BleepingComputer Jul 20, 2026, 05:43 PM (UTC)
Read
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]
The Hacker News Jul 20, 2026, 05:29 PM (UTC)
Read
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against…
Infosecurity Magazine Jul 20, 2026, 03:00 PM (UTC)
Read
Cruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors
SecurityWeek Jul 20, 2026, 02:54 PM (UTC)
Read
Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others. The post Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software appeared first on SecurityWeek.
The Hacker News Jul 20, 2026, 02:33 PM (UTC)
Read
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malw…
SecurityWeek Jul 20, 2026, 02:11 PM (UTC)
Read
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek.
Infosecurity Magazine Jul 20, 2026, 02:05 PM (UTC)
Read
JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts
BleepingComputer Jul 20, 2026, 02:01 PM (UTC)
Read
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, l…
Infosecurity Magazine Jul 20, 2026, 02:00 PM (UTC)
Read
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain
The Hacker News Jul 20, 2026, 01:32 PM (UTC)
Read
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code…
SecurityWeek Jul 20, 2026, 12:32 PM (UTC)
Read
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek.
Cybersecurity Ventures Jul 20, 2026, 12:30 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 20, 2026 – Read the full story in Yahoo! Finance According to Cybersecurity Ventures, global cybercrime costs were projected to reach $10.5 trillion annually by 2025, u…
Infosecurity Magazine Jul 20, 2026, 12:30 PM (UTC)
Read
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel
The Hacker News Jul 20, 2026, 12:13 PM (UTC)
Read
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. Th…
BleepingComputer Jul 20, 2026, 11:56 AM (UTC)
Read
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. [...]
SecurityWeek Jul 20, 2026, 11:46 AM (UTC)
Read
Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek.
The Hacker News Jul 20, 2026, 11:30 AM (UTC)
Read
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long wo…
SecurityWeek Jul 20, 2026, 11:27 AM (UTC)
Read
Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek.
BleepingComputer Jul 20, 2026, 10:47 AM (UTC)
Read
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. [...]
SecurityWeek Jul 20, 2026, 10:31 AM (UTC)
Read
Attendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. The post Watch on Demand: Cloud & Data Security Summit appeared first on SecurityWeek.
SecurityWeek Jul 20, 2026, 10:25 AM (UTC)
Read
The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations. The post Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool appeared first on SecurityWeek.
BleepingComputer Jul 20, 2026, 10:06 AM (UTC)
Read
Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. [...]
Infosecurity Magazine Jul 20, 2026, 09:45 AM (UTC)
Read
Two chiefs of UK policing agencies said the Transport for London prosecution demonstrates the need for Cybercrime Risk Orders
SecurityWeek Jul 20, 2026, 09:36 AM (UTC)
Read
Targeting production infrastructure, the attack compromised internal datasets and service credentials. The post Hugging Face Hacked in Autonomous AI Attack appeared first on SecurityWeek.
BleepingComputer Jul 20, 2026, 09:29 AM (UTC)
Read
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]
The Hacker News Jul 20, 2026, 09:10 AM (UTC)
Read
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A…
The Hacker News Jul 20, 2026, 09:07 AM (UTC)
Read
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs…
SecurityWeek Jul 20, 2026, 08:12 AM (UTC)
Read
The fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek.
The Hacker News Jul 20, 2026, 05:27 AM (UTC)
Read
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infra…
SecurityWeek Jul 20, 2026, 05:21 AM (UTC)
Read
Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
The Hacker News Jul 20, 2026, 05:15 AM (UTC)
Read
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below…
The Hacker News Jul 19, 2026, 08:42 PM (UTC)
Read
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), a…
BleepingComputer Jul 19, 2026, 02:23 PM (UTC)
Read
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]
The Hacker News Jul 19, 2026, 01:30 PM (UTC)
Read
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA),…
The Hacker News Jul 19, 2026, 01:18 PM (UTC)
Read
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity…
BleepingComputer Jul 18, 2026, 07:32 PM (UTC)
Read
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]
BleepingComputer Jul 18, 2026, 05:22 PM (UTC)
Read
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...]
