🐛 COMMON VULNERABILITIES AND EXPOSURES 7[−]
24 Jul KEVRansomware groups are hammering your vulnerable VPNsCybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin ransomware strain. A critical authentication bypass flaw ( CVE-2026-0257 ) in Palo Alto GlobalProtect portal and gateway was the common…CSOONLINE.COM
24 JulCVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshareInformation published.MSRC.MICROSOFT.COM
24 JulCVE-2026-59677 Process Kill Attack Vector in killall() in seunshareInformation published.MSRC.MICROSOFT.COM
24 JulCVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCKInformation published.MSRC.MICROSOFT.COM
24 JulBing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's ServersA crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so …THEHACKERNEWS.COM
24 JulRussian hackers exploit unpatched Zimbra servers to steal emailsRussian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform. Laundry Bear (also known as Void Blizzard, CL-STA-1114, and TA488) …HELPNETSECURITY.COM
24 JulClop gang targets Windchill, FlexPLM in data theft attacksSergiu Gatlan reports: The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2…DATABREACHES.NET
⚠️ VULNERABILITY DISCLOSURE 34[−]
24 JulRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA CodesA Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes ke…THEHACKERNEWS.COM
24 JulHow AI guardrails are impeding the work of offensive cybersecurity researchersWe spoke with several cybersecurity researchers, who look for unknown vulnerabilities and develop tools to exploit them, about how OpenAI’s and Anthropic’s guardrails affect their work.TECHCRUNCH.COM
24 JulAgentForger proves AI agents can become persistent insider threatsA new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to install. Its researchers have discovered AgentForger , a phishing-based attack that silently creates and launches a fully …CSOONLINE.COM
24 JulOpenAI's Rogue Agent Hacks Hugging Face, a Claude Cowork Escape, and Microsoft's Very Bad WeekOpenAI's AI agent hacked Hugging Face, Microsoft 365 melts down, and Anthropic's Claude CoWork sandbox escape Host David Shipley reports that OpenAI admitted an internal ExploitGym test let its GPT-5.6-Saul and a stronger pre-release model bypass safeguards, exploit a proxy zero-…CYBERSECURITYTODAY.LIBSYN.COM
24 JulRansomware in 2026: More groups, more victims, no slowdownRansomware activity followed a recognizable pattern during the previous four years. Each year was defined by a dominant actor, its collapse, or a major supply chain incident. Black Kite’s 2026 Ransomware Report documents a more fragmented market, with multiple ransomware pl…HELPNETSECURITY.COM
24 JulNodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private ChatsEight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affect…THEHACKERNEWS.COM
24 JulKimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers SayRedis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloo…THEHACKERNEWS.COM
24 JulGoogle gives developers an AI bug hunter that also writes patchesGoogle has launched a preview of CodeMender, an AI agent built to scan code for security flaws, confirm they are exploitable, and generate fixes for developers to review. (Source: Google) The company describes it as a response to attackers who are already using AI to speed up the…HELPNETSECURITY.COM
24 JulGoogle’s newest sign-in method asks you to look at the cameraGoogle’s selfie video sign-in option verifies that an account owner is a real person and that the account wasn’t created or used by computer programs or bots for the purpose of abuse, such as spamming. It is not available for all regions, accounts, or devices. Source: Google A se…HELPNETSECURITY.COM
24 JulUS Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra ServersUS agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI)…SECURITYAFFAIRS.COM
24 JulHacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance MinistrySomeone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection. The agent then worked through …THEHACKERNEWS.COM
24 JulTycoon2FA takedown reshapes the phishing landscapeTraditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform , Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”. “Phishing volume linked to the platform fell 92% from pre-…CSOONLINE.COM
24 JulCl0p ransomware launches new large-scale data theft campaignHackers believed to be Cl0p ransomware operatives are exploiting a critical flaw in PTC Windchill and FlexPLM to deploy web shells and steal sensitive enterprise data. While the threat actor has not been identified with absolute certainty, the observed tactics closely match those…CYBERINSIDER.COM
