🚨 CISA KEV 1[−]
13 Jul KEVU.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco IOS flaw, tracked as CVE-2008-4128, to its Known Exploited Vulnerabili…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 2[−]
13 Jul KEViCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-DaysThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vu…THEHACKERNEWS.COM
13 JulRabbitMQ flaws expose OAuth secrets, risk complete takeover of the brokerRabbitMQ has patched two access control vulnerabilities affecting the widely used open-source message broker that could expose enterprise application data and, in some deployments, allow attackers to gain complete control over the messaging infrastructure. The flaws, discovered b…CSOONLINE.COM
⚠️ VULNERABILITY DISCLOSURE 34[−]
13 JulShareFile shutdown, double-agent ransomware negotiator sentenced, Helix uses vishingShareFile shutdown order, a double-agent ransomware negotiator sentenced, and vishing crews raid SharePoint Progress Software ordered customers running ShareFile Storage Zone Controllers to shut down the Windows servers immediately amid a credible external threat, offering no CVE…CYBERSECURITYTODAY.LIBSYN.COM
13 Jul99.9% of fixable AI vulnerabilities remain unpatchedOrganizations build, deploy, and operate AI in the cloud, but basic cybersecurity hygiene is often sacrificed for speed, according to Orca Security’s 2026 State of AI Security Report. Building AI without security Fifty-six percent of AI adopters have deployed agent frameworks int…HELPNETSECURITY.COM
13 JulCynative: Open-source deep research agentRunning a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke around can delete a bucket, flip a permission, or leak a secret on its way to a finding. Cynative, an op…HELPNETSECURITY.COM
13 JulCan AI narrow cybersecurity’s class divide?At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes. In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would then …CSOONLINE.COM
13 JulCopy-paste might be the riskiest thing your enterprise employees do all dayThis source of data leakage takes them less than a second and happens hundreds of times a day.CYBERSECURITYDIVE.COM
13 JulAustralian Cyber Agency Warns of Global CMS Exploitation CampaignAustralian Cyber Security Centre warns CMS users of mass scanning and exploitation campaignINFOSECURITY-MAGAZINE.COM
13 JulAustralia Alerts Organizations to Ongoing CMS Exploitation AttacksAustralia warns of a global campaign exploiting CMS flaws to deploy webshells on WordPress, Joomla, and other websites. Australia’s Signals Directorate has issued an alert about a large-scale exploitation campaign actively targeting content management systems (CMS) worldwid…SECURITYAFFAIRS.COM
13 JulJurassic Park, cybersecurity and the dangerous myth of controlJurassic Park wasn’t really about dinosaurs. It was about arrogant people building systems they believed were controllable. “Life finds a way” is probably the most famous line from the entire franchise. Ian Malcolm’s warning that no matter how sophisticated the technology becomes…CSOONLINE.COM
13 JulYour AI risk register is not an incident response planPicture the moment after an AI issue is reported. A security analyst is reviewing a ticket reporting that an internal AI tool produced the wrong recommendation in a live business workflow. The risk is not theoretical anymore. Someone wants to know whether this is a security incid…CSOONLINE.COM
13 JulHungry? We talk Smoked Meat, Poutine, and Bagel - also, Identiverse Interviews! - ESW #467Interview with François Proulx from Boost Security Software Supply Chain Security: Build Pipeline (CI/CD) Exploitation Boost Security is the creator of some very popular build pipeline security tools, like Bagel and Poutine. Today, we discuss their latest tool, Smoked Meat. They …YOUTUBE.COM
13 JulZimbra Patches Critical Code Execution VulnerabilityThe flaw results in malicious code embedded in crafted emails being executed when the emails are opened. The post Zimbra Patches Critical Code Execution Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulOrganizations Warned of Exploited Joomla Extension VulnerabilitiesThreat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution. The post Organizations Warned of Exploited Joomla Extension Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulIntel agencies warn of Russian state hackers targeting routers worldwideA coalition of 21 cybersecurity and intelligence agencies has warned that Russian state-sponsored hackers continue to compromise internet-facing routers by exploiting weak configurations and known vulnerabilities, enabling them to steal device configurations and gain insight into…CYBERINSIDER.COM
13 JulRabbitMQ Vulnerability Threatens Enterprise SystemsUnauthenticated attackers could obtain the broker's confidential OAuth client secret, allowing them to take control of the broker. The post RabbitMQ Vulnerability Threatens Enterprise Systems appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulTurning the Tables on Email Scammers With 'ScamBuster'An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations.DARKREADING.COM
