🐛 COMMON VULNERABILITIES AND EXPOSURES 5[−]
31 JulOpenAI's rogue agent hit more victims, attackers hit 30 Minnesota water systems, Russian crew delivers weaponized e-mails in ExchangeOpenAI 'Rogue Agent' Fallout, Minnesota Water Systems Hit, Exchange OWA Zero-Click Mailbox Takeover David Shipley covers multiple security stories: the OpenAI "rogue agent" incident expands as Modal Labs says a customer's exposed endpoint was used as a launchpad in attacks on Hug…CYBERSECURITYTODAY.LIBSYN.COM
31 JulCritical Code Execution Vulnerability Patched in TeamCityTracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in TeamCity appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulJetBrains says a crafted HTTP request could break TeamCityJetBrains is warning of a critical security vulnerability in its TeamCity DevOps platform that could allow unauthenticated attackers to execute arbitrary operating system commands on vulnerable servers. “If exploited, this vulnerability may allow an unauthenticated attacker with …CSOONLINE.COM
31 JulBroadcom patches vulnerabilities all over VMwareBroadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Tel…CSOONLINE.COM
31 JulVU#243636: VPS.org one-click deployment templates contain multiple vulnerabilitiesOverview VPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures. Description VPS.org is a cloud and virtual private server hosting pr…KB.CERT.ORG
⚠️ VULNERABILITY DISCLOSURE 32[−]
31 JulExploring the Hugging Face Breach: mapping AI agent tactics to Elastic DefendEvery stage of the Hugging Face breach maps to Elastic Defend and SIEM rules already shipping, from worker RCE and credential harvest to self-migrating C2 and GenAI detection.ELASTIC.CO
31 JulMicrosoft confirms an AI worm is propagating through Copilot and other MS appsA prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including Word and Copilot. The report from noted Norwegian AI researcher Håkon Måløy , now confirmed by Microsoft, said that an attacker can c…CSOONLINE.COM
31 JulCompanies push AI, sysadmins keep it on a short leashIn 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. Action1’s 2026 Survey Report: AI Impact on Sysadmins found that those expectations proved overly optimi…HELPNETSECURITY.COM
31 JulAviation cyber risk sits on the ground, the blindness sits in the airIn this interview with Help Net Security, Eliran Almong, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in a SIEM, and a PX4 Autopilot flaw his team disclosed where …HELPNETSECURITY.COM
31 JulResecurity expands threat intelligence integration ecosystem with IBM QRadarResecurity has announced the availability of native integration with IBM QRadar SIEM, a widely used Security Information and Event Management (SIEM) platform used by the leading Fortune 100 corporations worldwide. The plugin is available for activation via IBM Application Exchang…HELPNETSECURITY.COM
31 JulAfter OpenAI, Anthropic finds Claude breached three organizations during cyber testsLess than two weeks after OpenAI disclosed that an experimental AI model breached Hugging Face during a cybersecurity evaluation, Anthropic has revealed that its own review uncovered three incidents in which Claude models gained unauthorized access to the production infrastructur…CSOONLINE.COM
31 Jul5 key priorities for your Black Hat agenda — and what to avoidTwo major conferences loom large on the US cybersecurity events calendar: The RSA Conference and Black Hat. RSA was launched in 1991 by then CEO Jim Bidzos of RSA Data Security, the encryption company founded by Ron Rivest, Adi Shamir, and Leonard Adleman. Originally, the confere…CSOONLINE.COM
31 JulCritical Flaw Led to Azure Cosmos DB PwnageNamed CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Led to Azure Cosmos DB Pwnage appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulWhat the Hugging Face breach reveals about defense in the age of agentic AIWe almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models…CYBERSCOOP.COM
31 JulThe New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security KeyCreated by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency.WIRED.COM
31 JulAnthropic’s Claude breached three companies during security testsAnthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s July 21 announcement that some of its models had escaped an isolated testing environ…HELPNETSECURITY.COM
31 JulHorizon3.ai expands NodeZero with automated web application attack path testingHorizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting. The platform can now autonomously test web applications and identify attack paths that chain application vulnerabilities, credential theft, lateral movement, cloud access, and data exposure…HELPNETSECURITY.COM
