155Articles
9Categories
2026-07-23Date
🚨 CISA KEV 3[−]
23 Jul KEVMicrosoft’s 3-day patching directive comes with added operational riskMicrosoft 365 Director Jeremy Chapman this month took to video to tell Windows admins that the days of delaying security patches are over. Complex enterprise systems and historic incidents involving patch problems have caused many admins to hold fire on immediately applying secur…CSOONLINE.COM
23 Jul KEVCVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the WildOverview On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authentication bypass in the SmartConsole login process…RAPID7.COM
23 Jul KEVU.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploi…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 50[−]
23 JulCheck Point Patches Exploited SmartConsole Flaw Allowing Full Admin AccessCheck Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (CV…THEHACKERNEWS.COM
23 JulCVE-2026-53910 Heap-based Buffer Overflow in GNU diffutilsInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-40691 Packet of death for DNSCrypt over TCPInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-55990 Packet of death for a DNSCrypt misconfigured UnboundInformation published.MSRC.MICROSOFT.COM
23 JulCVE-2026-50045 'max-global-quota' reset by DNSSEC validation restartsInformation published.MSRC.MICROSOFT.COM
23 JulNine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL InstallsRefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives…THEHACKERNEWS.COM
23 Jul KEVNew Check Point Zero-Day Vulnerability Exploited in the WildThe vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
23 Jul KEVCheck Point patches actively exploited SmartConsole authentication bypass flawCheck Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is being actively exploited. Check Point has released security updates to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentica…SECURITYAFFAIRS.COM
23 JulAttackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauth…HELPNETSECURITY.COM
23 JulNew RefluXFS Linux flaw lets attackers gain root privilegesA nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. [...]BLEEPINGCOMPUTER.COM
23 JulLinux XFS has a decade-old race condition allowing full root accessLinux systems using the XFS filesystem suffer from a race condition that could enable an unprivileged local user to gain full root access. The flaw affects systems with Linux kernel 4.11 or later that have enabled the XFS feature reflink, which permits the creation of copies of a…CSOONLINE.COM
23 JulVU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handlingOverview The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA, replay externally issue…KB.CERT.ORG
23 Jul KEVCheck Point hole grants unauthenticated attackers full SmartConsole admin privilegesCheck Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin privileges, is now being exploited in the wild. The vulnerability, CVE-2026-16232 , was given a CVSS score of 9.3. In its se…CSOONLINE.COM
⚠️ VULNERABILITY DISCLOSURE 37[−]
23 Julwp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command executionWe ran the wp2shell WordPress RCE chain end-to-end with Elastic Defend. Detection rule walkthrough, IOCs, and hunt guidance.ELASTIC.CO
23 JulID: Kootenai County notifies residents of data breachNick Hawthorne reports: Kootenai County has begun notifying residents whose personal information may have been compromised in a ransomware attack detected on the county’s computer network in late March. According to a Kootenai County press release, the County discovered the…DATABREACHES.NET
23 JulTN: Data breach delays start of Sumner County school yearCamellia Burris reports: One Middle Tennessee school district is delaying the start of the school year due to a data breach in its computer network. School officials in Sumner County discovered the breach in its computer network earlier this week and subsequently revised the dist…DATABREACHES.NET
23 JulBuilding a defense in depth strategy for sensitive dataIn this Help Net Security video, Venkata Pavan Kumar Gummadi, Professional Software Engineer at Broadridge, explains how to build a defense in depth strategy for protecting sensitive data. He argues that a single control, like encrypting a disk or turning on DLP, leaves gaps that…HELPNETSECURITY.COM
23 JulRed flags ahead.This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave Bittner⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠…THECYBERWIRE.COM
23 JulMulti-patch vulnerability fixes can leave open source exposedVulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two or more commits where the first one leaves the fla…HELPNETSECURITY.COM
23 Jul KEVCheck Point warns of SmartConsole zero-day exploited in attacksIsraeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel. [...]BLEEPINGCOMPUTER.COM
23 JulGitHub revamps bug bounty program with new VIP tier, payout changesGitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will take effect on July 27, 2026. Reports submitted before that date will be honored under the previous bounty …HELPNETSECURITY.COM
