154Articles
10Categories
2026-07-09Date
🚨 CISA KEV 1[−]
9 Jul KEVAI Is Annoying & IoT Devices Still Get Hacked - PSW #934In the security news: - Son of Anton strikes again! - HalluSquatting and using Claude to defend itself - CISA KEV’s Revolving Door - LLM's hallucinate and companies get sued - Additionally - GitLost - Yet even more Linux vulnerabilities - Citrix just keeps bleeding - Old hardware…YOUTUBE.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 40[−]
9 JulUnpatched Backdoor in Tenda Firmware Grants Admin Access to DevicesTracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device's web management interface. The post Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulCVE-2026-9547 SSH improper host validationInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-11856 cross-origin Digest auth state leakInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-8925 SASL double-freeInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-56002 libXfont2 PCF Font Parsing Heap Buffer OverflowInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53336 nvmem: layouts: onie-tlv: fix hang on unknown typesInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53327 debugobjects: Do not fill_pool() if pi_blocked_onInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-9079 stale proxy password leakInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-8927 env-set cross-proxy Digest auth state leakInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-12064 proto-default skips SSH verificationInformation published.MSRC.MICROSOFT.COM
9 JulCVE-2026-53167 fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate foliosInformation published.MSRC.MICROSOFT.COM
9 JulMicrosoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM PrivilegesMicrosoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection E…THEHACKERNEWS.COM
9 JulMicrosoft Patches Defender ‘RoguePlanet’ VulnerabilityThe privilege escalation vulnerability tracked as CVE-2026-50656 has been patched with a Microsoft Malware Protection Engine update. The post Microsoft Patches Defender ‘RoguePlanet’ Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulMicrosoft fixed Defender flaw RoguePlanet (CVE-2026-50656)Microsoft fixed RoguePlanet (CVE-2026-50656), a Defender flaw allowing local attackers to gain higher privileges through the Malware Protection Engine. Microsoft released security updates for RoguePlanet, a vulnerability tracked as CVE-2026-50656 (CVSS score of 7.8) affecting the…SECURITYAFFAIRS.COM
9 JulVU#734812: Xerte Online Toolkit contains an authentication bypass that allows for RCEOverview Two vulnerabilities have been discovered in Xerte Online Toolkits, an open-source e-learning authoring toolsuite intended for the creation of learning materials within a web browser. CVE-2026-14261 tracks the persistence of the /setup/ directory after installation, which…KB.CERT.ORG
9 JulMicrosoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656)Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation vulnerability triggered by the RoguePlanet exploit. The vulnerability and the fix CVE-2026-50656 is due to imp…HELPNETSECURITY.COM
9 JulVU#152953: PayRange Android app version 7.0.7 contains multiple vulnerabilitiesOverview PayRange is a mobile payment app that allows users to pay for vending machines, laundromats, and other unattended machines using a smartphone with Bluetooth. Two vulnerabilities were discovered in version 7.0.7 of the PayRange app that is available in the Google Play sto…KB.CERT.ORG
⚠️ VULNERABILITY DISCLOSURE 37[−]
9 JulNayax investigating breach; The Syndicate claims it acquired 1 billion card records and other important dataNayax is a global fintech company headquartered in Israel that provides cashless payment and management solutions for unattended retail and self-service machines. The firm is publicly traded on both the Tel Aviv and Nasdaq stock exchanges. This month, Nayax submitted a Form 6-K t…DATABREACHES.NET
9 JulFake 7-Zip Installers Turn Devices Into Residential Proxy NodesCybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains. The activity dates back to at least August 2…THEHACKERNEWS.COM
9 JulWood you fall for this?This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠…THECYBERWIRE.COM
9 JulTop AI Agents Built to Catch Malicious Code Can Be Tricked Into Running ItAsk an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls "Friendly Fire." It works agai…THEHACKERNEWS.COM
9 JulMicrosoft patches RoguePlanet Defender zero-day vulnerabilityMicrosoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. [...]BLEEPINGCOMPUTER.COM
