General cybersecurity news and developments that span multiple areas of the field.
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Microsoft released patches for 622 vulnerabilities today, more than tripling the previous Patch Tuesday record of roughly 200 flaws. Two of these vuln…
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
SAP released patches in July 2026 for CVE-2026-44747, a critical vulnerability in SAP NetWeaver Application Server ABAP with a CVSS score of 9.9. The …
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Threat actors are exploiting an OAuth client ID spoofing technique to validate stolen credentials against Microsoft Entra ID without triggering securi…
Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read
xAI's Grok Build coding assistant uploaded complete Git repositories, including full commit histories, to xAI-controlled Google Cloud Storage buckets …
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes
Microsoft patched 622 vulnerabilities across its product ecosystem this week, including three zero-day flaws already exploited in the wild. The patch …
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Cybersecurity researchers at Blackpoint Cyber have identified LabubaRAT, a previously unknown remote access trojan written in Rust that disguises itse…
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Miggo's security team disclosed two access control vulnerabilities in RabbitMQ that expose OAuth secrets and compromise multi-tenant isolation. The fl…
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Microsoft-signed UEFI shims dating back several years contain vulnerabilities that permit attackers to circumvent Secure Boot protections on systems r…
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Researchers at KU Leuven analyzed 85 widely used cryptocurrency wallet browser extensions and uncovered critical privacy failures that expose users to…
How Pentera Turns AI Security Workflows into Validation Engines
Pentera has integrated artificial intelligence into its attack surface management platform, positioning the tool as a validation engine rather than ju…
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
CrashStealer, a newly identified macOS information stealer, leverages Apple's own notarization system to bypass Gatekeeper security checks and establi…
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
Google and Microsoft removed ModHeader from their official extension stores after researchers discovered dormant data-collection code embedded in the …
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
Security researchers have identified an intrusion campaign using an AI-generated PowerShell script to enumerate and map Active Directory environments.…
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
A misconfigured web server exposed an active Microsoft 365 phishing operation, revealing infrastructure shared across three separate Evilginx campaign…
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
CISA has confirmed active exploitation of two critical zero-day vulnerabilities in popular Joomla extensions. Both flaws carry maximum CVSS 10.0 sever…
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Citrix ShareFile vulnerability and Citrix Bleed 2 ransomware dominated threat activity this week, with attackers leveraging both patched flaws and unp…
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
Researchers have identified MemGhost, a novel attack that exploits how AI agents with memory capabilities process email. The attack works by injecting…
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
Forg365, a phishing-as-a-service operation distributed via Telegram, targets Microsoft 365 accounts using a multi-layered attack chain that combines d…
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots
Security operations centers face a critical decision about how to deploy artificial intelligence. The debate centers on whether to embrace fully auton…
Lessons Learned from CISA’s Recent GitHub Leak
A CISA contractor exposed dozens of internal credentials, including AWS Govcloud keys, in a public GitHub repository for nearly six months before disc…
Vidar Infostealer Hammers SMBs via Malvertising Campaign
Threat actors are leveraging malvertising campaigns to deliver Vidar infostealer to small and medium-sized businesses. The operation uses deceptive ad…
State IDs for AI Agents: Will Estonia Set a Precedent?
