🐛 COMMON VULNERABILITIES AND EXPOSURES 9[−]
6 JulAI-Run Ransomware, New Oracle Critical Flaw, NetNut bustedAI-Run Ransomware, New Oracle 9.8 Flaw Exploited, NetNut Proxy Network Busted, and Pegasus Hits EU Spyware Investigator This episode covers researchers' report of "Jade Puffer," the first ransomware attack run end-to-end by an autonomous AI agent, which exploited a patched Langfl…CYBERSECURITYTODAY.LIBSYN.COM
6 JulBad Epoll Flaw Gives Attackers Root Access on Linux and AndroidBad Epoll (CVE-2026-46242) lets local attackers gain root on Linux and Android. The flaw was missed by AI but found by a security researcher. A newly disclosed Linux kernel vulnerability, named Bad Epoll (CVE-2026-46242), allows a local attacker with no special privileg…SECURITYAFFAIRS.COM
6 JulThis AI agent autonomously hacked a network, adapted on the fly, and demanded a ransomA fully autonomous AI agent conducted an end-to-end cyber intrusion and extortion campaign after exploiting a vulnerable Langflow server, demonstrating how large language models could accelerate ransomware operations, according to research published by Sysdig. Sysdig detailed the…CSOONLINE.COM
6 JulMax severity Adobe ColdFusion flaw now exploited in attacksAttackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, the Canadian Center for Cyber Security (CCCS) warned on Thursday. [...]BLEEPINGCOMPUTER.COM
6 JulThreat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After DisclosureThreat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the "X-WEB…THEHACKERNEWS.COM
6 JulVU#828543: HP Deskjet 2800 Printer Series Webservers contain Missing Authorization VulnerabilityOverview HP Printers in the Deskjet 2800 Series running firmware version <=TBP1CN2612AR contain a missing authorization vulnerability tracked as CVE-2026-13753. This vulnerability allows unauthenticated access to the printer's webserver API endpoints, exposing Wi-Fi credential…KB.CERT.ORG
6 Jul16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 SystemsA use-after-free bug in Linux's KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. Dubbed 'Januscape' and tracked as CVE-2026-53359, the flaw sits in the shadow MMU code that KVM shares across both I…THEHACKERNEWS.COM
6 JulVU#213560: Tenda firmware (multiple versions) contains hidden authentication backdoorOverview Several versions of Tenda firmware contain an undocumented authentication backdoor that grants administrative access to the devices' web management interfaces. An attacker can expoit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification proce…KB.CERT.ORG
6 Jul KEVAdobe ColdFusion flaw CVE-2026-48282 now exploited in the wildAttackers are exploiting the critical Adobe ColdFusion flaw CVE-2026-48282, which allows remote code execution on unpatched servers. Attackers have started exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. The flaw is a path traversal issue that cou…SECURITYAFFAIRS.COM
⚠️ VULNERABILITY DISCLOSURE 31[−]
6 JulThe future of payment fraud could be automatedPayment fraud is becoming more organized as criminal groups use fake websites, large-scale operations, and, in some cases, forced labor to steal money and personal information. Advances in agentic AI could automate many stages of payment fraud, from collecting and assembling stol…HELPNETSECURITY.COM
6 JulFlipper Zero firmware development gets a fresh set of community rulesOwners of the Flipper Zero, the pocket-sized wireless testing tool, spent recent weeks worried that its official firmware had gone quiet. Pavel Zhovner, CEO of Flipper Devices, moved to settle that concern with word that the company has set aside staff to keep the firmware mainta…HELPNETSECURITY.COM
6 JulRisky Bulletin: EU official’s phone infected with PegasusA European MP’s phone was infected by Pegasus spyware, Android drops its PIN guessing limit from 1,800 attempts to 20, Alibaba bans employees from using Claude at work, and there’s a new vulnerability in the Linux kernel.RISKY.BIZ
6 JulSecuring the inbox: Where identity, brand and security meetGetting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. You have to work with a DMARC partner for setting up DMARC and BIMI, then use a trusted Certificate Authority (CA) to purchase a Mark Certificate, and this mean…HELPNETSECURITY.COM