9 JulOpen-source collaboration is growing worldwide and putting pressure on maintainersDevelopers are pushing code and opening pull requests across economy borders at a rate GitHub has rarely seen. Outbound collaboration, the sum of git pushes and pull requests sent from developers in one economy to public repositories in another, grew by 16% from Q4 2025 to Q1 202…HELPNETSECURITY.COM
9 JulLateral movement risk rises as enterprises emphasize convenience over containmentPoorly segmented networks and weak security controls continue to undercut security organizations’ ability to identify and contain attacks, giving attackers free rein after initial compromise, according to a recent study based on real-world enterprise security telemetry. Zero Netw…CSOONLINE.COM
9 JulCybercriminals Plant Malicious AI Agents in Open Source Tool RepositoriesCybersecurity researchers at ESET identify big rise in suspicious and malicious toolsets which put users at risk from cyber-attacksINFOSECURITY-MAGAZINE.COM
9 JulAssuranceAmerica data breach exposes records of 6.9 million driversAmerican insurance company AssuranceAmerica has disclosed a data breach impacting nearly 7 million drivers after attackers gained access to its systems earlier this year. [...]BLEEPINGCOMPUTER.COM
9 JulChrome 150 Update Patches 27 VulnerabilitiesThe security refresh resolves 13 use-after-free bugs, including two critical-severity flaws found by Google. The post Chrome 150 Update Patches 27 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulAI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old TechniqueWiz has disclosed the details of a new AI coding assistant attack method it has dubbed GhostApproval. The post AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulAgentic AI identity: A 6-stage maturity model for non-human identitiesIn a client engagement last year, an LLM-based deployment agent with standing access to a production Kubernetes cluster triggered a four-hour outage through a malformed configuration push. In the IAM, the agent appeared as a service account with a long-lived API key, no MFA, no s…CSOONLINE.COM
9 JulWhy fixing your data architecture matters more than upgrading your detection modelsSecurity leaders have been on a spending sprint. The global AI in cybersecurity market is valued at $44 billion in 2026 and is projected to reach $213 billion by 2034 , a trajectory that reflects genuine belief that machine learning will close the gap between the volume of threat…CSOONLINE.COM
9 JulPolice arrests 5,800 suspects in global anti-fraud crackdownLaw enforcement agencies have arrested 5,811 suspects and seized $293 million in illicit assets in a global anti-fraud operation spanning 97 countries. [...]BLEEPINGCOMPUTER.COM
9 JulAssuranceAmerica data breach exposed driver’s licenses of 7 million peopleAssuranceAmerica is notifying nearly 7 million people that hackers stole sensitive customer information, including driver's license numbers, following a cyberattack discovered in March. The incident affected 6.99 million individuals, making it the largest known exposure of Americ…CYBERINSIDER.COM
9 JulSecure self-hosted team chat platform Chatto goes open sourceGerman developer Hendrik Mans has released the source code for Chatto, a privacy-focused team messaging platform, making the project open source and available for anyone to self-host. The milestone fulfills a promise made when the project was first unveiled in late 2025 and opens…CYBERINSIDER.COM
9 Jul15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From GoogleAffecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access. The post 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google appeared first on SecurityWeek .SECURITYWEEK.COM
9 Jul5,811 arrests, $293 million seized over social engineering scamsCriminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign against these schemes wrapped up, and police in 97 countries and territories took part. Thousands of arrest…HELPNETSECURITY.COM
9 JulTwo arrests this week in unrelated crimes involved Japanese teenagers using ChatGPT to assist in their crimesThe Japan Times reports: An 18-year-old man has been arrested for his suspected involvement in a cyberattack on the operator of the Kaikatsu Club internet cafe chain, according to investigative sources. On Wednesday, the Metropolitan Police Department’s cybercrime countermeasure …DATABREACHES.NET
9 JulAttack on Amazon Bedrock-linked AI gateway highlights new cloud security riskA cloud intrusion that ended with the deployment of cryptomining malware has exposed a bigger risk for enterprises: AI gateways that concentrate access to cloud identities, permissions, and foundation models in a single, highly privileged system. Researchers from cybersecurity fi…CSOONLINE.COM
