🚨 CISA KEV 2[−]
16 Jul KEVCISA urges immediate SharePoint hardening as exploits mountThe US Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to immediately secure Microsoft SharePoint deployments after warning that three vulnerabilities affecting the on-premises collaboration platform are being actively exploited. A recent advisory …CSOONLINE.COM
16 Jul KEVCVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server VulnerabilitiesFour Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments. Key Takeaways CISA confirmed active exploi…TENABLE.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 4[−]
16 JulZoom Patches Critical Windows Flaw That Could Enable Account TakeoverZoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Z…THEHACKERNEWS.COM
16 JulZoom Fixes CVE-2026-53412, a Critical Account Takeover BugZoom warns of a critical Windows flaw, tracked as CVE-2026-53412, that could let attackers take over accounts without authentication. Zoom has fixed a critical Windows vulnerability, tracked as CVE-2026-53412 (CVSS score of 9.8) that could allow unauthenticated attackers to hijac…SECURITYAFFAIRS.COM
16 JulAge of Empires II patch fixes RCE bug exploitable through multiplayer lobbiesA recent update for Age of Empires II: Definitive Edition fixed a remote code execution (RCE) vulnerability that could have allowed attackers to compromise other players' systems through multiplayer. The flaw, tracked as CVE-2026-50663, stemmed from a relative path traversal bug …CYBERINSIDER.COM
16 JulVU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystemOverview A Pickle deserialization vulnerability has been discovered within the SGLang project , enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsyste…KB.CERT.ORG
⚠️ VULNERABILITY DISCLOSURE 43[−]
16 JulTuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet DevelopmentCybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. "While th…THEHACKERNEWS.COM
16 JulGPT-Red beat human red teamers on a prompt injection testGPT-Red is an automated red-teaming model that OpenAI trains to find prompt injection weaknesses. It works the way a human red-teamer does. It sends a prompt, watches how a GPT model responds, and iterates toward a goal such as a successful data exfiltration. Training runs on sel…HELPNETSECURITY.COM
16 JulFinance phishing works because it sounds boringly normalFinance departments process a constant stream of invoices, contracts, payment notices, and procurement emails, making email one of the most common initial access vectors for threat actors. According to Cofense, attackers exploit those workflows with phishing emails that resemble …HELPNETSECURITY.COM
16 JulCaught on ScamTokThis week, while Maria is out hosts Dave Bittner and Joe Carrigan are discussing the latest in social engineering…THECYBERWIRE.COM
16 JulCompanies keep getting breached by vulnerabilities they already knew aboutScanning tools have gotten good at their work. Organizations now find more weaknesses across more of their systems than at any earlier point in the industry’s history. A survey from the security firm Vicarius points to a gap that opens after that discovery, in the work of a…HELPNETSECURITY.COM
16 JulReading between the lines of a cyber insurance policyEnterprises in regulated industries often carry cyber insurance policies because contracts require it or boards ask for documented risk transfer. The global market for these policies reached about $16 billion in premiums in 2024. Coverage has become widespread. Payouts have grown…HELPNETSECURITY.COM
16 JulWhat public money does to open-source projectsMost of the software running inside a typical company was written by volunteers the company never paid. Open-source code sits under web apps, build pipelines, and the machine learning stacks getting so much attention right now. Roughly 96 percent of codebases carry some of it. Th…HELPNETSECURITY.COM
16 Jul KEVFlaw surge fuels need for CISOs to rethink vulnerability managementSecurity experts are calling on enterprises to revise their vulnerability management strategies and move towards “just in time” patching in response the increased pace of vulnerability exploitation. Attackers are turning to AI to increase the rate of vulnerability exploitation an…CSOONLINE.COM
16 JulNightmare Eclipse Drops ‘LegacyHive’ Windows Zero-DayThe researcher stripped the proof-of-concept (PoC) exploit to prevent immediate exploitation of the vulnerability. The post Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulSrsly Risky Biz: Ransomware uses AI to amp up negotiationsTom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI. The relatively new FulcrumSec group uses simple techniques to breach companies and then uses AI to get more leverage over victims in its extortion negotiations. They also discuss the…RISKY.BIZ