23 JulMonths-long breach exposes South Korean diplomats’ personal dataSouth Korea’s Foreign Ministry has disclosed that attackers breached the Korea National Diplomatic Academy’s online education system, compromising personal data belonging to current and former ministry staff and diplomats stationed abroad. The Korea National Diplomati…HELPNETSECURITY.COM
23 JulEnd-to-End Encryption and “Going Dark”New paper: “ Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate “: Abstract : This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call …SCHNEIER.COM
23 JulWhatsApp Web chats exposed by Adobe’s Acrobat extension flawHermeticReader is a now-patched vulnerability in Adobe's popular Acrobat Chrome extension that could have been used to spy on WhatsApp Web users.MALWAREBYTES.COM
23 JulAI Agents Now the Enterprises Fastest Growing Exposed Attack SurfaceSophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threatsINFOSECURITY-MAGAZINE.COM
23 Jul20-year-old web server flaw shipped in modern security cameraA popular Wansview indoor security camera was shipping in 2026 with a web server vulnerable to a flaw first disclosed more than two decades ago. The finding comes from firmware security company Finite State, whose researchers analyzed the Wansview WVC Q5, an inexpensive Wi-Fi cam…CYBERINSIDER.COM
23 JulCobalt adds Autonomous Pentest to scale application security testingCobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization’s application portfolio by delivering actionable penetration testing results in as little as 24 hours. AI-assisted development enables organizat…HELPNETSECURITY.COM
23 JulGoogle Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability HuntingGoogle DeepMind unveiled Gemini 3.5 Flash Cyber, an AI model for vulnerability discovery and patching, available only to governments and trusted partners. Google DeepMind announced Gemini 3.5 Flash Cyber on Tuesday, a security-focused AI model built on top of the existing 3.5 Fla…SECURITYAFFAIRS.COM
23 JulHow attackers hosted a fake Claude download page on the claude.ai domainA threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app and clicking a sponsored…HELPNETSECURITY.COM
23 JulWhat Happened Between OpenAI and Hugging Face?The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry…RAPID7.COM
23 JulIranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical InfrastructurePublication: April 7, 2026 Last Update: July 22, 2026 TLP: Clear From the updated version of the Joint Cybersecurity Advisory: Executive Summary The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational…DATABREACHES.NET
23 JulClaude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac FilesCybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which sh…THEHACKERNEWS.COM
23 JulAI Is Repeating Cloud's MistakesThe rapid adoption of AI shares similarities with the early cloud transition. Organizations moved quickly to adopt new capabilities while still learning how to manage costs, security, and governance. Moving fast without clear oversight can create new risks. However, unlike the ea…YOUTUBE.COM
23 JulIs Patching Dead? Vulnerability Management in the Post-Mythos EraYou cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching Dead? Vulnerability Management in the Post-Mythos Era appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulJoint cyber security advisory on Russian state-sponsored phishing campaign targeting Zimbra webmailThe joint advisory warns that Russia-sponsored threat actors associated with an advanced persistent threat group, known as Laundry Bear, are exploiting a known vulnerability in Zimbra webmail.CYBER.GC.CA
23 Jul KEVEU hits Google with a $1 billion fine.Check Point warns of actively exploited flaw. South Korea discloses a breach affecting diplomats.THECYBERWIRE.COM
23 JulRussia-backed threat actor targets Western organizations in phishing campaignThe threat actor exploited a zero-day flaw in Zimbra to exfiltrate months of emails and other sensitive information.CYBERSECURITYDIVE.COM
23 JulCISA, FBI warn that Iran-linked hackers are expanding target set for water, energyThe agencies said threat groups have disrupted critical infrastructure sites by exploiting vulnerable PLC devices.CYBERSECURITYDIVE.COM
23 JulRussian Hackers Exploit New ‘Zero-Click’ Attack Against Western OrganizationsInternational agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration SuiteINFOSECURITY-MAGAZINE.COM
23 JulRussian hackers exploit Zimbra zero-click flaw for email theftCISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]BLEEPINGCOMPUTER.COM
23 JulUS government says Iran-linked hackers are disrupting American water and energy providersAn updated government advisory warns that Iranian hackers are exploiting systems used by water and energy providers.TECHCRUNCH.COM
23 JulRussian espionage group using novel Zimbra exploit to steal sensitive data from Western countriesLaundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appea…CYBERSCOOP.COM
23 JulmacOS flaw lets malware replace trusted apps without security warningsSecurity researchers Talal Haj Bakry and Tommy Mysk have disclosed a macOS weakness that allows malware already running under a user's account to silently replace the executable of trusted applications downloaded from the web and relaunch them without triggering Gatekeeper warnin…CYBERINSIDER.COM
