🐛 COMMON VULNERABILITIES AND EXPOSURES 6[−]
10 JulCVE-2026-59818 etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocationInformation published.MSRC.MICROSOFT.COM
10 JulCVE-2026-56289 Loop with Unreachable Exit Condition in GNU patchInformation published.MSRC.MICROSOFT.COM
10 JulThe business case for burning down security debt: A practical approach for CISOsSecurity leaders have made strong progress in visibility. Most organizations can now identify vulnerabilities across their applications, dependencies and development pipelines with far more consistency than in the past. Yet a fundamental imbalance remains: Vulnerabilities are bei…CSOONLINE.COM
10 Jul“GhostLock” flaw survived in the Linux kernel code for 15 yearsA Linux kernel vulnerability remained hidden in virtually every major Linux distribution for more than 15 years before being fixed earlier this year. The flaw, tracked as CVE-2026-43499 and dubbed GhostLock, can be exploited by an unprivileged local attacker to gain root privileg…CYBERINSIDER.COM
10 JulVU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPsOverview GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlled FTP endpoint can redire…KB.CERT.ORG
⚠️ VULNERABILITY DISCLOSURE 28[−]
10 JulFormer DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jailAngelo Martino exploited his insider position and fed confidential information to ransomware co-conspirators to extort a combined $75.3 million from five U.S.-based victims. The post Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail appeare…CYBERSCOOP.COM
10 JulA questionable breach, bad routers at home and at work and AI gives defenders a winThis episode covers a hacker's claim of stealing 35GB from Accenture—including source code, Azure personal access tokens, RSA keys, and SSH keys—while Accenture calls it an isolated, remediated matter, leaving uncertainty about potential downstream risk to its Fortune 500-heavy c…CYBERSECURITYTODAY.LIBSYN.COM
10 JulOnly 28% of financial workforce MFA is phishing-resistantPasswords remain part of many workforce authentication flows in financial organizations, making phishing and credential theft major identity security risks, according to a new Secret Double Octopus report. Key challenges preventing universal implementation of phishing-resistant M…HELPNETSECURITY.COM
10 JulMicrosoft is rewriting Windows patch guidance because of AIMicrosoft is recommending that organizations shorten Windows update deployment timelines, warning that advances in AI are reducing the time attackers need to identify and exploit vulnerabilities after security updates are released. The company says organizations should reassess h…HELPNETSECURITY.COM
10 JulTurning software supply chain security into a daily habitIn this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every day for vulnerability triage, ve…HELPNETSECURITY.COM
10 JulCheck Point CTO Jonathan Zanger sees AI elevating the value of cyberCheck Point Software CTO Jonathan Zanger met with CSO Spain during the software company’s Engage 2026 user conference last week in Paris. At the event, Check Point executives and representatives discussed how the company is dealing with various types of threats, how it is adoptin…CSOONLINE.COM
10 JulThe open source library holding up your stack might have one maintainerEvery serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carr…HELPNETSECURITY.COM
10 JulWorkato expands Agent Studio with Headless API, AI guardrailsWorkato has announced two new capabilities for Agent Studio: Headless API and Agent Guardrails. Headless API lets Genies, Workato’s AI agents built on Agent Studio, be embedded into any business application surface, on web, mobile, or inside another agent’s own enviro…HELPNETSECURITY.COM
10 Jul‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery MechanismResearchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution. The post ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulAttackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency WalletsSecurity firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness…THEHACKERNEWS.COM
10 JulAI Surveillance and Social ProgressIn the near future, AI -powered surveillance systems will be able to track everything we do in public, and much of what we do in private. And if we do something wrong—shoplift, litter, jaywalk, you name it—the system will notice, retain it, tie it to your official gov…SCHNEIER.COM
10 JulUnpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 ServersA single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRIN…THEHACKERNEWS.COM
10 JulZimbra urges customers to patch critical web client XSS flawThe Zimbra security team urged customers to patch a critical vulnerability affecting the Classic Web Client used to access the Zimbra Collaboration suite. [...]BLEEPINGCOMPUTER.COM
10 JulChina, India-Linked Hackers Both Targeted Same Pakistani Police ForceBoth foes and allies have targeted the Balochistan Police force in Pakistan for at least two years, according to SentinelOne. The post China, India-Linked Hackers Both Targeted Same Pakistani Police Force appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulNew Ransomware Exploits Malicious Driver to Remove Cybersecurity ProtectionsGodDamn ransomware uses remote desktop application to secretly move around networks and drop the malicious PoisonX kernel driverINFOSECURITY-MAGAZINE.COM