16 JulThe executive profile your security team isn’t defendingA few years ago, I was retained to conduct a digital risk review for the chief executive of a mid-sized financial services firm. The brief was standard. Assess what was publicly available about the executive, identify exposure and advise on remediation. The AI tools I used comple…CSOONLINE.COM
16 JulUS Launches Gold Eagle to Coordinate AI-Driven Vulnerability ManagementThe White House announced Gold Eagle to help accelerate the discovery, prioritization and patching of flaws found by AIINFOSECURITY-MAGAZINE.COM
16 JulMicrosoft makes Windows SSO prompts easier to manageMicrosoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed en…HELPNETSECURITY.COM
16 JulOpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 SolOpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely. "GPT‑Red is a strong red-teamer, and our previous models are highly vulnerable to …THEHACKERNEWS.COM
16 JulWhen AI gets a body, it inherits an attack surfaceMost security leaders I know working on AI robotics are being shown the same kind of video. A humanoid folds a shirt, sorts a bin, walks a warehouse aisle and a vendor uses the clip to move an embodied AI system from pitch to purchase order. Someone then has to sign off. Robot de…CSOONLINE.COM
16 JulF5 Patches Multiple NGINX, BIG-IP VulnerabilitiesAttackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code. The post F5 Patches Multiple NGINX, BIG-IP Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulTenable One unifies code risks with enterprise exposure dataTenable has announced the expansion of the Tenable One Exposure Management Platform, unifying application security risks with all other exposure data. By integrating static code vulnerability data, Tenable One delivers complete, code-to-runtime visibility across the entire attack…HELPNETSECURITY.COM
16 JulUnpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-WidePull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people's Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext. A researcher pu…THEHACKERNEWS.COM
16 JulCISA urges software vendors to formalize vulnerability disclosure programsThe Cybersecurity and Infrastructure Security Agency (CISA) and four international cybersecurity agencies have published guidance urging software manufacturers and online service providers to establish coordinated vulnerability disclosure (CVD) programs, saying structured engagem…CSOONLINE.COM
16 Jul KEVCISA orders feds to patch actively exploited Oracle flaw by SaturdayCISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application. [...]BLEEPINGCOMPUTER.COM
16 JulSpaceXAI admits Grok retained developer data in open-source announcementSpaceXAI has acknowledged that Grok Build retained coding data for some users during its early beta, days after security researchers disclosed that the AI coding tool was uploading entire developer repositories. Alongside the admission, the company announced it is open-sourcing t…CYBERINSIDER.COM
16 JulValorC3 extends SaaS protection with immutable cloud backupsValorC3 Data Centers today announced the general availability of Backup as a Service, a fully managed offering that protects the SaaS data businesses rely on most, including Microsoft 365, Entra ID and Salesforce. Every backup is immutable, so data stays recoverable after deletio…HELPNETSECURITY.COM
16 JulThe best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26Agentic AI use is exploding, yet most security teams are building agents in isolation. Tenable is hosting Swarm, a build event at Black Hat 2026, for security practitioners to create and collaborate on agentic, open-source tooling to drive collective defense and stop adversaries …TENABLE.COM
16 JulRussian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutesA Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI) In more …HELPNETSECURITY.COM
16 JulAU: Regulator’s preliminary findings did not indicate Qantas breached privacy obligationsVlad Constantinescu reports that the Office of the Australian Information Commissioner has determined that although the Qantas data breach of 2025 resulted in 5.67 million customer records being compromised and leaked, the regulator’s preliminary inquiry did not indicate th…DATABREACHES.NET
16 JulThalha Jubair and Owen Flowers sentenced to prisonStanley Murphy-Johns, Rosie Shead, and Alex Levy report that Thalha Jubair, 20, and Owen Flowers, 18, were both sentenced at Woolwich Crown Court to 5 years and six months in prison for hacking Transport for London. In a televised sentencing, Mr Justice Turner addressed the defen…DATABREACHES.NET
