124Articles
8Categories
2026-07-07Date
🐛 COMMON VULNERABILITIES AND EXPOSURES 26[−]
7 JulInsignary Closes SBOM Accuracy Gap With Binary-Level Clarity for Regulatory RiskMost software composition analysis tools read what developers declare. Insignary Clarity’s patented binary-first platform analyzes what is actually built, shipped, and deployed — including the open-source components that never appear in any manifest. Insignary, Inc. , whose paten…CSOONLINE.COM
7 JulBeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRABeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices. The vulnerabilities are…THEHACKERNEWS.COM
7 JulCERT/CC Warns of Hidden Admin Backdoor in Tenda Router FirmwareSeveral versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices' web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday. …THEHACKERNEWS.COM
7 JulCVE-2026-9545 exposing HTTP/3 early dataInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-8932 incomplete mTLS config matching in conn reuseInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-8458 wrong reuse for different servicesInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-8924 trailing dot domain super cookieInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-10536 HTTP/2 stream-dependency tree UAFInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-8286 wrong STARTTLS connection reuseInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-8926 password leak with netrc and user in URLInformation published.MSRC.MICROSOFT.COM
7 JulCVE-2026-9080 UAF after pause in socket callbackInformation published.MSRC.MICROSOFT.COM
7 JulSuspected China-Aligned Hackers Exploit Roundcube Flaws Against UniversitiesA suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign. The activity involves the exploitation of now-patched, critical …THEHACKERNEWS.COM
7 JulHP DeskJet 2800 printer zero-day flaw leaks Wi-Fi credentialsHP DeskJet 2800 series printers are affected by a newly disclosed vulnerability that allows anyone on the same network to access sensitive configuration data without authentication. The flaw, tracked as CVE-2026-13753, affects devices running firmware version TBP1CN2612AR or earl…CYBERINSIDER.COM
7 JulHidden Tenda Router Backdoor Grants Admin Access, No Patch AvailableCERT/CC warns an unpatched backdoor in several Tenda routers lets attackers bypass login and gain full admin access with a hidden password. CERT/CC published an alert documenting an undocumented authentication backdoor in multiple Tenda firmware versions, tracked as CVE-2026-1140…SECURITYAFFAIRS.COM
7 JulCritical Adobe ColdFusion Vulnerability Exploited in AttacksHackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10. The post Critical Adobe ColdFusion Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
7 Jul KEVAttackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)CVE-2026-48282, one of the maximum severity vulnerabilities patched in Adobe ColdFusion on June 30, 2026, has been targeted by attackers in the wild. Exploitation attempts were detected on July 2, through the honeypot sensors of cybersecurity threat-intelligence service KEVIntel,…HELPNETSECURITY.COM
7 JulPicus Autonomous Exposure Validation Platform validates real-world CVE exploitabilityPicus Security has launched the Picus Autonomous Exposure Validation Platform, built for a world where frontier AI has collapsed the time between disclosure and attack. Adversaries now weaponize new CVEs in hours, against a backdrop of around 132 published every day. A CVE drops;…HELPNETSECURITY.COM
7 JulCVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
7 JulCritical Gitea Flaw Under Active Exploitation, Researchers WarnAttackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets. The post Critical Gitea Flaw Under Active Exploitation, Researchers Warn appeared first on SecurityWeek .SECURITYWEEK.COM
7 Jul16-year-old KVM flaw allows attackers to escape VMs and take over Linux serversA critical vulnerability in the Kernel-based Virtual Machine (KVM) module of the Linux kernel allows attackers with root access in a guest VM to execute arbitrary code on the host system. This violates the most important security boundary that cloud providers and enterprises rely…CSOONLINE.COM
