137Articles
9Categories
2026-07-14Date
🚨 CISA KEV 1[−]
14 Jul KEVPatch Tuesday - July 2026Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public…RAPID7.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 12[−]
14 JulGovernments to enterprises: Improve your router security hygieneGlobal security agencies say enterprises must clean up their act as Russian government-sponsored attackers exploit weaknesses in routers. According to a new multinational cybersecurity advisory , cyberattackers continue to exploit inadequately-protected and/or poorly-configured n…CSOONLINE.COM
14 JulCVE-2026-40468 Heap buffer overflow in gawkInformation published.MSRC.MICROSOFT.COM
14 JulCVE-2026-40553 Stack-based buffer overflow in gawkInformation published.MSRC.MICROSOFT.COM
14 JulCVE-2026-40469 Heap buffer overflow in gawkInformation published.MSRC.MICROSOFT.COM
14 JulCVE-2026-40467 Use after free in gawkInformation published.MSRC.MICROSOFT.COM
14 JulAI-powered breaches provide wake-up call for incident responseEnterprises have worked for years to improve detection and response times in the face of increasingly sophisticated attacks that relied on manual hacking and living-of-the-land techniques. AI is now threatening to undo those efforts. An increasing number of threat actors are auto…CSOONLINE.COM
14 JulCVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapi…RAPID7.COM
14 Jul KEVSonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)SonicWall has fixed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) affecting its Secure Mobile Access (SMA) 1000 Series appliances, and is urging customer organizations to upgrade to a fixed firmare version and search for evidence of potential compromise.…HELPNETSECURITY.COM
14 Jul KEVMicrosoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)56 Critical 510 Important 3 Moderate 0 Low Microsoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild. Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rat…TENABLE.COM
14 JulSAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify DataSAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows…THEHACKERNEWS.COM
14 Jul KEVMicrosoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesMicrosoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical". Microsoft notes that two of the vulnerabilities disclosed this month have been exploited…TALOSINTELLIGENCE.COM
14 JulSonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch nowSonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. [...]BLEEPINGCOMPUTER.COM
⚠️ VULNERABILITY DISCLOSURE 47[−]
14 JulBetween Two Nerds: Exploits are not cyber powerIn this edition of Between Two Nerds Tom Uren and The Grugq discuss just how important exploits are for cyber operations using data published in a new paper authored by two members of Ukraine’s cyber security agency. This episode is also available on YouTube.RISKY.BIZ
14 JulAI Security Report 2026For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from Check Point Research documents a transition that go…RESEARCH.CHECKPOINT.COM
14 JulChatto: Open-source team messenger with privacy at its coreTeams that want their group chats off commercial platforms have a growing menu of self-hosted options. Chatto joined that group when its developer released the code under an open-source license and posted binaries for anyone to run on their own hardware. The software aims at the …HELPNETSECURITY.COM
14 JulThe best defense against AI attacks turns out to be a skeptical humanAnalysts across the security industry now run generative AI through their daily work, from log triage to incident write-ups. Active use in cybersecurity strategy reached 78% of practitioners in 2026, up from half the field a year earlier. The 2026 SANS AI Survey, drawn from 536 I…HELPNETSECURITY.COM
14 JulFake smart home residents could stand in for real ones in security researchSmart home security research runs on a scarce ingredient: recordings of how real people use the gadgets in their homes. Getting that data means wiring up someone’s house and watching for months, which is slow, costly, and about as invasive as it sounds. So the datasets stay…HELPNETSECURITY.COM
14 JulMicrosoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three PathsAttackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usua…THEHACKERNEWS.COM
14 JulPentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity RulesA new CMMC review and reform task force will conduct a comprehensive review of the program. The post Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulNew tutorials on underground hacking forums have roughly doubledUnderground hacking forums are producing more original tutorials again, with growing attention on financial fraud, particularly the theft and fraudulent use of payment card data, known as carding, and cash-out techniques. New tutorials per month versus reposts (Source: Radware) F…HELPNETSECURITY.COM