Estonia is exploring digital identity credentials specifically designed for artificial intelligence agents, positioning itself as a potential global p…
Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
Threat actors are running a phishing campaign targeting marketing professionals through fake job listings bearing the names of major brands. The scam …
Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
Varonis disclosed a vulnerability in Google's Dialogflow CX platform that allowed attackers to extract sensitive data from AI chatbots through rogue a…
Apple Reverses Age-Old Patch Policy to Keep Up With AI
Apple is accelerating its security patching cadence in response to attackers using artificial intelligence to compress exploitation timelines. The com…
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
Researchers have attributed the Popa Android botnet to NetNut, a residential proxy service operated by publicly-traded Israeli firm Alarum Technologie…
'GodDamn' Ransomware Uses BYOVD to Smite US Companies
A newly emerged ransomware variant called GodDamn exploits a signed Microsoft kernel driver to disable security software before encrypting victim syst…
European Organizations Have a Collaboration Security Confidence Gap
Security leaders across Europe significantly overestimate the safety of their collaboration tools, according to a recent survey. This confidence gap c…
Mexico's New Cyber Plan Faces Its First Real Test
Mexico's newly rolled-out cybersecurity strategy faces an immediate operational stress test as the nation prepares to host major international events,…
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
A lone threat actor leveraged artificial intelligence tools and chained multiple AWS vulnerabilities to breach a major Amazon customer's cloud environ…
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
Version 8.14.0 of the jscrambler npm package contains a Rust-based infostealer that executes automatically during installation. The malicious release,…
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Threat actors operating under suspected Chinese and Indian sponsorship compromised web servers at Balochistan Police that process sensitive law enforc…
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Nebula Security researchers disclosed GhostLock, a 15-year-old Linux kernel vulnerability tracked as CVE-2026-43499, that grants any logged-in user ro…
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency added four vulnerabilities to its Known Exploited Vulnerabilities catalog on Tuesday, confir…
AI Gateways Offer Attackers the Keys to the Kingdom
AI gateways have emerged as a critical attack surface that exposes organizations to multifaceted threats, according to a recent cryptomining incident …
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra has released security patches for a critical vulnerability in its Classic Web Client that permits arbitrary code execution through malicious em…
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
Threat actors tracked as O-UNC-066 have launched a targeted campaign against multiple sectors using voice-based phishing to trick Microsoft 365 users …
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
A 41-year-old ransomware negotiator received a 70-month prison sentence for conspiring with BlackCat operators to extort victims and coordinating atta…
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
UAT-7810, a Chinese APT group, is actively expanding its ORB (Operational Relay Box) network by deploying new malware called LONGLEASH to compromise i…
AI Agents Are a New Kind of Identity — and Most Organizations Aren't Ready
# AI Agents Demand New Identity Management Strategies Organizations treating AI agents as standard service accounts or API tokens face emerging secur…
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Attackers compromised the GitHub repository for Injective Labs, a cryptocurrency infrastructure project, and used the access to publish a trojanized n…
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A misconfigured server exposed the infrastructure behind WP-SHELLSTORM, a large-scale WordPress backdooring operation targeting over 1.4 million websi…
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
Researchers analyzed 281 of the most downloaded free VPN applications from the Google Play Store and discovered widespread failures in basic privacy p…
More Countries Jump on the Social Media 'Ban Wagon'
Multiple countries have enacted or are pursuing age restrictions on social media platforms, but compliance enforcement remains inconsistent. The legis…
AI Coding: Do Security Risks Outweigh Productivity Gains?
AI-assisted coding platforms like GitHub Copilot and Amazon CodeWhisperer promise faster development cycles. Yet organizations adopting these tools fa…
Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched
Researchers at Ledger's Donjon security team disclosed a critical vulnerability in Tangem crypto wallet cards. A precisely timed laser pulse directed …
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
A researcher has disclosed an attack chain targeting WhatsApp hosts through three vulnerabilities in OpenClaw, a personal AI assistant. The flaws enab…
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
Silver Fox, a China-linked cybercrime group, deployed a new remote access trojan called MODBEACON that uses gRPC streaming to encrypt command-and-cont…
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
FoxIO security researcher Sébastien Féry disclosed a denial-of-service vulnerability in XQUIC, Alibaba's open-source QUIC and HTTP/3 library, on July …
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
Lumen Technologies discovered a massive gap between its known and actual asset inventory, revealing a problem that plagues most enterprises. The compa…
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
Datadog Security Labs has identified multiple coordinated campaigns targeting corporate GitHub environments through systematic reconnaissance attacks.…