7 JulCritical Gitea Docker Bug Under Active Exploitation Exposes Repositories and SecretsAttackers are exploiting a critical Gitea flaw (CVE-2026-20896) that bypasses authentication with a single HTTP header, exposing repositories and sensitive data. Sysdig researchers warn that attackers are actively exploiting a critical authentication bypass flaw, tracked as CVE-2…SECURITYAFFAIRS.COM
⚠️ VULNERABILITY DISCLOSURE 31[−]
7 JulZscaler finds autonomous agents succumb to IPI trapsIn a test of major LLMs, Zscaler found that some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans. The security vendor looked at various forms of indirect prompt injecti…CSOONLINE.COM
7 JulCybersecurity jobs available right now: July 7, 2026Application Security Lead Gett | Israel | Hybrid – View job details As an Application Security Lead, you will lead application and cloud security initiatives by integrating security into the SDLC, overseeing threat modeling, secure architecture, application securi…HELPNETSECURITY.COM
7 JulApple Container: Open-source tool for Linux containers on the MacDevelopers on Apple silicon Macs have run Linux containers through software built around a single shared virtual machine for years. Apple’s open-source Container project gives each Linux workload its own lightweight virtual machine. Container is written in Swift and tuned f…HELPNETSECURITY.COM
7 JulMicrosoft wants to keep your AI agents from going rogueMicrosoft has introduced Microsoft Execution Containers (MXC), a cross-platform, policy-driven execution layer for AI agents on Windows and Windows Subsystem for Linux (WSL), now available in early preview. Updated Agent 365 platform (Source: Microsoft) Developers can define cons…HELPNETSECURITY.COM
7 JulPower shortages could slow AI data center expansionAI adoption is increasing demand for data center capacity at the same time operators are running into limits around power, equipment, land, and permitting, according to NTT Data. Access to electricity is becoming a deciding factor in where new data centers are built, when new cap…HELPNETSECURITY.COM
7 Jul176: NSLOne day Nick got a visit from the FBI demanding he give them data on one of his customers. They asked for it in the form of a National Security Letter or NSL. Something wasn’t right about this letter. It seemed to violate the constitution. So he set out to change the law. Learn m…DARKNETDIARIES.COM
7 JulJanuscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape AttacksJanuscape: A 16-year-old Linux KVM flaw lets cloud VM tenants crash hosts and potentially escape guests. It affects Intel and AMD systems. Security researcher Hyunwoo Kim has published details of a use-after-free vulnerability in Linux’s KVM hypervisor that allows code runn…SECURITYAFFAIRS.COM
7 JulSuspected Chinese espionage group used a Roundcube exploit chain to burrow into universitiesProofpoint researchers said attackers targeted physics and engineering departments, and warn that the campaign is likely ongoing. The post Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities appeared first on CyberScoop .CYBERSCOOP.COM
7 JulHackers Exploit Maximum Severity Adobe ColdFusion FlawThreat actors are exploiting an Adobe ColdFusion vulnerability which has a CVSS score of 10.0INFOSECURITY-MAGAZINE.COM
7 JulWhy The Gentlemen ransomware is a test of identity and recovery controlsThe Gentlemen ransomware underscores a challenge many CISOs face: stopping attackers after they gain an initial foothold. Researchers say the malware can spread across enterprise networks using legitimate Windows management tools while simultaneously attempting to weaken security…CSOONLINE.COM
7 JulThe modern CISO is becoming the next CFOAt some point, every security leader gets asked a version of the same question: Are we good? It tends to arrive when something is at stake and the person asking needs to know they can rely on the answer. I learned what that question really means at a firm I was with earlier in my…CSOONLINE.COM
7 JulDefense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390Mobile applications have unique risks and threat models compared to server-side applications and infrastructure. Consequently, they need different strategies to ensure their business logic and workflows well secured. We'll dive into some of these defense-in-depth strategies and w…YOUTUBE.COM
7 JulThreat landscape for industrial automation systems. Q1 2026This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry.SECURELIST.COM