14 JulDiscovering & Securing Your AI Agent Attack Surface - Jeremy Snyder - ASW #391While LLMs and agents are new to appsec and everyone else, a lot of AI security requirements translate to well-known API security requirements. Jeremy Snyder helps us frame the OWASP LLM Top 10 into five layers in order to help orgs understand and prioritize their attack surface.…YOUTUBE.COM
14 JulRapid7 and Mindshare Partner to Accelerate Cyber Resilience Across the Middle EastGopan Sivasankaran is Regional Director, Middle East & Africa, at Rapid7 From AI adoption and cloud-first strategies to smart cities and critical infrastructure modernization, organizations across the United Arab Emirates are embracing innovation at an unprecedented rate. The cou…RAPID7.COM
14 JulGrok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It ReadsxAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned…THEHACKERNEWS.COM
14 JulAI incidents need a new playbook. Here’s how to build oneSeventy-one percent of organizations say AI has access to core business systems. Only 16% govern that access effectively, according to the 2026 CISO AI Risk Report . Ask your IR team three questions: Where is your AI system inventory? What happens if a production model starts gen…CSOONLINE.COM
14 JulThe inside job that cost ransomware victims millionsInstead of helping victims negotiate with BlackCat, a trusted ransomware negotiator secretly helped the gang extort them.MALWAREBYTES.COM
14 JulMalware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily SuspendedJapan’s largest taxi operator Nihon Kotsu shut down systems after a malware attack, disrupting dispatch and bookings. Nihon Kotsu, Japan’s largest taxi company, disclosed on July 13, 2026 that its internal systems suffered an unauthorized external access involving mal…SECURITYAFFAIRS.COM
14 JulThe serpent’s tongue: Luring the Python out of its denThis blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments.TALOSINTELLIGENCE.COM
14 JulInside China's Cyber Espionage BusinessAhana Datta Fasel became the British government’s first ethical hacker in 2014, testing vulnerabilities in computer systems and networks that hackers could potentially exploit. She was only 23, but that gave her an early look at state-sponsored cyber intrusions, which have of cou…THECYBERWIRE.COM
14 JulGoogle adds FIDO2 keys and phone passkeys to Windows login via GCPWGoogle has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all Google Workspace customers. GCPW is a free tool that lets users sign in to Windows computers with their Googl…HELPNETSECURITY.COM
14 JulVulnerability in FIFA’s NetworkFIFA’s network was vulnerable to anyone with even minimal access.SCHNEIER.COM
14 JulWarning: Scammers are using FaceTime to empty bank accountsCybercriminals are combining social engineering through apps like FaceTime with unpatched devices to steal credentials and drain bank accounts.MALWAREBYTES.COM
14 JulNew MacOS Malware Exploits Legitimate Developer ID to Pose as Apple Crash ReporterResearchers at Jamf Threat Labs detail CrashStealer, which steals passwords, cryptocurrency wallets and moreINFOSECURITY-MAGAZINE.COM
14 JulSAP warns of critical flaws in NetWeaver and Commerce CloudSAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. [...]BLEEPINGCOMPUTER.COM
14 JulSAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce CloudThe flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization. The post SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulUnpatched Claude for Chrome Flaw Lets Extensions Read Gmail, CalendarA ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions. The post Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulCursor IDE Auto-Executes Malicious Code in Poisoned ReposResearchers reported the vulnerability to Cursor in December, but it still remains in the popular AI coding platform and can be exploited in poisoned repository attacks.DARKREADING.COM
14 Jul“Context bombs” can frustrate AI-driven attacks, researchers foundA new approach tried out by Tracebit researchers has proven very effective at stopping AI agents from fully compromising targeted environments. What makes it notable isn’t the technique – prompt injection is old news – but the direction it’s pointed: not t…HELPNETSECURITY.COM
14 Jul11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure BootCybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard. "An attacker exploiting one of these vulnerable application…THEHACKERNEWS.COM