6 JulOmnigent: Open-source AI agent framework and meta-harnessPlenty of developers now keep several coding agents close at hand, reaching for Claude Code on one task and Codex or Cursor on the next. Each tool arrives with its own command line, its own handling of credentials, and its own way of running shell commands against a working direc…HELPNETSECURITY.COM
6 Jul7 cyber risk assessment gotchas to avoidA cyber risk assessment helps security teams identify, estimate, and prioritize potential threats and vulnerabilities to key enterprise digital and physical assets. Yet, despite its importance, many CISOs fall victim to several types of “gotchas” that prevent them from fully achi…CSOONLINE.COM
6 JulAI isn’t closing the skills gap — it’s exposing the validation gapIf you wanted to become a basketball star, how would you get started? You wouldn’t read a book on basketball and take an online course. You’d set up a hoop in your driveway, join a local team to train, and play in real matches. So why do we expect cybersecurity professionals to l…CSOONLINE.COM
6 JulFinding vulnerabilities was never the hard partAI is surfacing vulnerabilities at a scale the industry has never seen, and most organizations have no way to determine which ones actually matter. The post Finding vulnerabilities was never the hard part appeared first on CyberScoop .CYBERSCOOP.COM
6 JulNCA Issues Warning to Parents As Shared Child Photos Exploited by AI ToolsIWF and NCA warn that growing numbers of images and videos are being manipulated into sexual abuse materialINFOSECURITY-MAGAZINE.COM
6 JulSingle points of failure fail. The SaaS layer is not an exceptionHigher education has consolidated its entire academic operation into a handful of massive SaaS platforms. The LMS manages instruction, grading and communication. The SIS owns enrollment, records and financial aid. Identity and productivity live in a small number of cloud provider…CSOONLINE.COM
6 JulMastering agent permissions and Identiverse interviews - ESW #466Interview with Sandy Bird, co-founder of Sonrai Security In this week's interview, we kick off the conversation with how Sonrai's expertise in securing cloud identity permissions had the company well placed to address the explosion of AI agents and the clear risks they represente…YOUTUBE.COM
6 JulFrance to Stop Certifying Non-Quantum-Safe EncryptionFrance is accelerating its transition to post-quantum encryption: France’s cybersecurity agency ANSSI said on Tuesday it would stop certifying security products that lack quantum-resistant encryption, a move that will force government bodies and critical operators to shift …SCHNEIER.COM
6 JulPrompt Injection Attacks Trick AI Agents Into Making Crypto PaymentsResearchers uncovered two campaigns embedding indirect prompt injections in malicious websites to exploit autonomous AI agents browsing the web. The post Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulSeven Bugs in FatFs Put IoT and Embedded Devices at RiskrunZero found 7 flaws in FatFs, a filesystem used in IoT and embedded devices. Bugs can cause memory corruption, crashes, or data leaks via crafted storage. Cybersecurity firm runZero has disclosed seven vulnerabilities in FatFs, a compact open-source library that lets embedded d…SECURITYAFFAIRS.COM
6 JulProof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access VulnerabilityOrganizations are urged to patch after proof-of-concept code makes the Linux root escalation flaw easier to exploit. The post Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
6 Jul⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreA streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary. Home devices became a routing cover. Clean code pulled dirt from a de…THEHACKERNEWS.COM
6 JulNorth Korean Hackers Target Open Source Developers in Supply Chain AttacksThe PolinRider campaign has compromised more than 100 legitimate open source packages and repositories to deliver a backdoor and information stealer to developers. The post North Korean Hackers Target Open Source Developers in Supply Chain Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulCriminal IP integrates threat intelligence with OpenCTI for automated indicator enrichmentCriminal IP has integrated its threat intelligence with OpenCTI, enabling security teams to automatically convert IP addresses, domains, and URLs into structured intelligence within the platform’s knowledge graph. The integration automatically enriches ingested indicators w…HELPNETSECURITY.COM