7 JulLinux Kernel Vulnerability Allows VM Escape on Intel and AMD SystemsThe 16-year-old Januscape flaw affects Linux's KVM hypervisor, allowing attackers to escape virtual machines and potentially execute code on the underlying host. The post Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems appeared first on SecurityWeek .SECURITYWEEK.COM
7 JulWhat Changes When Your Software Supply Chain Includes AI Writing Your Code?Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, "software supply chain security" meant one question: what's in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody cho…THEHACKERNEWS.COM
7 JulNew Januscape Linux flaw allows VM escape on Intel, AMD devicesA 16-year-old Linux kernel vulnerability, dubbed Januscape, allows attackers to escape a virtual machine and execute arbitrary code on the host. [...]BLEEPINGCOMPUTER.COM
7 JulCommvault measures cyber recovery readiness with AI attack simulationsCommvault has announced Commvault Minutes to Recovery, a scenario-driven cyber resilience simulation that lets participants act as a hacker and run their own attacks using frontier AI tools. Then, participants are challenged to defend against and recover from an incident under pr…HELPNETSECURITY.COM
7 JulCourt Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider HackerU.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal complaint. Microsoft records tied that ID first to the account the attackers used to keep access durin…THEHACKERNEWS.COM
7 JulWriter AI Flaw Could Let Agent Previews Leak Session Tokens Across TenantsCybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise. The one-click vulnerability has been codenamed Write…THEHACKERNEWS.COM
7 JulBojangles sued again by workers over Russian hacker data breach. NC judge weighs inChase Jordan reports an update in the litigation stemming from a 2024 breach by Hunters International. This case has raised a number of issues about standing and negligence and has been up and down in the courts, with plaintiffs seeming to fare better in state court: A class-acti…DATABREACHES.NET
7 JulJacksonville, Texas, keeps some city systems offline after cyber incidentDysruptionHub reports: Jacksonville, Texas, took some city systems offline after detecting suspicious network activity Friday, leaving some online services unavailable Monday as officials investigated a cybersecurity incident. The city said it detected the activity July 3 and lat…DATABREACHES.NET
7 JulCERT/CC warns of an unpatched backdoor affecting Tenda routers.Maximum-severity ColdFusion flaw is under active exploitation. Canadian intelligence agencies hacked criminal groups.THECYBERWIRE.COM
7 JulSuspected Chinese Threat Group Targets Universities via Vulnerable Roundcube ServersA suspected Chinese threat cluster is exploiting Roundcube vulnerabilities to compromise university networks in the US and Canada and harvest user credentialsINFOSECURITY-MAGAZINE.COM
7 JulSophisticated threat campaign pushes Cisco to the very edgeA monthslong exploitation wave against Cisco SD-WAN systems raises larger questions about trust and the insecurity of network infrastructure.CYBERSECURITYDIVE.COM
7 JulOMB M-26-14: Why federal agencies must fix asset visibility firstThe new OMB logging directive raises the bar on log collection and explicitly ties every maturity milestone to how well agencies know what’s on their networks. Learn why asset visibility is the first problem to solve. Key takeaways M-26-14 rescinds M-21-31 and replaces blanket da…TENABLE.COM
7 JulEnforce zero data retention on Amazon Bedrock with Bedrock Projects and service control policiesWith the introduction of models that require data sharing with third-party providers—such as Claude Fable 5—organizations need a way to centrally enforce data retention policies. Amazon Bedrock gives you control over whether your prompts and model outputs are retained after an in…AWS.AMAZON.COM
7 JulChinese hackers develop LONGLEASH malware to expand ORB networkChinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. [...]BLEEPINGCOMPUTER.COM
7 JulWhy Streaming Apps Protect ContentFor streaming platforms, the most security-sensitive asset is often the content itself. Licensing agreements require providers to protect movies, shows, and live events from unauthorized distribution. Technologies like DRM and digital watermarking help enforce those protections a…YOUTUBE.COM