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Microsoft researchers have identified GigaWiper, a destructive Windows backdoor that functions as a modular toolkit rather than a single malware varia…
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
AI coding agents designed to identify malicious code can be manipulated into executing that same code on the user's system. Researchers at the AI Now …
AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready
AI agents are emerging as a distinct identity type that requires security controls fundamentally different from traditional service accounts and API t…
As Global Conflicts Go Digital, Businesses Need Wartime Gameplans
Cyberattacks during geopolitical conflicts extend damage well beyond military targets, affecting commercial enterprises and supply chains globally. A …
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
GitHub released npm version 12 with install scripts disabled by default, a major change targeting supply chain attacks through malicious package insta…
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
This week's threat landscape reveals a pattern of preventable security failures across cloud infrastructure, Windows systems, and fraud operations. Or…
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
Artificial intelligence has fundamentally accelerated attack timelines in ways traditional security operations centers were not designed to handle. Ta…
Summer of Clearinghouses
Security vendors have entered a competitive rush to establish threat intelligence clearinghouses, with multiple companies announcing platforms in rece…
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
GodDamn ransomware deploys a sophisticated kernel-level driver called PoisonX to disable endpoint detection and response tools before encrypting victi…
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz uncovered a symlink vulnerability affecting six major AI coding assistants that allows malicious repositories to execute arbitrary …
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Infoblox researchers identified a threat group called Lurking Lizard operating a residential proxy scheme that compromised thousands of devices throug…
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
Researchers have disclosed a fundamental cryptographic weakness in GitHub's commit verification system. Attackers can create multiple commits with ide…
The Verification Step Is the New ATO Battleground in 2026
Attackers are shifting tactics away from traditional credential stuffing toward exploiting verification mechanisms, the new weak point in account secu…
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
GitHub Copilot's safety guardrails fail when harmful requests shift from chat to code contexts, according to research by Abhishek Kumar and Carsten Ma…
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
Researchers have identified a new attack vector exploiting how AI coding assistants generate fictitious package names, then suggest installing them as…
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Ubiquiti released patches for five critical vulnerabilities spanning its UniFi product ecosystem. The flaws affect UniFi Connect, UniFi Talk, UniFi Ac…
New Ghost Phishing Wave Is Breaking Traditional Email Security
The EvilTokens campaign marks a critical evolution in phishing tactics. Threat actors are deploying "ghost phishing" attacks that circumvent tradition…
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
Elastic Security Labs identified a new banking malware operation targeting Mexican financial institutions. The threat actors, tracked as REF6045, dist…
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup acquiring zero-day vulnerabilities operates under the control of two convicted felons with documented ties to far-right conspi…
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
RedWing, a newly discovered Android malware operation, is being distributed as a malware-as-a-service (MaaS) package through Telegram channels. The th…
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
Varonis security researchers uncovered a critical vulnerability in Google Dialogflow CX that exposed Code Block-enabled chatbots to cross-agent compro…
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
A threat cluster suspected of Chinese state alignment has exploited critical flaws in Roundcube webmail to target physics and engineering departments …
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
The CERT Coordination Center revealed that Tenda router firmware contains a hidden administrative backdoor allowing unauthenticated access to device m…
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
BeyondTrust released emergency patches for two critical authentication bypass vulnerabilities in its Remote Support and Privileged Remote Access produ…
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A phishing campaign dubbed DEBULL exploits Microsoft's device-code authentication flow to compromise Microsoft 365 accounts. ZeroBEC researchers obser…
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
Researchers at Noma Security discovered a supply-chain vulnerability in GitHub Agentic Workflows that allows attackers to extract private repository c…
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
Artificial intelligence integration into software development pipelines introduces a new attack surface into already fragile supply chains. Developers…
JadePuffer: The First Complete LLM-Driven Ransomware Attack
Researchers have documented the first ransomware campaign powered entirely by a large language model, marking an escalation in automated attack sophis…
Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs
Australian enterprises report declining cybercrime targeting, but the relief comes with a catch. Enhanced institutional security defenses and tighter …
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
