Technology Intelligence
Threats against technology companies, software vendors, cloud services, and tech infrastructure.
Patelco Credit Union invests in Payfinia CUSO
Payfinia, an independent payment services firm providing an open payments framework, today announced a strategic partnership with Dublin, Calif.-based Patelco Credit Union (‘Patelco’ – $9.5 billion in assets and more than 550,000 members), marked by the credit union’s investment* in the Payfinia Credit Union Service Organization (CUSO).
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per
Zero-Day Remediation Meets Operational Resiliency
Executive Summary In the Frontier AI era, the number of CISA-known exploited vulnerabilities has increased by 6.5x over the past four years, and time-to-exploitation has collapsed to -7 days. Traditional monthly patch cycles cannot keep up. Organizations need a new operating model that detects at AI speed, hyper-prioritizes truly exploitable exposures, and remediates immediately. TruRisk […]
Chinese Actor Weaponizes DeepSeek AI Agent to Attack Security Firm
Researchers intercepted and investigated the model, which was attempting to compromise more than 1,200 hosts for proxyjacking to launch further attacks.
Agent Val Now Validates the Entire Attack Surface: From Network to Host
Powered by TruConfirm — Exploit Validation That Now Runs on the Network and the Host Executive Summary Qualys TruConfirm now validates exploitability across the entire attack surface, not just the network. Cloud Agent-Based TruConfirm brings the same proof-based validation model to the endpoint, closing the gap on local, kernel, browser, and post-authentication CVEs that network […]
Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion
The payments giant says BioCatch’s behavioral and device intelligence will help financial institutions combat account takeovers, scams and other forms of digital fraud. The post Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion appeared first on SecurityWeek .
CFTC fines UBS $8 million for AML failures
The Commodity Futures Trading Commission today announced an order filing and settling charges against UBS Financial Services Inc., a registered futures commission merchant, for failing to diligently supervise the configuration and operation of its anti-money laundering transaction monitoring systems for wire transfers denominated in foreign currencies (FX).
Mastercard closes acquisition of BVNK
Mastercard (NYSE: MA) today completed its acquisition of BVNK, expanding the company’s strategy to support greater choice in how people and businesses exchange value by enabling interoperability across fiat and digital currencies.
Free HIPAA Security Risk Assessment
A HIPAA security risk assessment assesses threats to the privacy and security of PHI, the likelihood of a threat occurring, […] The post Free HIPAA Security Risk Assessment appeared first on The HIPAA Journal .
ExfilSquad hackers leak info of over 100,000 UK police officers, staff
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. [...]
China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day
Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure
Metasploit Pro 5.1 Released
Today marks the release of Metasploit Pro 5.1 - building upon the foundation laid in 5.0, adding new evasion primitives for HTTP Meterpreter payloads, support for tracking service hierarchies, a deeper and more interactive Network Topology view, and continuing our commitment to a modern, consistent UI. This release is powered by Metasploit Framework 6.5 . Malleable C2 Profiles One of the most requ
Inside the Underground Business of BTMOB RAT
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]
Inside the Underground Business of the Android BTMOB RAT malware
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]
Midnight Blizzard Targets Travelers via Captive Portals
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens
Infinios goes live with Mastercard on stablecoin settlement
INFINIOS, the Bahrain‑based digital financial infrastructure company, today announced that it is officially live with Mastercard on stablecoin settlement, marking a major milestone in the evolution of regulated digital payments in the Middle East.
NVD CRITICAL: CVE-2026-69085 — SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree...
SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader token, or unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. Because the statement exec
NVD CRITICAL: CVE-2026-69084 — SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, whic...
SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. The endpoint is gated only by CheckAuth, making it reachable by the publish RoleReader token and by anonymous users when publish authentication is disabled. Because the u
NVD CRITICAL: CVE-2026-69083 — SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullT...
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data.
NVD CRITICAL: CVE-2026-64827 — Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x...
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP s
NVD CRITICAL: CVE-2026-18601 — A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the fun...
A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a manipulation of the argument filename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from
Is There Really a Fix for CISO Fatigue?
Accountability without any real authority is driving CISO burnout, and organizations need to take notice.
Visa agrees $2.4 billion deal to acquire BioCatch
Visa is buying Israeli behavioural biometrics company BioCatch from funds advised Permira for $2.4 billion in cash.
FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices
Him & Hers, a San Francisco, CA-based telehealth company, is being sued by the Federal Trade Commission (FTC) and the […] The post FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices appeared first on The HIPAA Journal .
AmGen Announces Cyberattack and Data Breach Involving Patient Data
Amgen Inc., a Thousand Oaks, CA-based biopharmaceutical company that develops and manufactures pharmaceutical products for oncological, hematological, and cardiovascular diseases, […] The post AmGen Announces Cyberattack and Data Breach Involving Patient Data appeared first on The HIPAA Journal .
CISA Issues Updated Guidance on Minimum Elements of an SBOM
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), and 15 international […] The post CISA Issues Updated Guidance on Minimum Elements of an SBOM appeared first on The HIPAA Journal .
Robinhood wins FCA approval to launch in the UK
Robinhood has received authorisation from the Financial Conduct Authority to begin offering crypto services in the UK.
NVD CRITICAL: CVE-2026-2346 — Authorization bypass through User-Controlled key vulnerability in Menulux Softwa...
Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affects Mobile App: through 12.05.2026.
NVD HIGH: CVE-2026-18598 — A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected elem...
A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC plugin. The manipulation of the argument module results in command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this d
River Bank Says Hackers Deleted Data Stolen in Ransomware Attack
The bank holding company was hacked in June, but the investigation into the incident continues. The post River Bank Says Hackers Deleted Data Stolen in Ransomware Attack appeared first on SecurityWeek .
An analysis of incidents at Brazilian educational institutions
Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.
Horizon3 Raises $250 Million to Fund Continuing Growth
Venture financing has become an essential factor in growing new business in today’s fast moving economy. Horizon3’s latest funding explains how and why. The post Horizon3 Raises $250 Million to Fund Continuing Growth appeared first on SecurityWeek .
Zero Networks targets AI agent security gaps with network-level ‘Least Agency’ controls
While AI security today is largely focused on restricting what an agent can do, Zero Networks says it has built a failsafe. The company says it can block a compromise midway by adding a network layer protection. On Monday, the company announced the launch of “Least Agency Enforcement,” a new capability designed to implement the Open Worldwide Application Security Project’s ( OWASP ) emerging Least
Say Hello to Agent Insta: Closing the Detection Gap in Exposure Management at Machine Speed
Executive Summary Frontier AI has turned CVE weaponization timelines to hours, making scan-bound detection a growing compliance and breach-risk challenge. Agent Insta powers InstaScan to deliver scanless detection by transforming existing inventory, telemetry, and threat intelligence into validated exposure findings within minutes of disclosure. Operating 24/7, InstaScan enables AI-speed detection
Biotech giant Amgen says patient data stolen from third-party cloud systems
The biotech giant Amgen informed regulators that patient information and proprietary company data were accessed through a breach of third-party cloud systems.
N‑able Patches Vulnerability Exploited to Hack N-central Servers
The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass. The post N‑able Patches Vulnerability Exploited to Hack N-central Servers appeared first on SecurityWeek .
KR: Seoul lawmaker criticizes 5,000-won compensation for 4.62 million-person data breach
The Herald Business reports: Seoul Facilities Corp. has drawn criticism over its plan to offer 5,000 won [$3.50 USD] per affected user in response to a personal data breach involving about 4.62 million people, with questions mounting over whether the compensation is adequate. Seoul Metropolitan Council member Im Gyu-ho of the Democratic Party of Korea... Source
UK: Details of 100,000 police staff leaked on the dark web after hack
Bill Curtis reports: The full names and contact details for more than 100,000 police officers and staff have been leaked on the dark web after a hack, The Times can reveal. As part of a major security breach, hackers compromised data belonging to the Ministry of Defence (MoD), the Home Office, National Crime Agency (NCA),... Source
Cyberattack hits Liechtenstein, with 31,000 records stolen
DPA reports: The tiny principality of Liechtenstein has fallen victim to a major cyberattack in which the data of 31,000 people were stolen, the government said on Sunday. The country, which lies between Switzerland and Austria, has a population of around 41,000. The government said it had convened a crisis team led by Prime Minister... Source
Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers' login credentials and infect devices with espionage malware, Microsoft said.
Brinks Home Discloses Data Breach as Hackers Leak Files
The physical security firm says its alarm monitoring and system functionality have not been affected. The post Brinks Home Discloses Data Breach as Hackers Leak Files appeared first on SecurityWeek .
FOMO in the SOC: Where AI Platforms like Claude Actually Fit
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs in the SOC, to where each type of AI delivers the most value. With so many new AI
HollowFrame Loader Uses Fake Python DLL to Evade Defender
New HollowFrame loader hid Go code in a fake Python DLL after pre-staging Defender exclusions
BBVA acquires SocGen's 50% stake in brokerage joint venture Altura Markets
BBVA has reached an agreement with Société Générale (SG) to integrate Altura Markets into the BBVA Group by acquiring the 50 percent stake currently owned by the French bank, becoming the company's sole shareholder. The transaction is subject to the relevant regulatory approvals.
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit. "
The OpenAI Hack Shows the Genie Is Out of the Bottle
This essay originally appeared in Foreign Policy . Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild . OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how g
FCA streamlines transaction reporting obligations
Transaction reporting requirements become smarter, simpler and more proportionate under new rules from the FCA.
Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement. The post Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks appeared first on SecurityWeek .
Santander embeds eSim package within mobile app
Banco Santader customers in Spain can now purchase and activate mobile data for roaming abroad, directly in the bank's mobile app.
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor. The post Pass the Passkey: A Novel Attack Surface in Passwordless Authentication appeared first on Unit 42 .
Egypt's One Zero Bank opens up to AIagents
The initiative will allow customers to bring their financial information into the conversational and work environments they already choose to use - initially ChatGPT and Claude, followed by additional tools and agents - and receive trusted financial information, insights and, in the future, real-time execution capabilities.