7 Jul KEVWelcome home, hacker.CERT/CC warns of an unpatched Tenda router backdoor. Adobe races to patch an actively exploited ColdFusion flaw. Canada pulls back the curtain on offensive cyber operations. Anthropic quietly removes hidden tracking from Claude Code. Chinese AI gains momentum as U.S. providers sw…THECYBERWIRE.COM
7 JulAccenture confirms breach after hacker offers stolen data for saleIT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. [...]BLEEPINGCOMPUTER.COM
7 JulWashington Dept. of Social and Health Services announces massive data breachKIRO7 reports: The Washington Department of Social and Health Services (DSHS) is issuing a notice of a massive data breach that happened in March, potentially compromising the personal data of around 8,600 people. An internal investigation revealed that a former DSHS employee acc…DATABREACHES.NET
📢 SECURITY ADVISORIES 14[−]
7 JulIran-Linked Hackers Use New Cavern C2 Framework to Target Israeli OrganizationsAn Iranian hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations. The activity, which has primarily single…THEHACKERNEWS.COM
7 JulRadware updates Agentic AI Protection with AI governance and compliance capabilitiesRadware has announced enhancements to its Agentic AI Protection solution to help organizations govern and secure AI agents across enterprise environments. The release adds compliance reporting to support alignment with leading global AI standards, enhanced visibility into agent e…HELPNETSECURITY.COM
7 JulUK cyber pledge draws only a handful of top firms despite ministerial appealThose that did sign include large firms such as Aviva, the London Stock Exchange Group and Marks & Spencer, which lost hundreds of millions of pounds in a cyberattack last year, as well as small cybersecurity consultancies.THERECORD.MEDIA
7 JulCISA Reportedly Using Anthropic’s Mythos to Scan Government Software for FlawsThe audits are reportedly being spearheaded by CISA’s Attack Surface Evaluation team, a specialized unit tasked with conducting digital defense assessments and simulated hacking exercises. The post CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws app…SECURITYWEEK.COM
7 JulBritain plans to build autonomous AI 'Cyber Shield' to defend nationThe capability, called Cyber Shield, is designed to counter a threat the National Cyber Security Centre (NCSC) said could see attackers “move at machine speed and greater scale, reducing opportunities for detection and response.”THERECORD.MEDIA
7 JulHidden backdoor in Tenda router firmware grants admin accessA hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device's web management panel. [...]BLEEPINGCOMPUTER.COM
🔥 INCIDENT REPORTING 5[−]
7 JulNothing left to StealC.Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Selena Larson⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠, ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Proofpoint⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ intelligence analyst and host of their podcas…THECYBERWIRE.COM
7 JulIran-Linked Hackers Using Modular C&C Framework in CyberattacksResearchers say the Iran-linked threat actor used an adaptable modular malware framework and compromised IT service providers to reach high-value targets in Israel. The post Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks appeared first on SecurityWeek .SECURITYWEEK.COM
7 JulHacktivists call out Trump by hacking and defacing US Army websitesThe U.S. Army has fixed two of its websites that were hacked to display messages calling President Trump a "pedophile" and a "thief."TECHCRUNCH.COM
7 JulMajor Japanese telco says cyberattack exposed 12 million emailsThe company said the breach affected an email system used to manage customer email accounts, webmail services and email storage for five Japanese internet service providers.THERECORD.MEDIA
7 JulCounty Government Reportedly Paid $1 Million to Cyber Extortion GroupThe alleged victim, believed to be a small Ohio county, reportedly paid the extortion group to prevent the public release of sensitive stolen data. The post County Government Reportedly Paid $1 Million to Cyber Extortion Group appeared first on SecurityWeek .SECURITYWEEK.COM
🕵️ THREAT INTELLIGENCE 26[−]
7 JulISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