23 JulBeyond the Vulnerability Apocalypse: Scaling Your Basics and Vulnerability ManagementDeveloped together with Usman Chaudhary @ Google for Public Sector ( his post ) Let’s call it what some in the industry are calling it: the vulnerability apocalypse . For years, finding vulnerabilities was slow, expensive, specialized work. LLMs made it cheap — in its first weeks…MEDIUM.COM
23 Jul4 ways AI-driven defense is rewriting the cybersecurity playbookThe cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive contr…CSOONLINE.COM
23 JulChaos ransomware deploys browser-based msaRAT to evade network detectionCisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire comm…SECURITYAFFAIRS.COM
23 JulDo not pass Go(ogle).Google gets a billion dollar fine from the EU. The White House considers sanctions against Chinese AI developers. The GAO criticizes overlap in cyber reporting regulations. The Feds warn of Iranian agents targeting OT systems. Researchers disclose a high-severity Linux kernel vul…THECYBERWIRE.COM
23 JulFixing Vulns Is Harder Than Finding Them - PSW #936In the news this week: - InfraTrust and knowing what to patch - Adversary in the middle triggered command injection - Exploitarium again - FreeRDP comes with free vulnerabilities - AI breaking out of sandboxes on its own - Wordpress RCE - DMA dangers - Nightmware eclypse is at it…YOUTUBE.COM
23 JulRussian Hackers Exploit Zimbra Zero-Day Against US, Ukraine TargetsA state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.DARKREADING.COM
23 JulThe Hidden Risk of Patch PrioritiesPatch management isn't just about fixing the highest number of vulnerabilities. Upgrade complexity, deployment time, and the actual severity of the vulnerabilities all influence what should be patched first. A massive upgrade may eliminate thousands of CVEs but consume weeks or m…YOUTUBE.COM
📢 SECURITY ADVISORIES 6[−]
23 JulUS Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS DevicesAn updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers. The post US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulANCHOR-CI could fix 20 years of broken government-industry collaborationThe government spent the past two decades learning what private sector partners have always known: cyber resilience requires everyone in the room. ANCHOR-CI is proof that the lessons may finally stick. The post ANCHOR-CI could fix 20 years of broken government-industry collaborat…CYBERSCOOP.COM
23 JulIranian Hackers Target Siemens and Schneider Industrial Systems, CISA WarnsUS government agencies have warned that Iranian cyber actors are targeting US-based Siemens and Schneider industrial equipmentINFOSECURITY-MAGAZINE.COM
23 JulGAO report details scope of cybersecurity regulation overlapA morass of rules is forcing companies to report the same information multiple times — and sometimes, those rules conflict.CYBERSECURITYDIVE.COM
23 JulRubio restricts visas for sextortionists, cyber scammersThe move stems from a Trump executive order as the administration continues to pursue cyber-enabled fraud and other crimes. The post Rubio restricts visas for sextortionists, cyber scammers appeared first on CyberScoop .CYBERSCOOP.COM
🔥 INCIDENT REPORTING 13[−]
23 JulRansomware Attack Puts a Chill On Japanese Frozen-Food ChainA cyberattack on a food and logistics firm disrupts the supply of frozen food to thousands of clients, including major franchises like Kentucky Fried Chicken.DARKREADING.COM
23 JulTwo-Thirds of Ransomware Victims Say AI Boosted Attack EffectivenessA new study of organizations which have fallen victim to ransomware suggests the rise of AI-tools being used by hackers is making life harder for defendersINFOSECURITY-MAGAZINE.COM
23 JulSwiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattackCybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after breaching a data exchange platform shared with one of its suppliers through compromised credentials. Stadler operates 16 production and component pl…HELPNETSECURITY.COM
23 JulNew msaRAT malware uses Chrome, Edge browsers to route C2 trafficThe Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. [...]BLEEPINGCOMPUTER.COM
23 JulPyPI hardens package security with new upload restrictionsThe Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users and reduce …HELPNETSECURITY.COM
23 JulChaos ransomware's msaRAT: Living off the browser to build a covert C2 channelThe Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.TALOSINTELLIGENCE.COM
23 JulUpbound Group Says Data Breach Led to $13 Million in Fraudulent Contract LossesHackers recently obtained non-sensitive customer information and other documents from the company. The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulChaos ransomware msaRAT hides its C2 channel inside a legitimate browser processCisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTo…HELPNETSECURITY.COM
23 JulAttackers Weaponize GitHub Actions Runners to Target cPanel and WHM ServersCybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions…THEHACKERNEWS.COM
23 JulWhen the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)Two disclosures, five days apart, described the same intrusion from opposite ends — one from the victim, one from the party that turned out to be responsible — and together they make one of the more instructive incidents of th…ISC.SANS.EDU