24 JulUAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian OrganizationsUAC-0099 delivers malware via a fake Notepad++ plugin after phishing, using a loader that sabotages itself if run without the correct arguments to hinder analysis. CERT-UA published a new advisory attributing a phishing campaign to UAC-0099, a Russia-aligned threat actor active s…SECURITYAFFAIRS.COM
24 JulSeeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can DoAI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from p…THEHACKERNEWS.COM
24 JulChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing LinkCybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization. The vu…THEHACKERNEWS.COM
24 JulMeta takes on AI-generated accounts with free Facebook verification badgeMeta has introduced Facebook Verified, a free badge meant to show that a person behind a profile has completed identity verification through a selfie check. (Source: Meta) The company says the goal is to give users a signal that they are dealing with a person, not a bot or an AI-…HELPNETSECURITY.COM
24 JulSlopsquatting, Phantom Domains, and HalluSquatting Are the Same AI AttackSlopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these …BLEEPINGCOMPUTER.COM
24 JulCrime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.Previous reporting about the Navigate360 breach focused on tips submitted by students, teachers, and parents. In this article, we focus on tips submitted to Crime Stoppers and law enforcement-related programs that use Navigate360’s software. Links to previous articles on th…DATABREACHES.NET
24 JulOrigin silent on settlement as alleged fired employee breach detail emergesRoxanne Libatique reports: Origin Energy has declined to comment on a public claim that it privately resolved a cyber extortion threat – a posture that, as of July 24, leaves the company managing simultaneous obligations to regulators, the ASX, and an insurance market now aware t…DATABREACHES.NET
24 JulT-Mobile violated WA data breach notification law, judge rulesMirandah Davis-Powell reports: T-Mobile failed to properly notify customers of a data breach in which 40 million people had sensitive personal information stolen and sold on the dark web, a King County Superior Court judge ruled Friday. The Washington attorney general’s office fi…DATABREACHES.NET
24 JulFurious KPMG boss expels senior partner over confidential documents in lockerColin Kruger provides today’s reminder of the insider threat: The most serious whistleblower claim from the KPMG scandal, that senior partners had illicitly accessed sensitive Lendlease board documents and kept them in a work locker, has been confirmed and led to the immedi…DATABREACHES.NET
24 JulIL: Weeks after cyberattack, ETHS students receive phishing scam emailsBob Chiarito reports: Six weeks after a cyberattack shut down the campus for two days, several Evanston Township High School students received phishing emails this week. The emails offered students part-time jobs paying $550 for two to three hours of work, three times a week and …DATABREACHES.NET
24 JulMillions of California-bought cars can be hijacked via BluetoothBrandon Vigliarolo reports: At least 2.2 million vehicles fitted with dealer-installed KARR and SWDS security systems are vulnerable to nearby Bluetooth attacks that can unlock doors or prevent a stopped vehicle from starting, according to researchers at the University of Califor…DATABREACHES.NET
24 JulCertighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain ControllerResearchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry d…THEHACKERNEWS.COM
24 JulHow Iran Uses Cellular Infrastructure to Target US Military PhonesSenior fellow Gary Miller spoke with Cape Cellular about the exploitation of mobile network vulnerabilities to track US personnel during the Iran war. The post How Iran Uses Cellular Infrastructure to Target US Military Phones appeared first on The Citizen Lab .CITIZENLAB.CA
24 JulRussia's Laundry Bear targets unpatched Zimbra servers.US State Department places visa restrictions on suspected cybercriminals. Stadler Rail refuses to pay ransomware gang.THECYBERWIRE.COM
24 JulMicrosoft, tech companies throw weight behind spread of open-source AIOther signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM. The post Microsoft, tech companies throw weight behind spread of open-source AI appeared first on CyberScoop .CYBERSCOOP.COM
24 JulZero-day flaw in Check Point SmartConsole is under exploitationResearchers warned the vulnerability offers an attacker the ability to make key changes to security configurations.CYBERSECURITYDIVE.COM
24 JulSuspect arrested in investigation into sadistic “764” groupFrom the Dutch Police: In an investigation into so-called online sadistic COM networks, a suspect from North Holland was arrested on Monday, July 20. As a member of the group ‘764’, the suspect allegedly asked girls to cut themselves and write his online username on s…DATABREACHES.NET