9 JulUK cyber agency unveils AI-powered Cyber Shield to counter attacks at machine speedThe UK’s National Cyber Security Centre (NCSC) wants to deploy autonomous AI agents capable of finding and neutralizing cyberattacks on national networks in real time, marking Britain’s push toward a sovereign, machine-speed cyber defense system. The blueprint, called Cyber Shiel…CSOONLINE.COM
9 JulOne Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law EnforcementChina and India ran separate espionage operations against the same Pakistani police force, each drawn by different stakes in Pakistan's internal security.SENTINELONE.COM
9 JulMicrosoft fixes RoguePlanet zero-day in DefenderThe RoguePlanet zero-day is now fixed in Microsoft Defender. Here's how to make sure your system is protected.MALWAREBYTES.COM
9 Jul12 Million Impacted by Data Breach at Japanese Telco KDDIHackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs. The post 12 Million Impacted by Data Breach at Japanese Telco KDDI appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulPalo Alto Networks Patches 13 VulnerabilitiesBuffer overflow, DoS, command injection, SSRF, authentication bypass, and other types of vulnerabilities have been found in PAN-OS software. The post Palo Alto Networks Patches 13 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 Jul764 splinter group leader sentenced to 40 years in jailAlexis Chavez coerced multiple girls to commit self harm and produce child sexual abuse material for notoriety in a sprawling violent extremist collective affiliated with the Com. The post 764 splinter group leader sentenced to 40 years in jail appeared first on CyberScoop .CYBERSCOOP.COM
9 JulThe Intercept’s Signal tipline username was hijacked for monthsThe Intercept has warned that its official Signal tipline username was compromised and used by an impersonator to pose as the investigative news outlet, potentially exposing confidential sources who attempted to submit sensitive information. Dr. Martin Shelton, of the Freedom of …CYBERINSIDER.COM
9 JulGhostApproval flaw exploits trust in major AI coding assistants.Interpol operation cracks down on social engineering scams. Chinese APT exploits Roundcube flaws to target US and Canadian universities.THECYBERWIRE.COM
9 JulThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More StoriesMost security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst par…THEHACKERNEWS.COM
9 JulWiz in the Verizon DBIR: How AI Acceleration and Cloud Sprawl Impact Modern DefenseVerizon's latest DBIR highlights how attackers are exploiting familiar weaknesses at increasing speed and scale. Here's what Wiz research reveals about vulnerabilities, trust relationships, and AI in modern cloud environments.WIZ.IO
9 JulWho you gonna call?GhostApproval puts AI coding assistants under the microscope. Microsoft fixes the RoguePlanet zero-day. More than 70 cybersecurity firms back a new AI Charter. An Ohio county may have paid a $1 million ransom. AssuranceAmerica discloses a breach affecting nearly seven million peo…THECYBERWIRE.COM
9 JulIran's Cyber Crosshairs Focus Beyond Critical InfrastructureObscurity isn't a defense. If your company has any Internet-facing vulnerability, you're at risk from multiple threats.DARKREADING.COM
9 JulMicrosoft Reins in RoguePlanet Zero-Day ThreatThe researcher known as "Nightmare-Eclipse" published a proof-of-concept (PoC) exploit for the Windows Defender vulnerability in early June after dropping several other Microsoft zero-days.DARKREADING.COM
9 JulWolfSSL, GeoVision, VTK vulnerabilitiesCisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adhere…TALOSINTELLIGENCE.COM
9 JulAI coding tool hole illustrates a big problem with human in the loopA security hole within AI dev tools has allowed attackers to escape sandboxes by misleading the humans in the loop who were supposed to knowingly approve the tool’s actions, according to cybersecurity research firm Wiz. “We discovered GhostApproval, a systematic vulnerability pat…CSOONLINE.COM
9 JulWhen Your Smart Vacuum DiesMany smart home devices depend on cloud services to function. When manufacturers discontinue products or shut down those services, expensive hardware can lose key features—or stop working entirely. Open-source alternatives offer a different model. By running locally and avoiding …YOUTUBE.COM
9 JulINTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 MillionINTERPOL’s Operation First Light 2026 led to 5,811 arrests, blocked $293M in criminal assets, and disrupted global fraud and money laundering networks. INTERPOL coordinated a four-month operation across 97 countries and territories that ended with 5,811 arrests and the inte…SECURITYAFFAIRS.COM
📋 SECURITY BULLETINS 1[−]
9 JulMicrosoft expects more Windows security updates from AI-discovered flawsMicrosoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 6[−]