13 JulRansomware negotiator who betrayed clients sentenced to 70 months in prisonA former ransomware negotiator at incident response firm DigitalMint has been sentenced to 70 months in prison after admitting he shared confidential client information with the BlackCat ransomware group and later helped carry out ransomware attacks. Prosecutors say Angelo Martin…HELPNETSECURITY.COM
13 JulEU and UK hit Russia with joint sanctions over cyberattacksBGNES News reports: The European Union and the United Kingdom have imposed coordinated sanctions against Russia in connection with cyberattacks in Europe. Brussels and London have accused the Federal Security Service of the Russian Federation (FSB) of recent malicious activities.…DATABREACHES.NET
13 JulA cyberattack in March resulted in ZEGO filing for insolvencyA statement on ZEGO Textilveredelungszentrum GmbH’s website explains why they are filing for insolvency: Insolvency proceedings have been initiated – and why we are still looking ahead Ladies and gentlemen, dear business partners, Today we are contacting you with a message …DATABREACHES.NET
13 JulProgress urges ShareFile admins to shut down servers over “credible” threatLawrence Abrams reports: Progress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a “credible external security threat” targeting the on-premises secure file-sharin…DATABREACHES.NET
13 JulWhy cloud security is mission-critical for federal civilian and defense agenciesBeyond IT compliance, cloud security is now the backbone of civilian agency resilience, national defense, and warfighter safety, as cloud environments become increasingly complex. Key takeaways For the Department of War (DoW), cloud security is an IT concern and a requirement for…TENABLE.COM
13 JulGhostcommit attack hides malicious AI instructions in imagesA proof-of-concept attack hides prompt injection in a PNG file, turning routine code reviews into a path for secret theft.MALWAREBYTES.COM
13 Jul13th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employ…RESEARCH.CHECKPOINT.COM
13 JulTidal Cyber connects assets, vulnerabilities, and threats through Threat-Led DefenseTidal Cyber has announced Threat-Led Asset Visibility and Vulnerability Prioritization, new innovations extending the company’s Threat-Led Defense platform. The announcement marks a significant advancement in defensive security, shifting the industry beyond static asset inv…HELPNETSECURITY.COM
13 JulPakistani Police Systems Hit by Chinese and Indian EspionageChinese and Indian spies converged on the same Balochistan police force, SentinelLabs foundINFOSECURITY-MAGAZINE.COM
13 JulCenters Lab NJ discloses data breach incident impacting 542,000 peopleCenters Lab NJ has revealed that a cybersecurity incident disclosed last month affected 542,377 individuals, according to a filing with the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR). The figure, published on the agency's breach portal, provide…CYBERINSIDER.COM
13 JulCloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226AI is changing cloud security fast, but the biggest challenge is not just adoption. It is governance. In this episode, Jess sits down with Brent Neil, CISO at RapidScale, to talk about what CISOs should be watching as AI becomes embedded in cloud environments, business workflows,…YOUTUBE.COM
13 JulUS authorities warn that state-linked hackers are targeting vulnerable networking devicesHackers linked to Russian intelligence have exploited vulnerabilities in Cisco Smart Install devices.CYBERSECURITYDIVE.COM
13 Jul KEVCISA warns of actively exploited RCE flaws in Joomla extensionsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. [...]BLEEPINGCOMPUTER.COM
13 JulEffective Patch Management Strategies: 7 Best Practices | HuntressStop letting bad actors exploit old bugs. Build a practical patch management strategy to keep them out and learn to stay secure without all the fluff.HUNTRESS.COM
13 JulApple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAIApple would not comment on the "security breach," which allegedly allowed a former employee to download sensitive files from Apple's network long after he departed the company for rival OpenAI.TECHCRUNCH.COM
13 JulHackers backdoor Jscrambler npm package with infostealer malwareThe Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. [...]BLEEPINGCOMPUTER.COM
13 JulNG: Zenith Bank, Others To Be Arraigned Over Alleged Data BreachFatima Abdullahi reports: The Federal High Court in Abuja has fixed July 21, 2026, for the arraignment of Zenith Bank Plc and three other defendants over allegations of illegally accessing and disclosing the confidential financial records of Makers Island Company Limited. The oth…DATABREACHES.NET
13 JulLidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data BreachLidl disclosed a third-party data breach affecting online shop customers in Germany, Belgium, and the Netherlands. Payment data was not exposed. Lidl contacted customers of its online shop in Germany, Belgium, and the Netherlands last week to inform them that their personal data …SECURITYAFFAIRS.COM