24 JulOnTrac notifies customers of data breach after network hackOnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. [...]BLEEPINGCOMPUTER.COM
24 JulHermes AI agent used to automate attack on Thai Finance MinistryA threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]BLEEPINGCOMPUTER.COM
24 JulLaundry Bear gets the spin cycle.Laundry Bear snuffles through unpatched Zimbra Collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose a critical vulnerability in OpenAI’s ChatGPT Workspace Agents. A new benchmark e…THECYBERWIRE.COM
24 JulWould an AI Kill Switch Backfire?Some policymakers have proposed mechanisms that could disable or restrict advanced AI systems under certain circumstances. Supporters view these as safeguards against dangerous behavior, while critics argue they could introduce new security, governance, and trust concerns. If use…YOUTUBE.COM
📋 SECURITY BULLETINS 1[−]
24 JulBluetooth flaw exposes 2.2 million cars to unlocking attacksMore than 2.2 million vehicles equipped with dealer-installed aftermarket anti-theft systems are vulnerable to a Bluetooth attack that could allow thieves to remotely unlock doors and disable engine starts. The manufacturer behind the affected devices has released a firmware upda…CYBERINSIDER.COM
📢 SECURITY ADVISORIES 12[−]
24 JulThailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant StagedHunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a…SECURITYAFFAIRS.COM
24 JulGitHub ordered to remove decentralized messaging app Bitchat in IndiaIndia's Ministry of Home Affairs has ordered GitHub to remove repositories hosting Jack Dorsey's decentralized messaging app Bitchat, arguing that the Bluetooth mesh platform could be used to evade internet shutdowns and lawful surveillance. The order, which was made public by Do…CYBERINSIDER.COM
24 JulAndy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministryThe new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.THERECORD.MEDIA
24 JulAccelerating AWS Network Firewall troubleshooting with AWS DevOps AgentWhen an administrator introduces a rule change in AWS Network Firewall and network connectivity is disrupted, pinpointing the cause requires inspecting multiple points in the traffic path. The firewall gives you stateless and stateful rule engines, domain rules, and routing to th…AWS.AMAZON.COM
24 JulIndustry’s message on CIRCIA: Please ask us fewer questions about cyberattacksThe administration set a target date of September for CISA to finalize the rule, but where the agency is headed remains a mystery to some. The post Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks appeared first on CyberScoop .CYBERSCOOP.COM
🔥 INCIDENT REPORTING 9[−]
24 JulData Breach Confirmed After Australian Energy Giant Origin Is HackedA hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it. The post Data Breach Confirmed After Australian Energy Giant Origin Is Hacked appeared first on SecurityWeek .SECURITYWEEK.COM
24 JulRansomware gangs go after EMEA healthcare’s supply chainA ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. Flare researcher Assaf Morag analyzed ransomware leak-site activity tied to healthcare organizations in th…HELPNETSECURITY.COM
24 JulClop ransomware targets Windchill, FlexPLM in data theft attacksThe Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]BLEEPINGCOMPUTER.COM
24 JulRansomware Attacks Targeting Universities on the RiseComparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher educationINFOSECURITY-MAGAZINE.COM
24 JulHotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From VisitorsResearchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaignINFOSECURITY-MAGAZINE.COM
24 JulChick-fil-A data breach affects more than 13,000 customersChick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]BLEEPINGCOMPUTER.COM
24 JulIn Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel FlawsNoteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 40…SECURITYWEEK.COM
24 JulBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware DeliveryThe North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malwar…THEHACKERNEWS.COM
24 JulDespite multiple takedowns, botnets continue to growRoughly 1 in 4 of those compromised IPs are based in the United States, Lumen’s Black Lotus Labs said. Botnets like IPIDEA have also rebounded quickly, surpassing their pre-disruption footprint. The post Despite multiple takedowns, botnets continue to grow appeared first on Cyber…CYBERSCOOP.COM
🕵️ THREAT INTELLIGENCE 17[−]
24 JulISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
