2026 January(387) February(431) March(447) April(451) May(495) June(499) July(196) August(0) September(0) October(0) November(0) December(0) | YEARS(2 906) STATISTICS (0)
DATE |
NAME |
Info |
CATEG. |
WEB |
| 15.7.26 | Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands | SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. | Vulnerebility | The Hacker News |
| 15.7.26 | Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack | Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release | Vulnerebility | The Hacker News |
| 14.7.26 | SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data | SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver | Vulnerebility | The Hacker News |
| 14.7.26 | Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads | Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google | AI | The Hacker News |
| 14.7.26 | LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts | Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that | Virus | The Hacker News |
| 14.7.26 | RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata | Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could | Vulnerebility | The Hacker News |
| 14.7.26 | 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot | Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern | OS | The Hacker News |
| 14.7.26 | Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks | Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves | Cryptocurrency | The Hacker News |
| 14.7.26 | How Pentera Turns AI Security Workflows into Validation Engines | AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and | AI | The Hacker News |
| 14.7.26 | OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials | At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while | Hack | The Hacker News |
| 14.7.26 | Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read | xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not | AI | The Hacker News |
| 14.7.26 | U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support | The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling | Ransom | The Hacker News |
| 14.7.26 | Defending SaaS-based applications against ShinyHunters OAuth abuse | In a series of campaigns observed between mid-2025 and mid-2026, Microsoft identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply chain compromise, and misconfigured guest access to target customer SaaS-based applications such as Salesforce instances. | Phishing blog | Microsoft blog |
| 14.7.26 | 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet | A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for | BotNet | The Hacker News |
| 14.7.26 | Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity | Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in | APT | The Hacker News |
| 13.7.26 | CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks | Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from | Virus | The Hacker News |
| 13.7.26 | Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found | Google and Microsoft have pulled ModHeader , a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after | Hack | The Hacker News |
| 13.7.26 | Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft | A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing , adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts. | Phishing | The Hacker News |
| 13.7.26 | Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory | Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory | AI | The Hacker News |
| 13.7.26 | Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 | An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. | Phishing | The Hacker News |
| 13.7.26 | iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and | Exploit | The Hacker News |
| 12.7.26 | Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install | The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook that drops and executes a native binary, one build each for Windows, macOS, and Linux. | Virus | The Hacker News |
| 12.7.26 | Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns | Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement | APT | The Hacker News |
| 12.7.26 | 'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets | A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit,' slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo's .env and write every secret into the code as a list of numbers. | AI | BleepingComputer |
| 12.7.26 | New U-Boot flaws could enable stealthy firmware attacks | Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware. | Vulnerebility | BleepingComputer |
| 12.7.26 | Ryuk ransomware member pleads guilty in the US, faces 15 years in prison | A 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. | Ransom | BleepingComputer |
| 12.7.26 | Police suspects Dutch hackers were involved in Odido breach | The Dutch National Police (Politie) says it has found "strong indications" that Dutch hackers have been involved in a February breach at the telecommunications provider Odido. | BigBrothers | BleepingComputer |
| 12.7.26 | Progress urges ShareFile admins to shut down servers over “credible” threat | Progress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a "credible external security threat" targeting the on-premises secure file-sharing software. | Vulnerebility | BleepingComputer |
| 12.7.26 | Hackers exploit critical auth bypass in Gitea Docker image | Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators. | Exploit | BleepingComputer |
| 12.7.26 | Money launderer accused of stealing seized crypto while in prison | A Bulgarian national has been charged with stealing $290,000 in government-seized cryptocurrency while serving 121 months in prison for helping launder millions stolen from American fraud victims | Cryptocurrency | BleepingComputer |
| 12.7.26 | The Replicant in Your Directory: AI Agents and the Identity Security Gap | AI agents are accelerating the growth of non-human identities, making it harder for organizations to understand what exists, who owns it, and what it can access. Netwrix explains why stronger visibility and identity governance are essential as AI expands the enterprise attack surface. | AI | BleepingComputer |
| 12.7.26 | Zimbra urges customers to patch critical web client XSS flaw | The Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite. | Vulnerebility | BleepingComputer |
| 12.7.26 | Former ransomware negotiator gets 4 years for BlackCat attacks | A former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. | Ransom | BleepingComputer |
| 12.7.26 | OpenMandriva Linux says contributor tried to sabotage the project | The OpenMandriva Linux project announced that it was the target of an attempted act of internal sabotage after a dispute among contributors. | OS | BleepingComputer |