9 Jul75% CISOs Fear Executives Don’t Understand Cybersecurity Risks Employees FaceSurvey of cybersecurity leaders by MetaCompliance finds that many feel boards are uninterested in ever-evolving cyber risksINFOSECURITY-MAGAZINE.COM
9 JulWhy we cannot wait for better post-quantum signature algorithmsNIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and argue that while they are in the works and show great potential, we should use ML-DSA for now — the best one currently availa…CLOUDFLARE.COM
9 JulEU Parliament voted to restore private communications scanningThe European Parliament has approved legislation that restores the temporary legal framework allowing online platforms to voluntarily scan private communications for child sexual abuse material (CSAM). This vote effectively revives a regime that expired in April after the EU Parl…CYBERINSIDER.COM
🔥 INCIDENT REPORTING 13[−]
9 Jul'GodDamn' Ransomware Uses BYOVD to Smite US CompaniesMicrosoft co-signed a malicious kernel driver, and now it's being used to kill security software in ransomware attacks.DARKREADING.COM
9 JulThe Language of AI Could Change How Humans SpeakLast week, national security agencies from the Five Eyes—that’s the rich, English-language-speaking countries club—jointly released a statement warning of the increasing cyber risks of AI models: in particular, their ability to autonomously hack into systems and…SCHNEIER.COM
9 JulMount Royal University Confirms Data Stolen in Ransomware AttackHackers accessed the institution’s internal network and deleted two drives containing employee, student, and university data. The post Mount Royal University Confirms Data Stolen in Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulGodDamn Ransomware Uses PoisonX Driver to Disable Endpoint DefensesCybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According to a new report published by the Threat Hunter Team from Symantec, the ransomwar…THEHACKERNEWS.COM
9 JulAI Gateways Offer Attackers the Keys to the KingdomA cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management (IAM) data.DARKREADING.COM
9 JulAssuranceAmerica Breach Exposes 7 Million Driver’s Licenses After Employee Account HackAssuranceAmerica confirmed a breach exposing nearly 7 million driver’s licenses after hackers compromised an employee account and stole customer data. U.S. auto insurer AssuranceAmerica has confirmed a data breach affecting nearly 7 million people, making it the largest kno…SECURITYAFFAIRS.COM
9 JulLatvian forestry company still restoring systems weeks after ransomware attackA foreign, financially motivated group was responsible for a cyberattack on state-owned forestry company Latvijas Valsts Mezi (LVM), officials said.THERECORD.MEDIA
9 JulData breach hits car insurance providerHackers gained access to more than 6.9 million records at AssuranceAmerica by targeting a company employee.CYBERSECURITYDIVE.COM
9 JulRansomware ecosystem grows, but ‘four-headed monster’ dominatesAI is helping hackers, a new report finds, but mostly by automating very human behaviors.CYBERSECURITYDIVE.COM
9 JulGigaWiper: Anatomy of a destructive backdoor assembled from multiple malwareGigaWiper is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware incorporates code from several previously separate malware families and provides guidance to help defenders de…MICROSOFT.COM
9 JulNew GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and SpywareMicrosoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from. Each is a different way to break a machine: wipe t…THEHACKERNEWS.COM
9 JulGodDamn Ransomware Uses PoisonX to Blind Security SoftwareGodDamn ransomware uses the signed PoisonX driver to disable security tools, marking a more advanced version of the Beast ransomware family. Symantec’s Threat Hunter Team found a new ransomware family called GodDamn that first appeared in the wild on May 21, 2026, and analy…SECURITYAFFAIRS.COM
9 JulInjective SDK on npm infected with cryptocurrency wallet stealerHackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 22[−]
9 JulISC Stormcast For Thursday, July 9th, 2026 https://isc.sans.edu/podcastdetail/10000, (Thu, Jul 9th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
9 Jul_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th)[This is a Guest Diary by Jason Callahan, an ISC intern as part of the SANS.edu BACS program] ISC.SANS.EDU
9 JulA single malware file can outweigh an entire AI datasetAntivirus vendors and security startups keep shipping AI features that promise to read malware the way a seasoned analyst would. The results inside security teams tell a quieter story. A new paper argues that static analysis of software, the job of deciding whether a program is m…HELPNETSECURITY.COM