16 JulModular macOS Stealer Uses Kill Loops to Force Password EntryNew ClickLock macOS stealer locked victims out of their own system until they surrendered a passwordINFOSECURITY-MAGAZINE.COM
16 JulCISA folds its own hard-won lessons into coordinated vulnerability disclosure guidanceOn Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a coordinated vulnerability disclosure (CVD) program. Six days earlier, CISA published a blog post explaining h…HELPNETSECURITY.COM
16 JulSunsetting the Public AttackerKB PlatformWhat’s changing, where AttackerKB-style analysis will live, and how users can continue finding Rapid7 vulnerability intelligence. On August 18, Rapid7 will sunset the standalone public AttackerKB website as part of a broader effort to unify our vulnerability intelligence, exploit…RAPID7.COM
16 Jul KEVCISA warns of actively exploited SharePoint flaws.A new stealthy ransomware family emerges. Law enforcement operation disrupts international fraud scheme.THECYBERWIRE.COM
16 JulLegacy Systems, Real-World Impacts: The Reality of OT SecurityLegacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. The post Legacy Systems, Real-World Impacts: The Reality of OT Security appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulZoom patches account takeover holeZoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.” The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, inc…CSOONLINE.COM
16 JulTwo Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL HackOwen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority's employ…THEHACKERNEWS.COM
16 JulVU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditionsOverview A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion an…KB.CERT.ORG
16 JulBTS #78 - Patching: The Race Against TimeIn this episode of Below the Surface, host Paul Asadoorian is joined by Vlad Babkin and Chase Snyder for a wide-ranging discussion on modern vulnerability management, network appliance visibility, AI-assisted exploitation, Linux kernel bugs, cold boot attacks, and software supply…ECLYPSIUM.COM
16 JulItaly fines WINDTRE €1.7 million over data breachesGianluca Semeraro reports: Italy’s data protection authority has fined telecoms operator WINDTRE €1.7 million ($1.94 million) for “serious shortcomings” in its data security systems, leading to two unauthorised breaches and the exposure of personal information belonging to more…DATABREACHES.NET
16 JulProgram to rotate cyber personnel through federal agencies saw little useThe number of people who got approval to be in the Federal Rotational Cyber Workforce program was in the single digits, GAO found. The post Program to rotate cyber personnel through federal agencies saw little use appeared first on CyberScoop .CYBERSCOOP.COM
16 JulClaude Chrome extension flaw lets malicious extensions trigger AI actionsA flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected services such as Gmail, Google Docs, Google Calendar, and Salesfor…BLEEPINGCOMPUTER.COM
16 JulFor hackers, sharing is caring.CISA warns of active SharePoint attacks. The NSA pushes coordinated vulnerability disclosure. ClickLock Stealer targets macOS. Splunk and Zoom patch critical flaws. Spirals ransomware strikes in under 24 hours. New Windows evasion techniques emerge. LabubaRAT poses as NVIDIA soft…THECYBERWIRE.COM
16 Jul1999 Called and It Wants It's Exploits Back - PSW #935This week, our technical segment covers a new open-source tool written by Paul (and Claude) that helps you keep your Linux systems up to date and assess supply chain risks. It's called "fettle" and is a pure Python implementation that gives you even more features than previously …YOUTUBE.COM
16 JulNew ClickLock macOS malware traps users into revealing login passwordA new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. [...]BLEEPINGCOMPUTER.COM
16 JulCoca-Cola says Fairlife ransomware attack halts US dairy productionThe Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. [...]BLEEPINGCOMPUTER.COM
16 JulThe Breach That Won’t End: An Update on Canvas, and how they created an EdTech’s Vendor Trust ProblemJeff Piontek comments on the Instructure breach: The forensic review has taken far longer than anyone expected. Through June, Instructure was still finalizing customer-specific findings and asking institutions to designate a security contact to receive them. In early July, the co…DATABREACHES.NET
📋 SECURITY BULLETINS 1[−]