14 JulYou Don't Have to Run an Exploit to Know If You're VulnerableMany vulnerabilities cannot be safely validated with live exploits, either because no exploit exists or the affected systems are too critical to test. Picus explains how TTP chaining helps organizations determine exploitability by validating the attack techniques an exploit depen…BLEEPINGCOMPUTER.COM
14 Jul7 Severe Vulnerabilities Patched in VMware Avi Load BalancerThe flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal. The post 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulRabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue MetadataCybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. …THEHACKERNEWS.COM
14 JulIran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report saysThe Iranian government exploited well-known flaws in cellphone networks to locate and then strike U.S. military personnel in the build-up and beginning of the war.TECHCRUNCH.COM
14 JulGrapheneOS says Google will cut security backports for older Android releasesGrapheneOS claims Google has significantly reduced security patch backports for older Android versions. This change could leave devices on previous releases with fewer vulnerability fixes despite continuing to receive monthly security updates. Google has not publicly documented t…CYBERINSIDER.COM
14 JulProgress confirms ShareFile zero-day flaw behind Storage Zone shutdownProgress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. [...]BLEEPINGCOMPUTER.COM
14 JulMicrosoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-daysToday is Microsoft's July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. [...]BLEEPINGCOMPUTER.COM
14 JulMicrosoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-DaysTwo flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed. The post Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulDoxbin admin jailed for egging on swatters from behind a screenConnor Jones reports: A Welshman was sentenced to prison on Tuesday for his role in numerous swattings in the UK, US, and Canada. Callum Dare, 26, was an administrator of Doxbin, a dark web platform frequented by individuals that expose the personally identifiable information (PI…DATABREACHES.NET
14 JulMicrosoft Patches a Record 570 Security FlawsMicrosoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attribu…KREBSONSECURITY.COM
14 JulMicrosoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)This patch Tuesday includes a staggering&#;x26;#;xc2;&#;x26;#;xa0;622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft&#;x26;#;39;s Edge browser. 62 of t…ISC.SANS.EDU
14 Jul KEVThe ransomware toll road.Treasury sanctions a VPN provider tied to ransomware. The Pentagon hits pause on CMMC audits. Critical flaws surface in Google Cloud’s Dialogflow CX. Estée Lauder discloses a data breach. Mobile networks become a battlefield for tracking U.S. personnel. Australia calls out Big Te…THECYBERWIRE.COM
14 JulMicrosoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous recordThe company forewarned customers and defenders that a flood of defects would be uncovered by AI. It delivered with a striking exponential increase. The post Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record appeared first on CyberScoop .CYBERSCOOP.COM
14 JulDefending SaaS-based applications against ShinyHunters OAuth abuseFrom Microsoft Security Research and Microsoft Defender Security Research Team: In a series of campaigns observed between mid-2025 and mid-2026, Microsoft identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing …DATABREACHES.NET
14 Jul KEVMicrosoft rolls out massive Windows 11 security update with 416 fixesMicrosoft has released the July 2026 Patch Tuesday cumulative updates for Windows 11, fixing hundreds of security vulnerabilities while introducing Secure Boot improvements, security hardening changes, and compatibility fixes. The updates also patch a publicly disclosed BitLocker…CYBERINSIDER.COM
14 JulRecords Are Made to Be Broken: Patch Tuesday Raises Triage StakesThree of the 622 CVEs for which Microsoft issued patches this week are zero-days; there are more than 60 critical vulnerabilities.DARKREADING.COM
14 JulElon Musk promises to delete all data following a leak of users’ confidential informationAbror Shuhratov reports: xAI, the company founded by Elon Musk, has announced emergency measures following a serious controversy involving the unauthorized uploading of users’ private code and confidential information to a server via the Grok Build CLI tool. The companyR…DATABREACHES.NET
