25Articles
7Categories
2026-07-25Date
🐛 COMMON VULNERABILITIES AND EXPOSURES 5[−]
25 JulChromium: CVE-2026-16804 Use after free in InputThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
25 JulChromium: CVE-2026-16805 Use after free in BlinkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
25 JulChromium: CVE-2026-16806 Use after free in WebMCPThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
25 JulChromium: CVE-2026-16807 Out of bounds write in CodecsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
25 JulFastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched AvailableSecurity firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked…THEHACKERNEWS.COM
⚠️ VULNERABILITY DISCLOSURE 8[−]
25 JulOpenAI models escaped containment to hack Hugging Face.Russia's Laundry Bear targets unpatched Zimbra servers. EU hits Google with a $1 billion fine. Extortion group wipes Romania's land registry database. The Trump administration's AI czar resigns.THECYBERWIRE.COM
25 JulResearcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as GitSecurity researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesti…THEHACKERNEWS.COM
25 JulRockwell Patches Code Execution Flaws in Arena Simulation SoftwareA researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations. The post Rockwell Patches Code Execution Flaws in Arena Simulation Software appeared first on SecurityWeek .SECURITYWEEK.COM
25 JulCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCEThreat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication infor…THEHACKERNEWS.COM
25 JulUS House Votes to Extend Cyber Sharing Law for 10 YearsChris Liotta reports: Lawmakers voted to extend a key cyberthreat sharing law for another decade, attaching the long-stalled reauthorization to Washington’s annual defense policy bill. The U.S. House of Representatives narrowly approved its $1.15 trillion fiscal year 2027 n…DATABREACHES.NET
25 JulAU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’Caitlin Powell reports: A male registered nurse from northern Sydney has been charged after allegedly downloading the data of multiple patients. Police received a report on Wednesday, July 22, that a NSW Health employee had allegedly accessed and downloaded patient information wi…DATABREACHES.NET
25 JulNo Need to Hack When It’s Leaking: Click to Pray editionJessica Lyons reports on today’s entry in the “No Need to Hack When It’s Leaking” files: Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked people’s names and email addresses for months – or lon…DATABREACHES.NET
25 JulAustralian energy provider Origin Energy disclosed a data breach impacting customer dataOrigin Energy confirmed a data breach after a hacker claimed to have stolen data from 2 million customers and threatened to leak it. Origin Energy disclosed a cyberattack that exposed customer data after a hacker claimed to have stolen records belonging to 2 million customers and…SECURITYAFFAIRS.COM
📢 SECURITY ADVISORIES 2[−]
25 JulDevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate PayoutsThe operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the ce…THEHACKERNEWS.COM
25 JulIran-Linked Actors Breach Are Targeting US Water and Energy Control SystemsUS agencies warn Iran-linked actors are targeting internet-exposed water and energy control systems, risking disruption. Federal agencies updated their cybersecurity advisory this week: Iran-linked actors are inside American water and energy control systems, and they’re not…SECURITYAFFAIRS.COM
🔥 INCIDENT REPORTING 6[−]
25 JulDavid Shiply Interviews Pratim Datta, PhD from Kent StateAI, Cybersecurity, and Public Policy: Export Controls, Arms Races, and the "New Radium" On Cyber Security Today (Weekend), the host interviews Pratim Datta, a Kent State University professor and former global consultant, about the past six months of AI and public policy as it int…CYBERSECURITYTODAY.LIBSYN.COM
25 JulThe OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for DaysPlus: Russian hackers are trying to steal US nuclear scientists’ emails, the State Department bans known scammers from entering the United States, and more.WIRED.COM
25 JulCTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account HijackingFor years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recen…THEHACKERNEWS.COM
25 JulAI Now Picks Cybercrime TargetsSome malware operations reportedly include AI-powered profiling features that analyze compromised systems and rank victims based on characteristics that may indicate higher financial value or operational importance. This helps attackers decide where to focus their efforts. Automa…YOUTUBE.COM
25 JulShinyHunters data leaks fuel $2,000 sextortion email scamThreat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]BLEEPINGCOMPUTER.COM
25 JulThe hacker who humiliated spyware makers and was never caughtAn awe-inspiring hacktivist who hacked two controversial government spyware makers may be the most prolific hacker to have never gotten caught. What do we know about Phineas Fisher?TECHCRUNCH.COM
🕵️ THREAT INTELLIGENCE 1[−]
25 JulCold lures, hot targets.This week, we are joined by ⁠Ondrej Kubovič⁠, Security Awareness Specialist from ⁠ESET⁠, discussing their work on "FrostyNeighbor: Fresh mischief and digital shenanigans." Ondrej walks us through ESET's latest research into FrostyNeighbor, a long-running Belarus-aligned cyberespi…THECYBERWIRE.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
25 JulOpenAI confirms ChatGPT is down worldwideChatGPT, the famous artificial intelligence chatbot that allows users to converse with various personalities and topics, has connectivity issues worldwide. [...]BLEEPINGCOMPUTER.COM
25 JulMalicious sites use JavaScript to build malware in browser memoryA massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. [...]BLEEPINGCOMPUTER.COM
📡 INFOSEC NEWS 1[−]
25 JulSteam forum ClickFix attacks infect gamers with XMRig cryptominersSteam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]BLEEPINGCOMPUTER.COM