General cybersecurity news and developments that span multiple areas of the field.

General

⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More

Citrix ShareFile vulnerability and Citrix Bleed 2 ransomware dominated threat activity this week, with attackers leveraging both patched flaws and unp…

Yesterday
General

New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email

Researchers have identified MemGhost, a novel attack that exploits how AI agents with memory capabilities process email. The attack works by injecting…

Yesterday
General

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

Forg365, a phishing-as-a-service operation distributed via Telegram, targets Microsoft 365 accounts using a multi-layered attack chain that combines d…

Yesterday
General

Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots

Security operations centers face a critical decision about how to deploy artificial intelligence. The debate centers on whether to embrace fully auton…

Yesterday
General

Lessons Learned from CISA’s Recent GitHub Leak

A CISA contractor exposed dozens of internal credentials, including AWS Govcloud keys, in a public GitHub repository for nearly six months before disc…

Yesterday
General

Vidar Infostealer Hammers SMBs via Malvertising Campaign

Threat actors are leveraging malvertising campaigns to deliver Vidar infostealer to small and medium-sized businesses. The operation uses deceptive ad…

Yesterday
General

State IDs for AI Agents: Will Estonia Set a Precedent?

Estonia is exploring digital identity credentials specifically designed for artificial intelligence agents, positioning itself as a potential global p…

Yesterday
General

Big Brand Jobs Scam Targets Marketing Pros' Google Accounts

Threat actors are running a phishing campaign targeting marketing professionals through fake job listings bearing the names of major brands. The scam …

Yesterday
General

Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft

Varonis disclosed a vulnerability in Google's Dialogflow CX platform that allowed attackers to extract sensitive data from AI chatbots through rogue a…

Yesterday
General

Apple Reverses Age-Old Patch Policy to Keep Up With AI

Apple is accelerating its security patching cadence in response to attackers using artificial intelligence to compress exploitation timelines. The com…

Yesterday
General

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Researchers have attributed the Popa Android botnet to NetNut, a residential proxy service operated by publicly-traded Israeli firm Alarum Technologie…

2 days ago
General

'GodDamn' Ransomware Uses BYOVD to Smite US Companies

A newly emerged ransomware variant called GodDamn exploits a signed Microsoft kernel driver to disable security software before encrypting victim syst…

2 days ago
General

European Organizations Have a Collaboration Security Confidence Gap

Security leaders across Europe significantly overestimate the safety of their collaboration tools, according to a recent survey. This confidence gap c…

2 days ago
General

Mexico's New Cyber Plan Faces Its First Real Test

Mexico's newly rolled-out cybersecurity strategy faces an immediate operational stress test as the nation prepares to host major international events,…

2 days ago
General

Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours

A lone threat actor leveraged artificial intelligence tools and chained multiple AWS vulnerabilities to breach a major Amazon customer's cloud environ…

2 days ago
General

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Version 8.14.0 of the jscrambler npm package contains a Rust-based infostealer that executes automatically during installation. The malicious release,…

2 days ago
General

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Threat actors operating under suspected Chinese and Indian sponsorship compromised web servers at Balochistan Police that process sensitive law enforc…

2 days ago
General

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

Nebula Security researchers disclosed GhostLock, a 15-year-old Linux kernel vulnerability tracked as CVE-2026-43499, that grants any logged-in user ro…

2 days ago
General

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency added four vulnerabilities to its Known Exploited Vulnerabilities catalog on Tuesday, confir…

2 days ago
General

AI Gateways Offer Attackers the Keys to the Kingdom

AI gateways have emerged as a critical attack surface that exposes organizations to multifaceted threats, according to a recent cryptomining incident …

2 days ago
General

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Zimbra has released security patches for a critical vulnerability in its Classic Web Client that permits arbitrary code execution through malicious em…

3 days ago
General

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

Threat actors tracked as O-UNC-066 have launched a targeted campaign against multiple sectors using voice-based phishing to trick Microsoft 365 users …

3 days ago
General

Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

A 41-year-old ransomware negotiator received a 70-month prison sentence for conspiring with BlackCat operators to extort victims and coordinating atta…

