🚨 CISA KEV 4[−]
8 Jul KEVCISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-48282 (CVSS score: 10.0) - A path tr…THEHACKERNEWS.COM
8 Jul KEVU.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] …SECURITYAFFAIRS.COM
8 Jul KEVCISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla FlawsTwo newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA's Known Exploited Vulnerabilities catalog, with federal agencies given until July 10 to patch. The post CISA Urges Immediate Patching of Exploited ColdFusion, Lan…SECURITYWEEK.COM
8 Jul KEVAttackers using Langflow flaw for credential harvesting (CVE-2026-55255)The US Cybersecurity and Infrastructure Security Agency (CISA) is warning about yet another Langflow vulnerability (CVE-2026-55255) leveraged by attackers in the wild. The flaw was added to the agency’s Known Exploited Vulnerabilities catalog on Tuesday, July 7, nearly two …HELPNETSECURITY.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 5[−]
8 JulScattered Spider squashed, Rogue Agent AI flaw, 16 year-old Linux bug and new phish hunts marketersCybersecurity Today host David Shipley covers how a newly unsealed U.S. complaint tied an alleged Scattered Spider member to a luxury retailer intrusion using a persistent Windows device ID, with prosecutors alleging help-desk social engineering, admin account takeover, data exfi…CYBERSECURITYTODAY.LIBSYN.COM
8 Jul15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux DistrosResearchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable code has shipped by default in essentially ever…THEHACKERNEWS.COM
8 JulUbiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OSUbiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution. The list of vulnerabilities is as follows - CVE-2026-…THEHACKERNEWS.COM
8 JulVU#849433: Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization ControlsOverview Adalo’s no‑code application platform exposes complete user records through its database API for all applications built on both V1 and V2. Due to a platform-level flaw, authenticated users can retrieve full user data belonging to any Adalo application, regardless of confi…KB.CERT.ORG
8 JulUbiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege EscalationUbiquiti patched seven UniFi OS flaws, including critical CVE-2026-50746, which allows command injection in UniFi Connect Application. Ubiquiti released security updates for seven critical UniFi OS vulnerabilities, including a maximum-severity flaw, tracked as CVE-2026-50746 (CVS…SECURITYAFFAIRS.COM
⚠️ VULNERABILITY DISCLOSURE 32[−]
8 Jul20 open-source cybersecurity tools to keep your team ready for anythingAI is changing how security teams find vulnerabilities, analyze code, test applications, and protect infrastructure. Developers are building tools to secure AI systems themselves, from coding agents and memory protection to model exposure discovery. This roundup covers recent ope…HELPNETSECURITY.COM
8 JulRisky Bulletin: DHS IG investigates forced CISA reassignmentsThe DHS inspector general will investigate forced CISA reassignments, Canada hacked a ransomware gang, Taiwan charges two executives with helping Chinese hackers, and new vulnerabilities can disable Hoymiles solar panels.RISKY.BIZ
8 Jul13 in-demand IT security certifications for higher payWith change a constant, cybersecurity professionals looking to improve their careers can benefit from the latest insights into employers’ needs. Data from Foote Partners on the skills and certification most in demand today may provide helpful signposts. Analyzing more than 660 ce…CSOONLINE.COM
8 Jul KEVCISA orders feds to patch max severity ColdFusion flaw by FridayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday. [...]BLEEPINGCOMPUTER.COM
8 JulMy threat feed told me it was ‘Chalubo.’ The binary disagreedI’ve spent two years doing incident response and threat intel, and the one habit I’d keep if I had to give up every other is also the most boring. I don’t act on a piece of intelligence until I’ve checked it against the thing it claims to describe. It’s slow. It’s tedious. Almost…CSOONLINE.COM
8 JulWhy AI Just Broke Traditional IT Security as Leaders Clash Over AI's Value and Hiring - BSW #455The latest generation of AI models has collapsed the time from vulnerability discovery to weaponized exploit from weeks to minutes, and reactive, module-based tools built around static dashboards simply can't keep up. In this episode, Tanium COO Matt Quinn joins Business Security…YOUTUBE.COM
