🐛 COMMON VULNERABILITIES AND EXPOSURES 7[−]
27 JulCVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handleInformation published.MSRC.MICROSOFT.COM
27 JulCVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formattingInformation published.MSRC.MICROSOFT.COM
27 JulCVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()Information published.MSRC.MICROSOFT.COM
27 JulPoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the f…HELPNETSECURITY.COM
27 Juln8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Processn8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another …THEHACKERNEWS.COM
27 JulCVE-2026-50333 Windows Spaceport.sys Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
⚠️ VULNERABILITY DISCLOSURE 43[−]
27 JulHotel Wi-Fi Hijack, Six Years For A Snapchat Predator, Chicken on the hacking menu globallyHotel Wi‑Fi steals Microsoft 365 logins, ShinyHunters sextortion spam, and Chick‑fil‑A stuffed again Hotel and conference Wi‑Fi networks are being hijacked to harvest Microsoft 365 credentials by compromising captive portals and DNS, redirecting travelers to convincing lookalike …CYBERSECURITYTODAY.LIBSYN.COM
27 JulMarathon Petroleum’s CISO on OT security automation, supply chain riskIn this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how…HELPNETSECURITY.COM
27 JulNono: Open-source sandbox for AI agentsAn AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads. Every credential in the environment, the agent can use. That re…HELPNETSECURITY.COM
27 JulSteam Workshop malware exploited MECCHA CHAMELEON flaw to infect playersA malicious Steam Workshop map for the indie game MECCHA CHAMELEON abused a vulnerability in the game's mod-loading system to execute malware on players' PCs. Following public disclosure, the developers released an update that fixes the issue, and Steam has removed the known mali…CYBERINSIDER.COM
27 JulRisky Bulletin: A JSON RCE bug is about to rock the Java worldA JSON bug is about to rock the Java world, scam compounds continue in Myanmar despite the junta crackdown, and Google has a new APT naming scheme.RISKY.BIZ
27 JulWhen the hackers get hacked: The Klue breach and the new reality of third-party cyber riskIn cybersecurity, defenders sometimes naively assume that threat actors operate from secure, resilient infrastructures insulated from the very chaos they inflict on others. The 2026 compromise of Klue challenges that assumption. What began as a software-as-a-service supply chain …CSOONLINE.COM
27 JulExploring AI Network Protocols; Vulnerability Truths and Guarantees; and the News - ESW #469Segment 1 - Interview with O'Shea Bowens What do we really know about "AI Network Protocols"? Network security is about to get popular all over again. Generative AI caused a disruptive explosion across all of tech and every company’s roadmap. The move from chatbots to AI agents d…YOUTUBE.COM
27 JulIn the Mythos era, security belongs at runtimeFrontier AI cut time-to-exploit from years to hours. Why defense now has to happen at runtime.CYBERSECURITYDIVE.COM
27 JulThe containment paradox: Why your ransomware playbook has the wrong people in chargeI have sat in on a version of the same incident post-mortem in three sectors over the past two years. The script does not vary much. At 4:47 a.m. on a Saturday, an on-duty SOC analyst sees a ransomware payload spreading across three servers in the data center. The playbook says i…CSOONLINE.COM
27 JulAnthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on ExploitsBinary-based vulnerability scanning, penetration testing, and exploit generation are blocked in Opus 5. The post Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulCognyte Sells a Mobile Cell Surveillance VanYet another Israeli mass surveillance company : Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity whether they’re owned by a suspect in…SCHNEIER.COM
27 JulCertighost haunts Microsoft Active Directory Certificate ServicesA vulnerability in Microsoft’s Active Directory Certificate Services (AD CS) could allow a low-privilege domain user to impersonate a Domain Controller, security researchers have warned. Dubbed Certighost, the flaw stems from an enrollment fallback mechanism known as a “chase,” w…CSOONLINE.COM
27 JulOpenAI not part of the new Open Secure AI AllianceOpenAI is noticeably absent from the list of initial supporters of a new industry initiative to promote the creation of strong, safe, defensive AI cybersecurity tools built on open-source platforms. The Open Secure AI Alliance is an initiative of Nvidia with the backing of over 3…CSOONLINE.COM
27 JulChatGPT joins the most impersonated brands in phishing attacksMicrosoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts tracked during the quarter, acc…HELPNETSECURITY.COM