Mastercard strengthens Asia Pacific leadership team
Mastercard today announced that Joyce Bo has joined the company as Executive Vice President, Core Payments, Asia Pacific.
Korea’s Largest Telco KT Fined $38m After Femtocell Campaign
Korean telco KT has been fined $39m for a year-long breach linked to femtocell compromise
AutoRek acquires Grath
AutoRek, the leader in enterprise financial controls and reconciliation automation, today announced the acquisition of Grath, an innovative fintech recognised for its AI-driven approach to reconciliation and compliance challenges in financial services.
Ripple invests in UK digital assets platform Licuido
Capital markets tokenization platform Licuido has secured a strategic investment from Ripple to scale its operations and support the development of digital capital markets infrastructure on the XRP Ledger (XRPL).
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations. The post Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking appeared first on SecurityWeek .
PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident, identified on July 26, also exposed some names
Stop depending on heroics and start operationalizing third-party risk
In cybersecurity, third-party risk management normally looks simple on paper: evaluate your vendor, learn the risk, report out on the gaps and weaknesses, transfer to the contract, and continue. Unfortunately, it seldom works that way in practice. In my roles as a CISO, I find my teams in an intermediary position as the compliance and cybersecurity expert between the end-user purchaser and the ven
US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers. The post US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States appeared first on SecurityWeek .
Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked
A hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy bug
AI is making cybersecurity fundamentals more important than ever
When OpenAI disclosed that one of its models escaped a test environment and broke into Hugging Face’s systems on its own, headlines cast the incident as the start of a new era of AI-driven attacks. But the underlying cause of the incident was a familiar one: a misconfigured sandbox — the same kind of fundamental security failure that has enabled breaches for decades, with or without AI. AI systems
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as CVE-2026-17583 and rates it
Rapid7 Expands UK and Ireland Channel Presence Through Strategic Partnership with Exclusive Networks
Ross Baker is Senior Director, Northern Europe at Rapid7. As organizations across the United Kingdom and Ireland embrace AI, cloud technologies, and digital transformation in the name of enhancing customer experiences and accelerating business growth, the cybersecurity landscape must continue to evolve just as quickly. In this environment, business leaders still expect security to enable innovatio
NVD CRITICAL: CVE-2026-18589 — A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the...
A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very prof
NVD CRITICAL: CVE-2026-18588 — A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affect...
A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed v
NVD HIGH: CVE-2026-18587 — A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element...
A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of the argument Password can lead to os command injection. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is regarded as difficult. The exploit has been published and may be used. I
CrowdStrike: AI is now both the weapon and the target in cyberattacks
AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them. The post CrowdStrike: AI is now both the weapon and the target in cyberattacks appeared first on CyberScoop .
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. N-central is the remote monitoring and management platform
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. "These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the
Welcoming the Nepalese Government to Have I Been Pwned
Today, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Centre now has access to monitor Nepalese government domains against the data in HIBP. This gives the NCSC the ability to identify exposure across government email addresses and
CareCloud Notifies More Than 345,000 Patients About Cyberattack Data Theft
CareCloud Inc., a Somerset, New Jersey-based provider of cloud-based and AI-powered EHR, RCM, PM, and clinical documentation solutions, has determined […] The post CareCloud Notifies More Than 345,000 Patients About Cyberattack Data Theft appeared first on The HIPAA Journal .
Patients Warned About AnMed Communications After Cyberattack Closes 83 Facilities
The Anderson, South Carolina-based nonprofit health system AnMed said it is continuing to make progress restoring its systems after a […] The post Patients Warned About AnMed Communications After Cyberattack Closes 83 Facilities appeared first on The HIPAA Journal .
Weekly Update 515
Apparently, Aussies are so obsessed with coffee that it's referred to as the coffee capital of the world down here (some bits, at least). "But what about Italy?" people ask. Having spent a lot of time in a lot of Italy, no, it's just
BofA to buy UK cybersecurity firm MDSec Consulting
Bank of America is acquiring UK-based information security specialist MDSec Consulting as it bids to boost its in-house cyber defences.
Partior and OpenAssets PoC proves stablecoins and tokenised deposits can settle atomically
Bank-backed global settlement infrastructure platform Partior and digital asset infrastructure provider OpenAssets say that they have completed a joint proof of concept demonstrating atomic delivery-versus-payment between digital assets, regulated stablecoins, and commercial tokenised deposits.
OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems
OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. [...]
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]
NVD CRITICAL: CVE-2026-65321 — PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unau...
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape char
Google Chrome may soon block New Tab hijacker extensions by default
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]
A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach
They advertised and pinky swore “no logs.” But according to research by MysteriumVPN, they logged. Key takeaways from MysteriumVPN: A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database they claim was stolen from SplitVPN (formerly NotVPN), a Russian VPN used to bypass internet blocks. The Mysterium research team obtained... Source
Brinks Home Confirms Data Breach Following ShinyHunters Claim
Guru Baran reports: Brinks Home, one of North America’s largest residential security providers, has confirmed that hackers breached its IT systems after the notorious ShinyHunters extortion group claimed responsibility for stealing nearly five million records tied to the company’s Salesforce environment. The confirmation comes after the threat actors listed “BH Security, LLC (brinkshome.com)” on t
TN: Sumner County Schools provides limited update on data breach
Abbey Nutter reports: Sumner County Schools is still working through a reported network breach that forced the district to delay the start of the 2026-27 school year, officials told Main Street Media. The district reported the data breach during a meeting of the Sumner County Board of Education on July 21, one day after the... Source
NVD HIGH: CVE-2026-68580 — FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio inp...
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all pl
NVD CRITICAL: CVE-2026-68579 — FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the W...
FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStream_Read requests file contents from the RDP server and then copies the response into the caller's buffer using the serv
NVD HIGH: CVE-2026-68578 — ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the ...
ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.
NVD HIGH: CVE-2026-67357 — ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability ...
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and achieve full server compromise.
NVD HIGH: CVE-2026-67356 — ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigg...
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.
NVD HIGH: CVE-2025-71400 — better-auth passkey versions before 1.4.0 contain an insecure direct object refe...
better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys.
NVD CRITICAL: CVE-2026-8457 — The WooCommerce - Social Login plugin for WordPress is vulnerable to Authenticat...
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or validating the issuer, audience, or expiry claims, combined with the security nonce r
NVD HIGH: CVE-2026-18352 — The User Access Manager plugin for WordPress is vulnerable to Directory Traversa...
The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. This is possible because when attachment_url_to_postid() returns 0 for a traversal
NVD HIGH: CVE-2026-13339 — The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal i...
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. This is exploitable by unauthenticated attackers because the required nonce is publi
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG
Sixth Circuit to Rehear Case on FCC Data Breach Rules Case
Jake Neenan reports: A full panel of federal judges will rehear a case that upheld expanded telecom data breach rules. The Federal Communications Commission, now under Republican control, has indicated it’s likely to reverse the rules anyway. But industry groups and GOP lawmakers want the case’s precedent gone too. They told judges on the U.S.... Source
The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.
Miguel Gomez reports: The biopharmaceutical company Diater, founded in Madrid in 1999, has appeared on the list of victims that the ransomware group DeadLock is disseminating on the dark web. The intrusion affects a company that manages particularly sensitive information of patients and healthcare professionals. The contrast lies in the type of data compromised and... Source
Rails patches critical Active Storage flaw with RCE potential
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]
Suspected cyberattack disrupts Oceanside, California, school district systems
DysruptionHub reports: A suspected cyberattack disrupted work email, internet access, Google Drive and other applications at Oceanside Unified School District in California as officials investigated and worked to restore service. The district confirmed a computer network disruption but did not identify its cause. NC Pipeline reported that a separate district text described the incident as a cybera
AU: GO2 Health medical clinic in Brisbane waited almost three months to alert patients it was hacked
Will Murray reports: Another medical clinic has revealed it has been targeted by hackers, less than a week after Partnered Health announced a major data breach. GO2 Health in Everton Park, in Brisbane’s north, said the clinic’s main email mailbox was accessed in April after a phishing attack. It wasn’t until almost three months later... Source
Mon General Hospital notifies patients of phishing attack and breach
WDTV reports: Monongalia County General Hospital Company, known as Mon General, announced it was recently the victim of a phishing attack that may have compromised the personal and medical information of some patients. Hospital officials say the incident was discovered on May 6, when they identified that a phishing attack had targeted a small number... Source
NVD HIGH: CVE-2026-67352 — luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in...
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes JavaScript in the administrator's browser origin.
NVD HIGH: CVE-2026-67343 — ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the...
ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and execute administrative actions including user creation, database operatio
NVD CRITICAL: CVE-2026-67342 — ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in...
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by directly calling affected endpoints with arbitrary database parameters.
NVD CRITICAL: CVE-2026-67341 — ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks o...
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to administrators.
NVD CRITICAL: CVE-2026-67340 — ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host ...
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can create a JavaScript trigger that invokes java.lang.Runtime.getRuntime().exec() (or ProcessBuilder), achieving OS command execution when the trigger fires
NVD HIGH: CVE-2026-67336 — better-auth versions before 1.6.11 contain insecure cryptographic defaults in th...
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned tokens or intercept authorization codes when PKCE plain is used instead of the required S256 method.
NVD HIGH: CVE-2026-67333 — better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-bet...
better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp plugin (which wraps the same provider). An attacker can register an OAuth client with a javascript: redirect_uri, which the authorization server later returns unchanged in the consent response. If the deploy
NVD HIGH: CVE-2026-67331 — better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organi...
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalidate legitimate tokens, and authenticate to SCIM API routes with the attacker-controlled token.
NVD CRITICAL: CVE-2026-67330 — @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1....
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social account providers, and the same logical provider ID was used for both SCIM provider configuration and account ownership. An
NVD HIGH: CVE-2026-67329 — @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1...
@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference callback, but the handler reads the organization ID only from the request body and falls back to the caller's active organiz
NVD HIGH: CVE-2026-67328 — @better-auth/sso versions before 1.6.21 contain multiple authentication bypass v...