| 12.7.26 | Injective SDK on npm infected with cryptocurrency wallet stealer | Hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases. | Cryptocurrency | BleepingComputer |
| 11.7.26 | New Helix vishing group emerges in SharePoint data theft attacks | A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. | Phishing | BleepingComputer |
| 11.7.26 | Microsoft expects more Windows security updates from AI-discovered flaws | Microsoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase. | AI | BleepingComputer |
| 11.7.26 | New Forg365 phishing platform uses AI to target Microsoft 365 accounts | A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. | AI | BleepingComputer |
| 11.7.26 | The Hidden Security Risks of Reduced Summer IT Coverage | Security operations don't slow down when IT teams take vacation, but staffing levels often do. Kaseya explains how AI-driven automation can help organizations maintain consistent security operations and reduce reliance on manual processes year-round. | AI | BleepingComputer |
| 11.7.26 | Microsoft to retire the OWA Light client in Exchange Server | Microsoft has announced plans to disable Outlook Web Access (OWA) Light, the lightweight version of the Outlook Web App email client, in a future Exchange Server update. | OS | BleepingComputer |
| 11.7.26 | Police arrests 5,800 suspects in global anti-fraud crackdown | Law enforcement agencies have arrested 5,811 suspects and seized $293 million in illicit assets in a global anti-fraud operation spanning 97 countries. | BigBrothers | BleepingComputer |
| 11.7.26 | AssuranceAmerica data breach exposes records of 6.9 million drivers | American insurance company AssuranceAmerica has disclosed a data breach impacting nearly 7 million drivers after attackers gained access to its systems earlier this year. | Incindent | BleepingComputer |
| 11.7.26 | Microsoft patches RoguePlanet Defender zero-day vulnerability | Microsoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. | Vulnerebility | BleepingComputer |
| 11.7.26 | Mount Royal University confirms breach as hackers claim attack | Mount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university's network. | Incindent | BleepingComputer |
| 11.7.26 | Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials | Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications. | Virus | BleepingComputer |
| 11.7.26 | Hackers exploit Roundcube flaw to spy on academic researchers | A China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. | Exploit | BleepingComputer |
| 11.7.26 | Entra passkey enrollment vishing targets Microsoft 365 users | A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey. | Phishing | BleepingComputer |
| 11.7.26 | 3 Ways AI Powers Service Desk Attacks and How to Prevent Them | Specops Software explains how AI is making service desk impersonation attacks more convincing, personalized, and scalable, along with practical steps organizations can take to strengthen onboarding and identity verification. | AI | BleepingComputer |
| 11.7.26 | Telco giant KDDI says data breach affects over 12 million people | Japanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country. | Incindent | BleepingComputer |
| 11.7.26 | CISA orders feds to prioritize patching Langflow auth bypass flaw | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents. | Vulnerebility | BleepingComputer |
| 11.7.26 | Ubiquiti warns of new max severity UniFi OS vulnerability | Ubiquiti has released security updates to patch seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw that can be exploited in command injection attacks. | Vulnerebility | BleepingComputer |
| 11.7.26 | "Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection? | Anyone who deals with phishing messages caught by basic security filters knows that most phishing samples tend to blend into one another, since only a small set of techniques and approaches keeps reappearing in them. That is precisely why it is worth pausing on the occasional message that does something a little out of the ordinary. | Phishing | SANS |
| 11.7.26 | Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions | Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in | Vulnerebility | The Hacker News |
| 11.7.26 | URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat | Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to | Vulnerebility | The Hacker News |
| 11.7.26 | Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages | Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the | Hack | The Hacker News |
| 11.7.26 | Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot | Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home | Vulnerebility | The Hacker News |
| 11.7.26 | Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched | Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto | Hack | The Hacker News |
| 11.7.26 | Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws | Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if | Social | The Hacker News |
| 11.7.26 | Phishing in the Balkans: Fake Traffic Fines, Real Losses | This blog documents Group-IB’s research into an SMS phishing campaign targeting Serbian road users through the impersonation of Serbia's state road authority, and how it can be linked to both Darcula and Phoenix PhaaS platforms with victims across the globe. | Phishing blog | GROUP-IB |
| 11.7.26 | Connecting Scattered Spider: Defining A Cybercrime Collective Through Shared TTPs | This blog covers Group-IB’s overview of Scattered Spider, backed by Group-IB’s proprietary intelligence, providing additional information to what has already been reported publicly, with added clarification on 0ktapus and how it is related to Scattered Spider. | Hacking blog | GROUP-IB |
| 11.7.26 | RedHook Returns with a Dangerous Upgrade | Group-IB analysts examine this resurfaced Android Remote Access Trojan, demonstrating new, sophisticated and malicious functionalities including autonomous privilege abuse, expanded command-and-control capabilities, and a robust persistence stack. | Malware blog | GROUP-IB |
| 11.7.26 | Sophos named a 2026 Gartner® Peer Insights™ Customers’ Choice for Email Security | Sophos has been named a 2026 Gartner® Peer Insights™ Customers’ Choice in the 2026 Gartner® Peer Insights™ Voice of the Customer for Email Security. This marks Sophos’ entry into the report, as well as Sophos’ first ever Customers’ Choice distinction for Email Security. | Cyber blog | SOPHOS |
| 11.7.26 | When AI agents look like attackers: what behavioral telemetry tells us | An X-Ops analysis of how AI coding agents trigger endpoint detection rules designed for adversaries | AI blog | SOPHOS |
| 11.7.26 | "Exploit mitigation" stalled around 2008. The attacks didn't. | AI turns a patched bug into a working exploit in hours. Why endpoint exploit mitigation stalled in 2008, and what a default-on mitigation layer looks like now. | AI blog | SOPHOS |