16 JulSecurity updates available for Adobe, Chrome, Firefox, VMWare, and ZoomSeveral updates have been made available including those for Adobe, Chrome, Firefox, VMWare, and Zoom.MALWAREBYTES.COM
📢 SECURITY ADVISORIES 8[−]
16 JulWho governs your AI agents?Your team spent a decade maturing privileged access management. Then AI agents arrived and they don’t log in like humans. Now your biggest insider threat is an AI agent that lacks the access it needs, and then it goes to get it. In this episode Sundari Parekh, VP of AI Security a…THECYBERWIRE.COM
16 JulRomania’s land registry hit by cyber attack, data allegedly for saleRomania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical incident” has now …HELPNETSECURITY.COM
16 JulUkrainians rally against dismissal of tech-minded defense minister FedorovUkraine President Volodymyr Zelensky dismissed Defense Minister Mykhailo Fedorov, who championed the push to integrate drone technology and digital innovation into the military.THERECORD.MEDIA
16 JulSenator calls on Rubio, Blanche to push back against Canadian surveillance legislationDemocratic Sen. Ron Wyden says the Trump administration should pressure Canada not to enact a proposal that would "weaponize American technology infrastructure" for surveillance purposes.THERECORD.MEDIA
🔥 INCIDENT REPORTING 17[−]
16 JulUnpacking the AsyncAPI npm supply chain compromise and import-time payload deliveryThreat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses. The post Unpacking the AsyncAPI npm supply chain compromise and import-tim…MICROSOFT.COM
16 JulRansom demands are down, email is the top way attackers get inAn employee opens an email that looks like any other, clicks a link, and gives up a password without noticing. A stolen login opens a door deeper in the network. Files stop opening a few days later. That chain now sits at the front of most ransomware cases. Malicious email and ph…HELPNETSECURITY.COM
16 JulPolice Disrupt a €140M Cyber Fraud Ring in SpainIberian hackers carried out a variety of cyberattacks and laundered the winnings through complex financial networks.DARKREADING.COM
16 JulClaude Code and DeepSeek Powered Chinese Cyber Espionage CampaignChinese actors used Claude Code and DeepSeek to automate attacks that breached government systems and targeted financial firms. Hunt.io researchers stumbled onto an active intrusion campaign in June 2026 while pivoting on known TencShell command-and-control infrastructure. A sing…SECURITYAFFAIRS.COM
16 JulNew Spirals ransomware encrypts victim network in under 24 hoursA new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours. [...]BLEEPINGCOMPUTER.COM
16 JulGoSerpent: a persistent threat evolves with sophisticated data collection and exfiltrationTwo-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.SECURELIST.COM
16 JulScattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hackTwo leading members of the Scattered Spider cybercrime collective have been sentenced to more than five years in prison for carrying out the 2024 cyberattack against Transport for London (TfL).THERECORD.MEDIA
16 Jul23andMe to pay $18 million in new genetics data breach settlementGenetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers' genetic data. [...]BLEEPINGCOMPUTER.COM
16 JulTwo Scattered Spider Hackers Sentenced to Jail in UKThalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL). The post Two Scattered Spider Hackers Sentenced to Jail in UK appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulScattered Spider members jailed over Transport for London hack that cost £29 millionTwo members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters and cost the transport authority an es…HELPNETSECURITY.COM
16 JulThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More StoriesA lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation. Old bugs are back, weak d…THEHACKERNEWS.COM
16 Jul23andMe agrees to a $18 million settlement over 2023 data breachA bipartisan coalition of 43 attorneys general has secured an $18 million settlement with genetic testing company 23andMe over its failure to adequately protect customer data before the company's 2023 breach. The agreement also requires new cybersecurity and governance measures f…CYBERINSIDER.COM
16 JulRussian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrimeOfficials accused three Russian nationals, Media Land and ML.Cloud of supporting cyberattacks spanning 21 U.S. states and other countries, resulting in losses surpassing $62 million. The post Russian trio indicted for allegedly running bulletproof hosting providers that spurred c…CYBERSCOOP.COM