@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned provider accounts, unbound SAML assertions, or reflected XSS on logout endpoints to gain unauthorized session access and account takeover.
NVD HIGH: CVE-2026-67327 — better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-be...
better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is enabled. An attacker registers an account with the victim's email address and an attacker-chosen password; the account remains unverified. When the legitima
NVD HIGH: CVE-2026-67326 — GitPython before 3.1.50 fails to validate newline characters in the section para...
GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.
NVD HIGH: CVE-2026-67325 — GitPython before 3.1.51 contains an incomplete command injection blocklist that ...
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p instead of upload_pack, which git resolves to dangerous options and executes arbitrary commands.
NVD CRITICAL: CVE-2026-67324 — GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> ...
GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi_options=..., allow_unsafe_options=False), an attacker can supply -u<helper> to bypass the gate that blocks --upload-pack/-u, causing Git t
NVD HIGH: CVE-2026-67323 — GitPython before 3.1.51 fails to guard against dangerous Git options passed as k...
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). Additionally, Repo.iter_commits() and Repo.blame() do not check for leading-dash revision arguments, so a revision like --output=<path> can cause Git to o
NVD HIGH: CVE-2026-67322 — GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Re...
GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking git clone. An attacker who controls the clone URL can embed $NAME or ${NAME} tokens that are expanded to the values of the hosting process's environment
NVD CRITICAL: CVE-2026-67308 — Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub...
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are directly interpolated into run steps, enabling command execution and exfiltration of secrets including GITHUB_TOKEN and
NVD HIGH: CVE-2026-67304 — FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart...
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-state data to crash the process via null pointer access in free_reader_states functions.
NVD HIGH: CVE-2026-67301 — FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async u...
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and update_message_PolygonCB() allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points /
NVD HIGH: CVE-2026-67300 — FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities i...
FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends crafted update orders, the message proxy shallow-copies structures containing nested parser-owned pointers (e.g., titleInfo.string, windowRects, visibili
NVD HIGH: CVE-2026-67299 — FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async up...
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a freshly allocated lParam->iconInfo with the parser-owned windowIcon->iconInfo pointer. After the parser callback returns, update_recv_window_info_order()
NVD HIGH: CVE-2026-67298 — FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server...
FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_LENGTH from the peer-controlled orderLength field without first verifying orderLength is at least the header length. For orderLength values 0..3 this caus
NVD HIGH: CVE-2026-67297 — FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing T...
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.
NVD HIGH: CVE-2026-67296 — FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI se...
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.
NVD HIGH: CVE-2026-67291 — FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bound...
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes.
NVD HIGH: CVE-2026-67290 — FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TS...
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a crash by reading fixed offsets without validating source buffer length.
NVD CRITICAL: CVE-2026-67289 — FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and c...
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client connects through an HTTP proxy, is written directly into the proxy CONNECT request line and Host header by http_proxy_connect() without filtering. A malicious or
NVD HIGH: CVE-2026-67288 — FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart...
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process
NVD CRITICAL: CVE-2026-66402 — FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certif...
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's length-aware identity validation APIs, it (1) truncates DNS SAN values at embedded NUL bytes (accepti
NVD HIGH: CVE-2025-71403 — better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrig...
better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. Attackers can construct malicious callbackURL parameters that pass origin checks and trigger open redirects to steal sensitive tokens for account takeover.
Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments
The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek .
Ruby on Rails Patches Critical Vulnerability
The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek .
System Announcement: Maintenance
DataBreaches.net will be undergoing some maintenance and upgrades this weekend and may be unavailable at times. We’ll be back, though! Thank you for your patience. Source
NVD HIGH: CVE-2026-16635 — The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in a...
The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly into `WP_User::set_role()` without any allowlist validation, capability comparison, or permission check to constrain whic
NVD HIGH: CVE-2026-16144 — The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vu...
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This
NVD CRITICAL: CVE-2026-15964 — The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication ...
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopriv_ssoprocess_ajax` and therefore reachable without authentication — accepting an attacker-supplied `email` parameter with the `setnewpassword` operation an
NVD HIGH: CVE-2026-15450 — The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable ...
The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no realpath(), basename(), or allowlist check), combined with the insert_record() AJAX han
NVD HIGH: CVE-2026-15052 — The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin ...
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesse
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Anyone who visited a site carrying the affected script on July 27 and copied a Bitcoin,
NVD HIGH: CVE-2026-15988 — The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPre...
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to create new administrator accounts with attacker-supplied credentials via a CSRF-ba
Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as
NVD CRITICAL: CVE-2026-3141 — The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file d...
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authentication middleware in routes/rest/api.php. This makes it possible for unauthenticated attackers to
NVD HIGH: CVE-2026-15414 — The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privileg...
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only validations applied, `sanitize_key()` and `wp_roles()->is_role()`, both accept `'ad
NVD HIGH: CVE-2026-15006 — The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email...
The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
AMGEN reports breach to SEC
From Amgen’s filing on July 29 to the Securities and Exchange Commission: Item 1.05 Material Cybersecurity Incidents. In July 2026, Amgen Inc. (the “Company”) identified unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers. Upon detecting the activity, the Company activated its cybersecurity response plan, implemented con
NVD HIGH: CVE-2026-34641 — Premiere Pro is affected by an out-of-bounds write vulnerability that could resu...
Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
US CISA Urged to Order OT Security Improvements
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/us-cisa-urged-to-order-ot-security-improvements-image_small-8-a-32395.jpg" align=right hspace=4><b>Minnesota Water System Hacks Should Be Call to Action, Says OTCC</b><br>The U.S. Cybersecurity and Infrastructure Security Agency should order federal agencies to secure operational technology to head off hacks like those blamed on I
Anthropic, OpenAI AI Sandbox Failures Expose Testing Risks
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/anthropic-openai-ai-sandbox-failures-expose-testing-risks-image_small-10-a-32394.jpg" align=right hspace=4><b>Human Errors Let Frontier AI Models Reach Beyond Isolated Test Environments</b><br>Anthropic disclosed that three Claude models breached intended testing boundaries after human configuration mistakes while OpenAI previousl
Okta Buys Permiso to Extend ITDR Beyond Native Identity Logs
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/okta-buys-permiso-to-extend-itdr-beyond-native-identity-logs-image_small-3-a-32393.jpg" align=right hspace=4><b>Customers Gain Broader Identity Telemetry Across Cloud and Directory Services</b><br>Okta said its planned acquisition of Permiso will expand identity threat detection beyond native Okta telemetry by adding thousands of
North Korea’s APT Capabilities Are No Longer State-Exclusive
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/north-koreas-apt-capabilities-are-no-longer-state-exclusive-image_small-9-a-32392.jpg" align=right hspace=4><b>AhnLab Found Shared Malware, SSH Keys and Infrastructure Across Two Campaigns</b><br>Shared malware, infrastructure and access methods link Lazarus Group to Gunra ransomware activity, while former North Korean military ha
NVD CRITICAL: CVE-2026-68771 — ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrai...
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt ref
Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...]
DentaQuest Data Theft Hack Affects 15M Patients
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/dentaquest-data-theft-hack-affects-15m-individuals-image_small-5-a-32390.jpg" align=right hspace=4><b>Number of Victims Is 5 Times Higher Than Claims by ShinyHunters Ransomware Gang</b><br>Dental and vision benefits administrator DentaQuest is notifying 15 million patients that their information was compromised in a May hack. The
How AI Can Strengthen Public Health Response
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/how-ai-strengthen-public-health-response-image_small-3-a-32389.jpg" align=right hspace=4><b>Lucy Orr-Ewing of CHAI Discusses Effort to Advance Responsible Public Health AI Use</b><br>While many public health agencies may want to use AI, they often lack resources, tech knowledge and security guidance. A new pilot program will provi
Arch Linux disables AUR package adoption to stop malware flood
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...]
NVD CRITICAL: CVE-2026-68770 — sentence-transformers contains a security control bypass vulnerability that allo...
sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard condition includes an 'or os.path.exists(model_name_or_path)' clause that satisfies the trust gate whenever the supplied path exists on the local files
Online ad firm Adform’s script compromised to steal cryptocurrency
Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...]
Friday Squid Blogging: Squid Helps Discover New Marine Species
The Squid is a new scientific machine : One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world of exploring. We could see cells interacting with each other, exchanging material and building skeletons. And we could
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world
The president went against his intelligence agencies’ conclusions about Iran being the likely suspect in the campaign. The post Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world appeared first on CyberScoop .
OpenAI says its new GPT 5.6 models are becoming more cost-efficient
OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. [...]
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,
CISA Issues Fresh SBOM Guidance. Did They Get It Right?
A couple-dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.
AI Deepfakes Push Banks Beyond Voice Authentication
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ai-deepfakes-push-banks-beyond-voice-authentication-image_small-4-a-32388.jpg" align=right hspace=4><b>ABA's Paul Benda on Why Most Account Takeovers Stem From Scams, Not Hacks</b><br>Bank impersonation scams, deepfake audio and video are convincing customers to login and send money to criminals. With authentication methods erodin
ISMG Editors: A New Front in the Naming War
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ismg-editors-new-front-in-naming-war-image_small-7-a-32387.jpg" align=right hspace=4><b>Also: The AI Spending Reality Check, Nvidia Takes on Closed AI</b><br>In this week's panel, four ISMG editors discussed Google's controversial new threat actor naming system and the need for standardization, whether the artificial intelligence
CISA warns of spike in attacks on water systems as Minnesota incidents probed
The Cybersecurity and Infrastructure Security Agency said in a public alert on Thursday that facilities should “remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]
Cyber Command plans Silicon Valley office to drive innovation
The outpost will have its own director, though no one has yet been named for the post, and support the command’s nascent Cyber Warfare Innovation Center (CIWC).