A 16-year-old use-after-free vulnerability in Linux's KVM hypervisor enables guest virtual machines to escape to the host kernel on Intel and AMD x86 …
New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS
LevelBlue researchers uncovered QuimaRAT, a Java-based remote access trojan distributed as malware-as-a-service. The threat runs across Windows, Linux…
SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
Researchers at Hong Kong University of Science and Technology have demonstrated that malicious skills designed for AI coding agents can evade detectio…
'BusySnake' Infostealer Slithers into Critical Infrastructure Networks
Researchers have identified a new infostealer called BusySnake being deployed by the threat group Armored Likho against critical infrastructure target…
CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
Threat actors actively exploit CVE-2024-21893, a memory disclosure vulnerability in Citrix NetScaler, following the public release of a working proof-…
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
Threat actors launched exploitation attempts against CVE-2026-20896 within two weeks of its public disclosure, targeting Gitea Docker deployments glob…
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
Ordinary infrastructure suffered extraordinary breaches this week, exploited through broken trust assumptions across multiple vectors. Streaming boxe…
How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions
Organizations evaluating AI-powered Security Operations Center platforms face a crowded vendor landscape where marketing claims often obscure fundamen…
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
Suspected Chinese-linked threat actors are targeting Indian taxpayers and financial professionals using fraudulent tax filing software to deliver DcRA…
New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
Researchers at Shandong University disclosed TrojPix, a novel air-gap exfiltration technique that extracts data from isolated systems through video ca…
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Dutch law enforcement arrested two men operating internet hosting companies that provided infrastructure for Russian state-sponsored cyberattacks and …
Claude Fable relaunch disappoints users with nerfed performance
Anthropic's widely anticipated public rollout of Claude Fable, marketed as the company's most capable model, has generated negative user feedback with…
CISA: Microsoft SharePoint RCE flaw now actively exploited
Attackers are actively exploiting a remote code execution flaw in Microsoft SharePoint that the software giant patched in May, according to a warning …
Alleged Scattered Spider hacker extradited to the United States
A dual U.S.-Estonian citizen has been extradited to the United States to face charges for alleged membership in Scattered Spider, a hacking collective…
Chinese LLMs Broaden the Gap Between Attackers & Defenders
Chinese artificial intelligence companies have released large language models that match or exceed the capabilities of leading US systems, widening th…
Flipper Zero firmware development continues with community help
Flipper Devices confirmed that Flipper Zero firmware development will persist despite operational changes. The company will reduce its internal engine…
JadePuffer ransomware used AI agent to automate entire attack
Security researchers have identified JadePuffer, a ransomware operation believed to be the first attack conducted entirely by an autonomous AI agent p…
NetNut proxy network disrupted, 2 million infected devices cut off
Google and law enforcement partners have successfully disrupted NetNut, a residential proxy network operating across approximately 2 million infected …
ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit
ARToken operates as a phishing-as-a-service platform affiliated with EvilTokens, exposing a sophisticated toolkit explicitly designed to target Micros…
Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says
Anthropic clarified that Claude Fable 5 will remain available to subscription users beyond its July 7 removal date, contradicting initial concerns abo…
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
Attackers launched a large-scale password spray campaign against Microsoft Azure CLI, compromising at least 78 Microsoft user accounts across 81 milli…
Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery
A security researcher analyzed 3,000 live ClickFix payloads and discovered the scam now operates through API-driven infrastructure that delivers custo…
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
Security researchers at LayerX discovered BioShocking, a social engineering attack that exploits AI browser agents into revealing user credentials. Th…
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
An unauthenticated attacker can execute arbitrary commands as root on Progress Kemp LoadMaster appliances through a critical vulnerability in the devi…
Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs
Apple released security updates on Monday patching more than 30 vulnerabilities across iOS, macOS, and Safari. The update includes four WebKit flaws d…
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
North Korean threat actors associated with the Contagious Interview campaign have deployed 108 malicious packages and browser extensions across multip…
Microsoft Accelerates Post-Quantum Cryptography Shift to 2029
Microsoft is accelerating its transition to post-quantum cryptography, moving its target completion date to 2029 from the original 2030+ timeline. The…
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Attackers exploit a vulnerability in large language model outputs by purchasing domains that AI systems hallucinate and then recommend to users. Palo …
Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls
Anthropic has restored global access to Claude Fable 5 following the U.S. Commerce Department's decision to lift export controls imposed on the model …
Who Runs the Ransomware Group ‘The Gentlemen?’