7 JulReview: Building Machine Learning Systems with a Feature StoreMany people come to machine learning by training a model on a tidy dataset, and then meet a harder problem: making that model work for real users, on fresh data, every day. Jim Dowling’s O’Reilly book, Building Machine Learning Systems with a Feature Store, is written…HELPNETSECURITY.COM
7 JulYour company already adopted AI and nobody is governing accessIn this Help Net Security video, Antoine Berton, CTO at Elba Security, breaks down the AI attack surface. Your company already adopted AI, and every adoption creates access that nobody governs. A quick click on a Friday afternoon connects a free AI tool to your Google Workspace, …HELPNETSECURITY.COM
7 JulResearchers make the case for a cybersecurity AI scientistAutonomous AI agents have started doing real security work. Language-model agents probe software for flaws, run penetration tests, and chain together attack steps that once needed a human operator. Research about security has stayed slower and more manual, built around expert sca…HELPNETSECURITY.COM
7 JulKeyfactor Scores $1 Billion+ Investment for AI, Post-Quantum SecurityThe investment will accelerate Keyfactor's machine identity, PKI, and cryptographic security platform as enterprises prepare for AI-driven and post-quantum threats. The post Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security appeared first on SecurityWeek .SECURITYWEEK.COM
7 JulAI-Generated Malware Powers New Armored Likho APT CampaignArmored Likho APT uses AI-generated malware, phishing, and BusySnake Stealer to target governments and power grids in Russia, Kazakhstan, and Brazil. Kaspersky’s threat research team has documented a previously unknown APT group they’re calling Armored Likho, also tra…SECURITYAFFAIRS.COM
7 JulGoogle Is Suing Chinese Scammers Who Are Using GeminiNot sure this will have any effect, but I support the effort: According to Google’s legal filing, Outsider Enterprise operates through Telegram. The group offers phishing-as-a-service to individuals who may not be technically savvy enough to set up fraudulent websites and t…SCHNEIER.COM
7 JulUAT-7810 continues building ORB networks using new malwareTalos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.TALOSINTELLIGENCE.COM
7 JulThe Navy Spy who Sold Secrets for $377 a YearYou may have heard of the long-running TV show NCIS, based on the real work of the Naval Criminal Investigative Service. But you may never have heard of a unit inside it, called the Office of Special Projects, where staff work on espionage cases that originate inside the U.S. Nav…THECYBERWIRE.COM
7 JulCISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original ThinkerTarah Wheeler is CISO at TPO Group, a firm that provides cybersecurity consultancy for high-stakes organizations. But despite this elevated position, her journey was far from typical. The post CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Th…SECURITYWEEK.COM
7 JulBarracuda adds PAM and identity protection with Evo Security acquisitionBarracuda Networks has acquired Evo Security. The acquisition expands the BarracudaONE platform’s identity security capabilities by adding privileged access management (PAM), access control, identity protection, and identity threat detection and response. By combining Evo S…HELPNETSECURITY.COM
7 JulCyberProof Agentic MXDR Service brings AI agents to managed detection and responseCyberProof has announced the launch of the CyberProof Agentic MXDR Service which connects AI agents with human expertise and presents quantifiable security outcomes with CyberProof’s Reveal360. CyberProof modernizes managed detection and response by shifting security operat…HELPNETSECURITY.COM
7 JulPost-Mythos Cybersecurity: Can You Automate Infrastructure Assurance with AI?TL;DR: Security leaders should absolutely reassess their cybersecurity programs in light of Mythos, Daybreak, and other frontier AI models. AI will make some workflows easier to automate, some internal tools easier to build, and some vendor spend harder to justify. But the risk-r…ECLYPSIUM.COM
7 JulSecurity or Privacy: Which Comes First?Security and privacy don't always point in the same direction. Many modern applications rely on stronger verification or deeper system access to reduce fraud, cheating, and abuse. Those protections can also increase privacy concerns. Whether it's kernel-level anti-cheat software …YOUTUBE.COM