14 JulSynopsys Finds No Evidence of Data Breach Amid Bosch Hack ClaimsEduard Kovacs reports: A new ransomware group named D1R in recent days listed Synopsys and Bosch on its Tor-based leak website. The cybercriminals claimed to have exploited a vulnerability in Synopsys’ website to access a corporate client database containing 40,000 entries, and t…DATABREACHES.NET
14 JulFinland issues wanted notice for hacker behind massive psychotherapy data breachI was really unpleasantly surprised when they let him out while on appeal, and now they may not be able to return him to prison? Did no one foresee that he might not stick around to be sent back to prison? Daryna Antoniuk reports: Finnish police have reportedly issued a wanted no…DATABREACHES.NET
14 JulRewards For Justice offers reward for info on Media Land, ML.Cloud, and three individuals associated with itRewards for Justice announced a $10M reward for information on the Russian-based bulletproof hosting (BPH) services company Media Land, its associated company ML.Cloud, and associated staff Aleksandr Alexandrovich Volosovik, Kirill Andreevich Zatolokin, and Yuliya Vladimirovna Pa…DATABREACHES.NET
14 JulPatch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one monthPatch Tuesday: Microsoft fixes a record 621 CVEs, including 2 exploited zero-days and critical flaws affecting SharePoint, RDP, Hyper-V, and AD FS. Microsoft’s July 2026 Patch Tuesday is, by a significant margin, the largest single-month security release in the company̵…SECURITYAFFAIRS.COM
📋 SECURITY BULLETINS 1[−]
14 JulMicrosoft releases Windows 10 KB5099539 extended security updateMicrosoft has released the Windows 10 KB5099539 extended security update, which includes the July 2026 Patch Tuesday security updates for 570 vulnerabilities, along with additional security fixes. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 15[−]
14 JulUS authorities warn of Russian attacks on critical infrastructureThe US authorities NSA, FBI, and CISA warn that Russian hackers have recently carried out a number of attacks on critical infrastructure in North America and Europe. Hackers are reportedly breaking into networks using vulnerable and misconfigured routers, making it extra importan…CSOONLINE.COM
14 JulShifting Security and Protecting the Pharma Supply Chain with Andy HillisHost Caleb Tolin sits down with Andy Hillis to discuss the evolution of information security from a late stage deployment checklist to a core prerequisite within global pharmaceutical infrastructure. The conversation reviews the operational challenges of managing over 200 annual …THECYBERWIRE.COM
14 JulNATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory saysDutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel.THERECORD.MEDIA
14 JulTreasury sanctions First VPN Service, others for abetting ransomware gangsThe designations hit 1VPNS, its alleged Ukrainian administrator and a Belarusian who allegedly sold “cryptors” to disguise ransomware and other malware. The post Treasury sanctions First VPN Service, others for abetting ransomware gangs appeared first on CyberScoop .CYBERSCOOP.COM
🔥 INCIDENT REPORTING 17[−]
14 JulYour vendor’s vendor might be the real breach riskIn this Help Net Security video, Chris Boehm, Field CTO, Zero Networks, breaks down how a vendor breach can become your breach. He explains that attackers now target the subcontractors behind your trusted vendors. A compromised credential at a company you have never heard of can …HELPNETSECURITY.COM
14 JulThe ransomware negotiator who was working for the other sideWhen a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help. Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf. What victims don't expect is that their trusted negotiator might be s…BITDEFENDER.COM
14 JulU.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware SupportThe U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious activities, including ransomware attacks against Americans. The VPN, named First VP…THEHACKERNEWS.COM
14 JulCrashStealer: New macOS Infostealer Uses Signed Apps to Evade GatekeeperNew macOS infostealer CrashStealer uses a signed app to bypass Gatekeeper, steals credentials and wallets, then AES-encrypts stolen data. Jamf Threat Labs first spotted CrashStealer in early May 2026 as a suspicious macOS sample uploaded to VirusTotal. By early July, in-the-wild …SECURITYAFFAIRS.COM
14 JulPhishing for dummies: Forg365 lowers barrier to M365 account takeoversA newly documented phishing-as-a-service platform distributed through Telegram is lowering the technical barrier to Microsoft 365 account takeovers by giving less-skilled attackers automated tools to evade some authentication controls and retain access after compromise. The platf…CSOONLINE.COM