The Gentlemen ransomware gang has climbed to the second most active threat actor by victim count, deploying an aggressive affiliate recruitment model …
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
Security firm runZero disclosed seven vulnerabilities in FatFs, a lightweight filesystem library embedded in millions of consumer and industrial devic…
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A critical privilege escalation vulnerability tracked as CVE-2026-46242, dubbed "Bad Epoll," allows unprivileged local users to gain root access on Li…
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Security researchers have uncovered Avalon, a new modular malware framework that delivers the CrownX ransomware payload through multi-stage phishing a…
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Attackers deployed a new remote access trojan called ChocoPoC that masquerades as legitimate exploit code to target vulnerability researchers. The mal…
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog after detecting active exploitation of a critical remote code execution flaw …
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
North Korea-linked threat actors deployed malicious npm packages designed to mimic legitimate Rollup polyfill tooling and harvest developer credential…
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
Kaspersky researchers have identified Armored Likho, a previously undocumented threat actor conducting dual-purpose cyber operations across Russia, Br…
European Parliament Member Investigating Spyware Was Hacked With Pegasus
Stelios Kouloglou, a former European Parliament member investigating spyware abuse across the EU, fell victim to Pegasus spyware while serving on the …
PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
Jamf Threat Labs identified a new macOS information stealer called PamStealer that masquerades as Maccy, a legitimate open-source clipboard manager. A…
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
Researchers have linked the FortiBleed credential theft campaign directly to INC and Lynx ransomware operations. The discovery reveals that stolen For…
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Ransomware operators behind the Anubis operation have begun exploiting Citrix Bleed 2, a newly disclosed vulnerability tracked as CVE-2025-5777, to br…
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
ToddyCat, a persistent threat actor, has deployed a new malware family called Umbrij to compromise Gmail accounts by abusing OAuth authentication mech…
Identity Lifecycle Management Wasn't Built for AI Agents
Identity and access management systems face a fundamental architectural mismatch as AI agents proliferate across enterprise networks. Traditional iden…
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Sysdig's Threat Research Team identified JADEPUFFER, an AI-driven ransomware operator, executing what the firm believes is the first fully autonomous …
FBI Seizes NetNut Proxy Platform, Popa Botnet
The FBI seized hundreds of domains operated by NetNut, a residential proxy service run by Israeli firm Alarum Technologies, following evidence that th…
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
Security researchers uncovered a cluster of vulnerabilities this week affecting critical infrastructure across multiple domains, revealing a pattern o…
Google loses final appeal to overturn €4.1 billion EU fine
Google has exhausted its legal options in Europe after the Court of Justice of the European Union rejected its final appeal against a €4.1 billion ant…
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
Microsoft 365 accounts fall to OAuth-based attacks that bypass multifactor authentication entirely. Security researchers uncovered two attack techniqu…
Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.