BleepingComputer Jul 18, 2026, 02:17 PM (UTC)
Read
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...]
BleepingComputer Jul 18, 2026, 01:15 PM (UTC)
Read
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing bi…
The Hacker News Jul 17, 2026, 09:20 PM (UTC)
Read
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run cod…
BleepingComputer Jul 17, 2026, 08:45 PM (UTC)
Read
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its L…
The Hacker News Jul 17, 2026, 08:20 PM (UTC)
Read
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no a…
The Hacker News Jul 17, 2026, 06:54 PM (UTC)
Read
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of…
BleepingComputer Jul 17, 2026, 05:56 PM (UTC)
Read
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. [...]
The Hacker News Jul 17, 2026, 05:12 PM (UTC)
Read
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the imag…
The Hacker News Jul 17, 2026, 04:39 PM (UTC)
Read
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-…
Infosecurity Magazine Jul 17, 2026, 03:00 PM (UTC)
Read
Government organizations are targeted by attackers who know agencies cannot afford disruption to public services
BleepingComputer Jul 17, 2026, 02:55 PM (UTC)
Read
Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. [...]
Infosecurity Magazine Jul 17, 2026, 02:30 PM (UTC)
Read
23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements
BleepingComputer Jul 17, 2026, 02:00 PM (UTC)
Read
Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade mod…
The Hacker News Jul 17, 2026, 01:48 PM (UTC)
Read
North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. "Any user who ran the projec…
Cybersecurity Ventures Jul 17, 2026, 12:23 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 17, 2026 – Read the full story from Sophos With around 359 million businesses in the world, fewer than 35,000 have a CISO or security leader in place, according to the…
The Hacker News Jul 17, 2026, 11:44 AM (UTC)
Read
The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other a…
The Hacker News Jul 17, 2026, 11:30 AM (UTC)
Read
Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivere…
The Hacker News Jul 17, 2026, 10:53 AM (UTC)
Read
Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the…
Infosecurity Magazine Jul 17, 2026, 09:45 AM (UTC)
Read
US government agencies have until July 19 to patch two critical Fortinet vulnerabilities
Infosecurity Magazine Jul 17, 2026, 09:00 AM (UTC)
Read
Analysis of ransomware incidents by ReliaQuest indicates a shift in the ransomware landscape
The Hacker News Jul 17, 2026, 08:56 AM (UTC)
Read
ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pas…
The Hacker News Jul 17, 2026, 08:46 AM (UTC)
Read
Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering. Russian cyb…
The Hacker News Jul 17, 2026, 06:42 AM (UTC)
Read
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agen…
The Hacker News Jul 16, 2026, 05:09 PM (UTC)
Read
Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27,000 of the transpor…
The Hacker News Jul 16, 2026, 03:41 PM (UTC)
Read
A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation. Old b…
Infosecurity Magazine Jul 16, 2026, 03:00 PM (UTC)
Read
Global phishing campaign disguised a Lua loader as a font file to deploy RATs and infostealers
Cybersecurity Ventures Jul 16, 2026, 02:38 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 16, 2026 – Watch the YouTube videos Kevin Mitnick, the world’s most famous hacker, passed away three years ago on Jul. 16, 2023. Mitnick visited the Cybersecurity Ventu…
The Hacker News Jul 16, 2026, 01:33 PM (UTC)
Read
n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss. A valid token fro…
Infosecurity Magazine Jul 16, 2026, 01:30 PM (UTC)
Read
New ClickLock macOS stealer locked victims out of their own system until they surrendered a password
Infosecurity Magazine Jul 16, 2026, 01:30 PM (UTC)
Read
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackers
The Hacker News Jul 16, 2026, 12:50 PM (UTC)
Read
Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026. "The malware is full-featured, lightweight, and modular," Elastic Security Labs resea…
The Hacker News Jul 16, 2026, 12:33 PM (UTC)