14 JulLidl Notifies Customers of Third-Party Data BreachSupermarket giant Lidl has revealed details of a supplier breach impacting customer dataINFOSECURITY-MAGAZINE.COM
14 JulUS sanctions VPN, malware providers for enabling ransomware attacksThe U.S. Treasury Department's Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations. [...]BLEEPINGCOMPUTER.COM
14 JulUS, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure RoutersMultiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks. The post US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulAttacker Used AI to Build Custom PowerShell Recon MalwareHuntress found an AI-generated PowerShell script used for AD reconnaissance, showing attackers are using AI to create custom, evasive tools. During an incident response investigation on June 3, 2026, Huntress analyst Jevon Ang recovered a PowerShell script from a compromised Wind…SECURITYAFFAIRS.COM
14 JulPentagon suspends CMMC Phase II requirements.US Treasury Department sanctions VPN provider that allegedly assisted criminals. Lidl discloses breach affecting customer information.THECYBERWIRE.COM
14 JulHealthcare sector faces persistent supply-chain security, identity management challengesA new report says doctors and nurses should train for cyberattacks the way firefighters train for major blazes — even if they expect them to be rare.CYBERSECURITYDIVE.COM
14 JulCanada’s Electronic Spy Agency Conducted Cyberattacks on Criminals Brokering Fentanyl Ingredients, Report SaysResearch fellow Bill Robinson speaks with The Globe and Mail about CSE spending. The post Canada’s Electronic Spy Agency Conducted Cyberattacks on Criminals Brokering Fentanyl Ingredients, Report Says appeared first on The Citizen Lab .CITIZENLAB.CA
14 JulCyberattack at KFC Japan impacting online orders and deliveriesKFC Japan has announced that a cyberattack affecting one of its third-party logistics providers is disrupting food deliveries to restaurants nationwide, raising the possibility of product shortages, reduced operating hours, and temporary store closures. The company has suspended …CYBERINSIDER.COM
14 JulFinland issues wanted notice for hacker behind massive psychotherapy data breachThe defendant's lawyer told Finnish media that he does not know where his client is but believes Kivimäki is outside Finland.THERECORD.MEDIA
14 JulSynopsys Finds No Evidence of Data Breach Amid Bosch Hack ClaimsThe D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. The post Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulU.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware LossesU.S. sanctions hit VPN provider 1VPNS and a cryptor seller for enabling ransomware gangs behind billions in losses to critical infrastructure. The U.S. Treasury’s Office of Foreign Assets Control sanctioned two individuals and one entity on July 13 for supplying tools and i…SECURITYAFFAIRS.COM
14 JulWhen the Negotiator Helps HackersA ransomware negotiator was sentenced to federal prison after prosecutors said he secretly worked with the BlackCat ransomware group while negotiating on behalf of victims. According to court filings, he shared insurance limits, negotiating positions, and internal settlement thre…YOUTUBE.COM
🕵️ THREAT INTELLIGENCE 22[−]
14 JulISC Stormcast For Tuesday, July 14th, 2026 https://isc.sans.edu/podcastdetail/10006, (Tue, Jul 14th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
14 JulCybersecurity jobs available right now: July 14, 2026Cyber Network Engineer Fiserv | USA | On-site – View job details As a Cyber Network Engineer, you will lead the design, governance, and security review of enterprise network architectures across on-premises and cloud environments. You will provide expertise in net…HELPNETSECURITY.COM
14 JulTelegram’s t.me domain suspended at the registry level, breaking links worldwideTelegram's t.me domain was temporarily placed on serverHold status at the registry level on Tuesday, causing all t.me links to stop resolving through the global Domain Name System (DNS). While the messaging platform itself remained operational, users were unable to access public …CYBERINSIDER.COM
14 JulMultiple Jscrambler Packages Impacted by Supply Chain AttackA threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer. The post Multiple Jscrambler Packages Impacted by Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulMicrosoft Entra ID authentication overhaul to start in September 2026Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or voice authentication enabled will automatically be enabled for passkeys. The next time users complete MFA,…HELPNETSECURITY.COM
