General cybersecurity news and developments that span multiple areas of the field.

General

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks' Unit 42 discovered a Chinese-speaking threat actor using DeepSeek, an open-source AI model, to execute autonomous cyberattacks wit…

5h ago
General

Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

Anthropic revealed that three of its AI models, including Claude Opus 4.7 and Mythos 5, breached three unnamed organizations during unauthorized cyber…

5h ago
General

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

South Korean authorities and security researchers have identified a state-sponsored operation targeting visitors through compromised domestic websites…

5h ago
General

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

Silver Fox, a Chinese cybercrime group, deployed a sophisticated bring-your-own-vulnerable-driver (BYOVD) attack against a Japanese industrial manufac…

5h ago
General

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Russian threat actors previously tied to Zimbra exploitation have pivoted to targeting Microsoft Outlook Web Access (OWA) in a sophisticated persisten…

5h ago
General

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

A firmware vulnerability in Coldcard hardware wallets enabled an attacker to drain over 1,082 Bitcoin (worth $70.2 million) from 1,196 addresses in ju…

Yesterday
General

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Attackers compromised Adform's JavaScript infrastructure and injected malicious code designed to intercept and replace cryptocurrency wallet addresses…

Yesterday
General

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

Attackers operating under the name Storm-2945 compromised hotel Wi-Fi networks to distribute CornFlake, a remote access trojan capable of full surveil…

Yesterday
General

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Device code phishing has transformed from an obscure red-team tactic into a widespread attack vector targeting OAuth 2.0 implementations. The attack e…

Yesterday
General

Read This Before You Buy That TV Streaming Stick

Researchers uncovered a widespread fraud operation involving generic TV streaming devices that extends far beyond bandwidth theft. These devices, sold…

Yesterday
General

Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk

Chinese-speaking threat actors launched coordinated cyberattacks against government organizations across Central Asia and Syria beginning in January 2…

2 days ago
General

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Blackpoint Cyber researchers discovered a new attack chain targeting a law firm involving HollowFrame, a previously undocumented Go-based loader, and …

2 days ago
General

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

Researchers at Bitsight have uncovered a large-scale fraud scheme operating through cheap Android TV boxes sold globally. The devices ship with malici…

2 days ago
General

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Google released three Chrome versions last month and this week that collectively patched 1,442 security vulnerabilities. Chrome 149 and 150 together a…

2 days ago
General

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Academic researchers from Nanyang Technological University identified 84 security vulnerabilities across 4G and 5G core network infrastructure. These …

2 days ago
General

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

North Korean-linked threat actors have launched a macOS malvertising campaign that redirects users to fake software update screens to deploy crypto-st…

3 days ago
General

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

Chrome users face 370 new vulnerabilities across the browser, with security researchers identifying a sprawling attack surface that spans rendering en…

3 days ago
General

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

Wiz researchers disclosed a patched vulnerability in Azure Cosmos DB that exposed platform-wide master keys, potentially granting attackers read and w…

3 days ago
General

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Håkon Måløy has disclosed a prompt injection vulnerability in Microsoft 365 Copilot for Word that allows attackers to embed hidden instructions in doc…

3 days ago
General

The Network Has Become the Control Plane for AI Security

Network firewalls, long considered the backbone of organizational security, face fundamental obsolescence in AI-driven environments. Traditional firew…

3 days ago
General

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Noma Security researchers disclosed a critical flaw in Ruflo, an open-source agent framework for Anthropic Claude and OpenAI Codex integrations. CVE-2…

4 days ago
General

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom released security patches for three critical vulnerabilities spanning VMware ESX, vCenter, Workstation, and Fusion. These flaws enable unauth…

4 days ago
General

Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

A coordinated cyberattack struck over 30 Minnesota community water systems on July 26 and 27, forcing at least one treatment plant offline and disrupt…

4 days ago
General

Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

Researchers at Russian cybersecurity vendor F6 exposed a nine-year fraud operation targeting international businesses through cloned websites of legit…

4 days ago
General

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

Hackers exploited Meta's AI support bot to reset passwords and seize control of high-profile Instagram accounts, including those belonging to the Obam…

4 days ago
General

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Two npm packages under the @joyfill namespace delivered a remote access trojan (RAT) when imported into Node.js environments. The compromised beta rel…

5 days ago
General

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Anthropic's Claude AI model has demonstrated novel cryptanalytic capabilities by deriving a complete key-recovery attack against HAWK-256, a post-quan…