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
The chart is interesting. On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non-Cl
Incomplete fix for CVE-2025-4318 code injection in Amazon &commat;aws-amplify/codegen-ui-react
<p><b>Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.</b></p>
RESOURCE: Thomson Reuters Foundation provides free resources and legal help for independent media around the world
From the Thomson Reuters Foundation, a welcome email describes the situation in South Africa and then turns to global support: I’m getting in touch to share some new reports and resources to support media freedom work in East and Southern Africa. Journalists who hold power to account are increasingly being targeted through “lawfare” tactics that silence, intimidate and financially... Source
CISA warns of cyberattacks disrupting U.S. water utilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...]
Weaponizing Exposed Data
Lab-1 Dark-web Research Team Contributors:Alex Necula, Anastasia Sentasnova, Ellis Stannard, Jeffrey Bell, Manuel Boll, Valéry Rieß-Marchive Mannie W writes: Ransomware and data-extortion groups are moving beyond bulk dumps to analyze, index and price stolen data before it is published or sold — removing the “weaponization tax” and turning breaches into searchable, tranched and targeta
Ransomware in Italy: RedACT report sheds light on an evolving threat environment
SuspectFile has published a great interview with the people behind RansomNews.online: Within this context, the first RedACT H1 2026 report, published by ransomNews.online, represents a valuable contribution to the analysis of ransomware activity targeting Italy. The project presents itself as a new independent initiative focused on continuously monitoring the ransomware ecosystem through the colle
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that
NVD HIGH: CVE-2026-18141 — A flaw was found in aap-gateway, a component of Ansible Automation Platform's Ev...
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error me
DefCon security conference bans smart glasses with recording capabilities
It’s a sign of the times: Security conference DefCon has added smart glasses to its list of banned audio- or video-recording devices . The organizers have said that, with no consistent way to understand whether smart glasses are recording or not, they have taken the step to ban them in their entirety on the grounds that they erode trust and invade people’s privacy. Putting corrective lenses in the
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research
Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research appeared first on SecurityWeek .
Circle granted New York trust charter
Circle Internet Group, Inc. (NYSE: CRCL), a global financial technology company and stablecoin market leader, today announced that it has received a limited purpose trust charter from the New York Department of Financial Services (NYDFS) for Circle Internet Trust Company LLC, d/b/a Circle New York Trust.
Appli signs Connect Credit Union
Appli, the creator of the industry's first AI-powered smart financial calculator, announced today that Connect Credit Union has selected its calculator solution to give members a more interactive way to explore their loan options online.
Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers
Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek .
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
A Chinese-speaking threat actor has been using DeepSeek’s AI models to orchestrate cyber-attacks targeting Asian organizations
Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks
Health sector organizations have been warned about an increase in successful attacks by the ShinyHunters threat group. In contrast to […] The post Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft Attacks appeared first on The HIPAA Journal .
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box
New York sues Kalshi for 'illegal gambling operation'
New York state has sued Kalshi, alleging that the prediction market is running an "illegal gambling operation".
This month in security with Tony Anscombe – July 2026 edition
OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup
ESET tracks rise in malicious AI skills and adaptable malware
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software. [...]
The Morning After We Pull a Root of Trust, Nobody Owns It
The most valuable move any security team can make is building a certificate and key inventory.
Consumer Dispute Panel Orders Coupang to Pay Affected Consumers 100,000 Won Each for Data Breach
Lee Yong-seong reports: The Consumer Dispute Settlement Committee has decided that Coupang must compensate affected consumers 100,000 won [about $70 USD] in cash or 100,000 won in Coupang Cash per person over a large-scale personal data breach, the committee said on the 31st. … The case began on December 8 last year, when 50 consumers... Source
Google adds to confusion with new names for threat actors
Google is creating a new naming scheme for the bad actors behind cybersecurity threats, hoping that it will help to standardize the way that attacks are reported. Spoiler: It won’t. Security researchers use these naming schemes so that they can attribute attacks without necessarily knowing exactly who is behind them. Google had naming schemes in use internally: one developed by its own Threat Anal
Broadcom patches vulnerabilities all over VMware
Broadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure CVE-206-59309 affects the VMware Directory Service. According t
Interpol Leverages Global System to Curtail Fraud Payments
When a fraudulent transaction occurs, law enforcement agencies must work quickly to halt payments before cybercriminals cash out.
DROP Platform Lets Californians Reduce Digital Footprint
The Delete Request and Opt-out Platform (DROP) launches Aug. 1 and hundreds of thousands of California residents already registered. Other states could follow if the process goes smoothly.
NVD HIGH: CVE-2026-18358 — A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux....
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations
NVD CRITICAL: CVE-2026-17561 — Improper Control of Generation of Code ('Code Injection') vulnerability in Innot...
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.108.
Anthropic AI Models Hacked 3 Real Companies
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/claude-hacking-tests-breached-3-real-companies-image_small-6-a-32384.jpg" align=right hspace=4><b>Setup Error Let Models Steal Data and Release Malware Online</b><br>Anthropic found three hacking tests in which Claude models reached real companies after a configuration error left them connected to the internet. One accessed custom
USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.
Microsoft almost gave away the keys to everyone’s Azure Cosmos DBs
Microsoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure Cosmos DB databases — both those of customers and Microsoft’s own. Google subsidiary Wiz found a flaw in the database’s Gremlin API, usually used for storing and managing property graph data. If bad actors had discovered it first, they could have e
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the
UniCredit, Accenture, and IBM join forces for pan-European banking expansion
UniCredit, one of Europe's leading pan-European banking groups, Accenture and IBM have announced a long-term strategic collaboration that establishes the technology foundation supporting UniCredit's growth across the thirteen European markets in which the Group operates.
Anthropic says its AI hacked real-world companies in three incidents
Claude maker Anthropic said its AI models escaped test environments and breached networks at three companies on the open internet.
South African crypto platform Luno to axe 20% of staff
Digital Currency Group’s crypto exchange Luno will cut 20% of its global staff in restructures, Bloomberg reported on Tuesday.
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session. The findings have been released by a group of researchers from Singapore's Nanyang Technological University
The $5 million threat: AI Is supercharging phishing attacks
According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,
Facial Recognition at Madison Square Garden
Last month, the story broke (alternate link ) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition. Turns out that the system was shut off for Taylor Swift’s wedding. Evan Greer—one of the people that MSG alerts on— comments : Ironically, Swift herself
JetBrains says a crafted HTTP request could break TeamCity
JetBrains is warning of a critical security vulnerability in its TeamCity DevOps platform that could allow unauthenticated attackers to execute arbitrary operating system commands on vulnerable servers. “If exploited, this vulnerability may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary commands,“ the company said in
Lloyds Banking Group and Caixabank complete tokenised deposit transactions through Project Agorá
Lloyds Banking Group has completed three live tokenised deposit transactions through tokenisation initiative Project Agorá.
Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace
The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase. The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek .
FinregE publishes framework in preparation for FCA's 2026 Cryptoasset Regime
FinregE, The End-to-End Regulatory Operating System (FinregE ROS), is urging digital asset firms to fundamentally change how they prepare for the UK's regulatory landscape. To achieve this, the company has introduced a strategic framework to bridge the widening “Execution Gap” ahead of the 2026 Financial Conduct Authority (FCA) Cryptoasset Regime.
NVD HIGH: CVE-2026-15722 — A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). Th...
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a repl
NVD HIGH: CVE-2026-11770 — A flaw was found in 389 Directory Server. An unauthenticated remote attacker can...
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication
NVD HIGH: CVE-2026-10079 — A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Wh...
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypas
Mastercard and National Bank of Egypt launch Egypt’s first USD corporate debit card
The National Bank of Egypt (NBE) has partnered with Mastercard to launch a USD debit card for Egyptian businesses.
Network Anomaly Detection in KATA
An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42 .
What the Hugging Face breach reveals about defense in the age of agentic AI
We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased […] The post What the Hugging Face breach reveals about defense i
EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels
When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. The post EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels appeared first on SecurityWeek .
AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks
AWS has linked North Korea to the axios campaign to other attacks on npm libraries
Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations
A security company’s systems were hacked after it installed a malicious Python package deployed by Claude. The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek .
zipdump.py: Metadata Encoding, (Fri, Jul 31st)
I was asked for help with a problem similar to the following.
Critical Flaw Led to Azure Cosmos DB Pwnage
Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Led to Azure Cosmos DB Pwnage appeared first on SecurityWeek .
Critical Flaw Allowed to Azure Cosmos DB Pwnage
Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Allowed to Azure Cosmos DB Pwnage appeared first on SecurityWeek .
After OpenAI, Anthropic finds Claude breached three organizations during cyber tests
Less than two weeks after OpenAI disclosed that an experimental AI model breached Hugging Face during a cybersecurity evaluation, Anthropic has revealed that its own review uncovered three incidents in which Claude models gained unauthorized access to the production infrastructure of three organizations during similar testing. Anthropic said it launched the review after OpenAI disclosed that one o
Anthropic Reveals Claude Escaped Testing, Breaching Three Companies
Anthropic has revealed that Claude AI models broke free of sandbox to compromise third-party organizations
CareCloud Data Breach Impacts Over 350,000
In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment. The post CareCloud Data Breach Impacts Over 350,000 appeared first on SecurityWeek .
NVD CRITICAL: CVE-2026-18452 — DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials v...
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
NVD HIGH: CVE-2026-16236 — The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Up...
The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for auth
NVD CRITICAL: CVE-2026-14483 — The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulner...
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by static, plugin-seeded API credentials that are identical across all installation
Defining Community Open Source Is Harder Than It Looks
<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/defining-community-open-source-is-harder-than-it-looks" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/Blog-Open%20Source%20Exemption%20Problem.jpg" alt="Image containing many hexagon shapes that appear as interconnected nodes like a software development environment" class="hs-featured
Critical Code Execution Vulnerability Patched in TeamCity
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in TeamCity appeared first on SecurityWeek .
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a "
Amazon: Custom Frontier Model Can Cut Costs, Target Niches
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/amazon-says-custom-frontier-model-cut-costs-target-niches-image_small-2-a-32382.jpg" align=right hspace=4><b>AWS Wants Greater Control Over Training Priorities and Model Economics</b><br>Amazon is redirecting engineering and computing resources from its Nova portfolio to a new frontier model, betting that specialization, customer-
Finland to disconnect fiber-optic link to Russia as lease expires
Finland stopped power transmissions with Russia at the start of the war in Ukraine, and two related telecom connections will stop at the end of this year, authorities said.
