazine Jul 30, 2026, 02:00 PM (UTC)
Read
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats
The Hacker News Jul 30, 2026, 01:34 PM (UTC)
Read
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said…
Infosecurity Magazine Jul 30, 2026, 01:00 PM (UTC)
Read
Action1 report finds sysadmins overestimated their use of AI in predictions made two years ago
Infosecurity Magazine Jul 30, 2026, 12:00 PM (UTC)
Read
Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure
The Hacker News Jul 30, 2026, 11:54 AM (UTC)
Read
Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of…
The Hacker News Jul 30, 2026, 11:32 AM (UTC)
Read
Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable mod…
The Hacker News Jul 30, 2026, 10:33 AM (UTC)
Read
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIG…
The Hacker News Jul 30, 2026, 10:32 AM (UTC)
Read
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos…
Infosecurity Magazine Jul 30, 2026, 09:15 AM (UTC)
Read
The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws
Infosecurity Magazine Jul 30, 2026, 08:25 AM (UTC)
Read
The UK’s National Cyber Security Centre wants network device makers to improve forensic observability
The Hacker News Jul 30, 2026, 07:40 AM (UTC)
Read
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as wel…
The Hacker News Jul 30, 2026, 07:28 AM (UTC)
Read
The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the equipment authorization required for import, marketing, or…
The Hacker News Jul 30, 2026, 06:05 AM (UTC)
Read
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at…
The Hacker News Jul 30, 2026, 05:08 AM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero…
BleepingComputer Jul 29, 2026, 11:44 PM (UTC)
Read
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. [...]
BleepingComputer Jul 29, 2026, 09:39 PM (UTC)
Read
Claude is down for some users, with Anthropic confirming elevated errors across multiple AI models. The disruption is causing requests to fail with a "529 Overloaded" message, including in Claude and tools that rely on its API. [...]
The Hacker News Jul 29, 2026, 06:10 PM (UTC)
Read
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose…
Infosecurity Magazine Jul 29, 2026, 04:00 PM (UTC)
Read
LogoKit now builds per-victim phishing pages using live screenshots of the target's real website
The Hacker News Jul 29, 2026, 03:39 PM (UTC)
Read
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-5…
The Hacker News Jul 29, 2026, 03:31 PM (UTC)
Read
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS s…
Infosecurity Magazine Jul 29, 2026, 03:10 PM (UTC)
Read
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
The Hacker News Jul 29, 2026, 01:48 PM (UTC)
Read
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outag…
The Hacker News Jul 29, 2026, 01:42 PM (UTC)
Read
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecur…
Cybersecurity Ventures Jul 29, 2026, 12:57 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 29, 2026 – Listen to the podcast Bent is the story of John J. Boseak’s phenomenal life of crime. Inked from head to toe, with an addiction to strippers and fast Cadilla…
The Hacker News Jul 29, 2026, 12:15 PM (UTC)
Read
AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like…
The Hacker News Jul 29, 2026, 11:57 AM (UTC)
Read
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. M…
The Hacker News Jul 29, 2026, 11:13 AM (UTC)
Read
Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The Stat…
The Hacker News Jul 29, 2026, 11:00 AM (UTC)
Read
The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal s…
Infosecurity Magazine Jul 29, 2026, 11:00 AM (UTC)
Read
IBM Cost of a Data Breach Report warns that the global average cost of a data breach has reached a record high of $4.99m – and AI-backed attacks have played a role
Infosecurity Magazine Jul 29, 2026, 10:15 AM (UTC)
Read
For now, the use of AI benefits vulnerability research more than vulnerability exploitation, a VulnCheck researcher said
Infosecurity Magazine Jul 29, 2026, 09:30 AM (UTC)
Read
AI is dramatically reducing the barriers to entry for scam phone farm operators, Human Security warns
The Hacker News Jul 29, 2026, 08:58 AM (UTC)
Read
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the…
Infosecurity Magazine Jul 29, 2026, 08:30 AM (UTC)
Read
The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery
The Hacker News Jul 29, 2026, 07:51 AM (UTC)
Read
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment also hacked multiple third-party accounts and services as part of the attack. The latest…