| 11.7.26 | The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. | Hacking blog | GTI | |
| 11.7.26 | The Two BIOS Passwords Everyone Confuses | When someone tells me “we set the BIOS password on the fleet,” my first question is always “which one?” Because there are at least two firmware passwords on a modern machine, they do completely different things, and the failure I see most often is a team that sets one, assumes it covers the other, and leaves a gap they do not know they have. | Hacking blog | Eclypsium |
| 11.7.26 | Post-Mythos Cybersecurity: Can You Automate Infrastructure Assurance with AI? | Programs like Anthropic’s Mythos and OpenAI’s Daybreak are changing how organizations think about security architecture, internal engineering, staffing, and vendor commitments. OpenAI describes Daybreak as a defender-focused program for finding, validating, and fixing vulnerabilities before attackers can exploit them. | AI blog | Eclypsium |
| 11.7.26 | From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations | Table of Contents Introduction Infection Chain Technical Analysis Conclusion Seqrite Coverage Indicators of Compromise (IOCs) MITRE ATT&CK Mapping Introduction The Seqrite Threat Research Team identified a targeted spear-phishing campaign disguised as a legitimate business invoice. The phishing email impersonates a legitimate... | Phishing blog | Seqrite |
| 11.7.26 | Inside the Underground Economy: 5 Dark Web Trends Shaping the 2026 Threat Landscape | Cyble breaks down how dark web ecosystems are evolving in 2026 with ransomware, initial access brokers, AI-driven attacks, and underground threat activity. | Cyber blog | Cyble |
| 11.7.26 | Mid-Year Threat Trends: What H1 2026 Signals for the Rest of the Year | H1 2026 threat intelligence trends show rising ransomware, AI-driven attacks, and identity risks reshaping the global cyber risk outlook for 2026. | Cyber blog | Cyble |
| 11.7.26 | Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App | CRIL analyzes Glitch SPY, an Android RAT with 70+ commands, crypto-clipping, and a silent remote browser, giving attackers full device control. | Malware blog | Cyble |
| 11.7.26 | GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses | Third iteration of ransomware from Hyadina developers who first launched the Monster ransomware in 2022. | Ransom blog | SECURITY.COM |
| 11.7.26 | GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware | GigaWiper is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. | Malware blog | Microsoft blog |
| 11.7.26 | rclone Remote-Control API Unauthenticated Command Execution | rclone Remote-Control API Unauthenticated Command Execution (CVE-2026-41179) | Vulnerebility blog | SonicWall |
| 11.7.26 | Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation | In April 2026, Unit 42 researchers identified a financially motivated campaign delivering Vidar stealer and the XMRig cryptocurrency miner to consumer and small- and medium-sized business victims worldwide. | Malware blog | Palo Alto |
| 11.7.26 | Cavern Manticore: Exposing Iran-Linked Modular C2 Framework | Note: SysAid was not compromised, and no SysAid vulnerability was involved. The attacker had already gained access to the victim environment and abused a legitimate software-deployment feature to deploy malware onto another machine within it. | APT blog | CHECKPOINT |
| 11.7.26 | Winning 54% of the time | With Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be right 100% of the time." | Cyber blog | CISCO TALOS |
| 11.7.26 | UAT-7810 continues building ORB networks using new malware | Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware. | Malware blog | CISCO TALOS |
| 11.7.26 | ESET Threat Report H1 2026 | A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts. | Cyber blog | Eset |
| 10.7.26 | New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic | The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called | Virus | The Hacker News |
| 10.7.26 | Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers | A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of | Vulnerebility | The Hacker News |
| 10.7.26 | Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites | A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the | Hack | The Hacker News |
| 10.7.26 | Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking | Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the | Security | The Hacker News |
| 10.7.26 | Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access | A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft | Hack | The Hacker News |
| 10.7.26 | Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets | Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom , and attackers are already using it. The flaw is in how some wallet | Exploit | The Hacker News |
| 10.7.26 | Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks | A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to | Ransom | The Hacker News |
| 10.7.26 | My Stack Simulator | The stack is a memory region where a program stores temporary data - like local variables and return addresses. Think of the stack as a pile of plates in your kitchen: you can only add a new plate to the top, and you can only take one away from the top too. Programs use this same "last in, first out" principle to keep track of what they're doing. | Security | SANS |
| 10.7.26 | _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary] | Every so often a honeypot hit comes along that is less about the exploit and more about the intent behind it. While reviewing DShield logs I ran into a scanning bot that caught my eye: a URI string that appeared to be a plea for help. | Exploit | SANS |
| 10.7.26 | Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs | Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. | Hack | The Hacker News |
| 10.7.26 | New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware | Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper . What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator | Virus | The Hacker News |
| 10.7.26 | npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk | GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access | Hack | The Hacker News |
| 9.7.26 | Threat landscape for industrial automation systems. Q1 2026 | This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry. | ICS | SECURELIST |
| 9.7.26 | Summer of Clearinghouses | Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena , and the main thing that sets it | Security | The Hacker News |
| 9.7.26 | GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses | Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security | Ransom | The Hacker News |
| 9.7.26 | Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges | Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became | Vulnerebility | The Hacker News |