23 JulMajor Australian energy supplier confirms customer data compromisedOrigin Energy said it was working to figure out how many Australians were affected by a recent data breach.THERECORD.MEDIA
23 JulChaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and EdgeThe Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. …THEHACKERNEWS.COM
23 JulAustralian energy provider Origin says data breach exposes client dataOrigin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 16[−]
23 JulISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
23 JulThe AI code vulnerabilities that grow with your appTheori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten from an aging PHP codebase. The …HELPNETSECURITY.COM
23 JulShadow AI is becoming enterprise security’s biggest blind spotArtificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft communications, analyze spreadsheets, write code, build automations, and create AI-powered workflows across nearly ev…HELPNETSECURITY.COM
23 JulProduct Showcase: AppViewX Agent Identity SecurityAI is multiplying enterprise identities as quantum computing reshapes the cryptographic trust that secures them, and enterprises need to solve both together. Traditional identity security was built for people with predictable, auditable access, not autonomous, short-lived agents …HELPNETSECURITY.COM
23 JulAxonius expands Asset Cloud with Cyber Assets and Exposures enhancementsAxonius has announced new capabilities across the Axonius Asset Cloud to better address asset intelligence and exposure management use cases. The enhancements make it easier than ever to address CMDB visibility gaps and respond to vulnerabilities, while extending asset intelligen…HELPNETSECURITY.COM
23 JulAssaf Keren Appointed New CISO of MetaHe replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulNew Dolphin X infostealer uses AI to identify high-value victimsA newly identified Windows malware called Dolphin X combines information-stealing capabilities with remote access features while targeting credentials from more than 300 applications. The malware also includes an AI-powered profiler that automatically ranks infected users, helpin…CYBERINSIDER.COM
23 JulNuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI ModelsSentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulClick. Click. Fake it until they make it… insideTL;DR The Problem In this online world it’s been easier than ever to order what you need, when you need and to the exact specifications you want… mostly.   The clothing world, alongside many other sectors, is plagued by fakes to t…PENTESTPARTNERS.COM
23 JulMozilla releases Thunderbird 153 with native Microsoft Exchange supportThunderbird 153 “Meadow” has been released, introducing native Microsoft Exchange support alongside a redesigned account setup experience, user interface improvements, and security fixes. The update marks the first time Exchange accounts can be configured directly in …CYBERINSIDER.COM
23 JulAbstract Raises $25 Million to Expand Composable Security Operations PlatformThe latest investment round brings the total raised by Abstract to nearly $50 million. The post Abstract Raises $25 Million to Expand Composable Security Operations Platform appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulRussian Global Webmail EspionageUnit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
23 JulChick-fil-A Accounts Get Fried in Credential Stuffing AttackThreat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts. The post Chick-fil-A Accounts Get Fried in Credential Stuffing Attack appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulThe case for a cooldown: Why Dependabot now waits before issuing version updatesA new default three-day cooldown delays version update pull requests so maintainers and security researchers can address findings in a release before it gets into your code. The post The case for a cooldown: Why Dependabot now waits before issuing version updates appeared first o…GITHUB.BLOG
23 JulOpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI InsiderAgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider appeared first on SecurityWeek .SECURITYWEEK.COM
23 JulEmail threat landscape: Q2 2026 trends and insightsIn the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly au…MICROSOFT.COM
🌐 CYBER THREAT LANDSCAPE 6[−]
23 JulBrazilian Banking Trojan Actively Spreading in PortugalPortuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets.DARKREADING.COM
23 JulNew Dolphin X Stealer Employs AI Profiling to Prioritize TargetsDolphin X is a new infostealer that uses AI to sort and rank victims, giving cybercriminals a faster way to identify lucrative targetsINFOSECURITY-MAGAZINE.COM
23 JulThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More StoriesMost of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threat…THEHACKERNEWS.COM
23 JulHackers abuse Notepad++ plugins to stealthily install malwareUkraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. [...]BLEEPINGCOMPUTER.COM
23 JulFake Claude app promoted by Bing ads pushes SectopRAT malwareA malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. [...]BLEEPINGCOMPUTER.COM