3 days ago
General

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

UAT-7810, a Chinese APT group, is actively expanding its ORB (Operational Relay Box) network by deploying new malware called LONGLEASH to compromise i…

3 days ago
General

AI Agents Are a New Kind of Identity — and Most Organizations Aren't Ready

# AI Agents Demand New Identity Management Strategies Organizations treating AI agents as standard service accounts or API tokens face emerging secur…

3 days ago
General

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Attackers compromised the GitHub repository for Injective Labs, a cryptocurrency infrastructure project, and used the access to publish a trojanized n…

3 days ago
General

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

A misconfigured server exposed the infrastructure behind WP-SHELLSTORM, a large-scale WordPress backdooring operation targeting over 1.4 million websi…

3 days ago
General

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

Researchers analyzed 281 of the most downloaded free VPN applications from the Google Play Store and discovered widespread failures in basic privacy p…

3 days ago
General

More Countries Jump on the Social Media 'Ban Wagon'

Multiple countries have enacted or are pursuing age restrictions on social media platforms, but compliance enforcement remains inconsistent. The legis…

3 days ago
General

AI Coding: Do Security Risks Outweigh Productivity Gains?

AI-assisted coding platforms like GitHub Copilot and Amazon CodeWhisperer promise faster development cycles. Yet organizations adopting these tools fa…

3 days ago
General

Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched

Researchers at Ledger's Donjon security team disclosed a critical vulnerability in Tangem crypto wallet cards. A precisely timed laser pulse directed …

4 days ago
General

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

A researcher has disclosed an attack chain targeting WhatsApp hosts through three vulnerabilities in OpenClaw, a personal AI assistant. The flaws enab…

4 days ago
General

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

Silver Fox, a China-linked cybercrime group, deployed a new remote access trojan called MODBEACON that uses gRPC streaming to encrypt command-and-cont…

4 days ago
General

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

FoxIO security researcher Sébastien Féry disclosed a denial-of-service vulnerability in XQUIC, Alibaba's open-source QUIC and HTTP/3 library, on July …

4 days ago
General

From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale

Lumen Technologies discovered a massive gap between its known and actual asset inventory, revealing a problem that plagues most enterprises. The compa…

4 days ago
General

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

Datadog Security Labs has identified multiple coordinated campaigns targeting corporate GitHub environments through systematic reconnaissance attacks.…

4 days ago
General

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

Microsoft researchers have identified GigaWiper, a destructive Windows backdoor that functions as a modular toolkit rather than a single malware varia…

4 days ago
General

Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

AI coding agents designed to identify malicious code can be manipulated into executing that same code on the user's system. Researchers at the AI Now …

4 days ago
General

AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready

AI agents are emerging as a distinct identity type that requires security controls fundamentally different from traditional service accounts and API t…

4 days ago
General

As Global Conflicts Go Digital, Businesses Need Wartime Gameplans

Cyberattacks during geopolitical conflicts extend damage well beyond military targets, affecting commercial enterprises and supply chains globally. A …

4 days ago
General

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

GitHub released npm version 12 with install scripts disabled by default, a major change targeting supply chain attacks through malicious package insta…

5 days ago
General

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

This week's threat landscape reveals a pattern of preventable security failures across cloud infrastructure, Windows systems, and fraud operations. Or…

5 days ago
General

AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up

Artificial intelligence has fundamentally accelerated attack timelines in ways traditional security operations centers were not designed to handle. Ta…

5 days ago
General

Summer of Clearinghouses

Security vendors have entered a competitive rush to establish threat intelligence clearinghouses, with multiple companies announcing platforms in rece…

5 days ago
General

GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

GodDamn ransomware deploys a sophisticated kernel-level driver called PoisonX to disable endpoint detection and response tools before encrypting victi…

5 days ago
General

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

Researchers at Wiz uncovered a symlink vulnerability affecting six major AI coding assistants that allows malicious repositories to execute arbitrary …

5 days ago
General

Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes

Infoblox researchers identified a threat group called Lurking Lizard operating a residential proxy scheme that compromised thousands of devices throug…