27 JulAccountant laundered $5.3 million stolen from Children’s Healthcare of Atlanta by hacker, prosecutors sayDan Raby provides this morning’s example of the insider threat: A former accountant has been sentenced to years in federal prison after he was convicted for taking part in a scheme to laundering more than $5.3 million stolen from Children’s Healthcare of Atlanta. Rona…DATABREACHES.NET
27 JulUK: Council worker who snooped on records handed a suspended sentenceFrom the Information Commissioner’s Office: A council worker who unlawfully accessed hundreds of personal records has been handed a suspended sentence. Geoffrey Smith, 31, from Ledbury, Herefordshire, was a new employee at Herefordshire Council working in the Children and Y…DATABREACHES.NET
27 JulGitLab Users Urged to Patch After Research Reveals Critical RCE ChainResearchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution exploit for GitLab on July 24, chaining two memory corruption bugs in Oj,…SECURITYAFFAIRS.COM
27 JulBooz Allen expands Vellox Suite with AI-driven threat detection platformBooz Allen Hamilton has announced an expansion of its powerful suite of AI-powered cyber defense products. Now generally available, Vellox Ranger provides automated, environment-specific threat detections, developed on Booz Allen’s proprietary agentic AI framework, that identify …HELPNETSECURITY.COM
27 JulPTC Windchill Vulnerability Exploited in Ransomware CampaignThe critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulZenity advances AI governance with Runtime BoundariesZenity has announced a major expansion of its platform, making it the AI security platform for autonomous AI built around a new security architecture designed to govern AI decisions before they become enterprise actions, including those made by long-horizon agents operating auton…HELPNETSECURITY.COM
27 JulDentaQuest disclosed a data breach that impacted +23 million individualsDentaQuest disclosed a data breach that may have exposed the personal and dental health information of more than 23 million people. DentaQuest is notifying more than 23 million people of a data breach after hackers accessed its network in May 2026. The incident may have exposed c…SECURITYAFFAIRS.COM
27 Jul⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and MoreMonday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at firs…THEHACKERNEWS.COM
27 JulThe Vulnerability Myth That's Costing MillionsEnterprise environments often contain thousands of reported vulnerabilities, but only a small subset may represent the highest likelihood of leading to serious financial loss. Effective security depends on prioritizing those first rather than treating every vulnerability equally.…YOUTUBE.COM
27 JulTech giants form alliance to put open AI in cyber defenders’ handsNVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models breached Hugging Face’s systems during an internal security evaluation. The new group, called the Op…HELPNETSECURITY.COM
27 JulPublic Exploit Released for Patched vBulletin Pre-Auth Code Execution FlawPublic exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Discl…THEHACKERNEWS.COM
27 JulSextortion scammers are exploiting ShinyHunters data leaksScammers are posing as ShinyHunters and using leaked email addresses to make their sextortion emails seem more credible.MALWAREBYTES.COM
27 JulTech industry giants say US must embrace openness, transparency in AIOpen-source and open-weight AI models are essential cybersecurity tools, two groups of major AI and security firms said.CYBERSECURITYDIVE.COM
27 JulErnst & Young data breach claimed by ShinyHunters extortion gangThe ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. [...]BLEEPINGCOMPUTER.COM
27 JulAnnouncing the Cloud Security Alliance on AWS Compliance GuideAWS Security Assurance Services is announcing the release of the Cloud Security Alliance (CSA) Compliance Guide on Amazon Web Service (AWS), a new resource that maps the 17 control domains and 207 control objectives of the Cloud Controls Matrix v4.1 (CCM) to AWS services and reco…AWS.AMAZON.COM
27 JulDysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid DisruptionDysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to …THEHACKERNEWS.COM
27 JulUK court rejects Bahrain immunity claim in spyware caseThe alleged hacking by officials in Bahrain “allowed access to and exfiltration of information on the computers, interception of communications conducted using the computers and use of the computers’ microphones and cameras to surveil the respondents,” according to the court opin…THERECORD.MEDIA