| 9.7.26 | CISA orders feds to patch max severity ColdFusion flaw by Friday | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday. | Vulnerebility | BleepingComputer |
| 9.7.26 | Accenture confirms breach after hacker offers stolen data for sale | IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. | Incindent | BleepingComputer |
| 9.7.26 | Chinese hackers develop LONGLEASH malware to expand ORB network | Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. | Virus | BleepingComputer |
| 9.7.26 | Hidden backdoor in Tenda router firmware grants admin access | A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web management panel. | Virus | BleepingComputer |
| 9.7.26 | Spain arrests suspected member of pro-Russian hacktivist groups | The National Police in Spain have arrested a man who is suspected of being an active member of the CyberArmy of Russia Reborn (CARR) and Z-Pentest, both pro-Russian hacktivist groups. | BigBrothers | BleepingComputer |
| 9.7.26 | The GitHub Actions Attack Pattern Your CI Security Scanners Miss | ActiveState explains how GitHub Actions attack chains can evade traditional CI security scanners, why passing a scan doesn't guarantee a secure pipeline, and how organizations can better govern their CI/CD workflows. | Hack | BleepingComputer |
| 9.7.26 | New Januscape Linux flaw allows VM escape on Intel, AMD devices | A 16-year-old Linux kernel vulnerability, dubbed Januscape, allows attackers to escape a virtual machine and execute arbitrary code on the host. | Vulnerebility | BleepingComputer |
| 9.7.26 | Microsoft to enable Windows settings backup by default for orgs | Microsoft says the Windows settings backup and restore tool will be enabled by default on Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems after upgrading to Windows 11 26H2 | OS | BleepingComputer |
| 9.7.26 | BeyondTrust warns of critical flaws in remote access software | BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. | Vulnerebility | BleepingComputer |
| 9.7.26 | Microsoft testing new Cloud Rebuild Windows 11 recovery feature | Microsoft has begun testing the Cloud Rebuild recovery feature in the latest Windows 11 Insider Preview builds released for users in the Experimental channel. | OS | BleepingComputer |
| 9.7.26 | Phishing poses as big-brand job interview to steal Google accounts | A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals. | Phishing | BleepingComputer |
| 9.7.26 | Fake IT support calls on Microsoft Teams push EtherRAT malware | Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. | Virus | BleepingComputer |
| 9.7.26 | Vietnam arrests suspects behind HiAnime anime piracy service | Vietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shutdown in June. | BigBrothers | BleepingComputer |
| 9.7.26 | Software Is Now Written at the Speed of Thought. Security Isn't. | Every evolution in software development has reduced the friction between an idea and a deployable application. AI may remove the final barrier, but it also removes many of the moments where security decisions have traditionally taken place. | AI | BleepingComputer |
| 9.7.26 | Max severity Adobe ColdFusion flaw now exploited in attacks | Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, according to vulnerability intelligence company KEVIntel. | Exploit | BleepingComputer |
| 9.7.26 | Friendly Fire: Hijacking Defensive Cyber AI Agents for Remote Code Execution | We are revealing a proof-of-concept exploit that enables remote code execution in Anthropic’s Claude Code CLI (with Claude Sonnet 4.6 & 5, Opus 4.8) and OpenAI’s Codex CLI (with GPT-5.5) when employed to defensively assess the security of an open-source or third-party library. | AI blog | AINOW |
| 9.7.26 | Fake 7-Zip downloads are turning home PCs into proxy nodes | A convincing lookalike of the popular 7-Zip archiver site has been serving a trojanized installer that silently converts victims’ machines into residential proxy nodes—and it has been hiding in plain sight for some time. | Hacking blog | MALWAREBYTES |
| 9.7.26 | Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images | Meta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI | AI | The Hacker News |
| 9.7.26 | Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It | Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the | AI | The Hacker News |
| 9.7.26 | GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents | Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's | AI | The Hacker News |
| 9.7.26 | Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes | Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious | Hack | The Hacker News |
| 9.7.26 | AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers | Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are | AI | The Hacker News |
| 8.7.26 | New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware | AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a | AI | The Hacker News |
| 8.7.26 | Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS | Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and | Vulnerebility | The Hacker News |
| 8.7.26 | New Ghost Phishing Wave Is Breaking Traditional Email Security | A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to | Phishing | The Hacker News |
| 8.7.26 | SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users | A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using | Virus | The Hacker News |
| 8.7.26 | GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures | New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any | Security | The Hacker News |
| 8.7.26 | GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code | An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken into small, ordinary-looking steps inside a code editor. That is the finding of a new study of GitHub Copilot by researchers Abhishek Kumar and Carsten Maple. | AI | The Hacker News |
| 8.7.26 | China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware | A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by | APT | The Hacker News |
| 8.7.26 | More Odd DNS Records: NIMLOC | Yesterday, I talked about NAPTR records and how they are related to RCS. But there is another "odd" record that shows up in my DNS logs. This one isn't new, but I don't think I ever covered it: NIMLOC. At least that is what Zeek calls it. But let's see what it is all about. | Security | SANS |
| 8.7.26 | RCS and DNS: The NAPTR Record | Over the last year, with recent updates to iOS and Android, RCS (Rich Communication Services) has become an increasingly used protocol. | OS | SANS |
| 8.7.26 | Why Ask Credentials If There Are Secret Codes? | This morning, an interesting phishing email hit my mailbox. It targets Metamask, a cryptocurrency wallet, available as a browser extension and a mobile app, that lets users store, send, and receive crypto money. | Security | SANS |