16 JulTwo Scattered Spider Members Sentenced to Prison Over £29 Million TfL CyberattackTwo members of the Scattered Spider cybercrime group received jail sentences in the UK for the 2024 cyberattack on Transport for London. A UK court sentenced two Scattered Spider members, Thalha Jubair (20) and Owen Flowers (18), for their role in the 2024 cyberattack on Transpor…SECURITYAFFAIRS.COM
16 JulCoca-Cola suspended production at its Fairlife dairy after a ransomware attackCoca Cola said dairy production at its Fairlife unit will "remain suspended" in the United States following a hack.TECHCRUNCH.COM
16 JulAnubis ransomware: what you need to knowThe Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.FORTRA.COM
16 JulAI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response ReportExplore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
🕵️ THREAT INTELLIGENCE 25[−]
16 JulISC Stormcast For Thursday, July 16th, 2026 https://isc.sans.edu/podcastdetail/10010, (Thu, Jul 16th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
16 JulTrend Micro, Tanium, ESET and Tenable Patch Severe Product VulnerabilitiesThe cybersecurity companies patched critical and high-severity vulnerabilities in some of their products. The post Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulOld UEFI Shims Expose Systems to Secure Boot BypassSigned by Microsoft, the vulnerable UEFI shim bootloaders could be abused on any system, regardless of the OS. The post Old UEFI Shims Expose Systems to Secure Boot Bypass appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulVS Code agent host runs Copilot, Claude, and Codex in a dedicated processDevelopers who lean on AI coding agents often keep several editor windows open at once, each tied to its own session. The 1.129 release of Visual Studio Code reworks that setup with a dedicated agent host. A dedicated process for agent sessions The agent host is a separate proces…HELPNETSECURITY.COM
16 JulChina’s Top Cybersecurity Firms Hit by Mounting Military Procurement BansChinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures. The post China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulPolice take down investment fraud network that stole €100 million a monthDutch police, working alongside Belgian authorities and Europol, have dismantled a major criminal network accused of operating a global investment fraud scheme through dozens of fraudulent call centers. Investigators estimate the organization generated more than €100 million a mo…HELPNETSECURITY.COM
16 JulLineation.ai focuses on runtime security for autonomous AI agentsLineation.ai has announced the public launch of its comprehensive agentic security platform. Delivering a solution at the intersection of genAI application security and runtime defense, lineation introduces a zero trust unified control plane and a lightweight endpoint daemon that…HELPNETSECURITY.COM
16 JulEFF: Apple the only major wearable vendor offering E2EE for health dataThe Electronic Frontier Foundation (EFF) says Apple is the only major wearable manufacturer among ten leading brands it examined that offers end-to-end encryption for users' cloud-synchronized health data. The privacy group's review also found that transparency around government …CYBERINSIDER.COM
16 JulRussian hackers trojanize WebEx, Zoom apps to push Starland malwareA financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT. [...]BLEEPINGCOMPUTER.COM
16 JulSplunk, Zoom Patch Critical VulnerabilitiesThe flaws could allow attackers to access credentials and data, take over accounts, and escalate their privileges. The post Splunk, Zoom Patch Critical Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulOak Emerges From Stealth Mode With $60 Million in FundingThe startup has built an AI-powered Identity Operating System that governs all identities across an organization’s environment. The post Oak Emerges From Stealth Mode With $60 Million in Funding appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulIntruder brings AI-powered, on-demand penetration testing to web applicationsIntruder has announced the launch of AI Pentesting for web applications, providing on-demand penetration testing. Following its initial release of issue-level investigations last quarter, the platform now allows organizations to securely connect their codebases via GitHub or GitL…HELPNETSECURITY.COM
16 Jul20+ Hijacked Government Websites Became
an Attack ChannelMore than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation revealed previously…THEHACKERNEWS.COM
16 JulDaxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM BackdoorAn advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin ("srt64.sys"), as the kernel-mode rootkit is referred to, was fi…THEHACKERNEWS.COM