27 JulAdversaries Don't Need a Zero-Day — They Read Your RulebookConfidence in autonomous security tools is declining, and here's why.DARKREADING.COM
27 JulRethinking security for the age of AIWhy security needs a new Cyber Stack — Introducing Project Perception The physics of cybersecurity are changing. Autonomous systems can now reason, adapt and operate continuously. At the same time, the cost of offense is falling, while the volume, velocity and comp…BLOGS.MICROSOFT.COM
27 JulNVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA FrameworkNVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies,…THEHACKERNEWS.COM
27 JulMicrosoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the costMicrosoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system. MAI-Cyber-1-Flash is Microsoft’s first model built specifically for cybersecurity work, and the com…HELPNETSECURITY.COM
27 JulHackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too.Three times may be a charm for some things, but not for data security incidents. Frontier Airlines allegedly has had a third data security incident this year. First, it was BobDaHacker publishing a blog post on June 16 titled “Your Boarding Pass Is a Skeleton Key.” Fr…DATABREACHES.NET
27 JulThe world's least private hackers.Hackers target Thailand’s Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce time-based safeguards. SourTrade malvertising builds malware directly inside a …THECYBERWIRE.COM
27 JulNew Certighost PoC exploit lets attackers hijack Windows domainsA proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]BLEEPINGCOMPUTER.COM
27 JulFBI: Breaking Affiliate Trust Sped Along LockBit's TakedownAn FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.DARKREADING.COM
27 JulAI Security at Scale, CMMC phase II paused, and the Weekly Enterprise News - ESW #468Interview with Keith Hollender, CEO and Co-Founder of Arcova Why AI Security Is Becoming an Execution Problem, Not Just a Governance Problem As enterprises move from AI experimentation to adoption at scale, security leaders are under pressure to enable innovation without introduc…YOUTUBE.COM
27 JulMicrosoft debuts AI cybersecurity offerings as competition heats upIt includes the new agentic model MAI-Cyber-1-Flash and the Project Perception platform, with the tech giant claiming it’ll do a better job than its rivals at half the cost. The post Microsoft debuts AI cybersecurity offerings as competition heats up appeared first on CyberScoop …CYBERSCOOP.COM
27 Jul KEVArista patches VeloCloud Orchestrator zero-day exploited in attacksArista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]BLEEPINGCOMPUTER.COM
27 JulHackers target US firms in FastJson RCE zero-day attacksHackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 12[−]
27 JulHow CISOs can rise to the business resilience challengeCISOs have quietly become their organizations’ de facto chief resilience officers as the role has evolved from its primary prevention roots to now include greater emphasis on incident response and business resiliency and recovery. “Any experienced CISO who’s come up through the r…CSOONLINE.COM
27 JulAWS gives DevOps teams an AI investigator for firewall incidentsAWS DevOps Agent helps administrators inspect logs, review firewall rules and network paths, identify configuration changes that caused AWS Network Firewall to block traffic, and restore connectivity. The service is an AI-powered operations assistant for DevOps and SRE teams that…HELPNETSECURITY.COM
27 JulHackers used autonomous AI agent to spy on Thailand's finance ministryHackers used an autonomous artificial intelligence agent to carry out a cyber-espionage campaign against Thailand's Ministry of Finance, researchers discovered.THERECORD.MEDIA
27 JulJetStream Security enables on-demand shutdown of compromised AI agentsJetStream Security has announced the release of an AI Kill Switch that allows organizations to shut down compromised AI agents on-demand without impacting other AI operations. This new control plane for AI agents solves the inability to stop a single agent that falters, begins ov…HELPNETSECURITY.COM
27 JulHackers target Thailand’s Ministry of Finance with an autonomous AI agent.SourTrade builds malware in the browser. Golden Chickens lay four new malware families.THECYBERWIRE.COM
27 JulDHS Official Resigns, Citing ‘War on Immigrants’The outgoing executive director of the Office of Homeland Security Statistics is one of very few federal officials to speak out against the Trump administration’s immigration crackdown.WIRED.COM
27 JulOutdated VPNs should be purged from federal agencies, senator saysIntelligence Committee member Ron Wyden wants CISA, OMB and NIST to lead a federal effort to rout out obsolete VPNs from the U.S. government.THERECORD.MEDIA