10 JulIncode brings on-device processing to age estimation for privacy-focused verificationIncode has launched On-Device Age Estimation, an age verification capability that performs age estimation and liveness detection directly on the user’s device, without transmitting facial data off the device. The company’s age estimation models are now available to ru…HELPNETSECURITY.COM
10 JulChina, India ran separate spying campaigns against same Pakistani police forceThe activity, in some cases breaching the exact same systems, ran between February 2024 and April 2026 and centered on the force responsible for the country’s southwestern province that has been the site of a long-running separatist insurgency.THERECORD.MEDIA
10 JulAnthropic and OpenAI Security Tools Could Fuel Cyber-Attacks, Researchers WarnResearchers at the AI Now Institute developed a proof-of-concept exploit showing common AI tools used for security could backfireINFOSECURITY-MAGAZINE.COM
10 JulResearcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw FlawsDetails have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the h…THEHACKERNEWS.COM
10 JulEU extends mass scanning of messages without a warrantMembers of the European Parliament (MEPs) have failed to block a proposal extending the mass scanning of private communications, a measure they have previously rejected twice. This time too, more votes were cast against the proposal than in favor, but due to the absence of numero…CSOONLINE.COM
10 JulCrowdStrike identifies five new prompt injection threats to AISecurity company CrowdStrike has identified five new prompt injection techniques that could leave enterprises at risk. Prompt injections attacks exploit the growing use of AI within organizations . They work by tricking LLMs into accepting instructions that a human operator would…CSOONLINE.COM
10 Jul KEVThe 72-Hour Vulnerability DeadlineThe EU Cyber Resilience Act introduces strict reporting requirements for vulnerabilities, including a 72-hour reporting window after becoming aware of an actively exploited vulnerability. Organizations must rapidly assess both technical evidence and regulatory obligations. Distin…YOUTUBE.COM
10 JulHackers exploit critical auth bypass in Gitea Docker imageHackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators. [...]BLEEPINGCOMPUTER.COM
10 JulAWS designated as a critical third party to the UK financial sectorAmazon Web Services EMEA Sarl (AWS) has been designated as a critical third party (CTP) to the UK financial sector by HM Treasury. The CTP regime came into force on January 1, 2025, and establishes a framework through which the Bank of England, PRA, and FCA (collectively the UK r…AWS.AMAZON.COM
10 JulInitial access broker linked to weaponization of CitrixBleed2 flawA similar pattern of exploitation was seen in prior attacks involving an open-source machine emulator. CYBERSECURITYDIVE.COM
10 JulGoshDarn it, that’s advanced.Researchers track ransomware they say is getting GoshDarn sophisticated. Zimbra patches a critical vulnerability affecting its Classic Web Client. A sophisticated vishing campaign targeting Microsoft 365 accounts. GigaWiper combines espionage capabilities with multiple destructiv…THECYBERWIRE.COM
10 JulFriday Squid Blogging: “Squidbleed” VulnerabilityIn a rare combined cybersecurity/squid post, a twenty-nine-year-old squid proxy bug can leak HTTP requests. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
10 JulUpdate Now: Critical Zimbra Classic Web Client Flaw Could Expose MailboxesZimbra addressed a critical stored XSS vulnerability in its Classic Web Client that lets malicious emails execute code when opened. Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Coll…SECURITYAFFAIRS.COM
📋 SECURITY BULLETINS 2[−]
10 JulJuly 2026 Patch Tuesday forecast: Is CVE tracking still practical?I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 and 104 for Windows 10. In addition, we saw large numbers in both common applications…HELPNETSECURITY.COM
10 JulMicrosoft Warns of Increase in Number of Security UpdatesMicrosoft has said the volume of Windows security updates is set to grow as it uses AI to find new bugsINFOSECURITY-MAGAZINE.COM
📢 SECURITY ADVISORIES 9[−]
10 JulMicrosoft uncovers GigaWiper, a backdoor designed for destruction on demandMicrosoft is warning defenders about a new backdoor that blurs the line between espionage malware and wipers. In a technical analysis published on Thursday, Microsoft Threat Intelligence detailed GigaWiper, a Golang-based implant first observed in October 2025 intrusions that com…CSOONLINE.COM
10 JulCISA details security lapses that led to GitHub leak of passwords, cloud access keysThe agency’s blog post came as lawmakers pressed the agency for answers.CYBERSECURITYDIVE.COM
10 JulCISA Details Incident Response to Exposed AWS GovCloud KeysCISA reveals how it responded after sensitive AWS GovCloud credentials and internal data were exposed in a public GitHub repositoryINFOSECURITY-MAGAZINE.COM