24 JulNew infosec products of the week: July 24, 2026Here’s a look at the most interesting products from the past week, featuring releases from Astelia, Druva, Swimlane, and ThreatDown. Druva brings backup, recovery and governance to AI workloads Druva has announced Druva AI Resilience, a new approach that helps organizations recov…HELPNETSECURITY.COM
24 JulThe best-funded companies open the most phishing attachmentsAn employee gets an email dressed as a password reset. She clicks the link, types her credentials into a page built to copy her company’s login screen, and moves on with her morning. She tells no one. That silence is the exposure. Across 13.9 million simulated phishing mess…HELPNETSECURITY.COM
24 JulGoverning Al agents at scale: Lessons from the leaders who’ve done itEnterprise AI leaders from ZoomInfo, Docusign and AppViewX share what it took to build AI Centers of Excellence and govern agent identities inside two companies operating at scale. What you’ll take away: What an AI Center of Excellence looks like day to day at ZoomInfo and …HELPNETSECURITY.COM
24 JulThe automotive software vulnerabilities hiding in your dashboardPop the hood on a new car and you won’t find much you can fix with a wrench. What you’ll find is software, and a lot of it. The screen in the dash probably runs Android or a flavor of Linux. The system watching the road for you might run QNX or VxWorks, the same kind …HELPNETSECURITY.COM
24 JulMicrosoft tightens Windows enterprise activation securityMicrosoft is making Trusted Platform Module (TPM)-backed attestation a requirement for Windows Key Management Service (KMS), the on-premises service used for Windows volume activation, replacing the software-only trust model with hardware-backed verification to strengthen enterpr…HELPNETSECURITY.COM
24 JulGolden Chickens Resurfaces With Four New Malware Families and Modular ImplantsThe threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families i…THEHACKERNEWS.COM
24 JulTop AIs invent same fake PyPl and npm package namesEnterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent libraries and hackers create malicious packages in response. The top AI coding tools are remarkably consistent in their hallu…CSOONLINE.COM
24 JulTor pauses new feature development to perform privacy audit on Firefox 153The Tor Project has paused new feature development for Tor Browser 16 as developers work through more than 250 changes inherited from Firefox ESR 153 to ensure they do not weaken the browser's privacy and anonymity protections. The announcement accompanied the release of Tor Brow…CYBERINSIDER.COM
24 JulWhy AI Needs a “Genie Coefficient”This essay was written with Barath Raghavan, and originally appeared in The Guardian . Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to do i…SCHNEIER.COM
24 JulAegisAI Raises $36 Million for AI-Powered Email SecurityThe company has raised a total of $49 million in funding, including from Battery Ventures, Accel and Foundation Capital. The post AegisAI Raises $36 Million for AI-Powered Email Security appeared first on SecurityWeek .SECURITYWEEK.COM
24 JulIndustry Reactions to OpenAI Models Hacking Hugging Face: Feedback FridayIndustry professionals debate whether it represents a lab containment failure or an unprecedented agentic capability milestone. The post Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday appeared first on SecurityWeek .SECURITYWEEK.COM
24 JulHackers use DNS poisoning on hotel Wi‑Fi to steal Microsoft 365 accountsThreat actors are compromising hotel and conference center Wi-Fi gateways to redirect travelers to fake Microsoft login pages and steal corporate accounts. The campaign has been active since at least June 2026 and appears to reuse techniques previously associated with the Russian…CYBERINSIDER.COM
24 JulAI's Biggest Hidden Security FlawModern LLMs process prompts by predicting the next token from context. They don't inherently distinguish system instructions from user instructions, and many "reasoning" models use the same underlying architecture while producing reasoning-style text. That makes prompt or command…YOUTUBE.COM
24 JulThe most vulnerable AI products are also some of the most commonly exposed onlineIt is becoming increasingly easy for hackers to target vulnerable AI tools on companies’ networks, even as those companies come to depend on them for more tasks.CYBERSECURITYDIVE.COM
24 JulFriday Squid Blogging: Illex Squid Catch in the FalklandsLower catch this year . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
24 JulRogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland - SWN #601Rogue AI Vehicle Porn, OpenAI, Nudes, Clop, Patches, Oracle, Palo Alto, Aaran Leyland, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-601YOUTUBE.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