The Hacker News Jul 29, 2026, 07:47 AM (UTC)
Read
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. T…
The Hacker News Jul 29, 2026, 07:07 AM (UTC)
Read
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked t…
The Hacker News Jul 29, 2026, 04:20 AM (UTC)
Read
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @j…
The Hacker News Jul 28, 2026, 06:59 PM (UTC)
Read
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature…
Infosecurity Magazine Jul 28, 2026, 03:15 PM (UTC)
Read
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it
The Hacker News Jul 28, 2026, 03:01 PM (UTC)
Read
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks La…
Infosecurity Magazine Jul 28, 2026, 02:45 PM (UTC)
Read
AI-assisted research uncovered Linux kernel use-after-free allowing root escalation
The Hacker News Jul 28, 2026, 02:41 PM (UTC)
Read
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed…
The Hacker News Jul 28, 2026, 01:33 PM (UTC)
Read
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privi…
Infosecurity Magazine Jul 28, 2026, 01:00 PM (UTC)
Read
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise
The Hacker News Jul 28, 2026, 12:56 PM (UTC)
Read
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advi…
Cybersecurity Ventures Jul 28, 2026, 12:50 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 28, 2026 – Listen to the podcast Meta is facing penalties of up to a massive $1.4 trillion from four U.S. states that sued the company over the addictive designs of The…
Infosecurity Magazine Jul 28, 2026, 12:45 PM (UTC)
Read
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model
The Hacker News Jul 28, 2026, 11:55 AM (UTC)
Read
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The…
Infosecurity Magazine Jul 28, 2026, 11:00 AM (UTC)
Read
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack
Infosecurity Magazine Jul 28, 2026, 09:40 AM (UTC)
Read
NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”
Infosecurity Magazine Jul 28, 2026, 08:57 AM (UTC)
Read
CREST’s new AI standards are optional add-on requirements for cybersecurity service providers wishing to demonstrate responsible AI usage
The Hacker News Jul 28, 2026, 08:11 AM (UTC)
Read
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), a…
The Hacker News Jul 28, 2026, 08:04 AM (UTC)
Read
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsyst…
The Hacker News Jul 28, 2026, 06:07 AM (UTC)
Read
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configu…
The Hacker News Jul 28, 2026, 04:43 AM (UTC)
Read
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command inject…
The Hacker News Jul 27, 2026, 06:10 PM (UTC)
Read
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise softwar…
The Hacker News Jul 27, 2026, 05:16 PM (UTC)
Read
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes t…
The Hacker News Jul 27, 2026, 02:40 PM (UTC)
Read
Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another us…
The Hacker News Jul 27, 2026, 02:10 PM (UTC)
Read
Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing lo…
The Hacker News Jul 27, 2026, 01:05 PM (UTC)
Read
n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-202…
Cybersecurity Ventures Jul 27, 2026, 12:50 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 27, 2026 – Listen to the podcast By the end of the nearly yearlong romance scam that began on LinkedIn, Anola Johnson, 67, a Utah-based travel specialist, was out aroun…
The Hacker News Jul 27, 2026, 12:37 PM (UTC)
Read
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools. "The victim was directed through compromised web infrastructure to a coun…
Infosecurity Magazine Jul 27, 2026, 11:30 AM (UTC)
Read
Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims
The Hacker News Jul 27, 2026, 10:51 AM (UTC)
Read
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra. According to a new analy…
Infosecurity Magazine Jul 27, 2026, 10:01 AM (UTC)
Read
Halcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight against
The Hacker News Jul 27, 2026, 08:48 AM (UTC)
Read
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TEL…
Cybersecurity Ventures Jul 24, 2026, 12:51 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 24, 2026 – Watch the YouTube video Black Hat USA 2026, the premier cybersecurity event of the year, returns to Mandalay Bay in Las Vegas with a re-engineered, six-day p…
Infosecurity Magazine Jul 24, 2026, 12:00 PM (UTC)
Read
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign
Infosecurity Magazine Jul 24, 2026, 11:15 AM (UTC)
Read