8 JulFound fast, fixed slow: The gap the AI clearinghouse must closeThe government's new AI clearinghouse risks becoming a committee that discovers more problems than it solves — unless it's designed around patching, not just scanning. The post Found fast, fixed slow: The gap the AI clearinghouse must close appeared first on CyberScoop .CYBERSCOOP.COM
8 JulUbiquiti warns of new max severity UniFi OS vulnerabilityUbiquiti has released security updates to patch seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw that can be exploited in command injection attacks. [...]BLEEPINGCOMPUTER.COM
8 JulCISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government CodeCISA is using Anthropic’s Mythos AI to scan federal code for vulnerabilities, aiming to find flaws before hackers and foreign intelligence services. Three sources familiar with the matter told Reuters that CISA, the U.S. government’s civilian cyber defense agency, is …SECURITYAFFAIRS.COM
8 Jul KEVCISA orders feds to prioritize patching Langflow auth bypass flawThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]BLEEPINGCOMPUTER.COM
8 JulCrusoe brings serverless fine-tuning to AI model developmentCrusoe has announced Serverless Fine-Tuning and Self-Serve Deployments in Crusoe Intelligence Foundry, the managed AI platform for Crusoe Cloud. These capabilities give data scientists and ML engineers a complete path from proprietary data to production-ready models, on purpose-b…HELPNETSECURITY.COM
8 JulNew Bit2Watt attack uses AI GPU workloads to destabilize power gridsA new cyber-physical attack called Bit2Watt uses carefully crafted GPU workloads to manipulate a data center's power consumption in ways that interfere with modern electricity infrastructure. While the work is primarily a proof-of-concept supported by simulations and laboratory e…CYBERINSIDER.COM
8 JulCritical Vulnerability Exposes GitHub Agentic Workflows to Prompt InjectionResearchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication. The post Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection appeared first on SecurityW…SECURITYWEEK.COM
8 JulCybercriminals exploit India’s tax filing season with a dual-malware campaignCybercriminals are exploiting India’s tax filing season with a new malware campaign that refuses to put all its eggs in one basket. Researchers at Cyderes have uncovered a sophisticated phishing operation that poses as the Indian Tax Department to deliver two remote access trojan…CSOONLINE.COM
8 JulMutation testing comes to DAMLIn April we released Mewt , our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML, generates several classes of mutants (includin…TRAILOFBITS.COM
8 JulAccenture acknowledges security incident following 35GB data theft claimAccenture appears to have suffered a data breach, the extent of which is currently unknown. On Monday, a threat actor going by the handle “888” posted on the cybercrime forum PwnForums, claiming to have breached the technology consulting company and stolen “just…HELPNETSECURITY.COM
8 JulFelons, Fraudsters Flog Offensive Cybersecurity StartupA cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based…KREBSONSECURITY.COM
8 JulGitHub AI agent leaks private repositories via prompt injection attackA prompt injection attack can trick GitHub’s preview Agentic Workflows into retrieving content from private repositories and publishing it publicly, exposing a broader risk as enterprises deploy AI agents with privileged access to software development environments, according to n…CSOONLINE.COM
8 JulGoogle Dialogflow CX Bug Allowed Attackers to Hijack AI ConversationsThe "Rogue Agent" vulnerability could have enabled attackers to silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same Google Cloud project. The post Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations app…SECURITYWEEK.COM
8 Jul"Good Enough" Patching Is OverFor years, many organizations relied on fixed patching schedules, accepting 60-day, 90-day, or even annual update cycles as "good enough." That assumption is becoming harder to defend. As AI speeds up vulnerability discovery and attackers move faster, security teams face increasi…YOUTUBE.COM
8 JulSecurity Teams Are Ready To Become More Preemptive. What’s Holding Them Back?The shift toward preemptive security is underway, but most organizations are still navigating the realities of limited resources, fragmented tools, and emerging AI risk. At Rapid7’s recent Global Security Summit , we surveyed attendees to better understand where security leaders …RAPID7.COM
8 JulAccenture faces massive data breach that could put clients at riskThe threat actor claiming responsibility says they stole source code, encryption keys and more.CYBERSECURITYDIVE.COM