9 JulProduct showcase: Protect your iPhone with McAfee Mobile SecurityMcAfee Mobile Security for iOS combines scam protection, web protection, VPN, Wi-Fi security, and device security checks in a single app. It is also available for Android. After downloading the app from the App Store, I created an account and completed a short onboarding process.…HELPNETSECURITY.COM
9 JulWireshark 4.6.7 patches a dozen security flawsNetwork analysts who open packet captures in Wireshark push untrusted data through a large set of protocol dissectors, and each parser is a spot where a malformed frame can trip up the software. The 4.6.7 maintenance release closes twelve of those weak points. The fixes reach fro…HELPNETSECURITY.COM
9 JulMessaging fraud trends point to smarter attacks, stronger blockingFraudsters spent 2025 investing in scale. New routes, new tools, and higher message volumes moved through the SMS, voice, and chat channels that businesses rely on to reach customers. Money follows that activity. The Communications Fraud Control Association puts global telecom fr…HELPNETSECURITY.COM
9 JulMalicious AI agent skills can slip past the scanners built to stop themDevelopers who build with AI coding agents grab capabilities off public marketplaces the same way they grab packages from npm or PyPI. The add-ons are called agent skills. Each one is a little bundle of plain-English instructions, scripts, and files that a tool such as Claude Cod…HELPNETSECURITY.COM
9 JulThe fake report message that ends with a stolen Reddit accountA direct message arrives on Reddit from a stranger, and it invites a reply. That reply is the point. This scheme runs on social engineering, with no malware and no malicious links, and it has spread across Reddit, Discord, and similar platforms. The goal is a single piece of info…HELPNETSECURITY.COM
9 Jul8Layers Raises $2.9 Million for Identity Security PlatformThe Spanish startup has closed an extended pre-seed funding round two months after launching its digital identity protection platform. The post 8Layers Raises $2.9 Million for Identity Security Platform appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulDetection engineering in the AI eraAI is lowering the barrier to sophisticated attacks. Explore why detection engineering matters and where most programs fall short. The post Detection engineering in the AI era appeared first on Intezer .INTEZER.COM
9 JulAWS centralizes access, spending, and governance for ClaudeClaude apps gateway for AWS is a self-hosted control plane that gives organizations a single point of control over access, costs, and policies for Claude Code and Claude Desktop. It replaces per-developer cloud credentials, manual distribution of managed settings to developer lap…HELPNETSECURITY.COM
9 JulNetSPI pairs AI pentesting with expert-validated security findingsNetSPI has announced the expansion of its AI-powered continuous pentesting platform, broadening the suite of services that organizations can use to ensure critical assets are always protected. The new services comprise continuous web application penetration testing, continuous AI…HELPNETSECURITY.COM
9 JulYour coding agent says no in chat and yes in the codeMillions of developers share their keyboard with GitHub Copilot. Inside Visual Studio Code, it opens their files, writes and edits code, runs scripts, and reworks its own output across many turns. The safety testing that vets these agents still runs on chatbot rules: one harmful …HELPNETSECURITY.COM
9 JulThe Two BIOS Passwords Everyone ConfusesTL;DR: The setup password and the boot password are different controls that protect different things; vendors give them half a dozen different names, and mixing them up leaves real gaps below the OS. Two Passwords, Two Different Jobs When someone tells me “we set the BIOS p…ECLYPSIUM.COM
9 JulVibe-Coded Malware Caught in Active Directory AttackHuntress found a threat actor using vibe-coded PowerShell to map an Active Directory networkINFOSECURITY-MAGAZINE.COM
9 JulCitrix launches MCP Gateway to secure enterprise AI agentsCitrix has announced updates to its high-performance application delivery and security platform NetScaler, introducing MCP Gateway functionality to allow enterprises to securely route, govern and observe agent traffic to backend Model Context Protocol (MCP) servers. In addition, …HELPNETSECURITY.COM
9 JulVectogate debuts platform to secure and govern autonomous AI agentsVectogate has launched an AI governance platform designed to give organizations centralized control over AI agents as they increasingly take on autonomous tasks with access to sensitive data and internal business systems. The company aims to address one of the key governance chal…HELPNETSECURITY.COM