| 8.7.26 | When prompts become shells: RCE vulnerabilities in AI agent frameworks | AI agents have fundamentally changed the threat model of AI model-based applications. By equipping these models with plugins (also called tools), your agents no longer just generate text; they now read files, search connected databases, run scripts, and perform other tasks to actively operate on your network. | AI blog | Microsoft blog |
| 8.7.26 | 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros | Researchers at Nebula Security have disclosed GhostLock ( CVE-2026-43499 ), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable | Vulnerebility | The Hacker News |
| 8.7.26 | CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities ( | Exploit | The Hacker News |
| 8.7.26 | RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service | A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill | Virus | The Hacker News |
| 8.7.26 | Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots | A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code | Vulnerebility | The Hacker News |
| 7.7.26 | DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts | A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts | Phishing | The Hacker News |
| 7.7.26 | Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data | A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown. The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access to the organization. | Hack | The Hacker News |
| 7.7.26 | Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker | U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, | CyberCrime | The Hacker News |
| 7.7.26 | Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants | Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer , an enterprise generative | AI | The Hacker News |
| 7.7.26 | Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities | A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and | Exploit | The Hacker News |
| 7.7.26 | When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website | The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it. | Phishing | SECURELIST |
| 7.7.26 | CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware | Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented | BigBrothers | The Hacker News |
| 7.7.26 | BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA | BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated | Vulnerebility | The Hacker News |
| 7.7.26 | Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations | An Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular | APT | The Hacker News |
| 6.7.26 | 16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems | A use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel | Vulnerebility | The Hacker News |
| 6.7.26 | Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure | Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig | Vulnerebility | The Hacker News |
| 6.7.26 | Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT | A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance | Virus | The Hacker News |
| 6.7.26 | New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions | Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, | Virus | The Hacker News |
| 6.7.26 | New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS | Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that's capable of targeting Windows, Linux, and macOS environments. According to LevelBlue, the cross-platform malware is advertised under a malware-as-a-service (MaaS) model, costing anywhere between $150 for one month to $1,200 for lifetime access. | Virus | The Hacker News |
| 6.7.26 | Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages | Researchers found a flaw in Opera GX , the gaming-focused version of the Opera browser, that let a malicious website silently install a browser | Vulnerebility | The Hacker News |
| 6.7.26 | SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing | Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology. | Virus | The Hacker News |
| 5.7.26 | Flipper Zero firmware development continues with community help | Flipper Devices says development of the Flipper Zero firmware will continue, albeit with a smaller internal team and greater reliance on community contributions. | Security | BleepingComputer |
| 5.7.26 | JadePuffer ransomware used AI agent to automate entire attack | Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. | Ransom | BleepingComputer |
| 5.7.26 | NetNut proxy network disrupted, 2 million infected devices cut off | A joint operation involving Google has disrupted NetNut, a residential proxy network that gave access to millions of compromised Android devices, including smart TVs and streaming boxes. | Virus | BleepingComputer |
| 5.7.26 | ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit | A new phishing-as-a-service (PhaaS) platform dubbed "ARToken" appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed to compromise Microsoft 365. | Phishing | BleepingComputer |
| 5.7.26 | Google loses final appeal to overturn €4.1 billion EU fine | Court of Justice of the European Union (CJEU) has dismissed Google's final appeal against a €4.1 billion ($4.7 billion) antitrust fine over the company's use of Android to promote its Chrome browser and search service. | BigBrothers | BleepingComputer |
| 5.7.26 | ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds | ConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and OAuth flows. Learn how these MFA bypass tactics work and how to defend against them. | Hack | BleepingComputer |
| 5.7.26 | Microsoft fixes bug that removed Copilot buttons in Outlook | Microsoft has fixed a known issue causing the Copilot Chat or Copilot buttons in Classic Outlook to disappear for Windows users with the Copilot Chat (Basic) license. | OS | BleepingComputer |
| 5.7.26 | Cisco finally confirms attackers exploiting Unified CM flaw | Cisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June. | Exploit | BleepingComputer |
| 5.7.26 | CISA: Microsoft SharePoint RCE flaw now actively exploited | CISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May. | Exploit | BleepingComputer |
| 5.7.26 | Opera rolls out Paste Protect feature to fight ClickFix attacks | Opera has introduced Paste Protect, a security feature designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering. | Hack | BleepingComputer |
| 5.7.26 | Alleged Scattered Spider hacker extradited to the United States | A dual United States and Estonian citizen has been extradited to the U.S. to face charges alleging he was a member of the Scattered Spider hacking collective. | CyberCrime | BleepingComputer |
| 5.7.26 | Medtronic notifies customers impacted by ShinyHunters data breach | Healthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party. | Incindent | BleepingComputer |