OpenAI’s chatbot tool ChatGPT ranked among the top 10 most impersonated brands in phishing attacks for the first time
Infosecurity Magazine Jul 24, 2026, 09:15 AM (UTC)
Read
Comparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher education
Infosecurity Magazine Jul 23, 2026, 03:50 PM (UTC)
Read
International agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration Suite
Infosecurity Magazine Jul 23, 2026, 02:00 PM (UTC)
Read
CoreView research finds that security leadership is concerned about AI Assistant exposing confidential data
Infosecurity Magazine Jul 23, 2026, 01:30 PM (UTC)
Read
US government agencies have warned that Iranian cyber actors are targeting US-based Siemens and Schneider industrial equipment
Cybersecurity Ventures Jul 23, 2026, 12:27 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 23, 2026 – Listen to the podcast Jim Rutt, CISO at The Dana Foundation, a private philanthropic organization in New York City that is dedicated to advancing neuroscienc…
Infosecurity Magazine Jul 23, 2026, 11:30 AM (UTC)
Read
Sophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threats
Infosecurity Magazine Jul 23, 2026, 10:19 AM (UTC)
Read
Dolphin X is a new infostealer that uses AI to sort and rank victims, giving cybercriminals a faster way to identify lucrative targets
Infosecurity Magazine Jul 23, 2026, 08:00 AM (UTC)
Read
A new study of organizations which have fallen victim to ransomware suggests the rise of AI-tools being used by hackers is making life harder for defenders
Infosecurity Magazine Jul 22, 2026, 03:00 PM (UTC)
Read
New TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP pattern
Cybersecurity Ventures Jul 22, 2026, 12:41 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 22, 2026 – Watch our Videos at Cybercrime.TV CISOs and security leaders have spoken up on our hottest content and the award-winning Cybercrime Magazine YouTube Channel…
Infosecurity Magazine Jul 22, 2026, 11:40 AM (UTC)
Read
Hugging Face recently disclosed a security breach. OpenAI has now said that it was its AI models which broke containment and hacked Hugging Face themselves
Infosecurity Magazine Jul 22, 2026, 10:50 AM (UTC)
Read
New Ubuntu snap-confine race condition lets local users escalate to root on default installs
Infosecurity Magazine Jul 22, 2026, 10:30 AM (UTC)
Read
CodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitable
Krebs on Security Jul 22, 2026, 01:10 AM (UTC)
Read
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 perc…
Cybersecurity Ventures Jul 21, 2026, 02:15 PM (UTC)
Read
AI Delivers Value Only When It’s Built Into the Security Workflow – Christophe Briguet, Sr. Director of Product Management – AI & Security Analytics, Stellar Cyber San Jose, Calif. – Jul. 21, 2026 Every security leader has heard the promise by now: AI will tra…
Infosecurity Magazine Jul 21, 2026, 02:00 PM (UTC)
Read
Russian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude models
Infosecurity Magazine Jul 21, 2026, 01:00 PM (UTC)
Read
Analysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmented
Cybersecurity Ventures Jul 21, 2026, 12:38 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 21, 2026 – Read the full story in StationX Nathan House, founder and CEO at StationX, one of the UK’s first cybersecurity companies founded in 1999 and trusted by more…
Infosecurity Magazine Jul 21, 2026, 12:00 PM (UTC)
Read
FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites
Infosecurity Magazine Jul 21, 2026, 09:38 AM (UTC)
Read
Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theft
Infosecurity Magazine Jul 21, 2026, 09:30 AM (UTC)
Read
In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans
Infosecurity Magazine Jul 20, 2026, 03:00 PM (UTC)
Read
Cruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors
Infosecurity Magazine Jul 20, 2026, 02:05 PM (UTC)
Read
JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts
Infosecurity Magazine Jul 20, 2026, 02:00 PM (UTC)
Read
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain
Cybersecurity Ventures Jul 20, 2026, 12:30 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 20, 2026 – Read the full story in Yahoo! Finance According to Cybersecurity Ventures, global cybercrime costs were projected to reach $10.5 trillion annually by 2025, u…
Infosecurity Magazine Jul 20, 2026, 12:30 PM (UTC)
Read
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel
Infosecurity Magazine Jul 20, 2026, 09:45 AM (UTC)
Read
Two chiefs of UK policing agencies said the Transport for London prosecution demonstrates the need for Cybercrime Risk Orders