6 JulLTM’s BlueVerse RightLogic combines AI risk assessment with cyber remediation planningLTM has launched BlueVerse RightLogic, a cybersecurity assessment and risk assurance framework designed to help enterprises identify, assess and remediate cyber exposure as they accelerate AI adoption. AI is now capable of autonomously identifying and exploiting vulnerabilities, …HELPNETSECURITY.COM
6 JulA Day With Your Vector Command Red Team PodAnyone trying to understand continuous red teaming usually gets the same high-level explanation: it is ongoing, attacker-informed, and designed to uncover risk between formal assessments. Useful as that description is, it still leaves most people with the same question, which is …RAPID7.COM
6 JulAlberta, Centurion Project sued over alleged data breach that affected millions of votersCarrie Tait reports: A retired lawyer is suing Alberta, its Chief Electoral Officer and two organizations that support secession for their respective roles in an alleged data breach affecting 2.9 million residents in the province. Clint Docken, a former class-action lawyer, last …DATABREACHES.NET
6 JulCanadian spy agency says it hacked drug traffickers, extremists and a ransomware gang last yearThe hacking operations disclosed in a Canadian spy agency's annual report underscores some pressing national security threats facing the country and its top allies.TECHCRUNCH.COM
6 JulThe agentic blind spots in your zero trust programStephen Wilson, field chief technology officer for HashiCorp, an IBM company, likens AI agents to “really smart kindergartners.” “They know how to do something, but they have no clue as to why they should do it,” Wilson says. This combination of superior execution power and lack …CSOONLINE.COM
6 JulIdentity: The operational control plane for agentic AIExisting security controls weren’t designed for AI agents. Static credentials and standing privileges aren’t sufficient for an emerging model where organizations need to rapidly authorize, limit, and revoke permissions from autonomous agents, sometimes more than once within a sin…CSOONLINE.COM
6 JulEnforce least-privilege authorization in multi-agent AI chains using CedarIf you’re building multi-agent AI systems, you need to prevent authorization scope from silently expanding as agents delegate tasks through multi-hop chains. Without proper controls, an agent can potentially act beyond what the originating user authorized, even when role-based ac…AWS.AMAZON.COM
6 JulJapanese teen arrested over cyberattack that disrupted anime streaming serviceThe unnamed student, who lives in a city near Tokyo, allegedly exploited a flaw in a subscription-based anime streaming platform to fraudulently cancel more than 46,000 user subscriptions.THERECORD.MEDIA
6 JulJadePuffer: The First Complete LLM-Driven Ransomware AttackAn "agentic threat actor" successfully exploited a Langflow flaw to steal data from a production database server and encrypt other systems.DARKREADING.COM
6 JulGoogle Chrome extensions must meet new privacy standards by August 1Google has announced a set of Chrome Web Store policy changes that tighten rules around extension data collection, improve transparency requirements, and prohibit new categories of software. The updated Developer Program Policies will take effect on August 1, 2026, giving extensi…CYBERINSIDER.COM
6 JulNetNut gets cracked.The FBI disrupts a major residential proxy service. Attackers exploit Fortinet firewalls to target UK officials. European lawmakers call for a spyware investigation. A new macOS infostealer masquerades as a clipboard manager. Prompt injection campaigns targeting AI agents through…THECYBERWIRE.COM
6 JulCitrixBleed-ing Again? NetScaler Vulnerability Under AttackAttackers wasted little time targeting the latest memory disclosure flaw in Citrix's NetScaler products, after researchers published a proof-of-concept exploit (PoC).DARKREADING.COM
6 JulThe “Anonymous” Tip System That Wasn’t: Three Months Later, Why Hasn’t Navigate360 Notified Anyone?Trigger Warning: This post includes content from tips submitted to anonymous tiplines by or about students. While identity information is redacted, tips may include obscenities and explicit references to sexual abuse, rape, assault, self-harm, violence, suicidal ideation, pornogr…DATABREACHES.NET
📢 SECURITY ADVISORIES 16[−]
6 JulCavern Manticore: Exposing Iran-Linked Modular C2 FrameworkKey Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern M…RESEARCH.CHECKPOINT.COM