Read
ClickLock Stealer, a new macOS infostealer, answers a victim's refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim…
The Hacker News Jul 16, 2026, 11:58 AM (UTC)
Read
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation…
Infosecurity Magazine Jul 16, 2026, 11:51 AM (UTC)
Read
The perpetrators of the 2024 TfL cyber-attack have been jailed for five and a half years each after pleading guilty to Computer Misuse Act offences
The Hacker News Jul 16, 2026, 11:32 AM (UTC)
Read
Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click "Buy Now" instead. Ask a coding assistant to apply a maintainer's fix from a GitHub thread, and a fake comment can make it run a stranger's command on you…
The Hacker News Jul 16, 2026, 11:17 AM (UTC)
Read
An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin ("srt64.sys"), as the kernel-mode rootkit is…
The Hacker News Jul 16, 2026, 10:10 AM (UTC)
Read
Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, expl…
Infosecurity Magazine Jul 16, 2026, 09:25 AM (UTC)
Read
SANS Institute says governance programs are still nascent even as AI failures and threats grow
The Hacker News Jul 16, 2026, 09:23 AM (UTC)
Read
Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people's Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaint…
Infosecurity Magazine Jul 16, 2026, 08:50 AM (UTC)
Read
The White House announced Gold Eagle to help accelerate the discovery, prioritization and patching of flaws found by AI
The Hacker News Jul 16, 2026, 08:42 AM (UTC)
Read
OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely. "GPT‑Red is a strong red-teamer, and our previous models are h…
The Hacker News Jul 16, 2026, 07:22 AM (UTC)
Read
Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Workplace for Windows before version 7.0.0…
The Hacker News Jul 15, 2026, 06:43 PM (UTC)
Read
Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successfu…
The Hacker News Jul 15, 2026, 03:30 PM (UTC)
Read
A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet's own desktop softw…
Infosecurity Magazine Jul 15, 2026, 03:00 PM (UTC)
Read
Six-month phishing campaign used seasonal eCard lures to plant legitimate RMM tools on victims
Infosecurity Magazine Jul 15, 2026, 02:00 PM (UTC)
Read
Eleven forgotten Microsoft-signed UEFI shims can bypass Secure Boot on almost any machine
The Hacker News Jul 15, 2026, 01:18 PM (UTC)
Read
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a…
Cybersecurity Ventures Jul 15, 2026, 12:51 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 15, 2026 – Listen to the podcast Hunting Warhead is an award-winning investigative true-crime podcast from CBC Podcasts and the Norwegian newspaper VG. Hosted by Daemon…
Infosecurity Magazine Jul 15, 2026, 12:45 PM (UTC)
Read
Research of incidents by Sophos finds that phishing, brute force attacks and other identity-based threats have surpassed software vulnerabilities as means of delivering ransomware
Infosecurity Magazine Jul 15, 2026, 12:00 PM (UTC)
Read
Progress has restored access to its ShareFile Storage Zones Controller after a four-day suspension triggered by a credible external security threat
The Hacker News Jul 15, 2026, 11:50 AM (UTC)
Read
For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem…
The Hacker News Jul 15, 2026, 11:07 AM (UTC)
Read
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User…
The Hacker News Jul 15, 2026, 11:06 AM (UTC)
Read
A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reveals how this Approval Gap forms, and gives your team the blu…
The Hacker News Jul 15, 2026, 10:55 AM (UTC)
Read
Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your s…
Infosecurity Magazine Jul 15, 2026, 09:20 AM (UTC)
Read
Microsoft released fixes for a record 570 CVEs in its July Patch Tuesday update, as experts warn AI is dramatically accelerating vulnerability discovery and increasing patch volumes
The Hacker News Jul 15, 2026, 09:16 AM (UTC)
Read
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below - @asyncapi/generator-helper…
Infosecurity Magazine Jul 15, 2026, 08:48 AM (UTC)
Read
The UK government is warning of the potential impact of catastrophic cyber-attacks