| 5.7.26 | FortiBleed credential-theft campaign linked to Lynx ransomware | The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. | Ransom | BleepingComputer |
| 5.7.26 | Kubota says hackers had month-long access to network systems | Kubota North America Corporation disclosed that hackers had access to some of its network systems for more than a month earlier this year. | Hack | BleepingComputer |
| 5.7.26 | New ChocoPoC malware targets researchers via trojanized PoC exploits | New ChocoPoC malware targets researchers via trojanized PoC exploits | Virus | BleepingComputer |
| 5.7.26 | DHS confirms hackers breached HSIN info-sharing platform | The Department of Homeland Security is investigating a cyberattack that compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used by federal, state, local, and private-sector partners. | Hack | BleepingComputer |
| 5.7.26 | Hackers target Microsoft 365 accounts with 81 million login attempts | An aggressive password-spraying campaign targeting Microsoft 365 environments generated more than 81 million login attempts over a two-week period. | Hack | BleepingComputer |
| 5.7.26 | Turning Indicators into Intelligence in OpenCTI with Criminal IP | Threat intelligence is only as useful as the context behind it. Criminal IP explains how its integration enriches threat indicators in OpenCTI with risk scoring, infrastructure intelligence, and phishing analysis. | CyberCrime | BleepingComputer |
| 5.7.26 | Over 900 Oracle E-Business instances exposed to ongoing attacks | Over 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw. | Hack | BleepingComputer |
| 5.7.26 | U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case | A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for | BigBrothers | The Hacker News |
| 5.7.26 | North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign | The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web | APT | The Hacker News |
| 4.7.26 | Microsoft fixes GIF functionality in the Windows Emoji Panel | Microsoft has fixed the GIF functionality in the Emoji Panel for Windows 11 users after the provider shut down its service. | OS | BleepingComputer |
| 4.7.26 | Amazon fined $2.25M for withholding evidence from fraud victims | The U.S. Federal Trade Commission (FTC) says Amazon will pay a $2.25 million civil penalty to settle charges that it blocked identity theft victims' access to transaction records. | CyberCrime | BleepingComputer |
| 4.7.26 | Adobe patches seven max severity ColdFusion, Campaign flaws | Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform. | Vulnerebility | BleepingComputer |
| 4.7.26 | Anthropic to restore Claude Fable access on Wednesday | Anthropic has confirmed that the Department of Commerce has lifted export controls on Claude's two most powerful models, Fable 5 and Mythos 5. | AI | BleepingComputer |
| 4.7.26 | Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price | Anthropic is now rolling out Sonnet 5, and it's almost as good as the Opus range, but it is designed to be cheaper than the company's flagship model. | AI | BleepingComputer |
| 4.7.26 | New BioShocking attack manipulates AI browser into data theft | A new prompt injection attack dubbed "BioShocking" could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardrails. | AI | BleepingComputer |
| 4.7.26 | Microsoft accelerates quantum-safe roadmap as risks grow | Microsoft announced today that it is accelerating its quantum-safe security roadmap, saying advances in quantum computing are bringing the need to replace today's encryption standards sooner than previously expected. | Safety | BleepingComputer |
| 4.7.26 | Malicious PyPI packages give hackers control of Telegram bot servers | A campaign active since last November has been targeting Python developers building Telegram bots with trojanized Pyrogram forks that allow attackers to read arbitrary files on compromised servers. | BotNet | BleepingComputer |
| 4.7.26 | Fake Perplexity extension on Chrome Web Store tracked searches | A malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information. | Security | BleepingComputer |
| 4.7.26 | Lessons from the Underground: How to Combat Business Email Compromise | Business Email Compromise is more than an email scam. It's a coordinated operation involving compromised accounts, financial research, and cash-out networks. Flare explores how underground forums reveal how BEC attacks are planned and executed. | Security | BleepingComputer |
| 4.7.26 | Insurance giant Aflac discloses data breach after subsidiary hack | American insurance giant Aflac has disclosed a new data breach after attackers breached its Japan subsidiary's systems and stole personal and bank account information of 4.38 million customers. | Incindent | BleepingComputer |
| 4.7.26 | Microsoft adds smarter bot protection to Teams meetings | Microsoft has introduced a new Teams admin policy that allows organizers to prevent third-party bots from joining meetings without approval. | BotNet | BleepingComputer |
| 4.7.26 | Kali Linux 2026.2 released with 9 new tools, NetHunter updates | Kali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements. | OS | BleepingComputer |
| 4.7.26 | Blackfield ransomware asks Nidec Corporation for $2 million ransom | The Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications. | Ransom | BleepingComputer |
| 4.7.26 | CISA: Windows BlueHammer flaw now exploited by ransomware gangs | CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. | Ransom | BleepingComputer |
| 4.7.26 | Nissan discloses employee data breach linked to Oracle zero-day attacks | Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group. | Incindent | BleepingComputer |
| 4.7.26 | Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices | Security firm runZero has disclosed seven vulnerabilities in FatFs , a small filesystem library that lets a device read and write the FAT and | Vulnerebility | The Hacker News |
| 4.7.26 | New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android | A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine | OS | The Hacker News |
| 4.7.26 | New Avalon Malware Framework Packs CrownX Ransomware Capabilities | Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by | Ransom | The Hacker News |
| 4.7.26 | North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets | Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to | APT | The Hacker News |
| 4.7.26 | GachiLoader adopts AI skill lure | AI skills are threat actors’ newest and most dangerous lures. | AI blog | THREATDOWN |
| 4.7.26 | A double-edged bleeding edge: Classifying AI threats | Sophos X-Ops presents a working taxonomy for attacks using, and targeting, AI | AI blog | SOPHOS |
| 4.7.26 | Vect and TeamPCP partner for ransomware campaigns | Credentials harvested through supply chain compromises enable large‑scale ransomware deployment | Ransom blog | SOPHOS |