6 JulOperationalizing Agentic AI: from assisted to autonomousEver since ChatGPT made its public debut nearly four years ago, governance and security have largely lagged behind AI adoption. Eager to experiment with AI tools and find ways to improve their work and personal lives, users have uploaded corporate data, financial records, and eve…CSOONLINE.COM
6 JulKYC : Bypass age verification using generative video modelsHistorically reserved for the banking sector, the KYC (Know Your Customer) process is now making its way into many online services, driven by increasingly strict legislation on anonymity and age verification. To comply, platforms deploy significant measures aimed at guaranteeing …SYNACKTIV.COM
6 Jul5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture ManagementRead five key learnings from the Frost & Sullivan 2025 Frost Radar™ for CSPM to learn how CSPM is evolving from point-in-time compliance to continuous risk management. The post 5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management app…MICROSOFT.COM
6 JulAI Needs an Identity TooAI is transforming identity security in two directions. Organizations are using AI to automate identity management, while AI agents themselves are becoming identities that require permissions, monitoring, and governance. As AI agents access sensitive data and perform actions on b…YOUTUBE.COM
6 JulEFF-led coalition urges FTC to reject X’s bid to end privacy oversightA coalition of 15 public-interest organizations is urging the U.S. Federal Trade Commission (FTC) to reject X Corp.'s request to terminate or weaken a 2022 privacy order requiring the company to undergo regular compliance reviews after it repeatedly violated users' privacy. The g…CYBERINSIDER.COM
🔥 INCIDENT REPORTING 11[−]
6 JulHow to prioritize AI agent security by business impactYour CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had this level of access. The agent was connected to a spend management application to reconcile invoices, summa…HELPNETSECURITY.COM
6 JulResearchers Claim First Fully Agentic Ransomware: JadePufferResearchers have revealed JadePuffer, the first agentic AI-powered ransomware campaign, highlighting how autonomous agents can automate cyber-attacksINFOSECURITY-MAGAZINE.COM
6 JulICE’s Internal Watchdog Is Now Investigating Online CriticsThe Office of Professional Responsibility has opened more than 100 cases over what ICE officials call “incidents of doxing and threats” against ICE employees.WIRED.COM
6 JulSuspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRATA suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensitive data from compromised hosts. The multi-stage campaign, codenamed Operation Dr…THEHACKERNEWS.COM
6 Jul6th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES River Bank & Trust, a US financial institution, has experienced a ransomware incident after an unauthorized actor accessed the net…RESEARCH.CHECKPOINT.COM
6 JulFBI disrupts residential proxy network used by botnet.New macOS infostealer poses as a clipboard manager. AdaptHealth discloses data breach affecting patient information.THECYBERWIRE.COM
6 JulSysdig clocks first documented case of agentic ransomwareThe AI agent didn’t accomplish every step in the late June 2026 attack, but it allowed the threat actor to significantly reduce complexity, speed up the tempo and gain operational advantages. The post Sysdig clocks first documented case of agentic ransomware appeared first on Cyb…CYBERSCOOP.COM
6 JulMajor medical device manufacturer notifies nearly 4 million of breachInformation like Social Security numbers and health-related data was accessed, but the company said it had “no evidence that impacted information has been publicly posted or exposed on the internet.”THERECORD.MEDIA
6 JulBlogspot-Hosted Payloads Delivered in ‘Veil#Drop’ AttacksSecuronix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog information stealer. The post Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks appeared first on Se…SECURITYWEEK.COM
6 JulCanadian spy agency reports hacking three criminal groups in 2025A ransomware-as-a-service gang, an online foreign extremist group and drug traffickers were separately the targets of offensive operations in 2025, according to Canada's Communications Security Establishment.THERECORD.MEDIA
6 JulThe ‘first’ AI-run ransomware attack still needed a humanAn AI agent carried out the technical execution of a real-world ransomware attack for the first known time, but new details show a human still chose the victim, set up the infrastructure, and supplied stolen credentials — meaning it wasn't quite the fully autonomous cybercrime de…TECHCRUNCH.COM