7 JulBusinesses modernizing networks for AI fear expanding attack surface, limited visibilityIT leaders are worried that security controls aren’t keeping pace with threats to AI systems.CYBERSECURITYDIVE.COM
7 JulRedWing MaaS Packages Android Bank Fraud as a Telegram Rental ServiceA new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts. Zimperium's zLab…THEHACKERNEWS.COM
7 JulMicrosoft Windows telemetry identified hacker despite VPN useMicrosoft identified an alleged Scattered Spider member through Windows telemetry despite the suspect using a VPN to mask his IP address. The details appear in the superseding criminal complaint against Peter Stokes, whose extradition to the United States we covered last week. A …CYBERINSIDER.COM
7 JulMore Odd DNS Records: NIMLOC, (Tue, Jul 7th)Yesterday, I talked about NAPTR records and how they are related to RCS. But there is another "odd" record that shows up in my DNS logs. This one isn&#;x26;#;39;t new, but I don&#;x26;#;39;t think I ever covered it: NIMLOC. …ISC.SANS.EDU
7 JulWireVPN service linked to years-long residential proxy operationA VPN service with more than one million Android downloads is at the center of a long-running operation that allegedly recruits victims' devices into a residential proxy network. The Infoblox investigation began after researchers analyzed the infrastructure behind a malicious ins…CYBERINSIDER.COM
7 JulSpanish Police Arrest Man Linked to CARR, Z-Pentest, and NoName057(16)Spain arrested a suspected CARR and Z-Pentest collaborator in an FBI-led probe for aiding pro-Russian hackers, coordinating attacks, and using crypto. Spanish National Police arrested a man in Palencia last March on charges of membership in and collaboration with a terrorist orga…SECURITYAFFAIRS.COM
7 JulDeepfake CSAM lawsuit against xAI, Grok expandsTwo new alleged victims detailed how Grok was used by friends and family to generate sexual images of them as minors. The suit also adds Stability AI as a defendant. The post Deepfake CSAM lawsuit against xAI, Grok expands appeared first on CyberScoop .CYBERSCOOP.COM
7 JulWatch out for fake support calls in Microsoft TeamsPalo Alto Networks’ security division, Unit 42, is warning of yet another campaign targeting Microsoft Teams users . The new campaign begins with Teams users receiving an email asking if they would like to participate in a survey. If they open the attached PDF file, they will sho…CSOONLINE.COM
7 JulDune References, FAT, Claude, ZhiPu, PolinRider, RentaBot, Sony, Aaran Leyland & More - SWN #596Dune References, FAT, Claude, ZhiPu, PolinRider, RentaBot, Sony, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-596YOUTUBE.COM
7 JulSpain arrests suspected hacker linked to Russian hacktivist campaignAuthorities didn’t name the man or file formal charges, but accuse him of participating in attacks linked to Cyber Army of Russia Reborn and NoName. The post Spain arrests suspected hacker linked to Russian hacktivist campaign appeared first on CyberScoop .CYBERSCOOP.COM
7 JulVidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File InflationA cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination. The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
7 JulGitHub's Joke Backfired FastGitHub appeared to poke fun at Sony's decision to move away from optical media by offering developers CD-ROM copies of their public repositories. The offer included a real request form, and enough people treated it seriously that GitHub removed it early. Whether it began as a mar…YOUTUBE.COM
🌐 CYBER THREAT LANDSCAPE 1[−]
7 JulBig Brand Jobs Scam Targets Marketing Pros' Google AccountsThe phishing campaign uses several tactics, including nested redirects, to evade detection and steal credentials from unsuspecting targets.DARKREADING.COM
🎙️ PODCASTS 1[−]
7 JulBetween Two Nerds: Why AI has not meant more hacks. Yet.In this edition of Between Two Nerds Tom Uren and The Grugq talk about why we haven’t seen an explosion of devastating hacks even though AI has been used to discover lots and lots of bugs. This episode is also available on YouTube.RISKY.BIZ
📡 INFOSEC NEWS 20[−]
7 JulMicrosoft testing new Cloud Rebuild Windows 11 recovery featureMicrosoft has begun testing the Cloud Rebuild recovery feature in the latest Windows 11 Insider Preview builds released for users in the Experimental channel. [...]BLEEPINGCOMPUTER.COM
7 JulBeyondTrust warns of critical flaws in remote access softwareBeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. [...]BLEEPINGCOMPUTER.COM