16 JulAI Data Centers Are Being Built Faster Than They Can Be SecuredAI infrastructure introduces new security risks that traditional data center designs were never built to handle. The post AI Data Centers Are Being Built Faster Than They Can Be Secured appeared first on SecurityWeek .SECURITYWEEK.COM
16 Jul‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process KillingThe new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency. The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek .SECURITYWEEK.COM
16 JulAI Governance Is Everyone's ProblemAI adoption impacts nearly every part of an organization. Security teams must evaluate risks around data, access, and technology, but they cannot manage AI governance alone. A successful AI governance program requires shared ownership across security, IT, legal, privacy, finance,…YOUTUBE.COM
16 JulSandworm hackers have a CAPTCHA trick for UkrainiansRather than verifying they are human, the CAPTCHA users are instructed to copy and paste a PowerShell command into their Windows computers.THERECORD.MEDIA
16 JulAdaptiva simplifies secure patch management for air-gapped networksAdaptiva has announced AirGap for OneSite Patch, a new capability that extends autonomous patch management to air-gapped environments. Developed in response to growing demand from government agencies, critical infrastructure operators, and large enterprises managing highly secure…HELPNETSECURITY.COM
16 JulProtecting Privacy in an AI EraDaniel Solove argues in the Wall Street Journal (alternate link ) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug …SCHNEIER.COM
16 JulIran-nexus actors using AI to enhance cyber playbookA report shows state-linked and hacktivist groups have used ChatGPT and other tools for malware development, phishing and mapping out industrial sites.CYBERSECURITYDIVE.COM
16 JulGaps in network security, oversight strategy hamper US’s aviation cybersecurity regulatorsA new government audit identified several weaknesses at the two agencies that protect air travel from hackers.CYBERSECURITYDIVE.COM
16 JulLeast privilege for AI agents: Identity, access, and tool bindingAs AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure. The post Least privilege for AI agents: Identity, access, and tool binding appeared first on Microsoft Security Blog .MICROSOFT.COM
16 JulThe BIOS Password MistakeNot every "BIOS password" is actually the same thing. In this conversation, the distinction is made between a BIOS setup password, a boot password, a hard drive password, and a BitLocker recovery key. Each protects a different layer of the system. Confusing these terms can lead t…YOUTUBE.COM
16 JulACR Stealer: Two observed intrusion chains amid increased threat activityFrom late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterpri…MICROSOFT.COM
🌐 CYBER THREAT LANDSCAPE 6[−]
16 JulTELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chainsTELEPUZ is a modular malware that emerged through CLICKFIX-VIDAR attacks in April. We reverse-engineered it to show you the infrastructure and evasion techniques that matter.ELASTIC.CO
16 JulTuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and AllTuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes with an u…SECURITYAFFAIRS.COM
16 JulNew TELEPUZ Malware Spreads via ClickFix to Steal Data and Run CommandsCybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026. "The malware is full-featured, lightweight, and modular," Elastic Security Labs researcher Cyril François…THEHACKERNEWS.COM
16 JulNew ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their PasswordClickLock Stealer, a new macOS infostealer, answers a victim's refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim cancels, installs t…THEHACKERNEWS.COM
16 JulPhishing Campaign Hides Lua Loader as TrueType Font FileGlobal phishing campaign disguised a Lua loader as a font file to deploy RATs and infostealersINFOSECURITY-MAGAZINE.COM
16 JulPeriod tracker Stardust shares users’ health data with analytics firm, says Mozilla researchOne period tracker app tested by Mozilla was 'squeaky clean,' while another app was seen sharing users' health data with an analytics company, underscoring vast differences in user privacy among these apps.TECHCRUNCH.COM
🎙️ PODCASTS 1[−]
16 JulSmashing Security podcast #476: Remote-control rickshaws and rogue book marketersAn app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a s…GRAHAMCLULEY.COM
📡 INFOSEC NEWS 23[−]
16 JulThe future of transatlantic data sharing.This week, Dave and Ben look at how the Supreme Court's recent decision could impact data-sharing efforts with the European Union (EU). Additionally, they discuss how the LA Police Department has let its contract with Flock expire after reports emerged that the company was found …THECYBERWIRE.COM