NVD HIGH: CVE-2026-18157 — A flaw was found in yggdrasil-worker-package-manager. A local attacker with exis...
A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the
Microsoft confirms an AI worm is propagating through Copilot and other MS apps
A prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including Word and Copilot. The report from noted Norwegian AI researcher Håkon Måløy , now confirmed by Microsoft, said that an attacker can conceal instructions in a document that is later used as source material for Copilot-generated or Copilot-edited Word doc
Copilot worm can spread through Microsoft Word docs
An “AI worm” can spread through Microsoft Word documents using Copilot as a vector, a prominent Norwegian AI researcher reported on Tuesday. The report from Håkon Måløy , later confirmed by Microsoft, said that an attacker can conceal instructions in a document that is later used as source material for Copilot-generated or Copilot-edited Word documents, for example, as input to a financial report.
Anthropic says its AI accidentally hacked three companies during safety tests
Following OpenAI’s own incident, Anthropic reviewed its own evaluations and found three cases of Claude hacking external companies. The post Anthropic says its AI accidentally hacked three companies during safety tests appeared first on CyberScoop .
Claude uploaded malware to PyPI in Anthropic's botched test
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...]
Revolut offers customers free ChatGPT Go access
Revolut has teamed up with OpenAI to give retail customers up to a year's free access to ChatGPT Go.
NatWest appoints LSEG's Triona O’Keeffe chief data and analytics officer
NatWest has recruited London Stock Exchange executive Triona O’Keeffe as its new chief data and analytics officer as part of a move to bring its data, AI and engineering capabilities closer together.
NVD CRITICAL: CVE-2026-66421 — OpenClaw Dashboard contains a stored cross-site scripting vulnerability that all...
OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message containing inline event handler payloads such as an img tag with an onerror attribute with
NVD HIGH: CVE-2026-66420 — MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass v...
MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of th
Anthropic, Pentagon Clash Over First Amendment Claims
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/anthropic-pentagon-clash-over-first-amendment-claims-image_small-4-a-32381.jpg" align=right hspace=4><b>Judge Questions Defense Department's Blacklisting of AI Company</b><br>A San Francisco federal judge showed skepticism Thursday over whether the Department of Defense acted lawfully when it blacklisted artificial intelligence fi
South Korea fines telco giant KT $39 million for customer data breach
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. [...]
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems. The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first on SecurityWeek .
JetBrains warns of critical TeamCity remote code execution flaw
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...]
FTC Sues Telehealth Firm Hims & Hers Over Data Sharing
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ftc-sues-telehealth-firm-hims-hers-over-data-sharing-image_small-1-a-32376.jpg" align=right hspace=4><b>Feds May Renew Crackdown on Violations Related to Online Health Data Trackers</b><br>The Federal Trade Commission, along with Utah and California, have filed a lawsuit against telehealth firm Hims & Hers accusing the company of
Breach Roundup: OpenAI Models on a Hacking Tear
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/breach-roundup-openai-models-on-hacking-tear-image_small-5-a-32380.jpg" align=right hspace=4><b>Also, Russian Hackers Exploit Outlook Flaw, Coca-Cola Restarts Fairlife Production</b><br>This week: Sam Altman on hacking, Russia exploited an Outlook web access flaw, Coca-Cola restarted Fairlife production, U.K. education department
ThreatLocker Raises $190M to Counter Malicious AI Agents
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/threatlocker-raises-190m-to-counter-malicious-ai-agents-image_small-6-a-32379.jpg" align=right hspace=4><b>Series F Funding Supports Zero Trust Controls Built for Autonomous AI Workflows</b><br>ThreatLocker raised $190 million in Series F funding to expand zero trust protections against autonomous AI agents while using AI to simpl
A coordinated attack hit 30+ Minnesota water systems. Who did it, and what does a Rockwell notice add to the picture?
A coordinated cyberattack that targeted more than 30 Minnesota community water systems has alarmed industrial cybersecurity experts, not because it caused widespread disruption, but because it appears to represent the first distributed campaign against dozens of small utilities linked by a common operational technology weakness. While the affected communities reported that drinking water remained
NVD CRITICAL: CVE-2026-66803 — Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex...
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
NVD CRITICAL: CVE-2026-66418 — OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability t...
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive C
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.
Bank of America to Acquire Cybersecurity Firm MDSec
The acquisition will add approximately 65 cybersecurity professionals to Bank of America’s operations in the United Kingdom. The post Bank of America to Acquire Cybersecurity Firm MDSec appeared first on SecurityWeek .
Okta’s deal for Permiso aims to close gaps in identity threat detection
Ely Kahn, Okta's chief product officer, told CyberScoop the deal enriches the company's current threat detection tools and gives it deeper visibility into AI agent activity across enterprise systems. The post Okta’s deal for Permiso aims to close gaps in identity threat detection appeared first on CyberScoop .
NVD CRITICAL: CVE-2026-67594 — Spikster through commit e1cdf8c contains a missing authentication vulnerability ...
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing configuration. Attackers can invoke approximately 50 unprotected API endpoints to enumerate and provision servers, reset root pass
NVD CRITICAL: CVE-2026-67208 — Juggle through 1.6.0 contains a remote code execution vulnerability that allows ...
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authenticate with default credentials, and leverage the H2 CREATE ALIAS Runtime.exec() technique to execute
NVD HIGH: CVE-2026-67207 — Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in Backu...
Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can exploit the incorrect evaluation of the access control expression to create, download, and restore backups without admin
NVD HIGH: CVE-2026-67206 — Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileM...
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the file_manager_mkfile capability can write malicious PHP content into the web-accessible FILES_DIR directory and trigger executio
NVD CRITICAL: CVE-2026-12946 — IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject ar...
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
NVD HIGH: CVE-2026-11536 — IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execu...
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
Hugging Face Incident Spurs Calls for European AI Autonomy
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/hugging-face-incident-spurs-calls-for-european-ai-autonomy-image_small-10-a-32377.jpg" align=right hspace=4><b>European Union Looks to Launch 'AI Gigafactories'</b><br>OpenAI's inadvertent agentic hacking of Hugging Face's systems has startled some politicians in Europe, with Germany's top tech minister saying it demonstrated the
AI Harnesses Burst With Potential Exploit Opps
A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.
KEO Capital launches in Canada
KEO Capital ("KEO Capital" or the "Company"), today announced the establishment of its Canadian subsidiary and operations through Workeo Canada, expanding its B2B payment and financing solution, following the signing of a revolving senior loan facility of up to $50 million with a leading Canadian bank.
NVD HIGH: CVE-2026-66416 — Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows u...
Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in app/Http/Kernel.php. Attackers can craft malicious pages delivered via phishing emails or malicious websites to trigger unauthorized POST, P
NVD HIGH: CVE-2026-66415 — Leantime 3.6.2 contains a server-side request forgery and local file inclusion v...
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path validation. Attackers can submit crafted filenames containing URL wrappers or path traversal sequences through the JSON-RPC AP
NVD CRITICAL: CVE-2026-13435 — IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vuln...
IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
NVD CRITICAL: CVE-2026-12943 — IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1...
IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
NVD HIGH: CVE-2026-12942 — IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse ...
IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
NVD HIGH: CVE-2026-12733 — IBM DataPower Gateway could allow a remote attacker to cause a denial of service...
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
NVD CRITICAL: CVE-2026-12118 — IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated...
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
NVD HIGH: CVE-2026-10545 — IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redir...
IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via a crafted URL. If used in SSO authentication flows, this could result in exposure of session tokens and allow attackers to hijack user sessions.
NVD HIGH: CVE-2026-10535 — IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer...
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
NVD HIGH: CVE-2024-25039 — IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 throu...
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the web server to become unresponsive.
Okta to Acquire Identity Threat Detection Firm Permiso
The deal extends Okta's reach beyond identity management and into the realm of security operations, positioning the company to compete more directly on identity threat detection and response. The post Okta to Acquire Identity Threat Detection Firm Permiso appeared first on SecurityWeek .
Semiconductor chip titan Analog Devices reports data breach
In a filing for federal regulators, Massachusetts-based Analog Devices said intruders had exfiltrated data from its networks earlier this summer, but the scope of the incident is still under investigation.
JFrog Patches Flaws Behind OpenAI Models' Escape
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/jfrog-patches-flaws-behind-openai-models-escape-image_small-8-a-32372.jpg" align=right hspace=4><b>Artifactory Bugs Helped Models Reach Hugging Face Production</b><br>JFrog patched previously unknown flaws in self-hosted Artifactory after OpenAI models used them to escape a cyber test environment and reach Hugging Face production.
CISA issues recommendations to federal agencies on open-source software security
One expert said they were pleased by the guidance, which touches on open-weight AI models, patching and more. The post CISA issues recommendations to federal agencies on open-source software security appeared first on CyberScoop .
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. [...]
VMware fixes three critical flaws allowing auth bypass, VM escapes
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]
You were onto something with “It’s the Climb,” Miley
Amy hikes Virginia’s most difficult trail and muses on the persistent challenges of cybersecurity. The two aren't dissimilar.
Flailing Ransomware Hackers Resorting to Extreme Tactics
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/flailing-ransomware-hackers-resorting-to-extreme-tactics-image_small-1-a-32375.jpg" align=right hspace=4><b>Silent Ransom Bucks Trend of Fewer Victims Paying, and Paying Less When They Do</b><br>Fewer ransomware victims are choosing to pay a ransom than ever before, bar some big payoffs that largely trace to high-profile law firms
NVD HIGH: CVE-2026-9322 — IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv...
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.
NVD HIGH: CVE-2026-12945 — IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and m...
IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.
NVD CRITICAL: CVE-2026-12940 — IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote ...
IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables.
NVD HIGH: CVE-2026-11885 — IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71,...
IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call can cause the PowerVM hypervisor to crash or compromise OS memory integrity.
Cryptohack Roundup: Triple-A, Verus-Ethereum Bridge Exploits
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cryptohack-roundup-triple-a-verus-ethereum-bridge-exploits-image_small-1-a-32374.jpg" align=right hspace=4><b>Also: Hackers Use SparkKitty Malware to Steal Seed Phrases</b><br>This week, Triple-A wallet was compromised and Verus-Ethereum Bridge exploited, hackers used SparkKitty malware to steal seed phrases, fake IRS letters targ
Google says AI helped Chrome fix 1,072 security bugs in two releases
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI. [...]
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawlin
Family says woman violated HIPAA, ‘weaponized’ info
Chris Dickerson reports: A medical administrator spent years secretly accessing a family’s medical records and “weaponizing” their private health information for a family dispute, according to a newly filed civil lawsuit. The plaintiffs, identified only by their initials, filed the complaint July 23 in Kanawha Circuit Court against Sarah Gross, West Virginia University Medical Corporation... Sourc
ShinyHunters claims Brinks Home breach, threatens to leak stolen data
Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. [...]
American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
He’s being prosecuted for giving border officials a code that wiped his phone : The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick’s attorneys confirmed GrapheneOS was running on his phone. The software feature allows the device owner to set a passcode that deliberately w
NVD HIGH: CVE-2026-58222 — A security flaw combining LDAP filter injection and improper authorization check...
A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted context, bypassing normal Access Control List (ACL) enforcement. An authenticated low-pr
NVD HIGH: CVE-2026-57862 — Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability t...
Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controlled URLs. Attackers can submit hexadecimal-encoded internal IP addresses through the web link creation feature, causing cURL to resolve and connect to internal network resources such as cloud instance m
NVD CRITICAL: CVE-2026-4978 — Improper neutralization of special elements used in an SQL command ('SQL injecti...
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. This issue affects Traffic Analysis System: from 30 before 34.
NVD CRITICAL: CVE-2026-28323 — SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass...
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
NVD HIGH: CVE-2026-10842 — IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Serv...
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.
KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
Overview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability has a CVSSv4 score of 9.5 and is classified as Initialization of a Resource with an Insecure Default ( CWE-1188 ). An unauthenticated attacker
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]
Timeless Compliance: Why Better Questions Beat Bigger Frameworks
The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. The post Timeless Compliance: Why Better Questions Beat Bigger Frameworks appeared first on SecurityWeek .
Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway,
We know how to protect our troops from telecom attacks. We’re just not doing it.
The post We know how to protect our troops from telecom attacks. We’re just not doing it. appeared first on CyberScoop .
NVD HIGH: CVE-2026-67349 — OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, expo...
OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials. Additionally, adminAuthMiddleware fails open when ADMIN_TOKEN is unset, allowing unauthenticated attackers to modify GCP service account keys via POST /serviceKey to redirect billing calls.
NVD HIGH: CVE-2026-67348 — Julep contains an insecure direct object reference vulnerability in the get_exec...
Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply arbitrary execution_id values to retrieve sensitive execution records including task inputs, outputs, metadata, and temporal task tokens from other tenants.
NVD HIGH: CVE-2026-67346 — Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request fo...
Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers can supply user-controlled image or audio URLs that resolve to private, loopback, or metadata addresses to reach internal services and exfiltrate credentials.
NVD HIGH: CVE-2026-67345 — MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirec...
MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix matches a registered URI without proper dot-boundary anchoring. Attackers who control a domain ending with the registered
NVD HIGH: CVE-2026-16308 — IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3....
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.
NVD CRITICAL: CVE-2026-15435 — IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0....
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
NVD HIGH: CVE-2026-14980 — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerab...
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.
NVD HIGH: CVE-2026-14522 — IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0....
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
NVD HIGH: CVE-2026-14519 — IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0....
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability.
NVD HIGH: CVE-2026-12947 — IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0....
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user.
NVD HIGH: CVE-2026-11980 — IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution b...
IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
NVD HIGH: CVE-2026-11897 — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerab...
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.
NVD CRITICAL: CVE-2026-11707 — IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Applicati...
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.
Rapid7 named a Leader in the IDC MarketScape: Worldwide MDR Service for Midmarket 2026 Vendor Assessment
IDC has named Rapid7 a Leader in the 2026 Worldwide Managed Detection and Response Service for Midmarket 2026 Vendor Assessment ( Doc #US52992326, July 2026 ). We believe this recognition and research highlights where MDR is heading. Many security programs are still built around a reactive sequence of detect, triage, and respond, but the timelines surrounding modern attacks have changed too quickl
Analog Devices discloses data breach, says operations unaffected
American semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. [...]
Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims
Derrick Van Yeboah impersonated fake romantic partners and directly interacted with victims for more than nine years. The post Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims appeared first on CyberScoop .
Cryptominer Abuses Linux PAM to Hide From SOC Analysts
Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts
Metasploit Framework 6.5 Released
oday we’re proud to announce that Metasploit Framework version 6.5 has been released. Over the past two years, with the help of countless contributors, we’ve added 422 new modules along with a whole slew of new features. Malleable C2 Profiles for HTTP One of the latest and most requested features is support for Malleable C2 profiles across all current Meterpreter payloads. This feature enables use
NVD HIGH: CVE-2026-67351 — Serendipity before 2.6.1 contains an authentication context confusion vulnerabil...
Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independently without ensuring both use the same user record. An authenticated Editor can create a username collision with an Administrator account and obtain administrative privileges by logging in with their own password while the session loads the Administrat
NVD HIGH: CVE-2026-5219 — Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology...
Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce Pack: through 30072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
NVD HIGH: CVE-2026-57859 — e107 prior to version 2.3.8 contains a code execution vulnerability in the e_arr...
e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the user_prefs column. The e_array::unserialize() function in e107_handlers/core_functions.php performs only a prefix check for the string 'array' before passing the st
NVD HIGH: CVE-2026-12722 — Missing authentication for critical function vulnerability in FTC Software IT Se...
Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2.
Crime Stoppers International seeking tips on INC Ransom as part of new bounty program: Operation Silent Vector
Crime Stoppers International has announced a new program: Operation Silent Vector. And the first target they are offering a bounty for is INC Ransomware. Cybercriminals operate behind anonymity; this program pulls that mask off. Crime Stoppers International is seeking tips to accelerate the arrest of cybercriminals in the INC Ransomware Cybercrime-as-a-Service group as well as... Source
Unlimit scores MiCA licence
Unlimit, a global financial infrastructure company, today announced that Unlimit Crypto has been granted a Crypto-Asset Service Provider licence by the Cyprus Securities and Exchange Commission under the EU's Markets in Crypto-Assets Regulation (MiCA).
ICE agrees $5.7 billion MarketAxess acquisition
Nyse owner Intercontinental Exchange (ICE) has agreed a $5.7 billion deal to buy fixed income electronic trading platform MarketAxess.
Ecommpay brings full stack acquiring to PayControl
Inclusive global payments platform, Ecommpay, has gone live as a payment connector within PayControl's enterprise payment orchestration platform.
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066)
[object Object]
Equals to acquire OFX
Following the Strategic Review announced to the market on 5 February 2026, OFX Group Limited (ASX: OFX) (“OFX”) today announces that it has entered into a Transaction Process Deed (“Transaction Process Deed”) regarding an all-cash acquisition of 100% of the issued share capital of OFX by Alakazam Holdings Bidco Limited (“Equals”), the direct owner of UK- based international payments company Equals
After the Break-In: What Attackers Do Once They're Already Inside
Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove the malware. [...]
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats
Method unveils Portfolio Intelligence for lenders
Method, a financial connectivity platform supercharging innovation for leading fintechs and financial institutions, today announced the release of Portfolio Intelligence, a new product powering continuous post-origination monitoring for lenders.
DataBahn Raises $40 Million for Agentic Data Pipeline Management
The company will accelerate investments in R&D and product innovation to expand its agentic data control plane. The post DataBahn Raises $40 Million for Agentic Data Pipeline Management appeared first on SecurityWeek .
North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidence of deepening entanglement between Pyongyang-backed hackers and the ransomware ecosystem.
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a
NVD HIGH: CVE-2026-54368 — CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.Se...
CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API endpoint. Attackers can exploit unsanitized interpolation of the Field parameter directly into SQL query strings to write arbitrary files to th
NVD HIGH: CVE-2026-54367 — CentreStack before 17.2 contains an authentication bypass vulnerability that all...
CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId values using the static shared encryption key to forge identifiers for any user GUID, including the system-wide cluster
NVD HIGH: CVE-2026-54366 — CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerab...
CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. Attackers can send a crafted request to the unauthenticated StorageConfig endpoint causing the server to fetch and parse attacker-controlled XML containing external DTD
NVD HIGH: CVE-2026-54365 — CentreStack before 17.3 contains an unauthenticated deserialization vulnerabilit...
CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfigure parameter to the jsonimportuserbyupn, jsonimportuserbyupnex, or japiimportuserbyupn endpoints t
NVD CRITICAL: CVE-2026-54363 — CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability tha...
CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() across all installations. Attackers can use the hardcoded key to craft valid x-glad-auth headers and call privileged API endpoints such as a
MiFinity taps BVNK for global stablecoin payouts
Global payouts provider MiFinity has enlisted BVNK for a new global stablecoin-based enterprise payout service for merchants.
OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation
OSF Healthcare System and its Affiliated Covered Entities (OSF Healthcare) have agreed to pay a penalty of $552,250 to resolve […] The post OSF Healthcare System Pays $552,250 to Settle OCR HIPAA Investigation appeared first on The HIPAA Journal .
Walking the Walk on Package Registry Sustainability
<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/walking-the-walk-on-package-registry-sustainability" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/Blog%20-%20Walking%20the%20Walk%20on%20Package%20Registry%20Sustainability.png" alt="Image of two logos side by side, one being Sonatype's logo and the other being Packagist's logo." cla
Cantina Emerges From Stealth With $8 Million in Funding
The startup’s community-powered agentic security platform helps proactively identify, prioritize, and remediate vulnerabilities. The post Cantina Emerges From Stealth With $8 Million in Funding appeared first on SecurityWeek .