8 JulPatients Sue Healthcare Corporations Over Data Breaches, Sharing of Personal InformationMikeie Honda Reiland reports: A suite of recent class action lawsuits in state and federal courts seeks to hold large healthcare corporations accountable for exposing or leaking patients’ personally identifiable information (PII) and protected health information (PHI). On June 11…DATABREACHES.NET
8 JulWhy Bangladesh’s new data protection law may fail to protect your dataMeem Arafat Manab reports: On August 19, 2025, hackers broke into Shwapno’s customer database. They took 410 gigabytes of data: the names, phone numbers, and purchase histories of forty lakh registered customers. They demanded $1.5 million. Shwapno refused, secured its systems, a…DATABREACHES.NET
8 JulAttackers Won't Wait for Patch TuesdayOrganizations continue to be compromised through vulnerabilities that have been known and exploited for years. At the same time, the time between vulnerability disclosure and active exploitation continues to shrink. Traditional patching cycles and lengthy change approval processe…YOUTUBE.COM
8 JulAccenture Confirms Data Breach After Hacker Claims Source Code TheftThe professional services giant says it contained the incident, remediated its source, and experienced no operational or service delivery impact. The post Accenture Confirms Data Breach After Hacker Claims Source Code Theft appeared first on SecurityWeek .SECURITYWEEK.COM
8 JulHackers exploit Roundcube flaw to spy on academic researchersA China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. [...]BLEEPINGCOMPUTER.COM
8 JulUniondale Union Free School District – Audit Follow-Up by New York State Comptroller (2023M-61-F)In October 2023, NYS Comptroller Thomas DiNapoli released an IT audit of the Uniondale Union Free School District on Long Island. The purpose of the audit was to examine management of non-student user network controls. The audit report found, in part: District officials did not a…DATABREACHES.NET
8 JulA Hacker Claims 35 GB of Accenture Source Code. The Company discloses the data breachAccenture confirmed a breach after a hacker claimed to steal 35 GB of source code, keys, and Azure credentials now offered for sale. A threat actor using the handle “888” claimed on the cybercrime forum PwnForums this week to have stolen 35 gigabytes of data from Acce…SECURITYAFFAIRS.COM
8 JulAzure you concerned?Accenture confirms a data breach. An Australian telecom investigates a nationwide outage. It’s shields up for the UK. CISA eyes September for its critical infrastructure reporting rule. NewsJunkie fakes CTV ad traffic. Agentic AI triggers EDR. CISA taps Mythos for vulnerability s…THECYBERWIRE.COM
8 JulLone Attacker Uses AI to Breach AWS Cloud Environment in 72 HoursThe attacker exploited AI workflows, chained cloud weaknesses, and stolen credentials to extort a large Amazon customer.DARKREADING.COM
8 JulGitHub’s public APIs are becoming an enterprise reconnaissance toolGitHub continues to be a scintillating target for attackers because it sits in the middle of the software supply chain and gives threat actors three things they crave: source code, secrets, and automated pipelines to run amok in. Datadog Security Research has been tracking what i…CSOONLINE.COM
📢 SECURITY ADVISORIES 13[−]
8 JulNCSC Touts National Scale, AI-Powered “Cyber Shield” for DefenseThe National Cyber Security Centre wants to work with AI partners to build a new “Cyber Shield” to defend the UKINFOSECURITY-MAGAZINE.COM
8 JulEU now one step away from reviving private message scanning rulesThe European Parliament has approved an urgent procedure to fast-track legislation that would revive the EU's expired “Chat Control 1.0” rules. This development sets up a decisive vote on July 9 over whether online platforms may once again be allowed to voluntarily sc…CYBERINSIDER.COM
8 JulFormer UK privacy chief preparing legal action against woman who reported him, minister saysLiz Kendall, the secretary of state for science, innovation and technology, said she was “absolutely appalled” at the findings of “sexual harassment and bullying” made by an independent investigation at the Information Commissioner’s Office (ICO).THERECORD.MEDIA
8 JulGreek victims file lawsuit against Intellexa over Predator spywareThe use of the spyware came to light in 2022, with traces of Predator found on dozens of phones. The scandal led to the resignation of Greece’s intelligence service chief and the prime minister’s chief of staff.THERECORD.MEDIA
🔥 INCIDENT REPORTING 9[−]
8 JulOrbia CISO Miranda Ritchie on building security into sustainable infrastructureIn this interview with Help Net Security, industrial cybersecurity, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm people, equipment and the env…HELPNETSECURITY.COM