16 JulSamsung backs down on threat to delete health dataSamsung threatened to delete users' health data if they refused AI training. After a backlash, it quickly backed down.MALWAREBYTES.COM
16 JulSANS Warns of AI Governance Gap as Use by Security Teams SurgesSANS Institute says governance programs are still nascent even as AI failures and threats growINFOSECURITY-MAGAZINE.COM
16 JulAI Can Find Bugs, But Human Knowledge Still Proves ThemArtificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs,…THEHACKERNEWS.COM
16 JulThe Hunter's Paradox: Is it time to embrace automated threat hunting?Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like.TALOSINTELLIGENCE.COM
16 JulUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaignCisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.TALOSINTELLIGENCE.COM
16 Jul‘Selfish Bravado’ Behind TfL Cyber-Attack, Judge Says as Pair JailedThe perpetrators of the 2024 TfL cyber-attack have been jailed for five and a half years each after pleading guilty to Computer Misuse Act offencesINFOSECURITY-MAGAZINE.COM
16 JulWindows 11 24H2 Home and Pro reach end of support in 90 daysMicrosoft announced on Wednesday that systems running Windows 10 Enterprise LTSB 2016 and Home and Pro editions of Windows 11 24H2 will stop receiving updates in three months. [...]BLEEPINGCOMPUTER.COM
16 JulNew Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker CommandsAsk an AI agent to summarize the reviews on a product page, and a single planted review can make it click "Buy Now" instead. Ask a coding assistant to apply a maintainer's fix from a GitHub thread, and a fake comment can make it run a stranger's command on your computer. Neither …THEHACKERNEWS.COM
16 JulScattered Spider members behind TfL hack get five years in prisonTwo leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024. [...]BLEEPINGCOMPUTER.COM
16 JulSingle Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers ClaimCybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackersINFOSECURITY-MAGAZINE.COM
16 Juln8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuern8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss. A valid token from iss…THEHACKERNEWS.COM
16 JulHow a former DeepMind researcher raised at a $300M pre-seed valuation before launching a productDrawing on more than a decade spent helping build some of the world's most influential AI systems, including research that later informed the development of ChatGPT, Andrew Dai explains why he believes visual AI is one of the next major frontiers in artificial intelligence.TECHCRUNCH.COM
16 JulThe backlash against Flock cameras is spreadingPrivacy concerns have dogged Flock's automated license plate recognition system for years. Now accuracy and reliability are coming under scrutiny too.MALWAREBYTES.COM
16 JulHelloNet campaign — new malicious modules launched through the ViPNet update systemWe identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).SECURELIST.COM
16 JulAI Agents Broke the Security Playbook. Here's What Replaces It.Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own envir…BLEEPINGCOMPUTER.COM
16 JulUK cops say arrest of two young hackers disrupted the operations of an infamous hacking groupOwen Flowers and Thalha Jubair, two members of the prolific Scattered Spider hacking group, pleaded guilty and were sentenced to five years and six months in jail for hacking London’s metropolitan transit system.TECHCRUNCH.COM
16 JulUK investigates TikTok for alleged age-verification lapses, exposing kids to online harms“Age checks are a cornerstone of the UK’s online safety laws,” said Ofcom’s Chief Executive, Melanie Dawes. “Too many services have no or inadequate age checks in place, which is not good enough.”THERECORD.MEDIA
16 JulBegun, the Patch Wars haveLong foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.TALOSINTELLIGENCE.COM
16 JulEU tells Meta to make major changes to its social media platforms.Pentagon suspends CMMC program.THECYBERWIRE.COM
16 JulNew OkoBot framework deploys 20 payloads to steal data, cryptoA new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data. [...]BLEEPINGCOMPUTER.COM
16 Jul1M+ Emails Use Hidden Text to Dupe AI Security FiltersArtificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.DARKREADING.COM
16 JulAgentic AI Is Untamable: Ask the Right Security QuestionsForget about attackers. Agentic artificial intelligence is creating enough risks for organizations and demands a security reframe.DARKREADING.COM