13 JulVPN service favored by ransomware groups is sanctioned by USSuzanne Smalley reports: The U.S. government on Monday sanctioned a VPN provider and its Ukrainian administrator for abetting ransomware gangs behind attacks on American municipalities, hospitals, schools and businesses. First VPN Service (1VPNS) provided ransomware groups with t…DATABREACHES.NET
📋 SECURITY BULLETINS 2[−]
13 JulMicrosoft demystifies how Windows updates workMicrosoft has published a guide explaining the Windows servicing model, outlining the purpose of monthly security updates, optional preview releases, hotpatch updates, and the mechanisms used to deliver new features throughout the year. “Most individuals and organizations regular…HELPNETSECURITY.COM
13 JulMicrosoft Entra ID security updates: Passkeys are the default authentication method in Entra IDMicrosoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare. The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID appeared first on Micr…MICROSOFT.COM
📢 SECURITY ADVISORIES 13[−]
13 JulWhy SBOMs, signing, and provenance still don’t tell you if software is safeWe have made real progress in software supply chain security, improving visibility into software components, authenticity and build integrity. Much of this progress traces back to Executive Order 14028, which pushed agencies, contractors and enterprises to invest in SBOMs, signin…HELPNETSECURITY.COM
13 JulRussian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory WarnsCybersecurity agencies from 12 countries have warned that Russian state-backed hackers are actively targeting vulnerable routers using weak SNMP credentialsINFOSECURITY-MAGAZINE.COM
13 JulNew compliance guidance available: HITRUST i1 on AWSWe are pleased to announce the publication of a new AWS compliance implementation guidance: HITRUST i1 Compliance on AWS: Customer Implementation Guidance with an Illustrative Healthcare Platform. Healthcare organizations seeking HITRUST i1 certification increasingly rely on Amaz…AWS.AMAZON.COM
13 JulLessons Learned from CISA’s Recent GitHub LeakThe Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by Kr…KREBSONSECURITY.COM
13 JulOfficials once again warn defenders that Russian hackers are targeting network devicesState-sponsored attackers are targeting critical infrastructure networks in defense, communications, energy, finance, government and health care. The post Officials once again warn defenders that Russian hackers are targeting network devices appeared first on CyberScoop .CYBERSCOOP.COM
13 JulVPN service favored by ransomware groups is sanctioned by USThe U.S. Treasury Department announced sanctions against First VPN Service (1VPNS) and its Ukrainian administrator for aiding ransomware groups. Separately, a Belarusian man was sanctioned for malware "cryptors."THERECORD.MEDIA
13 JulAI Cannot Govern AloneAI can help organizations create stronger policies and improve security decision-making, but current AI systems are not perfectly precise. Because AI is non-deterministic, security teams still need humans involved in important decisions. Better outcomes require combining AI capab…YOUTUBE.COM
13 JulStates are building their own election defense networks as federal support evaporatesElection officials are facing an impossible choice: follow federal directives they don’t trust, or risk becoming targets of a criminal investigation. The post States are building their own election defense networks as federal support evaporates appeared first on CyberScoop .CYBERSCOOP.COM
🔥 INCIDENT REPORTING 15[−]
13 JulCenters Laboratory Data Breach Affects 540,000 IndividualsThe WorldLeaks extortion group claimed to have stolen 720 GB of data from the healthcare testing and laboratory services provider. The post Centers Laboratory Data Breach Affects 540,000 Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulHacker Extradited from Ukraine Pleads Guilty to Ryuk Ransomware ChargesAn Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operationINFOSECURITY-MAGAZINE.COM
13 JulFastNetMon eliminates third-party bgp lookups with NetomicsFastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built for internet service providers (ISPs), cloud provi…HELPNETSECURITY.COM
13 JulDutch Nationals Suspected in Odido Hack That Exposed Six Million CustomersDutch police suspect local hackers behind the Odido breach that exposed 6M customers after a phishing attack and seek public help identifying them. Dutch police have identified strong indications that Dutch nationals were involved in the February 2026 cyberattack on telecom provi…SECURITYAFFAIRS.COM
13 JulEU sanctions Russian GRU military hackers over cyberattacksThe European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Europe. [...]BLEEPINGCOMPUTER.COM
13 JulBreach at the Beach: Play the Ultimate Entra ID CTFLearn how attackers abuse Entra ID through a free hands-on Capture the Flag. Varonis created the Breach at the Beach CTF to teach defenders how to investigate Entra ID attack techniques using realistic scenarios. [...]BLEEPINGCOMPUTER.COM