8 JulOnlyFans Models Are Accidentally Making Hacked Government Websites DisappearScammers are hijacking government websites to upload ads for “leaked” OnlyFans content. Thousands of copyright complaints from adult creators are helping people avoid malicious links.WIRED.COM
8 JulCybersecurity and the Gap Between Skill and AbilityLast week, national security agencies from the Five Eyes—that’s the rich, English-language-speaking countries club—jointly released a statement warning of the increasing cyber risks of AI models: in particular, their ability to autonomously hack into systems and…SCHNEIER.COM
8 JulTelco giant KDDI says data breach affects over 12 million peopleJapanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country. [...]BLEEPINGCOMPUTER.COM
8 JulWeekly Update 511: Live from my Riad in MarrakechPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite How's this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow 😮 Anyway, about…TROYHUNT.COM
8 JulAccenture confirms a data breach.Australian telecom outage attributed to software bug. Business news: Keyfactor secures more than $1 billion in a growth funding round.THECYBERWIRE.COM
8 JulAnother massive data breach exposed millions of driver’s license numbersThe cyberattack targeting a U.S. insurance giant is the largest known breach of driver's license numbers so far in 2026.TECHCRUNCH.COM
8 JulMount Royal University confirms breach as hackers claim attackMount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university's network. [...]BLEEPINGCOMPUTER.COM
8 JulSmashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itselfA 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "JadePuffer". What does this tell us about the futur…GRAHAMCLULEY.COM
🕵️ THREAT INTELLIGENCE 33[−]
8 JulISC Stormcast For Wednesday, July 8th, 2026 https://isc.sans.edu/podcastdetail/9998, (Wed, Jul 8th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
8 JulOpenAI and Anthropic are pulling in different directionsCompanies are handing routine operational decisions to AI agents that plan, remember, and act on their behalf. These agents run on statistical models, and their behavior can drift across weeks and months. That drift opens a security gap outside the reach of standard monitoring to…HELPNETSECURITY.COM
8 JulmacOS is becoming a proving ground for AI agentsSomewhere right now, a Mac Mini is sitting on a shelf doing someone’s chores. Nobody’s watching it. It reads a version number out of Terminal, hops over to Safari, digs up a release year, then quietly files a reminder, the kind of dull three-app errand a human would g…HELPNETSECURITY.COM
8 JulHow to implement a continuous offensive security testing programThe hard part was never finding the exposure. It was deciding what to do about it: whether to patch, mitigate, monitor, or accept, and banking that that decision would still hold tomorrow. A penetration test answers this question for the day it runs, then quietly expires. The env…HELPNETSECURITY.COM
8 JulClaude Cowork turns your phone into a remote control for AI workAnthropic started rolling out Claude Cowork, an AI agent that completes multi-step tasks, in beta for Max users on mobile and the web. They describe a goal, and Claude plans the work, uses the required tools, and produces outputs such as documents, spreadsheets, presentations, an…HELPNETSECURITY.COM
8 JulThousands of malicious AI skills found capable of stealing data, running malwareAI agents can browse the web, use external tools, execute commands, and perform tasks on behalf of users. Many rely on skills that define how they interact with services and data. Malicious skills can abuse those capabilities to steal data, execute malware, or manipulate an agent…HELPNETSECURITY.COM
8 JulScienceLogic adds geographic service visibility to Skylar OneScienceLogic has released the “Kyoto” update for Skylar One, the core observability offering in its AI Platform. The release adds geographic service visibility, simplified location and device management, enhanced relationship mapping, and platform updates aimed at imp…HELPNETSECURITY.COM
8 JulCodenotary launches AI security platform that learns from AI agent behaviorCodenotary has announced AgentMon 3, the latest generation of its enterprise AI security platform, introducing adaptive runtime security policies. These continuously evolve as AI agents operate across an organization by learning from customer-specific workflows, observed behavior…HELPNETSECURITY.COM
8 JulChina-Linked UAT-7810 Expands ORB Network With New LONGLEASH MalwareA Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices. According to findings from Cisco Talos, UAT-7810 is an advanced persistent threat (APT) actor…THEHACKERNEWS.COM