9 JulQIZ Security Raises $17 Million for Cryptographic Governance PlatformThe Israeli company has developed a cryptographic posture and post-quantum cryptography management platform. The post QIZ Security Raises $17 Million for Cryptographic Governance Platform appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulUK Government Rolls Out Agentic AI Defense Plan Alongside Industry PledgeTwo announcements on July 7, 2026, demonstrate the government’s determination to improve the level of cybersecurity within the UK. The post UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge appeared first on SecurityWeek .SECURITYWEEK.COM
9 JulExtortion crew hijacks Microsoft 365 accounts via fake passkey setupThe Pink cyber extortion crew is tricking employees into giving them access to their Microsoft 365 accounts by faking Entra passkey enrollment requests. The attack The attack starts with a vishing call to an employee. The caller poses as IT and says it’s time to set up a pa…HELPNETSECURITY.COM
9 JulHow GitHub gave every repository a durable ownerGitHub had over 14,000 repositories. Fewer than half had clear ownership. Here's how we gave every active repository a validated owner in under 45 days, archived the rest, and made ownership the foundation for everything that followed. The post How GitHub gave every repository a …GITHUB.BLOG
9 JulInterpol cybercrime crackdown nets 5,800 arrests across 97 countriesThe anti-fraud crackdown, dubbed Operation First Light, identified more than 142,000 victims of various social-engineering scams. The post Interpol cybercrime crackdown nets 5,800 arrests across 97 countries appeared first on CyberScoop .CYBERSCOOP.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
9 JulEuropean Organizations Have a Collaboration Security Confidence GapA new survey shows security leaders have an inflated sense of safety regarding their collaboration tools and platforms.DARKREADING.COM
9 JulFake VPN and 7-Zip Apps Turn Victims Into Residential Proxy NodesFake apps like WireVPN and a trojanized 7-Zip turn victims’ devices into residential proxies, letting criminals route traffic through their IPs. Infoblox’s threat research team started pulling on a single thread in early 2026: a fake version of the 7-Zip archive utili…SECURITYAFFAIRS.COM
9 JulEU takes member states to court over unimplemented cybersecurity lawIreland, Spain, France and the Netherlands are more than 20 months late in transposing the NIS2 Directive for the cybersecurity of critical infrastructure.THERECORD.MEDIA
9 Julnpm 12 Disables Install Scripts by Default to Reduce Supply Chain RiskGitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The Microsoft-owned subsidiary noted that the following npm install beh…THEHACKERNEWS.COM
9 JulNew Helix vishing group emerges in SharePoint data theft attacksA new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. [...]BLEEPINGCOMPUTER.COM
🎙️ PODCASTS 1[−]
9 JulSrsly Risky Biz: US Supreme Court undermines Section 702 intelTom Uren and James Wilson talk about a new US Supreme Court decision that puts the current EU-US data sharing agreement at risk. American intelligence collection efforts have been at the centre of legal challenges of these on-again off-again data transfer agreements, and if the c…RISKY.BIZ
📡 INFOSEC NEWS 28[−]
9 JulGhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding AgentsResearchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead. Th…THEHACKERNEWS.COM
9 JulMeta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI ImagesMeta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI content, and it's enabled by default. "You can also @-mention Instagram accounts in the Meta AI app to bring specific Instagram profiles r…THEHACKERNEWS.COM
9 JulTurn off this Meta setting before someone generates AI images of youMeta's new Muse Image tool lets anyone generate AI images of you from your public Insta profile. You won't be notified, and it's on by default.MALWAREBYTES.COM
9 JulMadison Square Garden Kept a List of Gay CelebritiesAn MSG database tracked and categorized hundreds of celebs, famous Knicks superfans, and even some of Taylor Swift’s wedding guests. Labels included “LGBTQIA,” “DO NOT HOST,” and low to high “risk.”WIRED.COM
9 JulNew AI Security Charter Backed by Over 70 Cyber FirmsOver 70 cybersecurity organizations have signed the CREST AI Charter detailing responsible use of AI for securityINFOSECURITY-MAGAZINE.COM
9 JulGhostApproval Flaw Hits Six Major AI Coding AssistantsWiz discovered GhostApproval, a symlink flaw in six major AI coding assistants that bypasses approvalINFOSECURITY-MAGAZINE.COM
9 JulMicrosoft to retire the OWA Light client in Exchange ServerMicrosoft has announced plans to disable Outlook Web Access (OWA) Light, the lightweight version of the Outlook Web App email client, in a future Exchange Server update. [...]BLEEPINGCOMPUTER.COM