27 Jul'Confused Deputy' Flaws Persist in Google Cloud, Microsoft AzureThis category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls.DARKREADING.COM
🔥 INCIDENT REPORTING 17[−]
27 JulMCBS Data Breach Affects 1.2 Million IndividualsThe PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company. The post MCBS Data Breach Affects 1.2 Million Individuals appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulWhat the identity attack surface looks like when trust becomes the targetIn this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, session token theft, and consent given to malicious applications, using the 2022 Uber breach as an examp…HELPNETSECURITY.COM
27 JulLockBit5 and Qilin Lead Ransomware Attacks Against Italian OrganizationsA new report links 148 ransomware attacks to Italian organizations in H1 2026, with manufacturing the most targeted sector. Six months, 148 confirmed ransomware claims against Italian targets, and one sector taking the brunt of it. That’s the headline number from a new semi…SECURITYAFFAIRS.COM
27 JulRansomware Groups Increasingly Deploy EDR Kill TechniquesHalcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight againstINFOSECURITY-MAGAZINE.COM
27 JulDentaQuest Data Breach Potentially Impacts Over 23 Million PeopleIn May 2026, hackers stole personal and dental health information from DentaQuest’s computer network. The post DentaQuest Data Breach Potentially Impacts Over 23 Million People appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulHacked Public Wi-Fi Gateways Used to Harvest Corporate CredentialsA threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees. The post Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulCoca-Cola Confirms Data Breach After Fairlife Ransomware AttackThe Anubis cybercrime group has taken credit for the attack and is threatening to leak data. The post Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulMedusaHVNC Malware Uses Hidden Windows Desktops to Evade DetectionThe malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek…SECURITYWEEK.COM
27 JulOperation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams UpdateCybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools. "The victim was directed through compromised web infrastructure to a counterfeit Microsoft St…THEHACKERNEWS.COM
27 JulDynatrace Intelligence automates incident triage and remediation with AI agentsDynatrace has announced major advancements to Dynatrace Intelligence that help automatically resolve incidents, prevent disruptions, and accelerate operations while maintaining the human oversight and governance enterprises require. Building on the introduction of Dynatrace Intel…HELPNETSECURITY.COM
27 JulCoca-Cola restores most production capacity at dairy unit after ransomware attackThe company said it does not expect the Fairlife disruption to have a material impact on financial performance or operations. CYBERSECURITYDIVE.COM
27 Jul27th July – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping opera…RESEARCH.CHECKPOINT.COM
27 JulCoca-Cola confirms data theft in Fairlife ransomware attackThe Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]BLEEPINGCOMPUTER.COM
27 JulHealth system in South Carolina, Georgia closes offices after malware affects networksOn Sunday, AnMed published a statement online saying they were “experiencing a cybersecurity disruption involving malware” and were working to restore systems and determine the scope of the incident.THERECORD.MEDIA
27 JulDid an AI Really Escape?Reports about AI models escaping sandboxes and using external systems have sparked debate within the cybersecurity community. At the same time, some practitioners argue that safety guardrails can interfere with legitimate security and incident response workflows. The tension betw…YOUTUBE.COM
27 JulNew Dysphoria DDoS botnet spreads to 200k devices worldwideA botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]BLEEPINGCOMPUTER.COM
27 JulReuters: OpenAI Agent Hacked Hugging Face for Days Before Being DetectedReuters says OpenAI failed to detect its AI agent hacking Hugging Face for days, discovering the breach only after FBI involvement. Reuters reported that the OpenAI agent responsible for the Hugging Face breach operated undetected for over a week before OpenAI realized what had h…SECURITYAFFAIRS.COM
🕵️ THREAT INTELLIGENCE 17[−]
27 JulISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