The Hacker News Jul 15, 2026, 05:30 AM (UTC)
Read
SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below - CVE-2026-154…
The Hacker News Jul 14, 2026, 08:25 PM (UTC)
Read
Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of aro…
Krebs on Security Jul 14, 2026, 07:22 PM (UTC)
Read
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last mont…
The Hacker News Jul 14, 2026, 06:17 PM (UTC)
Read
SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds wr…
The Hacker News Jul 14, 2026, 05:27 PM (UTC)
Read
Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar. Both this and ClaudeBleed need a rogue extension that can already run a sc…
The Hacker News Jul 14, 2026, 04:52 PM (UTC)
Read
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. "LabubaRAT creates a reusable foothold for hands-on activity," Bla…
Infosecurity Magazine Jul 14, 2026, 03:28 PM (UTC)
Read
The US Department of Defense announced the immediate suspension of the CMMC Phase II requirements until further review
The Hacker News Jul 14, 2026, 01:48 PM (UTC)
Read
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass…
Cybersecurity Ventures Jul 14, 2026, 12:51 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 14, 2026 – Watch the YouTube video “When high-trust individuals are compromised, the blast radius reaches well beyond them to their companies, partners, and networks,”…
Infosecurity Magazine Jul 14, 2026, 12:00 PM (UTC)
Read
Researchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and more
Infosecurity Magazine Jul 14, 2026, 09:43 AM (UTC)
Read
Supermarket giant Lidl has revealed details of a supplier breach impacting customer data
Infosecurity Magazine Jul 14, 2026, 08:21 AM (UTC)
Read
Five UK residents have been charged in relation to supplying Russian Coms fraud devices and apps
Infosecurity Magazine Jul 13, 2026, 03:30 PM (UTC)
Read
Misconfigured server exposed three phishing operators running Evilginx forks to bypass MFA
Krebs on Security Jul 13, 2026, 03:03 PM (UTC)
Read
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before…
Infosecurity Magazine Jul 13, 2026, 02:45 PM (UTC)
Read
Chinese and Indian spies converged on the same Balochistan police force, SentinelLabs found
Infosecurity Magazine Jul 13, 2026, 01:00 PM (UTC)
Read
New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments
Cybersecurity Ventures Jul 13, 2026, 12:41 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 13, 2026 – Listen to the podcast Larry Clinton is the President and CEO of the Internet Security Alliance. Since 2001, ISA strives to promote the recognition of cyberse…
Infosecurity Magazine Jul 13, 2026, 12:05 PM (UTC)
Read
Progress Software, the provider of the popular file-sharing and data storage solutions, has urged customers to shut down the server hosting their Storage Zone Controller
Infosecurity Magazine Jul 13, 2026, 10:40 AM (UTC)
Read
Cybersecurity agencies from 12 countries have warned that Russian state-backed hackers are actively targeting vulnerable routers using weak SNMP credentials
Infosecurity Magazine Jul 13, 2026, 09:30 AM (UTC)
Read
An Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operation
Infosecurity Magazine Jul 13, 2026, 08:30 AM (UTC)
Read
Australian Cyber Security Centre warns CMS users of mass scanning and exploitation campaign
Infosecurity Magazine Jul 10, 2026, 04:00 PM (UTC)
Read
CISA reveals how it responded after sensitive AWS GovCloud credentials and internal data were exposed in a public GitHub repository
Infosecurity Magazine Jul 10, 2026, 03:30 PM (UTC)
Read
A new multi-purpose backdoor allows cyber threat actors to conduct both quiet espionage activity and destructive wiping operations
Infosecurity Magazine Jul 10, 2026, 01:45 PM (UTC)
Read
Researchers at the AI Now Institute developed a proof-of-concept exploit showing common AI tools used for security could backfire
Infosecurity Magazine Jul 10, 2026, 01:00 PM (UTC)
Read
GodDamn ransomware uses remote desktop application to secretly move around networks and drop the malicious PoisonX kernel driver