🕵️ THREAT INTELLIGENCE 15[−]
6 JulProduct showcase: Is that text a scam? Malwarebytes Mobile Security can help you find outMalwarebytes Mobile Security for iPhone combines scam prevention, privacy protection, and identity monitoring in a single app. It evaluates a device’s security posture, provides recommendations to improve protection, and is available for Windows, macOS, Android, iOS, and Ch…HELPNETSECURITY.COM
6 JulOAuth, guest accounts, and weak MFA drive SaaS riskOrganizations often create guest accounts to give contractors, suppliers, and partners temporary access to files and SaaS applications. Many of these accounts remain active long after they are needed, creating overlooked access paths to corporate data. Guest accounts accounted fo…HELPNETSECURITY.COM
6 JulWhen checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft websiteThe OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it.SECURELIST.COM
6 JulISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
6 JulRCS and DNS: The NAPTR Record, (Mon, Jul 6th)Over the last year, with recent updates to iOS and Android, RCS (Rich Communication Services) has become an increasingly used protocol [1]. RCS is supposed to eventually replace SMS, and in addition to richer formatting, provides added (but optional) security. RCS messa…ISC.SANS.EDU
6 JulUkrainian media outlets now among 'priority targets' for Russian hackersA top Ukrainian security official described two previously unreported attacks on TV media organizations and said Russia has ramped up hacking activities against the industry.THERECORD.MEDIA
6 JulOpenSSH 10.4 arrives with security fixes and a post-quantum signature optionOperators who manage remote access to Unix and Linux systems keep a close watch on OpenSSH, the software that carries most SSH traffic across the internet. The project released version 10.4 with eight security fixes, a set of bug corrections, and a couple of new features. What th…HELPNETSECURITY.COM
6 JulCheap AI Will Handle Most TasksFuture AI systems are expected to split work between lightweight local models and larger cloud-based foundation models. Simple tasks can be completed by inexpensive models, while advanced reasoning is reserved for more capable—and more expensive—AI. This hybrid approach could low…YOUTUBE.COM
6 JulAlleged member of Scattered Spider extradited to USA man with dual US-Estonian citizenship was charged in connection to the hack of a luxury jewelry retailer.CYBERSECURITYDIVE.COM
6 JulThe Shift Toward Business-Aligned Risk ManagementMoving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. The post The Shift Toward Business-Aligned Risk Management appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulArmored Likho APT Targeting Government, Electric Power EntitiesThe threat actor uses modular RATs and information stealers in financially motivated and cyber espionage campaigns. The post Armored Likho APT Targeting Government, Electric Power Entities appeared first on SecurityWeek .SECURITYWEEK.COM
6 JulUS Army websites defaced with pro-Kurdish sentiments, insults to TrumpAt least two websites appear to be victim to 404 hijacking attacks. Army officials took the sites down after being contacted by CyberScoop. The post US Army websites defaced with pro-Kurdish sentiments, insults to Trump appeared first on CyberScoop .CYBERSCOOP.COM
6 JulExpressVPN adds passkeys on password manager, passes security auditExpressVPN has announced a major update to its standalone ExpressKeys password manager, adding passkey support, secure credential sharing, and direct vault imports. Alongside the release, the company published a new independent security assessment by Cure53, which found no severe…CYBERINSIDER.COM
6 JulFake IT support calls on Microsoft Teams push EtherRAT malwareThreat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. [...]BLEEPINGCOMPUTER.COM
6 JuluBlock Origin Chrome extension now blocks known ClickFix sitesuBlock Origin has quietly added protections against ClickFix attacks to its built-in badware filter list, helping block access to websites that attempt to trick users into copying and executing malicious commands. The capability came to light through a user discussion on Mastodon…CYBERINSIDER.COM
🌐 CYBER THREAT LANDSCAPE 6[−]
6 JulSkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting PackingScanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology. Their strongest trick slipped pa…THEHACKERNEWS.COM