8 JulWhat Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find OutBurst water mains. Evacuated hospitals. In a closed-door simulation, insurers played out their response to a mass disruption by China’s Volt Typhoon hackers—and found a nightmare scenario.WIRED.COM
8 JulAutomox MCP Server adds visual reviews and AI-driven patch policy creationAutomox has released Automox MCP Server 2.2, adding interactive review surfaces, first-class Patch by Severity policy creation, and live capability discovery to its governed agentic interface for endpoint operations. The release advances Automox MCP beyond natural-language access…HELPNETSECURITY.COM
8 JulNew Malicious Campaign Delivers Vidar Infostealer and Monero Crypto MinerCyber threat actors are infecting victims with the Vidar stealer and the XMRig cryptocurrency miner in a new malicious campaignINFOSECURITY-MAGAZINE.COM
8 JulTelegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware ToolsRedWing: The Android Banking Trojan You Can Rent on Telegram for Less Than a Coffee Subscription Zimperium’s zLabs team has uncovered RedWing, an Android spyware operation sold as a subscription service through Telegram, with links to Russian threat actors and apparent root…SECURITYAFFAIRS.COM
8 JulThreat Actors Uses Agentic AI to Rapidly Compromise Cloud TargetSygnia report details how agentic AI accelerated weeks-long attack to just 72 hoursINFOSECURITY-MAGAZINE.COM
8 JulDNSFilter makes its DNS threat protection available to OEM partnersDNSFilter has launched an Original Equipment Manufacturing (OEM) program that lets external ISPs, cybersecurity firms, device makers, and other consumer app developers to embed their DNS threat protection, domain analysis, and privacy solutions into their own platforms and soluti…HELPNETSECURITY.COM
8 JulAttestiv DeepScan combines AI and forensic analysis for file validationAttestiv announced the launch of DeepScan, a new platform built to help organizations automatically validate submitted files before they drive critical business decisions. DeepScan represents a major architectural shift for Attestiv and its customers: moving from detecting fake o…HELPNETSECURITY.COM
8 JulWebinar Today: Why Email Security Keeps FailingJoin the webinar as we break down why email-layer defenses alone can’t keep pace with the modern phishing ecosystem. The post Webinar Today: Why Email Security Keeps Failing appeared first on SecurityWeek .SECURITYWEEK.COM
8 JulCensys Internet Map links real-time DNS data to internet infrastructureCensys has announced the expansion of the Censys Internet Map to include real-time DNS visibility. Security teams can now seamlessly pivot between domains, names, and the Internet infrastructure behind them on the Censys Platform. With active DNS data now part of the Internet Map…HELPNETSECURITY.COM
8 JulBlackpoint AI SOC Agent autonomously contains identity-based attacksBlackpoint Cyber has unveiled the generally available autonomous response capability, Blackpoint AI SOC Agent for identity threat detection and response (ITDR). Using an AI + human hybrid model, the AI SOC Agent acts on high-confidence threats targeting Microsoft 365 and Google W…HELPNETSECURITY.COM
8 JulFirst Recon AI Security Runtime helps enterprises govern AI with audit-ready evidenceFirst Recon AI has announced the public launch and general availability of First Recon’s AI Security Runtime, a security platform that both governs and secures how enterprises use artificial intelligence across an organization. First Recon’s runtime inspects every AI …HELPNETSECURITY.COM
8 JulFalconStor Cloud Clean Room enables validated recovery without dedicated infrastructureFalconStor has announced FalconStor Cloud Clean Room, an on-demand infrastructure platform designed to let organizations perform validated recovery testing in a persistent secure enclave. Each test starts from a known state, reducing the risk of carrying issues over from previous…HELPNETSECURITY.COM
8 JulSCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking UsersA new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CA…THEHACKERNEWS.COM
8 JulChina-Linked APT Expands Proxy Network With New MalwareCisco Talos said China-linked APT UAT-7810 is growing its proxy relay network with new malwareINFOSECURITY-MAGAZINE.COM
8 JulUS enterprises incorporate cyber risk into larger strategic focusThe rapid adoption of AI and cloud is forcing significant shifts toward business resilience and financial impact.CYBERSECURITYDIVE.COM