IBM and Red Hat are deploying 20,000 engineers to Project Lightwell, a new service aimed at identifying and remedying vulnerabilities in open-source s…
Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS
Phishing attackers are now fingerprinting victims by harvesting user-agent data to deliver operating system-specific payloads, a technique that substa…
VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer
Securonix researchers identified a multi-stage malware delivery chain dubbed VEIL#DROP that exploits Google's Blogger platform to distribute PureLogs,…
2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience
Organizations increasingly recognize cyber threats but struggle to translate that awareness into effective defensive action, according to Bitdefender'…
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Canadian and U.S. authorities arrested a 23-year-old Ottawa resident accused of operating Kimwolf, an IoT botnet that compromised millions of connecte…
FortiBleed credential-theft campaign linked to Lynx ransomware
A large-scale credential theft campaign targeting Fortinet devices has direct ties to the INC and Lynx ransomware operations. Researchers traced the F…
New ChocoPoC malware targets researchers via trojanized PoC exploits
Threat actors deployed trojanized proof-of-concept exploits on GitHub to distribute ChocoPoC, a Python-based remote access trojan targeting cybersecur…
Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures
Fortinet's FortiGuard Labs identified a new banking trojan campaign targeting Spanish and Portuguese bank customers. The malware, called Ousaban, orig…
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe has patched seven maximum-severity vulnerabilities across ColdFusion and Campaign Classic, all rated CVSS 10.0. These flaws enable arbitrary cod…
Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
Cato AI Labs disclosed two critical vulnerabilities in Cursor, a popular AI code editor used by developers. The flaws, tracked as CVE-2026-50548 and C…
Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
Progress Software has disclosed a critical pre-authentication remote code execution vulnerability in Kemp LoadMaster, its widely deployed load balanci…
AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android
Researchers have discovered the first documented ransomware variant generated by an AI model that exploits a legitimate Chromium browser capability to…
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
Citrix released patches for six NetScaler flaws that expose ADC and Gateway deployments to file disclosure and denial-of-service attacks. The most cri…
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
Researchers at QiAnXin's XLab identified RustDuck, a new two-stage botnet written in Rust that targets consumer routers, IP cameras, Android boxes, an…
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
An unidentified threat actor exploits CVE-2026-48558, a critical authentication bypass flaw in SimpleHelp, to deliver two newly identified malware fam…
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks
Security researchers have disclosed six vulnerabilities in Apple's AirDrop and Google's Quick Share that allow nearby attackers to crash file-sharing …
Microsoft accelerates quantum-safe roadmap as risks grow
Microsoft announced it is accelerating its quantum-safe security roadmap in response to faster-than-expected advances in quantum computing capabilitie…
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
Threat actors exploit a critical remote code execution vulnerability in Langflow to deploy Monero miners on exposed AI application endpoints. The atta…
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks
Adversa AI discovered a critical bypass vulnerability affecting open-source AI coding agents. The flaw, named GuardFall, exploits a decades-old shell …
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
Researchers discovered that 282 of 444 AI chatbot applications for iOS leak sensitive authentication credentials in plaintext network traffic. The exp…
What the Numbers Say About FIFA 2026 Cyber Risk
Check Point Research documented a coordinated threat landscape targeting FIFA World Cup 2026 months before the tournament's June 11 launch. Threat act…
Fake Perplexity extension on Chrome Web Store tracked searches
A counterfeit Perplexity AI extension distributed through the official Chrome Web Store intercepted user search queries and collected browsing data wi…
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
Oracle has disclosed active exploitation of CVE-2026-46817, a critical flaw in Oracle E-Business Suite affecting the Payments module. The vulnerabilit…
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
Microsoft researchers discovered a malicious Chrome extension impersonating Perplexity, the AI search engine. The extension intercepted all search que…
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
Gamaredon, a Russian APT group, has accelerated its cyber operations against Ukraine by launching 35 distinct spear-phishing campaigns targeting new v…
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
Microsoft removed 119 malicious Edge extensions from its add-ons store that belonged to a single threat actor operating since at least 2021. The exten…
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
A public exploit is now circulating for CVE-2026-55200, a critical vulnerability in libssh2 that allows attackers to achieve code execution on SSH cli…
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
Mustang Panda, a China-aligned espionage group, launched targeted attacks against Indian government agencies and hydropower infrastructure using novel…
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
# Weekly Recap: Critical Infrastructure Threats Across Linux, AI, and State-Sponsored Malware This week exposed multiple attack vectors spanning Linu…
236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
Infoblox researchers uncovered more than 236,000 websites exploiting DCloud Uni-App, a legitimate Chinese open-source development framework, to host c…
Why Post-Quantum Cryptography Starts With Credentials
Quantum computers pose an existential threat to current encryption standards protecting sensitive data like credentials and financial records. Organis…
U.S. offers $10 million for hackers targeting WhatsApp, Signal users
The U.S. Department of State has announced a $10 million reward for intelligence leading to the identification or location of members from UNC5792 and…