Cybersecurity Ventures Jul 10, 2026, 12:18 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 10, 2026 – Watch the video The Cybercrime Magazine media team will step into the Business Hall at Black Hat USA in Las Vegas Aug. 2-4 and experience the future of cyber…
Infosecurity Magazine Jul 10, 2026, 09:33 AM (UTC)
Read
Microsoft has said the volume of Windows security updates is set to grow as it uses AI to find new bugs
Infosecurity Magazine Jul 10, 2026, 09:00 AM (UTC)
Read
NHS tells staff they could face prison for “inappropriate” access to patients’ medical records
Infosecurity Magazine Jul 9, 2026, 02:00 PM (UTC)
Read
Huntress found a threat actor using vibe-coded PowerShell to map an Active Directory network
Cybersecurity Ventures Jul 9, 2026, 12:29 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 9, 2026 – Listen to the podcast Strangers were watching your children sleep. For months, anyone with basic technical knowledge could access 1.1 million baby monitors an…
Infosecurity Magazine Jul 9, 2026, 12:00 PM (UTC)
Read
Survey of cybersecurity leaders by MetaCompliance finds that many feel boards are uninterested in ever-evolving cyber risks
Infosecurity Magazine Jul 9, 2026, 11:45 AM (UTC)
Read
Operation First Light 2026, coordinated by Interpol and funded by the Chinese government, has led to 5,811 arrests
Infosecurity Magazine Jul 9, 2026, 11:00 AM (UTC)
Read
Wiz discovered GhostApproval, a symlink flaw in six major AI coding assistants that bypasses approval
Infosecurity Magazine Jul 9, 2026, 09:30 AM (UTC)
Read
Over 70 cybersecurity organizations have signed the CREST AI Charter detailing responsible use of AI for security
Infosecurity Magazine Jul 9, 2026, 07:30 AM (UTC)
Read
Cybersecurity researchers at ESET identify big rise in suspicious and malicious toolsets which put users at risk from cyber-attacks
Infosecurity Magazine Jul 8, 2026, 03:30 PM (UTC)
Read
Zimperium found RedWing, an Android spyware sold as a service via Telegram to target banking apps
Infosecurity Magazine Jul 8, 2026, 02:30 PM (UTC)
Read
Cisco Talos said China-linked APT UAT-7810 is growing its proxy relay network with new malware
Cybersecurity Ventures Jul 8, 2026, 12:59 PM (UTC)
Read
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 8, 2026 – Listen to the podcast The Internet is often portrayed as a neutral space, open and even democratic, a place full of possibilities. But for many women, the web…
Krebs on Security Jul 8, 2026, 12:31 PM (UTC)
Read
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a…
Infosecurity Magazine Jul 8, 2026, 12:30 PM (UTC)
Read
Sygnia report details how agentic AI accelerated weeks-long attack to just 72 hours
Infosecurity Magazine Jul 8, 2026, 11:00 AM (UTC)
Read
Cyber threat actors are infecting victims with the Vidar stealer and the XMRig cryptocurrency miner in a new malicious campaign
Infosecurity Magazine Jul 8, 2026, 08:10 AM (UTC)
Read
The National Cyber Security Centre wants to work with AI partners to build a new “Cyber Shield” to defend the UK
Cybersecurity Ventures Jul 7, 2026, 07:04 PM (UTC)
Read
Because scaling security isn’t just about better detection—it’s about removing the friction around it – Mayuresh Ektare, Senior Vice President, Product Management San Jose, Calif. – Jul. 7, 2026 Every security team wants better outcomes. Faster detection. Fast…
Infosecurity Magazine Jul 7, 2026, 03:40 PM (UTC)
Read
A suspected Chinese threat cluster is exploiting Roundcube vulnerabilities to compromise university networks in the US and Canada and harvest user credentials
Infosecurity Magazine Jul 7, 2026, 02:00 PM (UTC)
Read
Group-IB analysis argued Scattered Spider is a decentralized collective of independent clusters
Infosecurity Magazine Jul 7, 2026, 10:00 AM (UTC)
Read
More than 60 organizations, including M&S, Microsoft UK and Vodafone, have signed the UK government's Cyber Resilience Pledge, a new initiative aimed at boosting cyber security and resilience across British businesses
Infosecurity Magazine Jul 7, 2026, 08:20 AM (UTC)
Read
Threat actors are exploiting an Adobe ColdFusion vulnerability which has a CVSS score of 10.0
Infosecurity Magazine Jul 7, 2026, 07:00 AM (UTC)
Read
Attacks also used a compromised chatbot in campaign to steal sensitive information from Business Users