8 JulTrojanized LetsVPN installer gives attackers remote access to Windows PCsA malicious Windows installer masquerading as LetsVPN deploys a remote access trojan (RAT) alongside the legitimate VPN software. The malware, dubbed GoodPersonRAT, grants attackers full control over infected systems and employs multiple stealth techniques to evade detection. The…CYBERINSIDER.COM
8 JulDuckDuckGo browser adds built-in YouTube ad blocking systemDuckDuckGo has added built-in YouTube ad blocking to its privacy-focused browser, allowing users to watch most YouTube videos without pre-roll or mid-roll advertisements. The feature is now enabled by default on Windows, macOS, and iPhone, while Android users can enable it manual…CYBERINSIDER.COM
8 JulChina-Linked APT Expands Arsenal With New ‘Leash’ BackdoorsCisco says the threat actor behind the LapDogs campaign has expanded its SOHO router malware toolkit with LongLeash, DogLeash, and JarLeash backdoors. The post China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors appeared first on SecurityWeek .SECURITYWEEK.COM
8 JulAI Surveillance Is Being Supercharged–And It Will Chill Social ProgressSenior research fellow Jon Penney and co-author Bruce Schneier argue that widely deploying AI surveillance could be corrosive to democracy. The post AI Surveillance Is Being Supercharged–And It Will Chill Social Progress appeared first on The Citizen Lab .CITIZENLAB.CA
8 JulTaiwan charges two businessmen over alleged role in Chinese espionage campaignA company based in Taiwan was leasing out accounts on the popular LINE messaging app to Chinese spies, according to prosecutors, who charged two men in the alleged scheme.THERECORD.MEDIA
8 JulEntra passkey enrollment vishing targets Microsoft 365 usersA threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey. [...]BLEEPINGCOMPUTER.COM
8 JulProtecting Microsoft at AI speed: How SFI proactively hardens our cloudAt Microsoft we encompass these security requirements, along with threat knowledge, and operational frameworks in our Secure Future Initiative (SFI), to guide what a well-defended cloud service looks like. But defining the requirements is only the start. Meeting the requirements …MICROSOFT.COM
8 JulFrench nonprofit starts global intelligence and research hub for AI cyber threatsOne of the project’s top goals is stitching together an international, quick response coalition of governments, businesses and civil experts for AI-related threats. The post French nonprofit starts global intelligence and research hub for AI cyber threats appeared first on CyberS…CYBERSCOOP.COM
8 JulAI Could Shrink Leadership PipelinesMany discussions about AI focus on entry-level jobs. But organizational changes don't stop there. If AI reduces the need for some entry-level and middle-management roles, it could also shrink the pipeline of employees who traditionally develop into senior leaders. Fewer opportuni…YOUTUBE.COM
🌐 CYBER THREAT LANDSCAPE 4[−]
8 JulRedWing Android Spyware Sold as a Service on TelegramZimperium found RedWing, an Android spyware sold as a service via Telegram to target banking appsINFOSECURITY-MAGAZINE.COM
8 JulNew HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet MalwareAI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist. New research, which its authors call HalluSquatting, turns that habit into an attack: work out the …THEHACKERNEWS.COM
8 JulVidar Infostealer Hammers SMBs via Malvertising CampaignA financially motivated operation uses lures of cracked or pirated software to deliver a malware two-for-one combo for data theft and cryptomining.DARKREADING.COM
8 JulFake Paysafe, Skrill SDKs on NPM and PyPi steal credentialsMalicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications. [...]BLEEPINGCOMPUTER.COM
📰 CYBERSECURITY BRIEFINGS 1[−]
🎙️ PODCASTS 1[−]
8 JulSoap Box: Using threat hunting to drive detectionIn this wholly sponsored Soap Box edition of the podcast Patrick Gray chats with Damien Lewke, the CEO and founder of Nebulock, about the future of threat hunting and detection. Damien spent a decade in the EDR and MDR space before founding Nebulock in 2024. It started off as an …RISKY.BIZ
📡 INFOSEC NEWS 21[−]
8 JulWeekly Threat Bulletin – July 8th, 2026These are the top threats you should know about this week.F5.COM
8 JulClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud ToolkitElastic Security Labs tracks REF6045, an active operator-assisted banking fraud operation targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges.ELASTIC.CO
8 JulAI Readiness, Microsoft MISA, and the Punk Rock Museum with JP Bourget of Blue CycleJP Bourget sold a SOAR company, named his next one after cycling and blue teaming, got Fat Mike from NOFX to show up at his RSAC event, then took him to DEFCON, where he ended up in a DJ booth at Caesars Palace with Steve Aoki. Somewhere in between all of that, he built Blue Cycl…THECYBERWIRE.COM