10 JulMore Countries Jump on the Social Media Ban WagonAge restrictions on accounts may be more of a ban(d) aid, because industry compliance is already falling short. Tech giants are struggling to follow the laws without affecting users.DARKREADING.COM
10 JulCISA looks to remedy ailments from big May credential leakA major credential leak spurred the Cybersecurity and Infrastructure Security Agency to strengthen protections for its sensitive materials, improve how researchers can report agency vulnerabilities and develop plans for similar incidents, the agency said in a forensic report rele…CYBERSCOOP.COM
10 JulAttackers Have the Advantage NowThe pace of cyberattacks has accelerated dramatically. Techniques that once required weeks can now happen in minutes, hours, or days, making it increasingly difficult for defenders to respond using traditional security processes. The concern isn't that attackers will always have …YOUTUBE.COM
🔥 INCIDENT REPORTING 19[−]
10 JulDormant GitHub Accounts Help Attackers Blend In While Mapping Corporate OrgsDatadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operators rely on automated scraping tooling with custom or legitimate-sounding us…THEHACKERNEWS.COM
10 JulRisky Bulletin: NSA Tailored Access Operations is backThe NSA’s Tailored Access Operations team is back, India bans an app used to hack e-rickshaws, Accenture has another data breach, and a leak exposes a suspected Chinese cyber contractor. The Risky Bulletin newsletter and podcast will be on an editorial break until July 20.RISKY.BIZ
10 JulNHS Warns Staff Over Unauthorized Access to Patient DataNHS tells staff they could face prison for “inappropriate” access to patients’ medical recordsINFOSECURITY-MAGAZINE.COM
10 JulFormer ransomware negotiator gets 4 years for BlackCat attacksA former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. [...]BLEEPINGCOMPUTER.COM
10 JulRansomware Negotiator Gets 70 Months in Prison for Aiding BlackCat AttacksA 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple victims and working with two other cybersecurity profession…THEHACKERNEWS.COM
10 JulGigaWiper Combines Multiple Malware for System-Level SabotageThe backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command. The post GigaWiper Combines Multiple Malware for System-Level Sabotage appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulGigaWiper Merges Three Malware Families Into One Destructive BackdoorMicrosoft uncovered GigaWiper, a modular Go backdoor combining three malware families with espionage, remote control, and destructive wiping features. In October 2025, Microsoft’s threat intelligence team identified destructive wiping activity inside compromised environment…SECURITYAFFAIRS.COM
10 JulFormer Ransomware Negotiator Sentenced to 70 Months in Prison for Secretly Helping BlackCat GangA former ransomware negotiator was sentenced to nearly six years for secretly helping BlackCat extort victims while betraying his clients. A U.S. court sentenced former ransomware negotiator Angelo Martino, 41, to 70 months in prison for conspiring with the BlackCat ransomware ga…SECURITYAFFAIRS.COM
10 JulThird US Security Expert Sentenced to Prison for Helping Ransomware GangAngelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group. The post Third US Security Expert Sentenced to Prison for Helping Ransomware Gang appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulRansomware Never Stopped: Over 9,000 Confirmed Attacks Since 2018Ransomware remains above 1,400 attacks yearly since 2023. Qilin leads in 2026, while the U.S. remains the main target. Ransomnews has independently confirmed 9,291 ransomware attacks worldwide between January 2018 and July 2026, tracking incidents only when verified through victi…SECURITYAFFAIRS.COM
10 JulFlorida ransomware negotiator convicted for helping ransomware gang extort US companiesA third ransomware negotiator has been jailed for helping a notorious ransomware group extort American victim companies into paying the hackers.TECHCRUNCH.COM
10 JulIn Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware OpsOther noteworthy stories that might have slipped under the radar: Abnormal AI sued by Anthropic, AssuranceAmerica data breach affects 7 million people, NSA brings back TAO. The post In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops app…SECURITYWEEK.COM
10 JulPolice suspects Dutch hackers were involved in Odido breachThe Dutch National Police (Politie) says it has found "strong indications" that Dutch hackers have been involved in a February breach at the telecommunications provider Odido. [...]BLEEPINGCOMPUTER.COM
10 JulCybercriminals Flock to Healthcare Businesses as Attacks SurgeWhile cyberattacks against hospitals and clinics grew modestly in the first half of 2026, attacks on service providers and other healthcare businesses more than doubled.DARKREADING.COM
10 JulInjective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm PackagesUnknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, …THEHACKERNEWS.COM