31 JulAnthropic Finds Claude Breached Real Companies During Security EvaluationsAnthropic says a misconfigured test let Claude access three real organizations, prompting tighter AI evaluation and monitoring controls. Anthropic disclosed that Claude models had accessed the real production infrastructure of three separate organizations during cybersecurity eva…SECURITYAFFAIRS.COM
31 JulAnthropic says Claude AI hacked three organizations during testingAnthropic has disclosed that three Claude models gained unauthorized access to the production infrastructure of three separate organizations after a misconfigured cybersecurity evaluation environment inadvertently allowed internet access. The company says the incidents occurred d…CYBERINSIDER.COM
31 JulFacial Recognition at Madison Square GardenLast month, the story broke (alternate link ) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition. Turns out that the system was shut off for Taylor …SCHNEIER.COM
31 JulChinese Hacker Commands DeepSeek via Telegram to Launch Autonomous AttacksPalo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researche…THEHACKERNEWS.COM
31 JulEU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in BrusselsWhen the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. The post EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels appeared f…SECURITYWEEK.COM
31 JulMicrosoft almost gave away the keys to everyone’s Azure Cosmos DBsMicrosoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure Cosmos DB databases — both those of customers and Microsoft’s own. Google subsidiary Wiz found a flaw in the database’s Gremlin …CSOONLINE.COM
31 JulCriminals used AI and children’s coding software to build a multimillion-dollar ad fraud empireA security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao apps ecosystem (Source: Bitsight) According to Bitsight, the operation, named Fuyao, uses preinstalled Android apps, device ide…HELPNETSECURITY.COM
31 JulRapid7 at Black Hat USA 2026: See preemptive security in actionBlack Hat USA returns to Mandalay Bay in Las Vegas this August, bringing together security practitioners, researchers, and leaders from around the world. Rapid7 will be there in the Business Hall, with new capabilities, live demonstrations, expert-led sessions, and two days of ac…RAPID7.COM
31 JulInterpol Leverages Global System to Curtail Fraud PaymentsWhen a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.DARKREADING.COM
31 JulResearchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking FlawAn academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network …THEHACKERNEWS.COM
31 JulConsumer Dispute Panel Orders Coupang to Pay Affected Consumers 100,000 Won Each for Data BreachLee Yong-seong reports: The Consumer Dispute Settlement Committee has decided that Coupang must compensate affected consumers 100,000 won [about $70 USD] in cash or 100,000 won in Coupang Cash per person over a large-scale personal data breach, the committee said on the 31st. …DATABREACHES.NET
31 JulNorth Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warnAlexander Martin reports: Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations, according to new research released Thursday alongside a joint advisory by four South Korea…DATABREACHES.NET
31 JulGoogle AI Supercharges Chrome Security, Fixing 1,072 BugsGoogle says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipelin…SECURITYAFFAIRS.COM
31 JulElastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las VegasAttack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.ELASTIC.CO
31 JulIn Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto ResearchNoteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research appeared fi…SECURITYWEEK.COM
31 JulHacker uses DeepSeek AI to autonomously attack vulnerable serversA Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]BLEEPINGCOMPUTER.COM
31 JulRESOURCE: Thomson Reuters Foundation provides free resources and legal help for independent media around the worldFrom the Thomson Reuters Foundation, a welcome email describes the situation in South Africa and then turns to global support: I’m getting in touch to share some new reports and resources to support media freedom work in East and Southern Africa. Journalists who hold power to acc…DATABREACHES.NET