7 JulScammers are using AI to sell impossible flowersAI-generated flower scams are blooming online, with scammers using fake images to sell seeds for plants that don't exist, like these "cat's face orchids."MALWAREBYTES.COM
7 JulUK Government Launches Cyber Resilience Pledge, Claiming 60+ SignatoriesMore than 60 organizations, including M&S, Microsoft UK and Vodafone, have signed the UK government's Cyber Resilience Pledge, a new initiative aimed at boosting cyber security and resilience across British businessesINFOSECURITY-MAGAZINE.COM
7 JulMicrosoft to enable Windows settings backup by default for orgsMicrosoft says the Windows settings backup and restore tool will be enabled by default on Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems after upgrading to Windows 11 26H2. [...]BLEEPINGCOMPUTER.COM
7 JulSavi’s app aims to protect consumers from realistic AI scams like kidnappers demanding ransomThe company just raised $7 million in seed funding, and is launching its app for iPhone and Android on Tuesday.TECHCRUNCH.COM
7 JulClaude Code’s hidden tracker was an “experiment,” says AnthropicAnthropic's hidden Claude Code tracker has raised new questions about prompt steganography and developer trust.MALWAREBYTES.COM
7 JulWebinar tomorrow: Why modern email attacks require a new approach to defenseTomorrow's webinar explores how behavioral AI can help organizations detect sophisticated phishing, business email compromise, and account takeover attacks while reducing alert fatigue through automated investigation and response workflows. [...]BLEEPINGCOMPUTER.COM
7 JulTwo arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraudTwo young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
7 JulFake Netflix, Coca-Cola, and FIFA job scams target marketersA fake recruiter phishing campaign uses trusted brands, nested redirects, and fake Google prompts to steal accounts.MALWAREBYTES.COM
7 JulScattered Spider’s Structure More Like a Cybercrime Collective Than a Unified GangGroup-IB analysis argued Scattered Spider is a decentralized collective of independent clustersINFOSECURITY-MAGAZINE.COM
7 JulThe GitHub Actions Attack Pattern Your CI Security Scanners MissActiveState explains how GitHub Actions attack chains can evade traditional CI security scanners, why passing a scan doesn't guarantee a secure pipeline, and how organizations can better govern their CI/CD workflows. [...]BLEEPINGCOMPUTER.COM
7 JulPublic GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo DataA public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown. The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access …THEHACKERNEWS.COM
7 JulSpain arrests suspected member of pro-Russian hacktivist groupsThe National Police in Spain have arrested a man who is suspected of being an active member of the CyberArmy of Russia Reborn (CARR) and Z-Pentest, both pro-Russian hacktivist groups. [...]BLEEPINGCOMPUTER.COM
7 Jul'GitLost' Flaw Leaks Private Data from GitHub's Agentic WorkflowsThe flaw allows an unauthenticated attacker to craft a GitHub Issue in an org's public repository and then silently pull data from its private repos, too.DARKREADING.COM
7 JulDEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 AccountsA Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. "The campaign did not depend on a fake Microsoft password pa…THEHACKERNEWS.COM
7 JulSupreme Court allows Texas app law requiring age verification to take effectA student advocacy organization and tech trade group had appealed to the high court to stay the Texas App Store Accountability Act on an emergency basis until the lower court rules.THERECORD.MEDIA
7 JulRogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX ChatbotsA critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project. From there, they could read live conversations, steal the data users shared, and make…THEHACKERNEWS.COM
7 JulHow the Reddit and Discord false report scam steals accountsScammers are tricking Reddit and Discord users into handing over login codes by claiming they were involved in a false report.MALWAREBYTES.COM
7 JulDialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data TheftVaronis reported the flaw to Google in late 2025 and it has been addressed, but it reminds defenders to take a fresh look at their AI Infrastructure security.DARKREADING.COM