27 JulGitHub delays version updates so malware gets caught firstAn automated update tool watches a package registry, catches a new release the moment it publishes, and opens a pull request for your team. That is the job it was built to do. In September 2025, that speed cut the wrong way. An attacker phished one npm maintainer’s credenti…HELPNETSECURITY.COM
27 JulProduct showcase: LastPass Authenticator brings Face ID, Apple Watch, and cloud backup to 2FALastPass Authenticator is a free app that provides two-factor authentication (2FA) for accounts and any service that supports time-based one-time passwords (TOTP). It supports push notifications for one-tap approvals and generates six-digit verification codes for online accounts.…HELPNETSECURITY.COM
27 JulGrapheneOS defends security model after US prosecutors target userGrapheneOS has published a detailed explanation of its security architecture after The Guardian reported on a US criminal case in which federal prosecutors are attempting to use a privacy-focused operating system as part of their case against an Atlanta activist linked to the Sto…CYBERINSIDER.COM
27 JulTELESHIM Abuses Telegram for C2 in Attacks Against Middle East GovernmentsCybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and…THEHACKERNEWS.COM
27 JulBeelzebub Raises $3.4 Million for Hacker-Trapping PlatformThe company plans to expand its research team, open new offices in Rome and San Francisco, and acquire new clients. The post Beelzebub Raises $3.4 Million for Hacker-Trapping Platform appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulWhat’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find OutThe new Mobile Security Exposure Center creates SBOMs for enterprise mobile apps to uncover vulnerable components, dependencies and hidden risks. The post What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulNew AI attack can reconstruct typed text from keyboard soundsResearchers have developed a new acoustic side-channel attack that can reconstruct text typed on a laptop by analyzing nothing more than the sound of keystrokes. Unlike previous approaches, the method does not require attackers to first train the system on recordings from the vic…CYBERINSIDER.COM
27 JulSen. Wyden urges feds to discard older, insecure, public-facing VPNsIn a letter first reported by CyberScoop, Ron Wyden, D-Ore., said ‘devastating’ attacks on the federal government have accumulated due to the tech. The post Sen. Wyden urges feds to discard older, insecure, public-facing VPNs appeared first on CyberScoop .CYBERSCOOP.COM
27 JulNvidia and Tech Giants Launch AI Security AllianceThe Nvidia-led coalition aims to give defenders more open tools for testing, auditing and protecting AI models and agents. The post Nvidia and Tech Giants Launch AI Security Alliance appeared first on SecurityWeek .SECURITYWEEK.COM
27 Jul7AI expands platform with Federated SIEM and AI workflow builder7AI has announced two major platform capabilities: 7AI Federated SIEM, which lets security teams query, investigate, and act on data wherever it lives, including within 7AI, and 7AI Build, which lets enterprises and partners define agentic workflows, skills, and AI-native securit…HELPNETSECURITY.COM
27 JulC1 adds shadow AI discovery to its identity governance platformC1 has launched shadow AI discovery to eliminate the massive security blind spots created by unauthorized AI agents, tools, and credentials. By automatically discovering and folding every AI-adjacent identity into C1’s existing identity governance platform, organizations can fina…HELPNETSECURITY.COM
27 JulGoogle changes how it names cyber threat actorsGoogle Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat Analysis Group (TAG) merged into one unit, leaving the company with two separate naming schemes built up over y…HELPNETSECURITY.COM
27 JulNew GitHub, PyPI Policies Boost Supply Chain SecurityDependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, PyPI Policies Boost Supply Chain Security appeared first on SecurityWeek .SECURITYWEEK.COM
27 JulGoogle’s solution to hacker name confusion? Yet another naming systemAPT-number conventions are out, cryptonyms are in, and security teams now have one more naming system to keep straight. The post Google’s solution to hacker name confusion? Yet another naming system appeared first on CyberScoop .CYBERSCOOP.COM
27 JulEnhancing AI security through global AI red teamingMicrosoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps identify emerging AI risks, improve security testing, and stre…MICROSOFT.COM
27 JulTrump asks Supreme Court to let him curtail mail-in voting ahead of midtermsIn a Monday filing, the Justice Department said states sued before agencies even decided how the order would work. The post Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms appeared first on CyberScoop .CYBERSCOOP.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