10 JulRyuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentenceOne man accused of deploying Ryuk ransomware pleaded guilty Wednesday in an Oregon federal court to conspiracy and computer fraud, while another man received a 70-month federal prison sentence in a Florida court for helping the Blackcat/AlphV gang extort multiple victims.THERECORD.MEDIA
10 JulRyuk ransomware member pleads guilty in the US, faces 15 years in prisonA 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. [...]BLEEPINGCOMPUTER.COM
10 JulArmenian national pleads guilty to Ryuk ransomware attacksKaren Vardanyan faces up to 15 years in federal prison and agreed to pay nearly $1.2 million in restitution. The post Armenian national pleads guilty to Ryuk ransomware attacks appeared first on CyberScoop .CYBERSCOOP.COM
10 JulNo Manners Here: The Ruthless Rise of The Gentlemen RansomwareUnit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
🕵️ THREAT INTELLIGENCE 14[−]
10 JulISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
10 JulNew infosec products of the week: July 10, 2026Here’s a look at the most interesting products from the past week, featuring releases from Attestiv, Automox, Codenotary, and First Recon AI. Codenotary launches AI security platform that learns from AI agent behavior Codenotary has announced AgentMon 3, the latest generation of …HELPNETSECURITY.COM
10 JulAWS gives its ERP agent deny-by-default rules and a separate identityAccounts receivable teams at large companies spend hours each day matching incoming bank payments to invoices by hand. When those payments sit unmatched for days, cash flow suffers and days sales outstanding climbs. The same pattern repeats across blocked invoices, purchase order…HELPNETSECURITY.COM
10 JulMost data brokers won’t tell you what happened to your deletion requestData brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask a broker to delete your records, or to sto…HELPNETSECURITY.COM
10 JulNetwork of 200 GitHub Repositories Used for Malware InfectionA Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware. The post Network of 200 GitHub Repositories Used for Malware Infection appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulMeta automatically opts public Instagram accounts into AI image generationMeta has launched Muse Image, a new AI image-generation model that lets users incorporate photos from public Instagram accounts into AI-generated images by simply tagging a username in a prompt. The feature has sparked privacy concerns because public Instagram accounts are enroll…CYBERINSIDER.COM
10 JulFlying with the Flipper ZeroWhy is the world so alarmed about taking the Flipper on board planes? Is it just poorly educated armchair cyber commentators of the ‘don’t use open Wi-Fi / USB juicejacking’ style of fearmongering, or is there something to it? TL;DR Why are people worried? …PENTESTPARTNERS.COM
10 JulLineageOS adds browser-based flashing tool for older Android devicesLineageOS has introduced a browser-based flashing tool that significantly lowers the barrier to installing the popular aftermarket Android operating system. The new feature makes it easier for users to install LineageOS on supported devices, helping extend the life of smartphones…CYBERINSIDER.COM
10 JulHackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 AccessA threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with an aim to carry out data extortion attacks. The threat actor, tracked by Okta under the moniker O-U…THEHACKERNEWS.COM
10 JulOkta Warns of Vishing Attacks Targeting Microsoft 365 CustomersThe attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages. The post Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers appeared first on SecurityWeek .SECURITYWEEK.COM
10 JulZimbra patches a critical flaw in its Classic Web Client.GigaWiper combines espionage capabilities with destructive payloads. Helix extortion gang conducts device-code phishing attacks.THECYBERWIRE.COM
10 JulMicrosoft Warns New 'GigaWiper' Malware Combines Espionage and Destructive CapabilitiesA new multi-purpose backdoor allows cyber threat actors to conduct both quiet espionage activity and destructive wiping operationsINFOSECURITY-MAGAZINE.COM
10 JulSecuring our future: July 2026 progress report on Microsoft’s Secure Future InitiativeMicrosoft’s latest Secure Future Initiative report outlines progress on secure foundations, AI-powered defense, and future-ready cybersecurity. The post Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative appeared first on Microsoft Securi…MICROSOFT.COM
10 JulBorg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Josh Marpet & More - SWN #597Borg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Locutus, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-597YOUTUBE.COM
🌐 CYBER THREAT LANDSCAPE 7[−]
10 JulFrom 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at ScaleMost enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report, only 45% of organizations consolidate their asset and exposure data into a sing…THEHACKERNEWS.COM
10 JulExposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress SitesA cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the expos…THEHACKERNEWS.COM