23 JulNew Dolphin X malware uses AI to rank high-value targetsA new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. [...]BLEEPINGCOMPUTER.COM
🎙️ PODCASTS 1[−]
23 JulSrsly Risky Biz: Knives are out for open-weight AI modelsTom Uren and James Wilson talk about the future of open-weight models. For different reasons, both the Chinese and American governments have reasons to crack down on them. They also talk about arrests of several members of the Scattered Spider juvenile cybercrime collective. This…RISKY.BIZ
📡 INFOSEC NEWS 23[−]
23 JulGitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP TierBeginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before that date, in…THEHACKERNEWS.COM
23 JulAI’s political and copyright reckoning.This week, Dave and Ben look at two stories centered around AI. The first involves how politicians are trying to combat how AI chatbots spread inaccurate or incomplete information on their campaigns to voters. The second story looks at how existing copyright laws are not robust e…THECYBERWIRE.COM
23 JulMicrosoft working to fix Exchange Online mailbox quarantine issueMicrosoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers' mailboxes since Sunday. [...]BLEEPINGCOMPUTER.COM
23 JulPreview: Cisco Talos at Black Hat USA 2026Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk.TALOSINTELLIGENCE.COM
23 JulHow Synthetic Identity Fraud is Coming for Machine IdentitiesMost people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several…THEHACKERNEWS.COM
23 JulGoogle Adds Selfie Video Recovery for Users Locked Out of Their AccountsGoogle on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone numb…THEHACKERNEWS.COM
23 JulMillions of cars could be tracked and unlocked by a hidden security flawA hidden flaw in a dealer-installed car alarm could let attackers unlock vehicles and track their locations. Many owners don't know they have one.MALWAREBYTES.COM
23 JulAgentic AI Challenges Progress in Confidential ComputingCore issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Experts have some answers.DARKREADING.COM
23 JulEU fines Google $1 billion for search, app store antitrust violationsThe European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union's Digital Markets Act (DMA), which ensures fair online competition. [...]BLEEPINGCOMPUTER.COM
23 JulMicrosoft Copilot Deployments Delayed Over Security ConcernsCoreView research finds that security leadership is concerned about AI Assistant exposing confidential dataINFOSECURITY-MAGAZINE.COM
23 JulFedRAMP Rev5 Is Ending: What the 20x Transition Really RequiresFedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assura…BLEEPINGCOMPUTER.COM
23 JulChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare AttacksAn exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. G…THEHACKERNEWS.COM
23 JulOpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to knowYou can't have failed to hear the news headlines about "rogue" OpenAI models hacking into another AI organisation, Hugging Face. But what has actually happened, who is to blame, and is it as serious as some of the reports suggest? Find out in my article on the Hot for Security bl…BITDEFENDER.COM
23 JulMicrosoft 365 outage affects Teams, SharePoint and other servicesMicrosoft Teams and several Microsoft 365 services are experiencing an ongoing outage, with users reporting problems accessing Teams, SharePoint, Excel and the Microsoft 365 Admin Center. [...]BLEEPINGCOMPUTER.COM
23 JulEnterprise security at machine speed: AWS Black Hat 2026 previewBlack Hat 2026 (Aug 1-6, 2026) brings together over 22,000 security practitioners, researchers, and CISOs who build, break, and defend enterprise infrastructure. They’re security professionals who push the limits of offensive and defensive security and demand proof over promises.…AWS.AMAZON.COM
23 JulState Department imposes visa restrictions on foreign cyber scammersIndividuals connected to transnational cyber-scam operations face U.S. visa restrictions under a new policy announced by Secretary of State Marco Rubio.THERECORD.MEDIA
23 JulInternational alert spotlights Russia-linked attacks on Zimbra webmailA Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.THERECORD.MEDIA
23 JulIntelligence Insights: July 2026ClearFake claims the crown again and CastleLoader debuts in this month’s edition of Intelligence Insights.REDCANARY.COM
23 JulAegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishingThe Series A was led by Battery Ventures, bringing AegisAI total funding to $49 million.TECHCRUNCH.COM
23 JulFor Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went DarkMSG’s sprawling surveillance system can monitor guests down to the second. Its owners made an exception for the pop star’s rehearsal dinner.WIRED.COM
23 JulForgot your Google password? Now you can log in with a selfie.Google's selfie videos can be used for account access, AI Avatars, and age verification.ARSTECHNICA.COM
23 JulDon’t swing at everythingThorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.TALOSINTELLIGENCE.COM
23 JulEU issues largest DSA fine against AliExpress.OpenAI backs Massachusetts AI safety efforts.THECYBERWIRE.COM