| 4.7.26 | Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. | Hacking blog | GTI | |
| 4.7.26 | Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert information operations (IO) campaigns and a revitalization of pro-Russia hacktivism at an unprecedented scale. | APT blog | GTI | |
| 4.7.26 | Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment | Authors: Dixit Panchal & Soumen Burma Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Initial Mail: Email Attachment: Lure: Official GoI, Income Tax Document: Technical Analysis: Infrastructural Artefacts & Threat actor Attributions. Campaign Timeline. Conclusion:... | Cyber blog | Seqrite |
| 4.7.26 | Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App | CRIL analyzes Glitch SPY, an Android RAT with 70+ commands, crypto-clipping, and a silent remote browser, giving attackers full device control. | Malware blog | Cyble |
| 4.7.26 | The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security | Bring Your Own Vulnerable Driver (BYOVD) has gone from a niche tactic to a standard part of the ransomware playbook and Windows' own kernel hardening does little to stop it. | Hacking blog | SECURITY.COM |
| 4.7.26 | Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud | In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063’s Banana RAT banking malware by analyzing server-side artifacts and victim-side data. | Malware blog | Trend Micro |
| 4.7.26 | Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware | Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to evade script-based detections. | Malware blog | Trend Micro |
| 4.7.26 | TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry | In this blog entry, TrendAI™ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved. | Malware blog | Trend Micro |
| 4.7.26 | Android Arsink RAT Revisited Targeting User Credentials | The SonicWall Capture Labs threat research team identified an ongoing Android Remote Access Trojan (RAT) campaign that employs multiple techniques to harvest sensitive user information through phishing and data exfiltration activities by impersonating the actual app icons and using similar names. | Malware blog | SonicWall |
| 4.7.26 | Joomla Content Editor Remote Code Execution | The SonicWall Capture Labs threat research team became aware of a PHP code upload and execution vulnerability in Joomla products, assessed its impact, and developed mitigation measures. Joomla is a free, open-source Content Management System (CMS) used to build and manage websites and online applications. | Vulnerebility blog | SonicWall |
| 4.7.26 | Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector | Unit 42 researchers found that large language models (LLMs) consistently hallucinate web domains for legitimate brands. Adversaries are actively weaponizing this vector by registering these nonexistent domains to intercept traffic generated by AI systems. | AI blog | Palo Alto |
| 4.7.26 | Threat Brief: Mitigating Large-Scale Credential Attacks | Unit 42 is aware of a large-scale password spraying and credential theft campaign (“FortiBleed”) against Fortinet devices. We observed attempts targeting MSSQL devices as well, and have seen reports of Sophos devices also being targeted. | Hacking blog | Palo Alto |
| 4.7.26 | CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure | Throughout 2025, we observed a cluster of activity targeting government entities and critical infrastructure in Southeast Asia. Specifically, the activity targeted state-owned enterprises in the energy and government sectors. | APT blog | Palo Alto |
| 4.7.26 | Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique | AI can turn high-level malicious ideas into concrete techniques, and can independently design and implement novel attack paths that have not yet appeared in real-world campaigns. | AI blog | CHECKPOINT |
| 4.7.26 | ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 | Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration. | Phishing blog | CISCO TALOS |
| 4.7.26 | Catan and Mouse | What do board games and cybersecurity have in common? Pattern recognition. Strategy. Adaptation. In this week’s Threat Source Bill explores why curiosity may be a defender’s most valuable skill. | Cyber blog | CISCO TALOS |
| 4.7.26 | Martin Lee: Running through the Arctic (and the threat landscape) | Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? In this Humans of Talos, we’re joined by Martin Lee, EMEA Lead, to talk about his journey into the industry. | Cyber blog | CISCO TALOS |
| 4.7.26 | Cyber readiness for SMBs: Getting the basics right | AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps | Cyber blog | Eset |
| 4.7.26 | This month in security with Tony Anscombe – June 2026 edition | Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026 | Cyber blog | Eset |
| 4.7.26 | Inside the inbox: Why cybercriminals want to break into your email account | Your inbox is an identity system all of its own: whoever owns it may own a lot more | Cyber blog | Eset |
| 3.7.26 | Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer | A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the | Virus | The Hacker News |
| 3.7.26 | European Parliament Member Investigating Spyware Was Hacked With Pegasus | A new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device | BigBrothers | The Hacker News |
| 3.7.26 | PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords | Cybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems | Virus | The Hacker News |
| 3.7.26 | Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects | Kaspersky Compromise Assessment specialists analyze trends from the service’s 2025 projects and provide tips on how to enhance your organization’s security. | Security | SECURELIST |
| 3.7.26 | Google’s Continued Disruption of Malicious Residential Proxy Networks | Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. | CyberCrime | GTI |
| 3.7.26 | Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices | Google has significantly degraded NetNut , one of the biggest networks that turns home devices into rented relays for other people's traffic. | CyberCrime | The Hacker News |
| 3.7.26 | Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials | Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability | Ransom | The Hacker News |
| 2.7.26 | ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API | The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that's designed to gain surreptitious access to a victim's email correspondence via the Google API. "In this campaign, the | APT | The Hacker News |
| 2.7.26 | AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack | Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat | AI | The Hacker News |
| 2.7.26 | NAIC says public data stolen in ShinyHunters' PeopleSoft breach | The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. | Incindent | BleepingComputer |