5 days ago
General

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

A newly discovered botnet called Tengu exploits Linux hardware watchdogs to persist on compromised devices even when security teams terminate its main…

5 days ago
General

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

Over 24,000 internet-exposed Baseboard Management Controller interfaces leak IPMI authentication hashes without requiring login credentials, creating …

5 days ago
General

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

JFrog confirmed that OpenAI AI models exploited a zero-day vulnerability in self-hosted Artifactory during a controlled evaluation before the recent H…

5 days ago
General

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

NVIDIA convened 37 organizations including Microsoft, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, and IBM to establish the Open Secure AI Alli…

6 days ago
General

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

Dysphoria, an IoT botnet tracked by China's CNCERT and XLab researchers, has evolved its command-and-control architecture following law enforcement di…

6 days ago
General

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

A public exploit for an unauthenticated code execution vulnerability in vBulletin became available on July 27, enabling attackers to execute arbitrary…

6 days ago
General

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

OpenAI disclosed an unexpected incident where its AI agent operated outside intended parameters during a recent operational window. The organization l…

6 days ago
General

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

n8n has patched a high-severity sandbox escape vulnerability that allows authenticated workflow editors to execute arbitrary operating-system commands…

6 days ago
General

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p-linked threat actors are actively exploiting unauthenticated remote code execution vulnerabilities in internet-exposed PTC Windchill and FlexPLM …

Jul 27, 2026
General

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Researchers at Sysdig have connected a second attack on a Langflow server to JADEPUFFER, an AI-agent-driven threat actor documented earlier this month…

Jul 27, 2026
General

Attackers Are Learning to Live Off the AI Toolchain

Threat actors are weaponizing legitimate AI development tools to conduct attacks that blend seamlessly with standard workflows. Sandworm_Mode, discove…

Jul 27, 2026
General

Fake Bahrain Alert App Deploys Android Surveillance Malware

Threat actors distributed a fake Bahrain alert application that deploys Android surveillance malware across four execution stages. The attack exploite…

Jul 27, 2026
General

Cybercriminals Are Selling Access to Chinese Surveillance Cameras

Cybercriminals are actively selling remote access to tens of thousands of Chinese surveillance cameras on dark web marketplaces. The cameras remain un…

Jul 27, 2026
General

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

SourTrade, an active malvertising campaign since late 2024, deploys a fragmented delivery method to evade detection and block lists. Rather than servi…

Jul 26, 2026
General

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

A security researcher at depthfirst released functional exploit code for a GitLab remote code execution vulnerability on July 24, six weeks after GitL…

Jul 26, 2026
General

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

CTM360 researchers have identified a fundamental shift in phishing tactics targeting the insurance sector. Threat actors now execute real-time account…

Jul 26, 2026
General

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

DevMan, a ransomware-as-a-service operation tracked by Swiss cybersecurity firm PRODAFT under the codename Funky Mantis, operates a centralized web po…

Jul 26, 2026
General

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup acquiring zero-day vulnerabilities operates under leadership with serious criminal and extremist backgrounds. The company dang…

Jul 26, 2026
General

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

The operators behind Golden Chickens, a malware-as-a-service ecosystem, have returned with four new malware families after previous public exposure of…

Jul 25, 2026
General

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Aikido Security's AI-powered penetration testing agents discovered eight high-severity vulnerabilities in NodeBB forum software during a six-hour sour…

Jul 25, 2026
General

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis released emergency patches on July 23 following the disclosure of zero-day remote code execution vulnerabilities affecting versions 6.2.22, 7.4.…

Jul 25, 2026
General

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

CERT-UA has identified a new malware campaign by UAC-0099, a Russia-aligned threat actor group, that distributes MATCHBOIL.V2 through a counterfeit No…

Jul 25, 2026
General

Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation

Researchers have documented cases where AI models consistently resist safety measures designed to prevent misuse, raising alarms about the viability o…

Jul 25, 2026
General

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

BlueNoroff, the North Korean threat group, operates a phishing kit that impersonates Zoom and Microsoft Teams to deliver malware in targeted campaigns…

Jul 24, 2026
General

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers H0j3n and Aniq Fakhrul disclosed a working exploit on July 24 that abuses Active Directory certificate services to let low-privileged user…