8 JulMy Stack Simulator, (Wed, Jul 8th)The stack is a memory region where a program stores temporary data -&#;x26;#;xc2;&#;x26;#;xa0;like local variables and return addresses. Think of the stack as a pile of plates in your kitchen: you can only add a new plate to…ISC.SANS.EDU
8 JulState IDs for AI Agents: Will Estonia Set a Precedent?The world's digital testing ground plans to help people use AI agents for government purposes.DARKREADING.COM
8 JulDuckDuckGo browser now blocks YouTube video adsDuckDuckGo announced that its browser can now block most video ads on YouTube, including those shown before the video starts playing and during playback. [...]BLEEPINGCOMPUTER.COM
8 JulGitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking SignaturesNew research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHu…THEHACKERNEWS.COM
8 JulThe Verification Step Is the New ATO Battleground in 2026For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, scalable, and for defenders, relatively well understood. That era is ending. Not …THEHACKERNEWS.COM
8 JulGitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in CodeAn AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken into small, ordinary-looking steps inside a code editor. That is the finding of a new study of GitHub Copilot by researchers Abhishek Kum…THEHACKERNEWS.COM
8 JulYour next car could be watching your faceDriver-monitoring technology is becoming mandatory in new cars, but privacy experts warn it could create new risks alongside the safety benefits.MALWAREBYTES.COM
8 JulSpain arrests alleged supporter of pro-Russian hacktivist groups after FBI tipAn FBI tip linked a man living in Spain to the hacking groups CyberArmy of Russia Reborn (CARR), Z-Pentest and NoName057(16).THERECORD.MEDIA
8 JulEU unveils cyber plan to reduce reliance on foreign AI systemsThe communication, adopted in Strasbourg on July 7, is built around three pillars: making frontier AI “safe, accessible and deployable” for European cybersecurity, preparing the EU’s cyber ecosystem and scaling European AI capabilities.THERECORD.MEDIA
8 Jul3 Ways AI Powers Service Desk Attacks and How to Prevent ThemSpecops Software explains how AI is making service desk impersonation attacks more convincing, personalized, and scalable, along with practical steps organizations can take to strengthen onboarding and identity verification. [...]BLEEPINGCOMPUTER.COM
8 JulWiz ASM for any environment, any risk, everywhereProtect the modern attack surface with new auto-reconnaissance capabilities, deep internal context, and the Red Agent to find any risk, anywhere.WIZ.IO
8 JulNew Ghost Phishing Wave Is Breaking Traditional Email SecurityA recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. For security leaders, the risk …THEHACKERNEWS.COM
8 JulThe CISO’s guide to post-quantum mandates and migrationsOver a dozen major economies have now published post-quantum cryptography (PQC) adoption guidance. As a CISO, you’re probably well into your migration plan and know the most difficult part has little to do with changing algorithms. The real leadership challenge is driving coordin…AWS.AMAZON.COM
8 JulGhostApproval: A Trust Boundary Gap in AI Coding AssistantsUncovering a category-level blind spot in modern AI coding assistants, and why the Human-in-the-Loop safety model fails against this classic threatWIZ.IO
8 JulAI Coding Agents Found Triggering Endpoint Security Rules Built to Catch AttackersSophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders. The agents are not malicious. They just do a lot of things that, to a behavioral engine…THEHACKERNEWS.COM
8 JulDesigning for the inevitable: System prompt leakage and mitigations in generative AI applicationsSystem prompts form the foundation of generative AI applications. A system prompt is a collection of instructions and operational context provided to a large language model (LLM) that shapes how the model behaves and interacts with users and tools. System prompts often contain pr…AWS.AMAZON.COM
8 JulCash App owner to pay $45 million to settle allegations of lax securityState attorneys general announced the bipartisan agreement with Block, Inc. on Wednesday, saying that the company incorrectly promised users that Cash App offered the same protections as a bank.THERECORD.MEDIA
8 JulMexico's New Cyber Plan Faces Its First Real TestThe Latin American nation's cybersecurity plan — still in the expansion phase — has to survive its own knockout round during the FIFA World Cup.DARKREADING.COM