13 JulLidl discloses online shop breach after service provider hackGerman discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole their personal information in a breach at a service provider. [...]BLEEPINGCOMPUTER.COM
13 Jul⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and MoreSomewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets. That's the shape of this week. Trusted co…THEHACKERNEWS.COM
13 JulEurope strikes out against Russia’s Turla over espionage, ‘destructive attacks’The EU, its members and the U.K. took action against Russian government officials and others while attributing the winter cyberattacks against Poland’s energy grid to the FSB. The post Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’ appeared first …CYBERSCOOP.COM
13 JulHackers breach Lidl’s IT service provider, steal customer dataGerman discount supermarket chain Lidl has notified customers in Germany, Belgium, and the Netherlands that customer data was stolen after attackers breached one of its IT service providers. In notices published on its support websites in Belgium and the Netherlands, Lidl said it…HELPNETSECURITY.COM
13 JulCrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper ChecksCybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is…THEHACKERNEWS.COM
13 JulRussian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breachFollowing the breach of several of her Telegram channels, controversial Russian journalist Ksenia Sobchak claimed published screenshots of her correspondence with political figures were fake.THERECORD.MEDIA
13 JulState of the router.The U.S. and its allies warn of Russian cyber threats targeting critical infrastructure as Europe rolls out new sanctions. Apple sues OpenAI over alleged trade secret theft. Progress investigates a potential ShareFile security incident, Zimbra patches a critical flaw, and researc…THECYBERWIRE.COM
13 JulJapan's largest taxi operator shuts systems after cyberattackJapan's largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. [...]BLEEPINGCOMPUTER.COM
13 JulWeak Security Continues to Fuel Russian CyberattacksIn a first, the UK and the EU jointly impose sanctions on Russian individuals and entities for cyberattacks and disinformation campaigns in the region.DARKREADING.COM
🕵️ THREAT INTELLIGENCE 25[−]
13 JulISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
13 JulEnterprises are rethinking where their AI applications runGrowing demand for compute capacity, power, cooling and low-latency connectivity is prompting organizations to reassess where AI applications run, according to CoreSite. Public cloud continues to support experimentation and rapid deployment, while colocation is increasingly used …HELPNETSECURITY.COM
13 JulA hardware security AI assistant that checks chips for hidden backdoorsChip designers license blocks of circuitry from outside vendors and drop them into larger products. A single processor can carry components from a range of suppliers, each written by a company the buyer may never deal with directly. A malicious supplier can bury a hidden circuit …HELPNETSECURITY.COM
13 JulAI-generated code has made security debt a governance problemMoving from tool approval to true governance is the only way for CISOs to keep pace with the accelerating velocity of software risk. The post AI-generated code has made security debt a governance problem appeared first on CyberScoop .CYBERSCOOP.COM
13 JulProgress Prompts ShareFile Storage Zone Controller Shutdown Amid Security ConcernsThe company notified customers to manually shut down their servers while it is investigating a credible threat. The post Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulClaude Code users keep 50% higher limits until July 19Anthropic has extended a limited-time promotion that increases weekly usage limits in Claude Code by 50% through July 19, 2026, at 11:59 PM PT. When the promotion ends, weekly usage limits will return to their standard levels without any changes to users’ plans or billing. …HELPNETSECURITY.COM
13 JulAI Data Centers and the Concentration of WealthThis essay was written with Nathan E. Sanders, and originally appeared in The Guardian . Opposition to AI data centers has emerged as a primary theme in US politics, one that—surprisingly—doesn’t fall along party lines. We applaud people coming together for cons…SCHNEIER.COM
13 JulEU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying CampaignThe move targeted people and entities accused of links to an online spying network that the EU claims targeted governments and carried out sabotage operations against critical infrastructure. The post EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber S…SECURITYWEEK.COM
13 JulRust-proof your code with our new Testing Handbook chapterWe’ve added a new chapter to our Testing Handbook : a comprehensive guide to security testing Rust programs. This chapter covers the tools and techniques we use at Trail of Bits to validate the security of Rust programs and systems. fn main () {( | f: & dyn Fn ( u128 )-> B…TRAILOFBITS.COM