10 JulStudy of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and TrackingResearchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic private and secure. The apps flagged with at least one problem have been instal…THEHACKERNEWS.COM
10 Jul222 GitHub Repositories Linked to Fake Go Package Malware OperationResearchers uncovered 222 GitHub repositories spreading malware through fake Go packages, delivering loaders, stealers, RATs, and cryptominers. Socket’s security research team started with the investigation of a single malicious Go module: github[.]com/kaleidora/dnsub-scann…SECURITYAFFAIRS.COM
10 JulNew MODBEACON RAT Uses gRPC Streaming for Encrypted C2 TrafficThe China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that p…THEHACKERNEWS.COM
10 JulThis new Windows malware can take over your PC and wipe it cleanGigaWiper is a remote access Trojan that can spy on victims and permanently wipe their systems in three different ways.MALWAREBYTES.COM
10 JulNew U-Boot flaws could enable stealthy firmware attacksSix vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware. [...]BLEEPINGCOMPUTER.COM
🎙️ PODCASTS 1[−]
10 JulSponsored: Why Sublime doesn’t toss AI at every emailIn this Risky Business sponsored interview, Tom Uren chats with Sublime Security Product Manager AJ Williams about how the company targets its AI use. Rather than throwing its AI agents at everything, Sublime gives them the time-consuming email security tasks that humans don’t wa…RISKY.BIZ
📡 INFOSEC NEWS 15[−]
10 Jul"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)Anyone who deals with phishing messages caught by basic security filters knows that most phishing samples tend to blend into one another, since only a small set of techniques and approaches keeps reappearing in them. That is precisely why it is worth pausing on the occasional mes…ISC.SANS.EDU
10 JulTwo Chrome updates in two days fix critical vulnerabilitiesChrome updates are arriving within days of each other. Learn how to update Chrome and check if you're running the latest version.MALWAREBYTES.COM
10 JulHow mule betting scams recruit ordinary peopleEasy-money offers to open a gambling account could make you part of a money laundering operation. Here's how to spot a mule betting scam.MALWAREBYTES.COM
10 JulAI Coding: Do Security Risks Outweigh Productivity Gains?AI coding tools cost $19-$200/month/user, but security scanning, remediation, and false positives add hidden costs. Are the productivity gains worth it?DARKREADING.COM
10 JulThe Replicant in Your Directory: AI Agents and the Identity Security GapAI agents are accelerating the growth of non-human identities, making it harder for organizations to understand what exists, who owns it, and what it can access. Netwrix explains why stronger visibility and identity governance are essential as AI expands the enterprise attack sur…BLEEPINGCOMPUTER.COM
10 JulFresh ATM Crypto Software Bugs: Jackpot or Bust?Organizations, and possibly ATMs, are at risk of compromise, thanks to holes in a Microsoft BitLocker security wrapper.DARKREADING.COM
10 JulLaser Attack Resets Tangem Wallet Passwords on Cards That Can't Be PatchedResearchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to anything the attacker picks. No old password. No backup card. Once it is reset, whoever did…THEHACKERNEWS.COM
10 JulMoney launderer accused of stealing seized crypto while in prisonA Bulgarian national has been charged with stealing $290,000 in government-seized cryptocurrency while serving 121 months in prison for helping launder millions stolen from American fraud victims. [...]BLEEPINGCOMPUTER.COM
10 JulLicense plate cameras may be next target after Supreme Court reins in location trackingIf a warrant is ultimately needed for ALPR searches, experts say, it would radically limit how the networks of cameras can be used and would change modern policing.THERECORD.MEDIA
10 JulProgress urges ShareFile admins to shut down servers over “credible” threatProgress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a "credible external security threat" targeting the on-premises secure file-sharing software. [...]BLEEPINGCOMPUTER.COM
10 JulSix New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at BootResearchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs can crash a device. The other two …THEHACKERNEWS.COM
10 JulURGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security ThreatProgress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a "credible external security threat." The company has temporarily disabled access to the affected accoun…THEHACKERNEWS.COM
10 JulEurope revives law allowing big tech to scan for CSAMThe law known as Chat Control 2.0 passed in the European Parliament, permitting companies like Google, Meta and Microsoft to scan users' messages to hunt for CSAM.THERECORD.MEDIA
10 JulJen Ellis: Connecting Cyber Community With Political MachineryOn the heels of her recent honors as a Member of the Order of the British Empire (MBE), we take a look back at the events that shaped Ellis' advocacy on behalf of security researchers.DARKREADING.COM