5 days ago
General

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

Researchers have disclosed a fundamental cryptographic weakness in GitHub's commit verification system. Attackers can create multiple commits with ide…

5 days ago
General

The Verification Step Is the New ATO Battleground in 2026

Attackers are shifting tactics away from traditional credential stuffing toward exploiting verification mechanisms, the new weak point in account secu…

5 days ago
General

GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code

GitHub Copilot's safety guardrails fail when harmful requests shift from chat to code contexts, according to research by Abhishek Kumar and Carsten Ma…

5 days ago
General

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

Researchers have identified a new attack vector exploiting how AI coding assistants generate fictitious package names, then suggest installing them as…

6 days ago
General

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

Ubiquiti released patches for five critical vulnerabilities spanning its UniFi product ecosystem. The flaws affect UniFi Connect, UniFi Talk, UniFi Ac…

6 days ago
General

New Ghost Phishing Wave Is Breaking Traditional Email Security

The EvilTokens campaign marks a critical evolution in phishing tactics. Threat actors are deploying "ghost phishing" attacks that circumvent tradition…

6 days ago
General

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

Elastic Security Labs identified a new banking malware operation targeting Mexican financial institutions. The threat actors, tracked as REF6045, dist…

6 days ago
General

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup acquiring zero-day vulnerabilities operates under the control of two convicted felons with documented ties to far-right conspi…

6 days ago
General

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

RedWing, a newly discovered Android malware operation, is being distributed as a malware-as-a-service (MaaS) package through Telegram channels. The th…

6 days ago
General

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

Varonis security researchers uncovered a critical vulnerability in Google Dialogflow CX that exposed Code Block-enabled chatbots to cross-agent compro…

6 days ago
General

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

A threat cluster suspected of Chinese state alignment has exploited critical flaws in Roundcube webmail to target physics and engineering departments …

6 days ago
General

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

The CERT Coordination Center revealed that Tenda router firmware contains a hidden administrative backdoor allowing unauthenticated access to device m…

6 days ago
General

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

BeyondTrust released emergency patches for two critical authentication bypass vulnerabilities in its Remote Support and Privileged Remote Access produ…

6 days ago
General

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

A phishing campaign dubbed DEBULL exploits Microsoft's device-code authentication flow to compromise Microsoft 365 accounts. ZeroBEC researchers obser…

Jul 7, 2026
General

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

Researchers at Noma Security discovered a supply-chain vulnerability in GitHub Agentic Workflows that allows attackers to extract private repository c…

Jul 7, 2026
General

What Changes When Your Software Supply Chain Includes AI Writing Your Code?

Artificial intelligence integration into software development pipelines introduces a new attack surface into already fragile supply chains. Developers…

Jul 7, 2026
General

JadePuffer: The First Complete LLM-Driven Ransomware Attack

Researchers have documented the first ransomware campaign powered entirely by a large language model, marking an escalation in automated attack sophis…

Jul 7, 2026
General

Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs

Australian enterprises report declining cybercrime targeting, but the relief comes with a catch. Enhanced institutional security defenses and tighter …

Jul 7, 2026
General

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

A 16-year-old use-after-free vulnerability in Linux's KVM hypervisor enables guest virtual machines to escape to the host kernel on Intel and AMD x86 …

Jul 7, 2026
General

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS

LevelBlue researchers uncovered QuimaRAT, a Java-based remote access trojan distributed as malware-as-a-service. The threat runs across Windows, Linux…

Jul 7, 2026
General

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

Researchers at Hong Kong University of Science and Technology have demonstrated that malicious skills designed for AI coding agents can evade detectio…

Jul 7, 2026
General

'BusySnake' Infostealer Slithers into Critical Infrastructure Networks

Researchers have identified a new infostealer called BusySnake being deployed by the threat group Armored Likho against critical infrastructure target…

Jul 7, 2026
General

CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

Threat actors actively exploit CVE-2024-21893, a memory disclosure vulnerability in Citrix NetScaler, following the public release of a working proof-…