13 JulSecurity threat prompts Progress to disable ShareFile accounts, tell customers to shut down serversA “credible external security threat” targeting Progress Software’s ShareFile Storage Zone Controllers (SZC) – the on-premises, customer-managed server components where organizations store files shared via this popular enterprise platform – has spurr…HELPNETSECURITY.COM
13 JulAttacker Uses Suspected AI-Generated PowerShell Script to Map Active DirectoryCybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. "The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a direc…THEHACKERNEWS.COM
13 JulCybersecurity M&A Roundup: 37 Deals Announced in June 2026Significant cybersecurity M&A deals announced by 1Password, Accenture, Cisco, F5, Rubrik, and SailPoint. The post Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulFake OAuth client IDs are helping attackers slip past sign-in logsAttackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, the globally unique identifier assigned to an application and passed as client_id in an authentication requ…HELPNETSECURITY.COM
13 JulCloudflare Precursor uses continuous behavioral analysis to stop advanced botsCloudflare has announced the general availability of Precursor, a next-generation, continuous behavioral validation engine for bot management. Precursor runs seamlessly inside web browsers to monitor entire user sessions in order to detect bot automation. Unlike static CAPTCHAs, …HELPNETSECURITY.COM
13 JulLumen expands managed detection and response with Cortex XSIAM integrationLumen Technologies has announced Lumen Defender Advanced Managed Detection and Response (AMDR) for Palo Alto Networks Cortex XSIAM. Attackers are increasingly operating earlier in the lifecycle while AI is accelerating threat speed. This expanded service will bring together Lumen…HELPNETSECURITY.COM
13 JulEU Targets FSB-Linked Hackers in New Sanctions Over Cyber SabotageEU sanctions target nine people and four entities tied to Russia’s FSB over a 15-year cyberespionage and critical infrastructure sabotage campaign. The European Union imposed sanctions on Monday targeting nine individuals and four entities linked to a Russian cyberespionage…SECURITYAFFAIRS.COM
13 JulYour CI Pipeline Becomes the AttackDependency pinning helps ensure consistent builds, but it doesn't protect a CI/CD pipeline if an attacker can modify the workflow itself. A workflow is ultimately executable code, often defined in a YAML file, running on infrastructure that may have access to cloud credentials or…YOUTUBE.COM
13 JulHacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to RedemptionOnce a notorious blackhat hacker, McGraw shares his journey from high school hacking and prison to redemption as a cybersecurity advocate. The post Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption appeared first on SecurityWeek .SECURITYWEEK.COM
13 JulEU and UK blacklist Russia’s cyber operators over efforts to destabilize EuropeThe EU and the UK jointly sanctioned dozens of Russian individuals and entities, accusing Moscow of coordinating a malicious cyber ecosystem targeting Europe, its member states, and international partners. The UK sanctioned 24 individuals and entities, while the EU imposed restri…HELPNETSECURITY.COM
13 JulWestern intelligence agencies warn of Russian hackers targeting critical infrastructure.Progress Software tells ShareFile admins to shut down servers immediately. Researchers identify a new macOS infostealer.THECYBERWIRE.COM
13 JulHackers find a new trick to collect Microsoft Entra user data without raising red flagsOrganizations should check their logs for signs of an increasingly popular obfuscation technique, Proofpoint said.CYBERSECURITYDIVE.COM
13 JulCloudflare expands behavioral tracking to fight AI bots, says user privacy protectedCloudflare has introduced Precursor, a new bot detection system that continuously monitors visitor behavior throughout an entire browsing session instead of relying solely on CAPTCHAs or isolated verification points. While the company says the technology is designed to combat inc…CYBERINSIDER.COM
13 JulGigaWiper Lets Threat Actors Choose Their Own Destructive AttackA modular implant borrows from various malware families to combine both backdoor and wiper activities to maximize impact and minimize operational output.DARKREADING.COM
13 JulLiving on the Edge: How Threat Actors Use Network Infrastructure Against YouThe post Living on the Edge: How Threat Actors Use Network Infrastructure Against You appeared first on Eclypsium | Supply Chain Security for the Modern Enterprise .ECLYPSIUM.COM
13 JulDefending SaaS-based applications against ShinyHunters OAuth abuseMicrosoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications. The post Defending SaaS…MICROSOFT.COM
🌐 CYBER THREAT LANDSCAPE 4[−]
13 JulA week in security (July 6 – July 12)A list of topics we covered in the week of July 6 to July 12 of 2026MALWAREBYTES.COM