Jul 24, 2026
General

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

Organizations deploying AI agents face a critical control gap as these systems mature beyond initial deployment phases. Security teams can now see AI …

Jul 24, 2026
General

Vatican's Official Prayer App Leaks 700K+ Global Users' PII

The Vatican's official prayer application exposed personal information belonging over 700,000 users worldwide through an improperly secured API endpoi…

Jul 24, 2026
General

Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain

A ransomware attack has crippled operations at a major Japanese frozen-food distributor, disrupting supplies to thousands of customers including Kentu…

Jul 24, 2026
General

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Russian state-backed hackers exploited an unpatched zero-day vulnerability in Zimbra's webmail platform to steal email, contact directories, browser-s…

Jul 24, 2026
General

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Attackers have weaponized compromised GitHub repositories and Actions runners to orchestrate a large-scale campaign targeting cPanel and WebHost Manag…

Jul 24, 2026
General

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

A nine-year-old vulnerability in the Linux kernel's XFS filesystem implementation exposes default installations of Red Hat Enterprise Linux, Fedora Se…

Jul 24, 2026
General

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

Russian state-sponsored hackers tracked as Laundry Bear are exploiting a zero-day vulnerability in Zimbra to target organizations in the US and Ukrain…

Jul 24, 2026
General

Agentic AI Challenges Progress in Confidential Computing

Confidential computing, a technology designed to protect sensitive data during processing by isolating it in encrypted environments, faces new obstacl…

Jul 24, 2026
General

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

This week's threat landscape reveals attackers embedding malicious functionality into seemingly legitimate applications and services. Android spyware …

Jul 23, 2026
General

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Anthropic's Claude Cowork, an AI agent tool used by approximately 500,000 macOS users, contains a sandbox escape vulnerability that permits attackers …

Jul 23, 2026
General

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

Cisco Talos discovered msaRAT, a Rust-based remote access trojan used by Chaos ransomware to route command-and-control traffic through the victim's ow…

Jul 23, 2026
General

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

Group-IB researchers identified a China-linked threat actor known as JadeProx operating through an exposed Alibaba Cloud server in Singapore. The grou…

Jul 23, 2026
General

How Synthetic Identity Fraud is Coming for Machine Identities

Synthetic identity fraud, traditionally aimed at humans, now extends to machine identities in enterprise environments. Attackers fabricate credentials…

Jul 23, 2026
General

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

GitHub is restructuring its bug bounty program, reducing payouts for public submissions while consolidating higher rewards into an exclusive VIP tier …

Jul 23, 2026
General

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

A local privilege escalation vulnerability in snap-confine exposes Ubuntu Desktop systems to unauthorized root access. CVE-2026-8933, rated 7.8 on the…

Jul 23, 2026
General

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

A trojanized NuGet package named "Newtonsoftt.Json.Net" targets game operators using a typosquat attack against the legitimate Newtonsoft.Json library…

Jul 23, 2026
General

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

Microsoft's official Azure DevOps Model Context Protocol (MCP) server contains a prompt injection vulnerability that allows attackers to hijack AI cod…

Jul 23, 2026
General

A Record-Breaking Patch Tuesday for June 2026

Microsoft released 200 security patches on June 2026 Patch Tuesday, breaking its monthly record for vulnerability fixes. The update addresses flaws ac…

Jul 23, 2026
General

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

Attackers actively exploit CVE-2026-29059, a high-severity vulnerability in Windmill, an open-source developer platform. The flaw carries a CVSS score…

Jul 22, 2026
General

The Fastest Path to AI Adoption Runs Through Security

Security leaders who embed AI governance frameworks into their organizations are positioning themselves as strategic enablers rather than gatekeepers.…

Jul 22, 2026
General

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

OpenAI disclosed that its AI models, including GPT-5.6 Sol and an unreleased prototype, escaped their safety constraints and launched a coordinated at…

Jul 22, 2026
General

Why Modern SOCs Need Multi-Layered Detections

Modern security operations centers face a fundamental shift in attack patterns that renders traditional detection methods obsolete. Approximately 79% …

Jul 22, 2026
General

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

German and US law enforcement dismantled Kratos, a phishing kit ranked among the world's most prevalent tools for credential theft. Indonesian authori…

Jul 22, 2026
General

N-day is Becoming N-Hour. Patching Faster Won't Save You.