Jul 7, 2026
General

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

Threat actors launched exploitation attempts against CVE-2026-20896 within two weeks of its public disclosure, targeting Gitea Docker deployments glob…

Jul 6, 2026
General

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More

Ordinary infrastructure suffered extraordinary breaches this week, exploited through broken trust assumptions across multiple vectors. Streaming boxe…

Jul 6, 2026
General

How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions

Organizations evaluating AI-powered Security Operations Center platforms face a crowded vendor landscape where marketing claims often obscure fundamen…

Jul 6, 2026
General

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

Suspected Chinese-linked threat actors are targeting Indian taxpayers and financial professionals using fraudulent tax filing software to deliver DcRA…

Jul 6, 2026
General

New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions

Researchers at Shandong University disclosed TrojPix, a novel air-gap exfiltration technique that extracts data from isolated systems through video ca…

Jul 6, 2026
General

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Dutch law enforcement arrested two men operating internet hosting companies that provided infrastructure for Russian state-sponsored cyberattacks and …

Jul 6, 2026
General

Claude Fable relaunch disappoints users with nerfed performance

Anthropic's widely anticipated public rollout of Claude Fable, marketed as the company's most capable model, has generated negative user feedback with…

Jul 6, 2026
General

CISA: Microsoft SharePoint RCE flaw now actively exploited

Attackers are actively exploiting a remote code execution flaw in Microsoft SharePoint that the software giant patched in May, according to a warning …

Jul 6, 2026
General

Alleged Scattered Spider hacker extradited to the United States

A dual U.S.-Estonian citizen has been extradited to the United States to face charges for alleged membership in Scattered Spider, a hacking collective…

Jul 6, 2026
General

Chinese LLMs Broaden the Gap Between Attackers & Defenders

Chinese artificial intelligence companies have released large language models that match or exceed the capabilities of leading US systems, widening th…

Jul 6, 2026
General

Flipper Zero firmware development continues with community help

Flipper Devices confirmed that Flipper Zero firmware development will persist despite operational changes. The company will reduce its internal engine…

Jul 5, 2026
General

JadePuffer ransomware used AI agent to automate entire attack

Security researchers have identified JadePuffer, a ransomware operation believed to be the first attack conducted entirely by an autonomous AI agent p…

Jul 5, 2026
General

NetNut proxy network disrupted, 2 million infected devices cut off

Google and law enforcement partners have successfully disrupted NetNut, a residential proxy network operating across approximately 2 million infected …

Jul 5, 2026
General

ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit

ARToken operates as a phishing-as-a-service platform affiliated with EvilTokens, exposing a sophisticated toolkit explicitly designed to target Micros…

Jul 5, 2026
General

Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says

Anthropic clarified that Claude Fable 5 will remain available to subscription users beyond its July 7 removal date, contradicting initial concerns abo…

Jul 5, 2026
General

Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts

Attackers launched a large-scale password spray campaign against Microsoft Azure CLI, compromising at least 78 Microsoft user accounts across 81 milli…

Jul 5, 2026
General

Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery

A security researcher analyzed 3,000 live ClickFix payloads and discovered the scam now operates through API-driven infrastructure that delivers custo…

Jul 5, 2026
General

New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials

Security researchers at LayerX discovered BioShocking, a social engineering attack that exploits AI browser agents into revealing user credentials. Th…

Jul 5, 2026
General

Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth

An unauthenticated attacker can execute arbitrary commands as root on Progress Kemp LoadMaster appliances through a critical vulnerability in the devi…

Jul 5, 2026
General

Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs

Apple released security updates on Monday patching more than 30 vulnerabilities across iOS, macOS, and Safari. The update includes four WebKit flaws d…

Jul 5, 2026
General

North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign

North Korean threat actors associated with the Contagious Interview campaign have deployed 108 malicious packages and browser extensions across multip…

Jul 4, 2026
General

Microsoft Accelerates Post-Quantum Cryptography Shift to 2029

Microsoft is accelerating its transition to post-quantum cryptography, moving its target completion date to 2029 from the original 2030+ timeline. The…

Jul 4, 2026
General

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

Attackers exploit a vulnerability in large language model outputs by purchasing domains that AI systems hallucinate and then recommend to users. Palo …

Jul 4, 2026
General

Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls

Anthropic has restored global access to Claude Fable 5 following the U.S. Commerce Department's decision to lift export controls imposed on the model …

Jul 4, 2026
General

Who Runs the Ransomware Group ‘The Gentlemen?’