13 JulUS and allies warn of Russian critical infrastructure attacksCybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks. [...]BLEEPINGCOMPUTER.COM
13 JulForg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session TheftA new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 36…THEHACKERNEWS.COM
13 JulNew CrashStealer malware poses as Apple crash reporting toolA new macOS information-stealing malware called CrashStealer pretends to be Apple's crash-reporting tool to steal credentials, keychain data, and crypto wallets. [...]BLEEPINGCOMPUTER.COM
🎙️ PODCASTS 1[−]
13 JulTrusting your kids online isn’t enough (Lock and Code S07E14)This week on the Lock and Code podcast, we speak with Anna Brading about what actually works in keeping her kids safe online.MALWAREBYTES.COM
📡 INFOSEC NEWS 21[−]
13 JulSomeone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th)The setup
ISC.SANS.EDU
13 JulMisconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history. From that one lapse…THEHACKERNEWS.COM
13 JulA Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban SurveillanceThe SFPD’s exposure of hours of videos from drone platform Skydio reveals how broadly it’s watching the city from above—and how the results can spill online.WIRED.COM
13 JulFake crypto gift card sites are getting harder to spotScam crypto gift card stores look almost identical to the real thing. One wrong click can leave you with no card and no way to get your money back.MALWAREBYTES.COM
13 JulProgress Software Warns of "External Security Threat" to ShareFileProgress Software, the provider of the popular file-sharing and data storage solutions, has urged customers to shut down the server hosting their Storage Zone ControllerINFOSECURITY-MAGAZINE.COM
13 JulMeta Files Patent for AI That Can Listen All Day and Track How You're FeelingMeta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read. Each read gets pinned to the moment it happened: the time, your location, what y…THEHACKERNEWS.COM
13 JulThinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst CopilotsA few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific inves…THEHACKERNEWS.COM
13 JulNovel OAuth Client ID Spoofing Technique Targets Cloud EnvironmentsNew research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environmentsINFOSECURITY-MAGAZINE.COM
13 JulIntroducing Precursor: detecting agentic behavior with continuous client-side signalsPrecursor, our new continuous behavioral validation engine for bot management, offers visibility into how humans and bots actually interact across the full user journey. By turning session-level behavior into bot detection signals, it identifies advanced automation with higher pr…CLOUDFLARE.COM
13 JulUK charges suspects linked to Russian Coms call spoofing platformUK authorities charged five people following a National Crime Agency (NCA) investigation into Russian Coms, a major caller ID spoofing platform used by criminals to make over 1.8 million scam calls. [...]BLEEPINGCOMPUTER.COM
13 JulLAPD lets contract with surveillance giant Flock expire, citing ‘serious concerns’ over civil liberties and privacyThe LAPD, one of Flock's biggest government customers, is ending its contract with the company citing civil liberties concerns.TECHCRUNCH.COM
13 JulWhy IaC Coverage Belongs on Your Security DashboardRethinking IaC coverage as a funnel that shows how much of your infrastructure is governed, traceable, and ready for remediation at speedWIZ.IO
13 JulTurning Secure Software Development into a Measurable PracticeCIS and SAFECode have updated Secure by Design: A Developer’s Guide to Building Safer Software to address the role of AI on software security.CISECURITY.ORG
13 JulNew MemGhost Attack Plants Persistent False Memories in AI Agents Through One EmailGive an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false "fact" about the user, hide the change, and quietly steer its answers in later sessions. Wh…THEHACKERNEWS.COM
13 JulOpen Directory Exposes Three Evilginx Phishing OperatorsMisconfigured server exposed three phishing operators running Evilginx forks to bypass MFAINFOSECURITY-MAGAZINE.COM
13 JulJoint guidance on improving router hygiene to protect against Russian state-sponsored targetingCYBER.GC.CA
13 JulGoogle and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector FoundGoogle and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version. The collector was dormant. An empty allow-li…THEHACKERNEWS.COM
13 JulGuidance on securely configuring authorization and authentication frameworks - ITSP.40.063CYBER.GC.CA
13 Jul'Yellow Teams' Are Defining the Future of AI SecurityIn some companies, engineers are building defense and attack tools to test the potential of artificial intelligence for cybersecurity — and its threat.DARKREADING.COM
13 JulEU leaders eye social media ban for children under age 13“While ultimately it is up to parents to decide when children get their first smartphones, what we already have is a consensus that there needs to be a start date for the age children can join social media,” says European Commission President Ursula van der Leyen.THERECORD.MEDIA