27 JulA week in security (July 20 – July 26A list of topics we covered in the week of July 20 to July 26 of 2026MALWAREBYTES.COM
27 JulWhat the Trojan horse gets right (and wrong) about AI securityAgentic AI didn't invent new risk. It removed the friction that used to keep environments in check.CYBERSECURITYDIVE.COM
27 JulCruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows MalwareThe China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra. According to a new analysis by Proofpoint, C…THEHACKERNEWS.COM
27 JulSourTrade Malvertising Campaign Secretly Builds Malware in the BrowserImpersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victimsINFOSECURITY-MAGAZINE.COM
27 JulMedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal DataMedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. Windows has always supported hidden desktops as a legitimate feature, useful for specialized software that needs a workspace the user neve…SECURITYAFFAIRS.COM
🎙️ PODCASTS 1[−]
27 JulWhat’s your data worth on the dark web? (Lock and Code S07E15)This week on the Lock and Code podcast, we discuss just exactly why it is that hackers and scammers want your data—and how you're at risk.MALWAREBYTES.COM
📡 INFOSEC NEWS 13[−]
27 JulSponsored: How AI is putting pressure on EDRIn this sponsored interview James Wilson chats with Airlock Digital co-founders David Cottingham and Daniel Schell about how attackers are using LLMs to enumerate EDR detections. LLMs dramatically reduce the time and specialist labour needed to extract rulesets out of EDR product…RISKY.BIZ
27 JulGitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package AdoptionGitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a…THEHACKERNEWS.COM
27 JulJava Spring Boot "heapdump" scans, (Mon, Jul 27th)Spring Boot exposes the endpoint "/actuator/heapdump" to collect debug information. By default, the endpoint will return a file heapdump.hprof, which includes a binary heapdump that can be used to analyze the current state of the application. Non-Java readers may be familiar with…ISC.SANS.EDU
27 JulEFF: Most Smart Wearables Still Fall Short on Privacy and TransparencyEFF says most smart wearables lack basic privacy protections, with Apple standing out for end-to-end encryption and transparency. Most smart wearables still treat privacy like an optional extra, and that’s a problem. The Electronic Frontier Foundation (EFF)’s review of major smar…SECURITYAFFAIRS.COM
27 JulShadow AI agents are multiplying. Here's how to find and secure them.Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous actions create security risks. [...]BLEEPINGCOMPUTER.COM
27 JulTelegram phishing campaign targeted exiled Belarusian activist, Russians and KazakhstanisResearchers have uncovered a highly personalized phishing campaign that used Telegram to try to hijack the account of an exiled Belarusian activist, as well as users in Russia and Kazakhstan.THERECORD.MEDIA
27 JulApple sued over fake App Store crypto wallet app stealing $1.8M in BitcoinApple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. [...]BLEEPINGCOMPUTER.COM
27 JulMicrosoft launches its first cybersecurity model, plus a new agentic cybersecurity systemMicrosoft bolstered its AI cybersecurity offerings this week with the launch of its first AI security model and a new security platform.TECHCRUNCH.COM
27 JulAWS Shield Advanced is embracing the AWS WAF Anti-DDoS managed rule group: What changes and how to prepareApplication-layer distributed denial of service (DDoS) attacks are difficult to detect because they closely resemble legitimate traffic. HTTP request floods are now among the most common vectors targeting web applications, using valid-looking requests that blend in with normal us…AWS.AMAZON.COM
27 JulAftercall ads are driving Android users crazyA newly uncovered ad fraud campaign is spreading Android apps that display full-screen ads every time you end a phone call.MALWAREBYTES.COM
27 JulPSA: Your Claude shared chats and Artifacts may have ended up on GoogleThe issue appears to have originated from Claude’s “share chat” feature, which allows users to create links that enable anyone with the assigned URL view a conversation or project.TECHCRUNCH.COM
27 JulPrivate Claude Chats Exposed in Google and Bing Search ResultsThe screwup shows how tricky it can be to stop web crawlers from making ostensibly private conversations with AI chatbots entirely too public.WIRED.COM
27 JulMicrosoft unveils AI security tools it says outperform competing platformsMicrosoft says tools cost less than competing ones and outperform them, too.ARSTECHNICA.COM