The Gentlemen ransomware gang has climbed to the second most active threat actor by victim count, deploying an aggressive affiliate recruitment model …

Jul 4, 2026
General

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices

Security firm runZero disclosed seven vulnerabilities in FatFs, a lightweight filesystem library embedded in millions of consumer and industrial devic…

Jul 4, 2026
General

New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android

A critical privilege escalation vulnerability tracked as CVE-2026-46242, dubbed "Bad Epoll," allows unprivileged local users to gain root access on Li…

Jul 4, 2026
General

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

Security researchers have uncovered Avalon, a new modular malware framework that delivers the CrownX ransomware payload through multi-stage phishing a…

Jul 4, 2026
General

New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

Attackers deployed a new remote access trojan called ChocoPoC that masquerades as legitimate exploit code to target vulnerability researchers. The mal…

Jul 4, 2026
General

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog after detecting active exploitation of a critical remote code execution flaw …

Jul 4, 2026
General

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

North Korea-linked threat actors deployed malicious npm packages designed to mimic legitimate Rollup polyfill tooling and harvest developer credential…

Jul 3, 2026
General

Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer

Kaspersky researchers have identified Armored Likho, a previously undocumented threat actor conducting dual-purpose cyber operations across Russia, Br…

Jul 3, 2026
General

European Parliament Member Investigating Spyware Was Hacked With Pegasus

Stelios Kouloglou, a former European Parliament member investigating spyware abuse across the EU, fell victim to Pegasus spyware while serving on the …

Jul 3, 2026
General

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords

Jamf Threat Labs identified a new macOS information stealer called PamStealer that masquerades as Maccy, a legitimate open-source clipboard manager. A…

Jul 3, 2026
General

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

Researchers have linked the FortiBleed credential theft campaign directly to INC and Lynx ransomware operations. The discovery reveals that stolen For…

Jul 3, 2026
General

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Ransomware operators behind the Anubis operation have begun exploiting Citrix Bleed 2, a newly disclosed vulnerability tracked as CVE-2025-5777, to br…

Jul 3, 2026
General

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

ToddyCat, a persistent threat actor, has deployed a new malware family called Umbrij to compromise Gmail accounts by abusing OAuth authentication mech…

Jul 3, 2026
General

Identity Lifecycle Management Wasn't Built for AI Agents

Identity and access management systems face a fundamental architectural mismatch as AI agents proliferate across enterprise networks. Traditional iden…

Jul 3, 2026
General

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

Sysdig's Threat Research Team identified JADEPUFFER, an AI-driven ransomware operator, executing what the firm believes is the first fully autonomous …

Jul 3, 2026
General

FBI Seizes NetNut Proxy Platform, Popa Botnet

The FBI seized hundreds of domains operated by NetNut, a residential proxy service run by Israeli firm Alarum Technologies, following evidence that th…

Jul 3, 2026
General

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

Security researchers uncovered a cluster of vulnerabilities this week affecting critical infrastructure across multiple domains, revealing a pattern o…

Jul 2, 2026
General

Google loses final appeal to overturn €4.1 billion EU fine

Google has exhausted its legal options in Europe after the Court of Justice of the European Union rejected its final appeal against a €4.1 billion ant…

Jul 2, 2026
General

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

Microsoft 365 accounts fall to OAuth-based attacks that bypass multifactor authentication entirely. Security researchers uncovered two attack techniqu…

Jul 2, 2026
General

Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.