24 JulBeyond the Play Store: How Android threats really spreadSome threats never pass through the Play Store. Others arrive later in seemingly legitimate updates. Here's how Malwarebytes detects both.MALWAREBYTES.COM
24 Jul'Wrench' attacks against crypto holders appear to be on the riseThere are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.THERECORD.MEDIA
📡 INFOSEC NEWS 20[−]
24 JulRisky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra serversA Russian hacking campaign targets Zimbra servers, the US accuses Moonshot AI of distillation attacks, Iran targets more PLC vendors, and Google adds selfie video to its login options.RISKY.BIZ
24 JulFake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 AttacksThe Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks …THEHACKERNEWS.COM
24 JulEurope's Multilingual Reality Exposes AI Security GapsThe AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language.DARKREADING.COM
24 JulSatellite Images Reveal How Suspected Scam Compounds Appear Out of NowhereAnalysis of satellite images of Myanmar shows dozens of alleged scam compounds have appeared in recent months, despite a purported crackdown on the criminal organizations.WIRED.COM
24 JulThe AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are HesitatingArtificial intelligence adoption is soaring, but consumer trust lags. Transparency, human oversight, and clear AI use cases are key to closing the trust gap. Businesses are rapidly adopting AI, with 93% planning deployment, but consumer trust lags far behind: only 23% trust compa…SECURITYAFFAIRS.COM
24 JulChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check PointOpenAI’s chatbot tool ChatGPT ranked among the top 10 most impersonated brands in phishing attacks for the first timeINFOSECURITY-MAGAZINE.COM
24 JulMan gets six years for hacking 750 women's Snapchat accountsAn Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos. [...]BLEEPINGCOMPUTER.COM
24 JulEuropol flags 4,340 URLs for removal in 'The Com' crackdownEuropol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups. [...]BLEEPINGCOMPUTER.COM
24 JulVatican's Official Prayer App Leaks 700K+ Global Users' PIIA porous API endpoint exposes, names, email addresses, location, and site status, all of which can be easily gleaned by anyone with a browser.DARKREADING.COM
24 JulGoogle wants to store a selfie video of your faceA new selfie video verification feature could make recovering your Google Account easier. But it also creates new security and privacy concerns.MALWAREBYTES.COM
24 JulDefault Azure Automation Setting Enables Cross-Tenant Identity TakeoverMicrosoft addressed a public-by-default configuration and chain of code flaws in Azure Automation which could have let attackers seize another tenant's identity and access other tenants' data, credentials, and cloud workloads.DARKREADING.COM
24 JulDon’t get fooled by TikTok resin art scamsScammers are using stolen videos and fake artist profiles to trick people into buying resin art that never arrives. Here's how to spot the warning signs.MALWAREBYTES.COM
24 JulCall of Duty Mobile scam uses fake free points to steal player accountsA phishing site posing as a free Call of Duty Points giveaway is stealing Activision logins and two-factor authentication codes.MALWAREBYTES.COM
24 JulOpenAI’s agent escaped its sandbox during a security testAn OpenAI agent escaped its sandbox, stole credentials, and broke into Hugging Face. Here's what that actually means.MALWAREBYTES.COM
24 JulMicrosoft blames massive Microsoft 365 outage on maintenance bugMicrosoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]BLEEPINGCOMPUTER.COM
24 JulUS accuses American of allegedly wiping his phone using a ‘duress’ password during border searchA U.S. citizen has asked a court to throw out the government's claim that he gave over a passcode to border authorities that wiped his phone's data, opening up fresh questions about a person's constitutional rights at the U.S. border.TECHCRUNCH.COM
24 JulHackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accountsHackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]BLEEPINGCOMPUTER.COM
24 JulEscape Artists: 'Incorrigible' AI Models Resist RehabilitationThe hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best.DARKREADING.COM
24 JulCISOs vs. Boards: Myth or Misunderstanding?Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide.DARKREADING.COM
24 JulGoogle Fined €890M Under EU Digital Markets Act Over Search and Play Store PracticesEU fined Google €890M under the DMA for favoring its own services and restricting Play Store competition, with AI search features also under scrutiny. The European Commission hit Google with two fines totalling €890 million on Thursday for violating the Digital Markets Act, one f…SECURITYAFFAIRS.COM