North Korean hackers behind major open-source supply chain attacks, Amazon says
A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.
AI agents gain access to financial workflows amid growing governance gaps
AI agents are now being allowed to create business records, approve transactions, and execute financial workflows. ERP security firm Pathlock says most organizations don’t know if that is all they are doing. The company’s 2026 AI Governance Gap Report found that 79% of organizations do not have a dedicated AI governance team, despite AI agents being increasingly plugged into business-critical oper
Discern Security Raises $13 Million in Series A Funding
The company will invest in accelerating the development and adoption of its agentic platform. The post Discern Security Raises $13 Million in Series A Funding appeared first on SecurityWeek .
AI and Automation Fall Short of Sysadmin Expectations
Action1 report finds sysadmins overestimated their use of AI in predictions made two years ago
Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge
A critical vulnerability in the open-source AI agent platform Ruflo could allow unauthenticated attackers to take control of enterprise AI environments by exploiting an exposed Model Context Protocol (MCP) bridge, according to research published by Noma Security. The flaw, tracked as CVE-2026-59726 and dubbed RufRoot, carries a maximum CVSS score of 10.0 and affects Ruflo versions prior to 3.16.3,
Onyx Security Raises $113 Million to Control AI Agents in the Enterprise
The Series B funding round brings the total raised by Onyx Security to $153 million. The post Onyx Security Raises $113 Million to Control AI Agents in the Enterprise appeared first on SecurityWeek .
NVD HIGH: CVE-2026-18381 — A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operato...
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.
NVD HIGH: CVE-2026-18378 — A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsC...
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token.
NVD HIGH: CVE-2026-15397 — The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing ...
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible for authenticated attackers, with shop manager-level access and above, to install a
‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale
Researchers warn that AI could turn dangling DNS takeovers into a nation-state weapon capable of disrupting governments, banks and global supply chains. The post ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale appeared first on SecurityWeek .
Schneider Electric IGSS
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA system used f
Watchfire Controller Software
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-09.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller.</strong></p> <p>The following versions of Watchfire Controll
Cyber extortionists steal data from UK Department for Education
Cybercriminals are attempting to extort Britain’s Department for Education (DfE) after compromising what the hackers said was more than 600,000 pieces of data allegedly including names, email addresses and phone numbers.
Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure
Open Source Software: Security Principles and Practices
<p>Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specif
MZ Automation GmbH libiec61850
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device.</strong></p> <p>The following versions of MZ Automation GmbH libiec61850 are affected:</p> <ul> <li>libiec6
Mitsubishi Electric CC-Link IE TSN Communication Protocol
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-07.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditi
MikroTik RouterOS
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associate
Toptech Systems RCU II+ and Multiload II+
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources.</strong></p> <p>The following versions of Toptech Systems RCU II
Johnson Controls OpenBlue Employee
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content.</strong></p> <p>The following versions of Johnson Contr
o6 Automation open62541
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-08.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code.</strong></p> <p>The following versions of o6 Automation open
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-05.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.</strong></p> <p>The following versions of Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communication
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
<p>CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modi
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session. Måløy's
BNPL fintech Cashea raises $100 million
Venezuelan buy now, pay later fintech Cashea has raised $100 million as it looks to branch out beyond its core installment product into broader payments and savings niches.
The Network Has Become the Control Plane for AI Security
Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model: users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations. Firewalls
HHS OCR Settles Ransomware Investigation of OSF Healthcare System and Affiliated Covered Entities
In June 2021, DataBreaches reported on a ransomware attack affecting OSF Healthcare by a little-known gang called Xing Team. Our reporting noted OSF’s lack or response to inquiries and lack of timely notification. When OSF issued a statement in October, DataBreaches reported on that, too, commenting that we did not find their incident response timely... Source
KR: KT Fined 54 Billion Won Over Data Breach via Illegal Base Stations
Two years after a malware incident that was not handled in accordance with South Korea’s requirements, KT has been fined. Lee Jin-seok reports: KT has been fined more than 53.9 billion won [USD $37,630,484.43] over a personal data breach and unauthorized micropayment damages caused by the exploitation of illegal small base stations (femtocells). The government... Source
Semiconductor Firm Analog Devices Discloses Data Breach
Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files. The post Semiconductor Firm Analog Devices Discloses Data Breach appeared first on SecurityWeek .
Should You Use AI for a Task? Here’s a Simple Way to Decide
This essay originally appeared in The Guardian . I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come as no surprise to you that my students regularly use AI to complete their writing assignments. Doing so is a waste of their tuition money. But if their entire career is going to include AI writing assistants, why shouldn’t the
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
Building secure Uniswap v4 hooks
<p>Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into application and hook code.</p> <p>The Cork and Bunni exploits are two app-level incidents that show what can go wrong in that code. Together, they account for more than $20M in losses. Neither incident stem
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
A Russia-aligned threat group used a “half-click” exploit against Microsoft Exchange’s Outlook Web Access to install a browser-based backdoor when recipients opened specially crafted emails. The campaign began on July 22 and was conducted by TA488, which is also tracked as Void Blizzard and Laundry Bear, according to a report from the cybersecurity firm Proofpoint. The attacks targeted government
Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors. A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent remote access. "In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42 .
Wise connects directly to PayNet, Malaysiaʼs national payments network
Wise, the global technology company building the best way to move and manage the worldʼs money, now has direct access to Malaysiaʼs national payments infrastructure, operated by Payments Network Malaysia PayNet). This integration enables Wise’s support for DuitNow.
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container. The post Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms appeared first on SecurityWeek .
Lloyds aims for a further £2 billion in cost savings with AI to the fore
Lloyds Banking Group is targeting another £2 billion in savings over the next three years after turning in a 23% jump in half-year profits.
1 in 5 Data Center Assets Are Within Easy Reach of Attackers
Claroty has analyzed 750,000 cyber-physical systems across some of the world’s largest data center facilities. The post 1 in 5 Data Center Assets Are Within Easy Reach of Attackers appeared first on SecurityWeek .
AccountsIQ rolls out Paraglide AI agents to automate collections
AccountsIQ, the leading cloud accounting software for mid-market businesses, has partnered with Paraglide to automate collections for its customers with AI agents.
North Korea’s elite hackers turned on their own government – and got caught
For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme. But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government
Google Releases Patches for 370 Vulnerabilities in Chrome 151
The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws
RBC and TD go live with Swift for international reail transfers
People in Canada receiving money from family, friends or businesses abroad will get a significantly better experience as Canadian financial institutions go live with a new consumer payments initiative from Swift, the organisation behind the global network that connects more than 11,500 financial institutions in over 200 markets.
Beyond the screenshot: Why you should verify what you see
The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine
NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices
The UK’s National Cyber Security Centre wants network device makers to improve forensic observability
A Scattered Spider member was indicted. Microsoft’s GDID went to trial.
A recently released criminal complaint against Peter Stokes , an alleged member of the Scattered Spider cybercrime group , reveals previously unpublicized details about Windows telemetry . Microsoft has never exactly had a reputation for being privacy-focused, however the complaint reveals the important part played by Microsoft’s Global Device Identifier (GDID), a persistent identifier tied to a W
US and Allies Update SBOM Guidance
Five years after the initial release, the refresh introduces new elements, removes others, and updates terminology. The post US and Allies Update SBOM Guidance appeared first on SecurityWeek .
Toy Ghouls’ new toy: the GenieLocker ransomware
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.
Chrome 151 Patches 370 Vulnerabilities
The major browser update resolves roughly 80 critical- and high-severity security defects. The post Chrome 151 Patches 370 Vulnerabilities appeared first on SecurityWeek .
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the equipment authorization required for import, marketing, or sale in the US. Previously authorized models can still be sold, and devices people already own are unaffected. Federal purchases and use
NVD CRITICAL: CVE-2026-7849 — Due to improper neutralization of special elements, an unauthenticated remote at...
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
NVD CRITICAL: CVE-2026-44108 — Due to a flaw in the execution order of scripts during shutdown, the firewall is...
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.
NVD HIGH: CVE-2026-44107 — A reboot of the charging controller can be triggered via Modbus TCP without auth...
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
NVD HIGH: CVE-2026-44106 — A privilege escalation vulnerability in the init-script for user-applications al...
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
NVD CRITICAL: CVE-2026-44104 — The firmware update process for the basemodule of the charging controller only v...
The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.
NVD CRITICAL: CVE-2026-44101 — Due to missing authentication the CHARX OCPP Agent service allows an unauthentic...
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.
NVD CRITICAL: CVE-2026-44100 — The CHARX JupiCore service allows an unauthenticated remote attacker to reconfig...
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.
NVD HIGH: CVE-2026-44099 — A privilege escalation vulnerability in the system configuration allows a low-pr...
A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
NVD HIGH: CVE-2026-44098 — This vulnerability allows an unauthenticated remote attacker with control over t...
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.
NVD HIGH: CVE-2026-44097 — A low-privileged remote attacker with "operator" access can upload arbitrary fil...
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.
NVD HIGH: CVE-2026-44096 — A privilege escalation vulnerability in udhcpc allows a local user "charx-web" t...
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.
NVD HIGH: CVE-2026-44095 — A privilege escalation vulnerability in a script used for network configuration ...
A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
NVD HIGH: CVE-2026-44094 — An unauthenticated remote attacker can enforce the system to fall back to a firm...
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.
NVD HIGH: CVE-2026-44093 — A local privilege escalation vulnerability in the init-script for user-applicati...
A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
NVD CRITICAL: CVE-2026-44092 — An unauthenticated remote attacker can inject malicious input into the ModbusSer...
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
NVD CRITICAL: CVE-2026-44091 — An unauthenticated remote attacker can post a malicious ID to the MQTT Broker re...
An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.
NVD CRITICAL: CVE-2026-44090 — Due to missing authentication, an unauthenticated remote attacker may access the...
Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.