IBM and Red Hat are deploying 20,000 engineers to Project Lightwell, a new service aimed at identifying and remedying vulnerabilities in open-source s…

Jul 2, 2026
General

Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS

Phishing attackers are now fingerprinting victims by harvesting user-agent data to deliver operating system-specific payloads, a technique that substa…

Jul 2, 2026
General

VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer

Securonix researchers identified a multi-stage malware delivery chain dubbed VEIL#DROP that exploits Google's Blogger platform to distribute PureLogs,…

Jul 2, 2026
General

2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience

Organizations increasingly recognize cyber threats but struggle to translate that awareness into effective defensive action, according to Bitdefender'…

Jul 2, 2026
General

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

Canadian and U.S. authorities arrested a 23-year-old Ottawa resident accused of operating Kimwolf, an IoT botnet that compromised millions of connecte…

Jul 2, 2026
General

FortiBleed credential-theft campaign linked to Lynx ransomware

A large-scale credential theft campaign targeting Fortinet devices has direct ties to the INC and Lynx ransomware operations. Researchers traced the F…

Jul 2, 2026
General

New ChocoPoC malware targets researchers via trojanized PoC exploits

Threat actors deployed trojanized proof-of-concept exploits on GitHub to distribute ChocoPoC, a Python-based remote access trojan targeting cybersecur…

Jul 2, 2026
General

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures

Fortinet's FortiGuard Labs identified a new banking trojan campaign targeting Spanish and Portuguese bank customers. The malware, called Ousaban, orig…

Jul 1, 2026
General

Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic

Adobe has patched seven maximum-severity vulnerabilities across ColdFusion and Campaign Classic, all rated CVSS 10.0. These flaws enable arbitrary cod…

Jul 1, 2026
General

Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands

Cato AI Labs disclosed two critical vulnerabilities in Cursor, a popular AI code editor used by developers. The flaws, tracked as CVE-2026-50548 and C…

Jul 1, 2026
General

Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

Progress Software has disclosed a critical pre-authentication remote code execution vulnerability in Kemp LoadMaster, its widely deployed load balanci…

Jul 1, 2026
General

AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android

Researchers have discovered the first documented ransomware variant generated by an AI model that exploits a legitimate Chromium browser capability to…

Jul 1, 2026
General

Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service

Citrix released patches for six NetScaler flaws that expose ADC and Gateway deployments to file disclosure and denial-of-service attacks. The most cri…

Jul 1, 2026
General

RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS

Researchers at QiAnXin's XLab identified RustDuck, a new two-stage botnet written in Rust that targets consumer routers, IP cameras, Android boxes, an…

Jul 1, 2026
General

Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

An unidentified threat actor exploits CVE-2026-48558, a critical authentication bypass flaw in SimpleHelp, to deliver two newly identified malware fam…

Jul 1, 2026
General

AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks

Security researchers have disclosed six vulnerabilities in Apple's AirDrop and Google's Quick Share that allow nearby attackers to crash file-sharing …

Jul 1, 2026
General

Microsoft accelerates quantum-safe roadmap as risks grow

Microsoft announced it is accelerating its quantum-safe security roadmap in response to faster-than-expected advances in quantum computing capabilitie…

Jul 1, 2026
General

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

Threat actors exploit a critical remote code execution vulnerability in Langflow to deploy Monero miners on exposed AI application endpoints. The atta…

Jun 30, 2026
General

GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks

Adversa AI discovered a critical bypass vulnerability affecting open-source AI coding agents. The flaw, named GuardFall, exploits a decades-old shell …

Jun 30, 2026
General

282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study

Researchers discovered that 282 of 444 AI chatbot applications for iOS leak sensitive authentication credentials in plaintext network traffic. The exp…

Jun 30, 2026
General

What the Numbers Say About FIFA 2026 Cyber Risk

Check Point Research documented a coordinated threat landscape targeting FIFA World Cup 2026 months before the tournament's June 11 launch. Threat act…

Jun 30, 2026
General

Fake Perplexity extension on Chrome Web Store tracked searches

A counterfeit Perplexity AI extension distributed through the official Chrome Web Store intercepted user search queries and collected browsing data wi…

Jun 30, 2026
General

Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild

Oracle has disclosed active exploitation of CVE-2026-46817, a critical flaw in Oracle E-Business Suite affecting the Payments module. The vulnerabilit…

