13Articles
7Categories
2026-07-04Date
🐛 COMMON VULNERABILITIES AND EXPOSURES 2[−]
4 JulNew "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits AndroidA newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out. Bad Epoll sits in the same small stretch of kernel code wh…THEHACKERNEWS.COM
4 JulCVE-2026-53223 net: guard timestamp cmsgs to real error queue skbsInformation published.MSRC.MICROSOFT.COM
⚠️ VULNERABILITY DISCLOSURE 2[−]
4 JulUnpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded DevicesSecurity firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter because FatFs is nearly everywhere. It ships inside the firm…THEHACKERNEWS.COM
4 JulAdaptHealth says attackers sweet-talked their way into cloud systems and stole patient dataConnor Jones reports: AdaptHealth says attackers used social engineering to breach its systems and steal sensitive patient data, including passwords associated with insurance billing. The medical equipment company disclosed the attack to the Securities and Exchange Commission (SE…DATABREACHES.NET
📋 SECURITY BULLETINS 1[−]
4 JulFBI: TeamPCP Compromised Dev Tools to Steal Cloud CredentialsFBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used d…SECURITYAFFAIRS.COM
🔥 INCIDENT REPORTING 4[−]
4 JulNew Avalon Malware Framework Packs CrownX Ransomware CapabilitiesCybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, …THEHACKERNEWS.COM
4 JulU.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion CaseA U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd part: the group that took the money …THEHACKERNEWS.COM
4 JulJadePuffer ransomware used AI agent to automate entire attackResearchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. [...]BLEEPINGCOMPUTER.COM
4 JulU.S. Government Agency Paid $1M to Data Extortion Group KairosA U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports. A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairo…SECURITYAFFAIRS.COM
🕵️ THREAT INTELLIGENCE 2[−]
4 JulNorth Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider CampaignThe North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider. "The campaign remains a…THEHACKERNEWS.COM
4 JulAI Tested Against Cyber ExpertsCybersecurity platforms like Hack The Box are being used to benchmark both human practitioners and AI models in the same realistic lab environments. Government AI security institutes have also used these systems to evaluate advanced models. This creates one of the clearest real-w…YOUTUBE.COM
📰 CYBERSECURITY BRIEFINGS 1[−]
4 JulSecurity Roundup: Apple’s Hide My Email Service Fails to Hide Your EmailPlus: Alleged Scattered Spider hacking member extradited, dozens of license plate reader errors, and Indian officials are concerned about WhatsApp’s username rollout.WIRED.COM
📡 INFOSEC NEWS 1[−]
4 JulAlibaba reportedly bans employees from using Claude CodeAlibaba has reportedly classified Claude Code as high-risk software.TECHCRUNCH.COM