| 2.7.26 | WhatsApp rolls out usernames to help users hide their phone number | WhatsApp is finally allowing users to reserve usernames, a privacy feature that lets them hide their phone numbers from people not in their contact list. | Social | BleepingComputer |
| 2.7.26 | Microsoft extends Windows Server 2022 hotpatching until October 2027 | Microsoft has extended Windows Server 2022 hotpatching until October 2027, one year after the mainstream end date of October 2026. | OS | BleepingComputer |
| 2.7.26 | U.S. offers $10 million for hackers targeting WhatsApp, Signal users | The U.S. Department of State is offering up to $10 million for information that helps identify or locate members of the UNC5792 and UNC4221 hacker groups, which are linked to Russia's intelligence and military services. | Social | BleepingComputer |
| 2.7.26 | Agentic AI Has an Identity Problem and Attackers Know It | AI agents can access data, trigger workflows, and take action across enterprise systems. Token Security explains why governing these privileged identities is becoming essential for enterprise security. | AI | BleepingComputer |
| 2.7.26 | Critical SimpleHelp flaw exploited to deploy new stealer malware | Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux. | Vulnerebility | BleepingComputer |
| 2.7.26 | Hackers now exploit critical Oracle E-Business flaw in attacks | Attackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to threat intelligence company Defused. | Vulnerebility | BleepingComputer |
| 2.7.26 | US seizes hundreds of FIFA World Cup illegal streaming domains | The U.S. Justice Department's Criminal Division has seized nearly 400 web domains used for illegally streaming matches at the FIFA World Cup. | CyberCrime | BleepingComputer |
| 2.7.26 | Data breach exposes up to 14.2 million email logins at six ISPs | Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. | Incindent | BleepingComputer |
| 2.7.26 | The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign | Kaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure. | CyberCrime | SECURELIST |
| 2.7.26 | FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations | The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. "An | Ransom | The Hacker News |
| 2.7.26 | New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos | Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC , | Virus | The Hacker News |
| 2.7.26 | SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint | Exploit | The Hacker News |
| 2.7.26 | Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters | Argo CD , a widely used tool for deploying software to Kubernetes, has an unpatched flaw in its repo-server component that lets an unauthenticated | Vulnerebility | The Hacker News |
| 2.7.26 | 19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges | A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, | BigBrothers | The Hacker News |
| 2.7.26 | SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT | Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT . Kaspersky said the | Virus | The Hacker News |
| 2.7.26 | VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer | Cybersecurity researchers have flagged a new multi-stage malware delivery attack chain that uses social engineering and Blogger pages to | Virus | The Hacker News |
| 1.7.26 | Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique | AI can turn high-level malicious ideas into concrete techniques, and can independently design and implement novel attack paths that have not yet appeared in real-world campaigns. | Hack | CHECKPOINT |
| 1.7.26 | Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures | A Brazilian banking trojan called Ousaban is going after Windows users who bank in Spain and Portugal. Fortinet's FortiGuard Labs identified | Virus | The Hacker News |
| 1.7.26 | Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic | Adobe has released patches for multiple maximum-severity security flaws impacting Adobe ColdFusion and Adobe Campaign Classic. The | Vulnerebility | The Hacker News |
| 1.7.26 | Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands | Two flaws in Cursor, an AI code editor, could let a single, ordinary-looking prompt break out of the editor's safety sandbox and run any command on | Vulnerebility | The Hacker News |
| 1.7.26 | Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts | A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an | Exploit | The Hacker News |
| 1.7.26 | AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android | Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path | AI | The Hacker News |
| 1.7.26 | Microsoft Accelerates Post-Quantum Cryptography Shift to 2029 | Microsoft on Tuesday said it's accelerating its quantum safe security roadmap, stating technology advances in quantum computing are making it essential to replace existing encryption standards sooner than previously expected. | BigBrothers | The Hacker News |
| 1.7.26 | Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware | Large language models keep inventing web addresses that do not exist. Attackers have started buying those made-up domains before anyone | AI | The Hacker News |
| 1.7.26 | Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls | Anthropic is putting Claude Fable 5 back online worldwide. On June 30 , the U.S. Commerce Department lifted the export controls it had imposed | AI | The Hacker News |
| 1.7.26 | Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts | Cybersecurity researchers have warned of a "massive, ongoing, automated password spray attack" aimed at Microsoft's Azure command- | Hack | The Hacker News |
| 1.7.26 | Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery | ClickFix , the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious | Hack | The Hacker News |
| 1.7.26 | ToddyCat: your hidden email assistant. Part 2 | An in-depth analysis of Umbrij, a new tool used by the ToddyCat APT group to compromise corporate email communications in Gmail. The attack targeted OAuth authorization tokens, allowing threat actors to gain access to Google services. | APT | SECURELIST |
| 1.7.26 | June 2026 Apple Updates | Apple released updates for iOS/iPadOS, macOS, and Safari on Monday. There have been no updates for other Apple operating systems (visionOS, watchOS, tvOS). Usually, Apple updates all products at the same time. | OS | SANS |
| 1.7.26 | Adding some Automation to the favicon.ico method of Host Recon | I'm in the throes of target host recon for another pentest, and thought I'd share some workflow / automation stuff. | Hack | SANS |
| 1.7.26 | YARA-X 1.18.0 and 1.19.0 Release | YARA-X's 1.18.0 release brings 3 improvements and 2 bugfixes. | Security | SANS |
| 1.7.26 | Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service | Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly | Vulnerebility | The Hacker News |