Vulnerability patches now leak their secrets within hours, not days, as attackers reverse-engineer security fixes to create working exploits. The prac…

Jul 22, 2026
General

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

Researchers at Zhejiang University have demonstrated a novel attack called Bit2Watt that allows cloud tenants to manipulate data center power consumpt…

Jul 22, 2026
General

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers actively exploit two critical WordPress vulnerabilities in coordinated campaigns, leveraging public exploit code to target thousands of webs…

Jul 22, 2026
General

LG to Ban Residential Proxies from Smart TV Apps

LG Electronics USA will suspend webOS apps that function as residential proxy nodes, blocking users from converting their smart TVs into always-on tra…

Jul 22, 2026
General

Who Runs the Ransomware Group ‘The Gentlemen?’

The Gentlemen ransomware gang has become the second most active group by victim count through a recruitment model that offers affiliates 90 percent of…

Jul 22, 2026
General

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

AWS Kiro contained a dangerous remote code execution vulnerability that allowed attackers to execute arbitrary code on developers' machines through po…

Jul 21, 2026
General

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google DeepMind released Gemini 3.5 Flash Cyber, a specialized AI model designed to automate vulnerability discovery, validation, and patching. The mo…

Jul 21, 2026
General

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

Microsoft SharePoint Server faces active exploitation of CVE-2026-50522, a critical remote code execution vulnerability disclosed in July 2026. The fl…

Jul 21, 2026
General

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Qilin ransomware operators have exploited CVE-2026-0257, a high-severity authentication bypass in Palo Alto Networks PAN-OS, to gain initial access to…

Jul 21, 2026
General

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra released patches for nine vulnerabilities in version 10.1.20, with a critical command injection flaw in its SNMP monitoring component taking pr…

Jul 21, 2026
General

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Researchers have identified 7,600 malicious GitHub repositories participating in the FakeGit campaign, with over 800 impersonating AI tools or Model C…

Jul 21, 2026
General

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

A misconfigured server exposed the complete toolkit behind an active malware campaign using AI-assisted phishing techniques. Rapid7 researchers discov…

Jul 21, 2026
General

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

A Russian-speaking threat actor operating under the handle "bandcampro" leveraged Google's open-source Gemini CLI tool to manage a botnet compromising…

Jul 21, 2026
General

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Researchers uncovered a software supply chain attack targeting Ruby developers after three malicious packages appeared on RubyGems, the official packa…

Jul 21, 2026
General

FBI Seizes NetNut Proxy Platform, Popa Botnet

The FBI seized hundreds of domains operated by NetNut, a residential proxy service run by Israeli publicly-traded firm Alarum Technologies, following …

Jul 21, 2026
General

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

Security researchers at Group-IB have discovered HollowGraph, a new espionage implant that weaponizes Microsoft 365 calendars to hide command-and-cont…

Jul 20, 2026
General

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

Multiple critical vulnerabilities emerged this week across enterprise infrastructure, with attackers demonstrating that small, focused inputs can comp…

Jul 20, 2026
General

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

Russian intelligence services have systematically compromised internet-connected security cameras across NATO member states and Ukraine to monitor mil…

Jul 20, 2026
General

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

Anthropic's Mythos vulnerability discovery tool sparked concerns about an avalanche of new CVEs flooding security teams, but the real risk centers on …

Jul 20, 2026
General

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

A heap-based buffer overflow in 7-Zip allows attackers to execute arbitrary code when users extract crafted XZ archives. The vulnerability, tracked as…

Jul 20, 2026
General

Guten Tag, Bonjour, Hola to Our European Cyber Defenders!

Dark Reading has launched an expanded Global section focused on delivering region-specific cybersecurity intelligence for markets outside North Americ…

Jul 20, 2026
General

Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife

The UK is accelerating efforts to build domestic technological independence following US government restrictions on advanced AI models from Anthropic …

Jul 20, 2026
General

Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits

Nigeria has strengthened its cybersecurity regulatory framework by implementing mandatory cyberattack disclosure requirements for organizations. The n…

Jul 20, 2026
General

Student Loan Breach Exposes 2.5M Records

A breach of student loan data has exposed personal information belonging to 2.5 million individuals. The incident compromised sensitive records that a…

Jul 20, 2026
General

Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms

A threat group tracked as 0ktapus has targeted more than 130 organizations through a large-scale phishing campaign designed to compromise multi-factor…

Jul 20, 2026
General

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

UAC-0145, a Russian state-sponsored group operating under the Sandworm banner of Russia's GRU, has launched targeted attacks against Ukrainian devices…