9 JulSummer of ClearinghousesEveryone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quietly months earlier, heads down, taking findings and shipping…THEHACKERNEWS.COM
9 JulChinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 ArrestsOperation First Light 2026, coordinated by Interpol and funded by the Chinese government, has led to 5,811 arrestsINFOSECURITY-MAGAZINE.COM
9 JulAI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps UpAI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the next host before your team clears the first alert. That is the gap, and it is not …THEHACKERNEWS.COM
9 JulInvited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at riskHave you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing up your interview technique, take a closer look at who is really behind it. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
9 JulNSA revives 'Tailored Access Operations' name for elite hacking unitNSA last week changed the moniker of its Office of Computer Network Operations (CNO) back to Tailored Access Operations (TAO), a name that is sure to elicit nostalgia among the broader digital community for a group with roots in the early 1990s.THERECORD.MEDIA
9 JulA Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They’re Going to Anyway.Companies will once again be allowed to scan citizens’ personal texts, emails, and social media messages via the “chat control” bill to find child abuse material online.WIRED.COM
9 JulNew Forg365 phishing platform uses AI to target Microsoft 365 accountsA new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. [...]BLEEPINGCOMPUTER.COM
9 JulThe Hidden Security Risks of Reduced Summer IT CoverageSecurity operations don't slow down when IT teams take vacation, but staffing levels often do. Kaseya explains how AI-driven automation can help organizations maintain consistent security operations and reduce reliance on manual processes year-round. [...]BLEEPINGCOMPUTER.COM
9 JulAs Global Conflicts Go Digital, Businesses Need Wartime GameplansThe fate of a Ukrainian tax software company shows how modern cyberwarfare can claim casualties far beyond the battlefield, and how businesses across the ocean still need to protect themselves.DARKREADING.COM
9 JulHow World Cup crypto prediction sites take your moneyCrypto prediction games promise easy wins, but some are little more than token sales or outright scams. Here's what to look for.MALWAREBYTES.COM
9 Jul6.9 million driver’s license numbers stolen from AssuranceAmericaMillions of AssuranceAmerica customers are being notified after attackers accessed driver's license numbers and other personal information.MALWAREBYTES.COM
9 JulThe SQL Server Unicode problem: why your data might not be what you think it is?Having examined Unicode handling in other databases, we will see that its implementation in SQL Server proves to be particularly complex. We will discover how the burden of backwards compatibility has given rise to new features which, in reality, have serious shortcomings.SYNACKTIV.COM
9 JulHow ProdSec uses WizAutomation, resilience, and security for the modern ageWIZ.IO
9 JulWhat About the Role of AI? Updated Guidance on Secure by DesignCIS and SAFECode have updated Secure by Design: A Developer’s Guide to Building Safer Software to address the role of AI on software security.CISECURITY.ORG
9 Jul5 Major Emerging Risks to Large-Scale EventsTo create safer, more secure large-scale events, read our recommendations for defending against five emerging risks to public gatherings.CISECURITY.ORG
9 JulWinning 54% of the timeWith Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be right 100% of the time."TALOSINTELLIGENCE.COM
9 JulThe Supreme Court allows Texas age-verification law.European Central Bank warns of AI risks.THECYBERWIRE.COM
9 JulReduce Human Risk | Build a Strong Security Awareness Training Program | HuntressBuild a security awareness training program that actually changes user behavior. Huntress Managed SAT delivers engaging content, phishing sims, and results.HUNTRESS.COM
9 JulAI Agents Are a New Kind of Identity & Most Organizations Aren't ReadyIf you're handling them like a service account or API token, consider yourself behind. AI agents need a fundamentally different approach.DARKREADING.COM
9 JulOpenMandriva Linux says contributor tried to sabotage the projectThe OpenMandriva Linux project announced that it was the target of an attempted act of internal sabotage after a dispute among contributors. [...]BLEEPINGCOMPUTER.COM
9 JulIntroducing OAuth Support for AWS MCP ServerAWS MCP Server using the same credentials and sign-in methods that you already use for connecting to the AWS Management Console or AWS Command Line Interface (AWS CLI) through a familiar browser-based experience powered by industry-standard OAuth. This new sign-in path supports A…AWS.AMAZON.COM