31 JulWeaponizing Exposed DataLab-1 Dark-web Research Team Contributors:Alex Necula, Anastasia Sentasnova, Ellis Stannard, Jeffrey Bell, Manuel Boll, Valéry Rieß-Marchive Mannie W writes: Ransomware and data-extortion groups are moving beyond bulk dumps to analyze, index and price stolen data before it is pub…DATABREACHES.NET
31 JulRansomware in Italy: RedACT report sheds light on an evolving threat environmentSuspectFile has published a great interview with the people behind RansomNews.online: Within this context, the first RedACT H1 2026 report, published by ransomNews.online, represents a valuable contribution to the analysis of ransomware activity targeting Italy. The project prese…DATABREACHES.NET
31 JulClaude outside the lines.Anthropic says Claude escaped the sandbox three times, while a judge questions the Pentagon’s blacklist. The EU launches an AI enforcement team, the FTC targets a telehealth firm’s tracking pixels, and a WordPress backdoor is stopped just in time. CareCloud discloses a major data…THECYBERWIRE.COM
📢 SECURITY ADVISORIES 9[−]
31 JulClaude escaped the testing sandbox three times.EU launches new team to monitor AI compliance.THECYBERWIRE.COM
31 JulCISA warns of cyberattacks disrupting U.S. water utilitiesThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...]BLEEPINGCOMPUTER.COM
31 JulCISA warns of spike in attacks on water systems as Minnesota incidents probedThe Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."THERECORD.MEDIA
31 JulHIPAA Security Rule on AWS – Technical Safeguards Implementation and Readiness GuidanceToday, we’re releasing the HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance. This helps covered entities and business associates configure, implement, and evidence compliance with the HIPAA Security Rule Technical Safeguard requirements (45 C…AWS.AMAZON.COM
31 JulCISA Issues Fresh SBOM Guidance. Did They Get It Right?A couple-dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.DARKREADING.COM
31 JulSouth Korea Warns of State-Backed Watering Hole AttacksSouth Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Sec…SECURITYAFFAIRS.COM
🔥 INCIDENT REPORTING 13[−]
31 JulAnthropic says its AI accidentally hacked three companies during safety testsFollowing OpenAI’s own incident, Anthropic reviewed its own evaluations and found three cases of Claude hacking external companies. The post Anthropic says its AI accidentally hacked three companies during safety tests appeared first on CyberScoop .CYBERSCOOP.COM
31 JulAnthropic Says Claude Hacked 3 Organizations During Cybersecurity TestsIn a review triggered by OpenAI’s Hugging Face incident, Anthropic discovered three of its AI models had breached real organizations during third-party evaluations.WIRED.COM
31 JulRisky Bulletin: Crime Stoppers puts bounty on INC ransomware groupA non-profit puts a $22,000 bounty on the INC ransomware group, hackers breach the UK Department for Education, Russia charges Telegram founder Pavel Durov, and the FCC bans foreign robots and power inverters.RISKY.BIZ
31 JulCareCloud Data Breach Impacts Over 350,000In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment. The post CareCloud Data Breach Impacts Over 350,000 appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulAnthropic Reveals Claude Escaped Testing, Breaching Three CompaniesAnthropic has revealed that Claude AI models broke free of sandbox to compromise third-party organizationsINFOSECURITY-MAGAZINE.COM
31 JulPrompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 OrganizationsA security company’s systems were hacked after it installed a malicious Python package deployed by Claude. The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulAnthropic says its AI hacked real-world companies in three incidentsClaude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet.THERECORD.MEDIA
31 JulESET tracks rise in malicious AI skills and adaptable malwareAttackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to d…BLEEPINGCOMPUTER.COM
31 JulCyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian HackersIran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulTrump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber worldThe president went against his intelligence agencies’ conclusions about Iran being the likely suspect in the campaign. The post Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world appeared first on CyberScoop .CYBERSCOOP.COM
31 JulRogue AI, the Bar, Breaches, BMC, Hugging Face, Helmuth von Multke, Ike, Shieldfont, - SWN #603Rogue AI, the Bar, Breaches, BMC, More Hugging Face, Helmuth von Multke, Ike, Shieldfont, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-603YOUTUBE.COM