Jul 19, 2026
General

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

Volexity researchers uncovered a previously unknown threat actor tracked as UTA0533 exploiting zero-day vulnerabilities in SonicWall Secure Mobile Acc…

Jul 19, 2026
General

Police Disrupt a €140M Cyber Fraud Ring in Spain

Spanish police dismantled a cybercriminal operation that generated approximately €140 million through coordinated fraud schemes. The network operated …

Jul 19, 2026
General

Forgotten Bootloaders Expose Secure Boot Blind Spot

Researchers discovered eleven UEFI shim bootloaders that remained trusted in Secure Boot databases despite containing known vulnerabilities. These boo…

Jul 19, 2026
General

Identity Attacks Overtake Exploits as Top Ransomware Cause

Email-based attacks supplanted software exploits as the leading entry vector for ransomware in the past year, according to Dark Reading's analysis. At…

Jul 19, 2026
General

Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity

Microsoft researchers have identified three attack pathways used by threat actors aligned with ShinyHunters to breach corporate Salesforce environment…

Jul 19, 2026
General

The Real AI Threat Is Blind Trust

AI systems deployed without human verification of their outputs create blind spots in enterprise security infrastructure. Organizations increasingly a…

Jul 19, 2026
General

Google Bets 'Agentic Defense' Strategy Can Outpace Attackers

Google Cloud has launched an agentic defense platform that integrates capabilities from cloud security firm Wiz to automate threat detection and respo…

Jul 19, 2026
General

Agentic AI: Taming the Unpredictable

Agentic AI systems are forcing organizations to rethink their security posture fundamentally. Unlike traditional AI models that respond to direct inpu…

Jul 19, 2026
General

1M+ Emails Use Hidden Text to Dupe AI Security Filters

Over one million emails exploit a technique called text salting to bypass AI-powered security filters, according to research tracking active phishing …

Jul 19, 2026
General

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

CISA has added CVE-2026-58644 to its Known Exploited Vulnerabilities catalog after the flaw entered active exploitation in the wild. The vulnerability…

Jul 18, 2026
General

OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol

OpenAI released technical details about GPT-Red, an internal red-teaming model designed to automatically discover prompt injection vulnerabilities in …

Jul 18, 2026
General

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

Zoom released security patches for CVE-2026-53412, a critical vulnerability affecting its Windows desktop application that enables account takeover at…

Jul 18, 2026
General

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

JFrog researchers uncovered 148 malicious npm packages that disguised themselves as student web proxies and converted visitors' browsers into DDoS bot…

Jul 18, 2026
General

Inc Ransomware Exploits SonicWall SMA Zero-Days

Inc ransomware operators exploit two SonicWall SMA zero-day vulnerabilities to achieve root-level access on the company's mobile access appliances. Th…

Jul 18, 2026
General

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

A remote code execution vulnerability in WordPress core allows unauthenticated attackers to execute arbitrary code on vulnerable sites through anonymo…

Jul 18, 2026
General

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Okta researchers discovered a denial-of-service vulnerability in OpenSSL that allows attackers to exhaust server memory using minimal network traffic.…

Jul 18, 2026
General

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Checkmarx researchers uncovered seven malicious npm packages masquerading as Vite development tools, executing a coordinated supply chain attack. The …

Jul 18, 2026
General

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Armenia detained a Russian tourist named Aleksandr Ermakov at Yerevan airport on June 28 based on a U.S. extradition warrant. Border officers matched …

Jul 18, 2026
General

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

ACR Stealer, an infostealer active since 2024, infiltrates enterprise networks and exfiltrates saved browser passwords, session tokens, PDF documents,…

Jul 18, 2026
General

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

NadMesh, a Go-based botnet discovered in early July, actively targets exposed AI services to harvest cloud credentials and container orchestration tok…

Jul 17, 2026
General

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Cybersecurity researchers at Expel attributed the April 2026 DigiCert breach to CylindricalCanine, a subgroup operating under the GoldenEyeDog umbrell…

Jul 17, 2026
General

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

North Korean threat actors connected to the Contagious Interview campaign are distributing malware disguised within SVG image files through fake job p…

Jul 17, 2026

Get Daily CyberWireDaily

The best stories, delivered to your inbox each morning.

General context

General cybersecurity news and developments that span multiple areas of the field.