6 JulA week in security (June 29 – July 5)A list of topics we covered in the week of June 29 to July 5 of 2026MALWAREBYTES.COM
6 JulNew TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable EmissionsResearchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them radiates a faint ra…THEHACKERNEWS.COM
6 JulNew Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOSCybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that's capable of targeting Windows, Linux, and macOS environments. According to LevelBlue, the cross-platform malware is advertised under a malware-as-a-service (MaaS) model, cos…THEHACKERNEWS.COM
6 JulNetNut botnet takes a hit. Don’t be part of the next one.Google, the FBI, and other partners have disrupted a residential proxy network built on millions of hijacked devices and used by criminals.MALWAREBYTES.COM
6 Jul'BusySnake' Infostealer Slithers into Critical Infrastructure NetworksA threat group researchers call "Armored Likho" has gained access to government agencies and electrical power entities in Russia, Brazil, and Kazakhstan.DARKREADING.COM
📡 INFOSEC NEWS 14[−]
6 JulOpera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited PagesResearchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits. In a proof of concept, they reconstructed a signed-in user's…THEHACKERNEWS.COM
6 JulThe security leaders defining the next decade aren’t in CISO seats yetThe first recognition program for the security leaders who will define the future of cybersecurity.CYBERSECURITYDIVE.COM
6 JulWhy schools are easy prey for hackers — and why they struggle to fight backPower plants and gas pipelines might receive more attention, but schools are arguably more vulnerable.CYBERSECURITYDIVE.COM
6 JulHow to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutionsBuilding a shortlist for an AI SOC evaluation can be tough. SIEM, SOAR, and pureplay AI SOC vendors are all saying the same thing. But behind the identical label sit very different products, from chat assistants bolted onto a legacy SIEM to agent platforms that run detection, tri…THEHACKERNEWS.COM
6 JulChoose your WhatsApp username carefullyWhatsApp is introducing usernames to help protect your phone number. Just make sure you don't undermine that privacy by choosing the wrong one.MALWAREBYTES.COM
6 JulHidden Web Prompts Trick AI Agents Into Sending MoneyHidden prompts on malicious websites trick AI agents into making payments or trusting fake sites, exposing new risks for autonomous AI workflows. Zscaler ThreatLabz documented two active campaigns that embed hidden instructions in web pages to manipulate AI agents, not human user…SECURITYAFFAIRS.COM
6 JulIndirect Prompt Injection in Web Content Targets AI AgentsZscaler found sites hiding prompt-injection text to manipulate AI agents into crypto paymentsINFOSECURITY-MAGAZINE.COM
6 JulOpera GX Flaw Let Sites Auto-Install Mods to Steal DataOpera GX flaw let sites automatically install mods to steal data from other pages, now patchedINFOSECURITY-MAGAZINE.COM
6 JulSoftware Is Now Written at the Speed of Thought. Security Isn't.Every evolution in software development has reduced the friction between an idea and a deployable application. AI may remove the final barrier, but it also removes many of the moments where security decisions have traditionally taken place. [...]BLEEPINGCOMPUTER.COM
6 JulNew Iran-Nexus Hacking Group Targets Israel Government and IT SectorsCheck Point researchers have identified a new cyber adversary targeting Israeli government and IT businesses, tracked as ‘Cavern Manticore’INFOSECURITY-MAGAZINE.COM
6 JulHow to tell if an image is AI-generatedScammers are using AI-generated images to make fake stories more convincing. Here's how to separate real from fake.MALWAREBYTES.COM
6 JulVietnam arrests suspects behind HiAnime anime piracy serviceVietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shutdown in June. [...]BLEEPINGCOMPUTER.COM
6 JulAttackers vote themselves $20 million in BONK cryptocurrencyBonkDAO said in a social media post that it was the victim of a “malicious governance proposal,” or an attack in which holders of a large amount of BONK used that leverage to vote more coins into their wallets.THERECORD.MEDIA
6 JulPhishing poses as big-brand job interview to steal Google accountsA phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals. [...]BLEEPINGCOMPUTER.COM