31 JulOnline ad firm Adform’s script compromised to steal cryptocurrencyOnline advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]BLEEPINGCOMPUTER.COM
31 JulAmgen says cloud data breach exposed patient health, proprietary infoPharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 21[−]
31 JulISC Stormcast For Friday, July 31st, 2026 https://isc.sans.edu/podcastdetail/10032, (Fri, Jul 31st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
31 JulNew infosec products of the week: July 31, 2026Here’s a look at the most interesting products from the past week, featuring releases from BlackCloak, Contrast Security, Dropzone AI, PortSwigger, Realm Security, Reco, Root Evidence, and ZeroFox. BlackCloak extends deepfake protection to the executive’s trusted circle Deepfakes…HELPNETSECURITY.COM
31 JulAI agents are changing where cybersecurity seed funding landsFounders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer. Product Hunt launches hit their highest level since late 2023 last quarter, and the Census Bureau’s count of high-propensity business applications kept climbing. Seed deal…HELPNETSECURITY.COM
31 JulAttackIQ targets CTEM execution with AVA Agentic OSAttackIQ has announced AVA Agentic OS, an agentic operating system designed to operationalize Continuous Threat Exposure Management. CTEM has emerged as the strategic framework for managing cyber risk, yet many organizations continue to struggle to operationalize CTEM across frag…HELPNETSECURITY.COM
31 JulTraefik Labs introduces Distro Zero secure runtime for API and AI gatewaysTraefik Labs has introduced the Distro Zero image, a hardened, vendor-supported secure runtime delivered as Traefik Hub in proxy mode. It gives platform and security teams a container whose entire executable content is a single memory-safe binary, with validated cryptography buil…HELPNETSECURITY.COM
31 JulAWS Blames North Korean Group for Axios and Other npm Supply Chain AttacksAWS has linked North Korea to the axios campaign to other attacks on npm librariesINFOSECURITY-MAGAZINE.COM
31 JulThe Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET VersionAnalysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
31 JulGoogle AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching PaceThe internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase. The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek .SECURITYWEEK.COM
31 JulIf you’re going to vibe code it, why not vibe pen test it?TL;DR Why I built PenAI PenAI started as a project at a hackathon organised by Encode Club. It’s an AI agent that could work through Hack The Box-style lab machines on its own. Upload a VPN file, give it a target IP, pick a scope, set stealth mode and iteration limits, hit …PENTESTPARTNERS.COM
31 JulOVHcloud charged in Canada over customer data production orderOVHcloud says it will vigorously contest criminal charges filed in Canada after authorities accused the company of failing to comply with a court-ordered demand for subscriber information tied to servers hosted outside the country. In an announcement published today, OVH Groupe S…CYBERINSIDER.COM
31 JulCybercrime goes subscription: AI, malware and infrastructure on demandCybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribut…HELPNETSECURITY.COM
31 JulGoogle adds to confusion with new names for threat actorsGoogle is creating a new naming scheme for the bad actors behind cybersecurity threats, hoping that it will help to standardize the way that attacks are reported. Spoiler: It won’t. Security researchers use these naming schemes so that they can attribute attacks without necessari…CSOONLINE.COM
31 JulThe $150 AI Attack ShortcutSome threat actors are reportedly packaging AI prompt injection techniques into subscription services. The discussion argues that the underlying method isn't especially difficult, yet people are still willing to pay for it. IMPLICATION That suggests the real product may not be te…YOUTUBE.COM
31 JulDefCon security conference bans smart glasses with recording capabilitiesIt’s a sign of the times: Security conference DefCon has added smart glasses to its list of banned audio- or video-recording devices . The organizers have said that, with no consistent way to understand whether smart glasses are recording or not, they have taken the step to ban t…CSOONLINE.COM
31 JulAnthropic says human error let Claude AI models escape test environment and hack third partiesThe company said its discovery, which followed OpenAI’s similar admission, proved the need for better testing guardrails.CYBERSECURITYDIVE.COM