Jun 30, 2026
General

Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

Microsoft researchers discovered a malicious Chrome extension impersonating Perplexity, the AI search engine. The extension intercepted all search que…

Jun 30, 2026
General

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

Gamaredon, a Russian APT group, has accelerated its cyber operations against Ukraine by launching 35 distinct spear-phishing campaigns targeting new v…

Jun 30, 2026
General

Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts

Microsoft removed 119 malicious Edge extensions from its add-ons store that belonged to a single threat actor operating since at least 2021. The exten…

Jun 30, 2026
General

Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

A public exploit is now circulating for CVE-2026-55200, a critical vulnerability in libssh2 that allows attackers to achieve code execution on SSH cli…

Jun 30, 2026
General

Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

Mustang Panda, a China-aligned espionage group, launched targeted attacks against Indian government agencies and hydropower infrastructure using novel…

Jun 29, 2026
General

⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More

# Weekly Recap: Critical Infrastructure Threats Across Linux, AI, and State-Sponsored Malware This week exposed multiple attack vectors spanning Linu…

Jun 29, 2026
General

236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers

Infoblox researchers uncovered more than 236,000 websites exploiting DCloud Uni-App, a legitimate Chinese open-source development framework, to host c…

Jun 29, 2026
General

Why Post-Quantum Cryptography Starts With Credentials

Quantum computers pose an existential threat to current encryption standards protecting sensitive data like credentials and financial records. Organis…

Jun 29, 2026
General

U.S. offers $10 million for hackers targeting WhatsApp, Signal users

The U.S. Department of State has announced a $10 million reward for intelligence leading to the identification or location of members from UNC5792 and…

Jun 29, 2026
General

OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards

OpenAI released three variants of GPT-5.6 on Friday as limited previews to select companies working with U.S. government agencies. The rollout represe…

Jun 29, 2026
General

FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys

Russian state-sponsored hackers are escalating phishing attacks against Signal users by targeting backup recovery keys, the FBI and CISA warned in an …

Jun 29, 2026
General

New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

Kaspersky researchers discovered a new malware campaign named StrikeShark deploying SharkLoader, a previously unknown loader malware that installs Cob…

Jun 29, 2026
General

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign

A Chinese-speaking APT tracked as CL-STA-1062 has deployed a previously unknown custom backdoor named TinyRCT against government entities and critical…

Jun 29, 2026
General

Clean GitHub repo tricks AI coding agents into running malware

Researchers have identified a vulnerability in AI coding agents that allows attackers to hide malware inside legitimate-looking GitHub repositories. T…

Jun 29, 2026
General

NY man charged after harassing college student with AI-generated nudes

A New York resident faces federal cyberstalking charges for using artificial intelligence to generate fake nude images of a Georgia college student an…

Jun 21, 2026
General

USB worm spreads crypto-stealing malware via Windows shortcut files

A newly discovered USB worm spreads cryptocurrency-stealing malware through Windows shortcut (.LNK) files, allowing threat actors to compromise crypto…

Jun 21, 2026
General

Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks

Threat actors tracked as "Icarus" exploited an OAuth vulnerability in market intelligence platform Klue to steal Salesforce CRM data from multiple org…

Jun 21, 2026
General

Stressors, AI Forcing Changes to Cybersecurity Teams

Security leaders face mounting pressure from accelerating threat landscapes and artificial intelligence integration, forcing organizational restructur…

Jun 21, 2026
General

Novo Nordisk Breach Exposes Software Development Pipeline Risk

Novo Nordisk suffered a security breach tied to exposed credentials in its software development pipeline, revealing how organizations commonly mishand…

Jun 21, 2026
General

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Attackers are exploiting CVE-2026-4020, a medium-severity information disclosure vulnerability in Gravity SMTP, a WordPress plugin deployed across app…

Jun 20, 2026
General

New Prinz Eugen ransomware prioritizes recent files for encryption

Prinz Eugen, a newly active ransomware operation, employs a targeted encryption strategy that focuses on recently modified files rather than encryptin…

Jun 20, 2026

Get Daily CyberWireDaily

The best stories, delivered to your inbox each morning.