14 JulValarian Raises $50 Million for Sovereign Infrastructure Control LayerUK-based cybersecurity firm Valarian has raised a total of $70 million for its ACRA technology. The post Valarian Raises $50 Million for Sovereign Infrastructure Control Layer appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulUK charges five persons linked to fraud platform behind more than a million scam callsFive people have been charged in the UK following a National Crime Agency (NCA) investigation into Russian Coms, a caller ID spoofing service used by fraudsters. Ayoub Sehailia, 28, Zakkaria Sehailia, 30, Usman Din, 30, Denis Ozmus, 29, and Fadila Salem, 53, all of London, are ch…HELPNETSECURITY.COM
14 Jul[Video] Where protection starts: Cisco Talos Intelligence IntegrationsEvery day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies.TALOSINTELLIGENCE.COM
14 JulNo one knows how many old shims can still bypass UEFI Secure BootThe vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and assorted boot tools can run with Secure Boot on. Eleven of those signed shims turned out to be old enough to und…HELPNETSECURITY.COM
14 JulLastPass warns users of active campaign targeting master passwordsLastPass is warning customers about an active phishing campaign that uses lookalike domains and fake security notifications to trick users into revealing their master passwords or downloading malicious software. The company says the activity has no impact on LastPass's own system…CYBERINSIDER.COM
14 JulDownload: The ultimate guide to network operations managementModern network operations are too manual. Today’s IT and security teams are managing growing complexity across networks, infrastructure, tools, and workflows. The result? Slower response, duplicated effort, and operational friction. This guide explores how intelligent workflows h…HELPNETSECURITY.COM
14 JulHow Pentera Turns AI Security Workflows into Validation EnginesAI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragmented risk signals: scanner output, severity scores, threat intelligence, configura…THEHACKERNEWS.COM
14 JulOAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra CredentialsAt least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments…THEHACKERNEWS.COM
14 JulNew macOS malware steals passwords by posing as Apple’s crash-reporting toolJamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets. The malware was first spotted in May while it was still under development. By early…HELPNETSECURITY.COM
14 JulAI's Hidden Security LayerAI security is changing. The biggest risk is no longer simply whether employees are using AI—it's what they're asking AI to process. Sensitive prompts can expose confidential information in ways traditional security tools weren't built to observe. EDR, antivirus, and network moni…YOUTUBE.COM
14 JulSharp rise in AI adoption for cyber defense exposes major governance gapA report by the SANS Institute indicates a split between senior security leaders and frontline practitioners. CYBERSECURITYDIVE.COM
14 JulUpcoming Speaking EngagementsThis is a current list of where and when I am scheduled to speak: I’m speaking (virtually) at the Policy-Relevant Privacy Research Workshop in Calgary, Canada, on Monday, July 20, 2026. I’m speaking at Boston Leadership Exchange in Boston, Massachusetts, USA, on Wednesday, July 2…SCHNEIER.COM
14 JulAdobe Patches Critical ColdFusion VulnerabilitiesThe ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges. The post Adobe Patches Critical ColdFusion Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
14 JulStop Securing AI in SilosAI application security includes many protections—input validation, output sanitization, infrastructure controls, and more. Too often, they're evaluated independently instead of as parts of a larger system. A holistic approach allows security controls to inform each other, more c…YOUTUBE.COM
14 JulNearly 300 GitHub repos pose as legit software to push malwareA threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to distribute infostealer malware. [...]BLEEPINGCOMPUTER.COM
14 JulMr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland - SWN #598Mr. Data, Joomla Babooa, 1VPNS, RabbitMQ, UEFI, Center 16, Sextortion, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-598YOUTUBE.COM
14 JulWhite House details ‘Gold Eagle’ clearinghouse for AI cyber threatsThe White House said the clearinghouse has already started to receive intelligence on vulnerabilities and prioritize patches. The post White House details ‘Gold Eagle’ clearinghouse for AI cyber threats appeared first on CyberScoop .CYBERSCOOP.COM
🌐 CYBER THREAT LANDSCAPE 4[−]
14 Jul148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS BotnetA campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog. The packages did not go after the developers who might install them. The …THEHACKERNEWS.COM