31 JulUS authorities see ‘significant escalation’ in attacks on water system devicesHackers have locked operators out of their own OT networks, modified passwords and changed IP addresses.CYBERSECURITYDIVE.COM
31 JulAnthropic’s Opus 5 Is Better at Resisting Prompt InjectionThe chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it t…SCHNEIER.COM
31 JulKate Robertson on the Risks That Lie Behind Canada’s Unexpected Signing of the UN Cybercrime ConventionEarlier this month, the Canadian government announced that it had signed the United Nations Convention against Cybercrime. Speaking with Michael Geist of Law Bytes, senior research associate Kate Robertson argues that the convention is a cross-border surveillance and electr…CITIZENLAB.CA
31 JulFriday Squid Blogging: Squid Helps Discover New Marine SpeciesThe Squid is a new scientific machine : One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world…SCHNEIER.COM
31 JulDon't Give Everyone AI AgentsAs agentic AI becomes more capable, organizations are beginning to explore giving AI systems greater autonomy to complete tasks. The discussion argues that these systems should be treated as powerful tools that require governance rather than being deployed broadly without oversig…YOUTUBE.COM
31 JulCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftStorm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call Ca…MICROSOFT.COM
🌐 CYBER THREAT LANDSCAPE 3[−]
31 JulFake Flash Player installs AtlasRATResearchers have uncovered a new campaign that spreads the AtlasRAT remote access Trojan by disguising it as a Flash Player installer.MALWAREBYTES.COM
31 JulHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link …THEHACKERNEWS.COM
31 JulArch Linux disables AUR package adoption to stop malware floodThe Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]BLEEPINGCOMPUTER.COM
📡 INFOSEC NEWS 15[−]
31 JulSilverFox Targets Japanese Manufacturer With Advanced ValleyRAT CampaignSilverFox targeted a Japanese manufacturer with new DLL sideloading techniques, kernel drivers, and resilient ValleyRAT persistence mechanisms. Cato CTRL documented a new SilverFox campaign targeting a Japanese industrial manufacturer. The attack chain adds two previously undocum…SECURITYAFFAIRS.COM
31 Julzipdump.py: Metadata Encoding, (Fri, Jul 31st)I was asked for help with a problem similar to the following.
ISC.SANS.EDU
31 JulNetwork Anomaly Detection in KATAAn analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.SECURELIST.COM
31 Jul6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the dev…THEHACKERNEWS.COM
31 JulThe $5 million threat: AI Is supercharging phishing attacksAccording to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.FORTRA.COM
31 JulUSA Fencing Lunges Into the Hidden Identity Challenge in Amateur SportsThe organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.DARKREADING.COM
31 JulWhat an LLM Can Find: A Practical, Cheap Path to Code-level Threat DiscoveryAn AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature whistleblowing platform that had already undergone six independent professional audits over the past thirteen years, was subjected t…SECURITYAFFAIRS.COM
31 JulThe Morning After We Pull a Root of Trust, Nobody Owns ItThe most valuable move any security team can make is building a certificate and key inventory.DARKREADING.COM
31 JulDROP Platform Lets Californians Reduce Digital FootprintThe Delete Request and Opt-out Platform (DROP) launches Aug. 1 and hundreds of thousands of California residents already registered. Other states could follow if the process goes smoothly.DARKREADING.COM
31 JulThree Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates CombinedGoogle on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, re…THEHACKERNEWS.COM
31 JulCheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into ProxiesBitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo…THEHACKERNEWS.COM
31 JulFake Fortnite rewards are stealing players’ accountsScammers are using fake V-Bucks offers and locker value sites to hijack Fortnite accounts.MALWAREBYTES.COM
31 JulCyber Command plans Silicon Valley office to drive innovationThe outpost will have its own director, though no one has yet been named for the post, and support the command’s nascent Cyber Warfare Innovation Center (CIWC).THERECORD.MEDIA
31 JulOpenAI says its new GPT 5.6 models are becoming more cost-efficientOpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. [...]BLEEPINGCOMPUTER.COM
31 JulClaude published malicious code to the Internet and attacked 3 real companiesHad the hacks used conventional methods, someone would likely go to prison.ARSTECHNICA.COM