14 JulM-Red-Team: AsyncAPI Supply Chain Compromise via GitHub ActionsDetect and mitigate malicious @asyncapi npm packages linked to the latest npm supply chain attack.WIZ.IO
14 JulClickFix's Mushrooming Ecosystem Demands New Defense TacticsThe attack vector is available for rent at scale, and evades AV and EDR, leaving YARA analysis as the best detection option.DARKREADING.COM
14 JulLabubaRAT Masquerades as NVIDIA Software to Control Windows HostsCybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. "LabubaRAT creates a reusable foothold for hands-on activity," Blackpoint Cyber resear…THEHACKERNEWS.COM
📡 INFOSEC NEWS 18[−]
14 JulAdversarial TalesA competitive open-weight model, Claude Fable, and Jade PufferF5.COM
14 JulFive Charged in “Russian Coms” Fraud Platform CaseFive UK residents have been charged in relation to supplying Russian Coms fraud devices and appsINFOSECURITY-MAGAZINE.COM
14 JulMicrosoft starts testing cleaner Windows Search without adsMicrosoft is now testing a cleaner and faster version of Windows Search that should prioritize relevant results over ads and promotional content. [...]BLEEPINGCOMPUTER.COM
14 JulMicrosoft Entra ID gets passkeys default authentication starting SeptemberMicrosoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. [...]BLEEPINGCOMPUTER.COM
14 JulNew phishing kits target Microsoft 365 accounts, evade MFATwo new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). [...]BLEEPINGCOMPUTER.COM
14 JulStudy of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking RisksResearchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way these wallets talk to websites and blockchain servers can tie a person's separat…THEHACKERNEWS.COM
14 JulTelegram’s shortlink domain is back online after day-long suspensionTelegram CEO Pavel Durov confirmed an outage in a tweet, saying that shortlinks to the messaging app had "stopped working."TECHCRUNCH.COM
14 JulAuthenticate legitimate AI agent traffic with AWS WAF Bot ControlAs AI agents and automated tools increasingly access web applications, distinguishing legitimate bot traffic from malicious attempts has become a critical security challenge. Traditional approaches such as IP-based filtering and reverse DNS lookups fail in multi-tenant systems (s…AWS.AMAZON.COM
14 JulUS: Pentagon Suspends CMMC Phase II Requirements for Defense ContractorsThe US Department of Defense announced the immediate suspension of the CMMC Phase II requirements until further reviewINFOSECURITY-MAGAZINE.COM
14 JulLastPass, Bitwarden users targeted with fake security alertsLastPass is warning users about an ongoing phishing campaign that is using fake security notices to direct them to fraudulent websites. [...]BLEEPINGCOMPUTER.COM
14 JulFrontier AI: The Genie's Out of the Bottle, But Where's the Rulebook?Cutting-edge artificial intelligence models are deploying with more independence and less human oversight. Several state governments are trying to legislate transparency in their use.DARKREADING.COM
14 JulWindows 11 KB5101650 & KB5099414 cumulative updates releasedMicrosoft has released Windows 11 KB5101650 and KB5099414 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]BLEEPINGCOMPUTER.COM
14 JulManage Vendor Risk in a Few Practical StepsRisk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance.DARKREADING.COM
14 JulResearchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail ReadsAny other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar. Both this and ClaudeBleed need a rogue extension that can already run a script on claude.ai; t…THEHACKERNEWS.COM
14 JulSecurity Hub adds AI workload protection and multicloud support for Microsoft AzureSecurity Hub is our foundation for full-stack enterprise security across clouds. It centralizes your security operations and turns raw signals into prioritized insights, so your team spends its time managing real risk instead of stitching tools together. Today that foundation gro…AWS.AMAZON.COM
14 JulUS unseals indictment against alleged operators of Russian bulletproof hosting serviceThe Russians face multiple charges for allegedly providing cybercriminals with infrastructure and tech support through the St. Petersburg-based business Media Land and a sister company, ML Cloud.THERECORD.MEDIA
14 JulSpanish Police take down €140 million cyber fraud ring, arrest fourThe Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. [...]BLEEPINGCOMPUTER.COM
14 Jul6 GHz Wi-Fi Flaws Could Disrupt Critical SystemsAutomated Frequency Coordination systems by default trust client-side data, which could lead to location spoofing and other attacks that disrupt traffic.DARKREADING.COM