Fortinet Sees On-Prem SASE Market Outpacing Cloud
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/fortinet-sees-on-prem-sase-market-outpacing-cloud-image_small-7-a-32368.jpg" align=right hspace=4><b>Enterprises Want Sensitive Data Processed Inside Their Own Infrastructure</b><br>Fortinet says AI-driven internal traffic and data sovereignty requirements are pushing enterprises toward hybrid and on-premises SASE, creating a mark
Cisco Secure FMC Zero-Day Exploited in the Wild
The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices. The post Cisco Secure FMC Zero-Day Exploited in the Wild appeared first on SecurityWeek .
NVD HIGH: CVE-2026-16529 — A signed integer overflow in the PCP __pmGetPDU() function can be exploited via ...
A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.
NVD HIGH: CVE-2026-16527 — An unauthenticated remote attacker can bypass access controls by sending crafted...
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
NVD HIGH: CVE-2026-16526 — A flaw in the PCP linux_sockets module exposes an unsecured internal connection....
A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
NVD HIGH: CVE-2026-16524 — A command injection flaw in PCP's linux_sockets PMDA allows malicious shell meta...
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages carrying more than 2 billion weekly downloads between them. The original Aikido and Wiz reports did not attribute the
NVD HIGH: CVE-2026-1360 — The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untruste...
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject ar
NVD CRITICAL: CVE-2026-16610 — The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to ...
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input
NVD HIGH: CVE-2026-14356 — The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in a...
The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the email address and password of any WordPress user, including administrat
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log
NVD CRITICAL: CVE-2026-48449 — Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi...
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
NVD HIGH: CVE-2026-48448 — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia...
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed.
SE Asian Cybercriminal Syndicates Become a Global Power
The groups move from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.
CISA unveils a six-step blueprint for isolating critical infrastructure during cyberattacks
Most IT operators understand that critical infrastructure should be isolated in crisis situations, but many don’t know how to do it in a way that maximizes security and minimizes disruption. Now, several global agencies are offering a step-by-step action plan, CI Fortify . Released by the US Cybersecurity and Infrastructure Security Agency (CISA) and several Five Eyes security agencies across the
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th)
[This is a Guest Diary by Adam Cann, an ISC intern as part of the SANS.edu BACS program]
'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
A premium-grade malware-as-a-service offering takes flight with multiple threat groups, building infostealers that drain victims' bank accounts.
NatWest teams with Uinsure to deliver home insurance quotes in seconds
NatWest has entered an exclusive partnership with insurance technology platform Uinsure to launch a new home insurance proposition designed to make finding, managing and reviewing cover simpler and faster for customers.
Freehand raises $75m for AI agents that manage supply chain spend
Freehand, a startup building AI agents that manage supply-chain spend for giants including Meta and Pfizer, has raised $75 million in funding.
Stripe vet buys a bank for his fintech
Increase, a banking infrastructure fintech founded by Stripe's first employee, has acquired its own community bank.
Secure at Inception: Announcing the Snyk Studio Integration for Snowflake Cortex Code
Snyk Studio integrates with Snowflake Cortex Code to scan AI-generated code, dependencies, and containers for vulnerabilities during development.
The Attacker Never Sleeps, Neither Can Your Testing
AI is accelerating software development and giving attackers machine-speed capabilities. Security teams must continuously test AI-built code, govern agents, and independently validate every finding.
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. [...]
Cybersecurity, Then & Now
Since 2006, Dark Reading has been at the forefront of covering cybersecurity. The more things change, the more they stay the same.
Plaid Builds AI Model to Decode Consumer Financial Behavior
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/plaid-builds-ai-model-to-decode-consumer-financial-behavior-image_small-10-a-32367.jpg" align=right hspace=4><b>Sequential Foundation Model Gives Banks More Context Beyond Transactions</b><br>Plaid has developed a sequential foundation model that analyzes the timing and order of financial transactions to help banks and lenders bet
NVD HIGH: CVE-2026-67595 — VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript p...
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, install
Cyera Bets $1B on Non-Human Identity Security With Oasis Buy
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cyera-bets-1b-on-non-human-identity-security-oasis-buy-image_small-10-a-32365.jpg" align=right hspace=4><b>Cyera-Oasis Deal Aims to Connect Permissions, Identities and Sensitive Data Context</b><br>Cyera plans to acquire non-human identity startup Oasis Security for $1 billion, combining identity intelligence with data security to
Agency's Push to Gather ER Data Sparks Privacy Clash
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/agencys-push-to-gather-er-data-sparks-privacy-clash-image_small-1-a-32363.jpg" align=right hspace=4><b>Hospitals Push Back, Question Scope of Consumer Safety Surveillance Record Demands</b><br>A federal agency charged with protecting the public against consumer product injuries is asking certain hospitals to provide electronic hea
Hackers Disrupt Controls at Minnesota Water Utilities
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/hackers-disrupt-controls-at-minnesota-water-utilities-image_small-5-a-32362.jpg" align=right hspace=4><b>MNIT Activates Statewide Incident Response as Federal Partners Probe OT Intrusions</b><br>A coordinated cyberattack disrupted operational technology at more than 30 Minnesota community water systems on July 26 and 27, forcing c
Anthropic confirms Claude is down worldwide
Claude is down for some users, with Anthropic confirming elevated errors across multiple AI models. [...]
Cisco warns of FMC static credential flaw exploited in zero-day attacks
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]
A little-known npm package was North Korea’s warm-up act for the axios hack
Amazon's threat intelligence team traced domain records from the open-source software hack to a smaller, earlier compromise by the same North Korean group. The post A little-known npm package was North Korea’s warm-up act for the axios hack appeared first on CyberScoop .
North Korea Behind Slew of JavaScript Supply-Chain Hacks
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/north-korea-behind-slew-javascript-supply-chain-hacks-image_small-3-a-32366.jpg" align=right hspace=4><b>Amazon Connects npm Hacks to Threat Hacker Known as 'Sapphire Sleet'</b><br>A slew of attacks against open-source libraries trace back to a financially-motivated North Korean nation-state threat actor, analysis from Amazon Web
Supply chain challenges loom large in quantum race, White House official says
Brad Blakestad, director of the National Quantum Coordination Office, also said encryption and measuring progress would pose challenges. The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop .
Claude Mythos Finds New Cryptographic Algorithm Attacks
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/claude-mythos-finds-new-cryptographic-algorithm-attacks-image_small-6-a-32360.jpg" align=right hspace=4><b>Cryptographers Welcome LLM-Driven Results, Including to Test Quantum-Safe Crypto</b><br>Large language models continue to evolve quickly, with researchers discovering working attacks against two cryptographic algorithms using
OpenAI's Rogue Model Claims More Victims Beyond Hugging Face
OpenAI revealed rogue AI models compromised more services than initially disclosed, including a Modal customer environment and others.
Red Agents vs. Blue Agents: How to Make AI Better At Defense
The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.
NVD HIGH: CVE-2026-67201 — V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery...
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers can craft a URL containing a backslash in the authority section such that net.urllib.parse() extracts the trusted host for allowlist validation while net.
NVD CRITICAL: CVE-2026-14529 — IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv...
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.
AI Attacks Turn Bank Breaches Into a 'Hostage Situation'
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ai-attacks-turn-bank-breaches-into-hostage-situation-image_small-1-a-32359.jpg" align=right hspace=4><b>TrendAI's Tom Kellermann on Autonomous Attack Response, AI Governance Practices</b><br>Cybercrime groups are using AI to automate attacks, disrupt incident response and maintain control of financial networks. Tom Kellermann of T
From Maps to Mission: Turning Geospatial Data into Real-time Action
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/accelerate-vector-search-for-enterprise-scale-ai-elastic-nvidia-image_small-6-a-31975.jpg" align=right hspace=4><b>An OnDemand Webinar from Elastic</b><br>Watch this webinar to learn how to build a geospatial operational view across departments, systems, and environments as well as how to identify shifts in terrain, routes, timing
NVD CRITICAL: CVE-2026-41939 — Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability ...
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Ar
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
Health-ISAC is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters, which are using social engineering to compromise single sign-on accounts and steal data from cloud services. [...]
BNY unveils blockchain-based transfer agency service
BNY has launched a digital version of its transfer agency business, tapping blockchain technology for its record keeping.
InvestiFi raises $20m
InvestiFi, a Credit Union Service Organization (CUSO) and the award-winning InvestTech platform enabling credit unions and community banks to offer digital investing directly within online banking, today announced it has raised $20 million in funding.
Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.
Hugging Face Hack Lessons for Cyber Defenders
Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.
OpenAI says rogue agent behind Hugging Face hack broke into additional services
The four additional targeted organizations weren’t named. OpenAI said they were not affected as severely as Hugging Face.
NVD HIGH: CVE-2026-18255 — A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is ab...
A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.
Measuring the Tendency of AI Agents to Go Rogue
This essay was written with Barath Raghavan, and originally appeared in The Guardian . In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Whoever was behind it captured internal security credentials and moved through systems over a weekend, running thousands of
When AppSec Scanners Become a Supply Chain Attack Vector
New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks.
MoonPay opens PayBox for AI agent transactions
MoonPay, the global financial technology company powering the movement of value across fiat and digital assets, has launched PayBox, the first payment vault built for AI that lets a person's AI agent transact on the open internet without leaving the conversation.
Bank of Luxemburg completes CSI core conversion
CSI, a leading provider of end-to-end financial software and technology, today announced that Bank of Luxemburg has successfully gone live on CSI's NuPoint® core banking platform following a seamless conversion.
Bank of Luxemburg goes live on CSI core platform
CSI, a leading provider of end-to-end financial software and technology, today announced that Bank of Luxemburg has successfully gone live on CSI's NuPoint® core banking platform following a seamless conversion.
NVD HIGH: CVE-2026-67192 — Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overfl...
Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated. Attackers can craft packets with an unvalidated length field passed directly to the GCM decrypt function, overwriting the stack cookie and return address to potentially achiev
NVD CRITICAL: CVE-2026-67191 — Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflo...
Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A logic error in the recv loop's termination condition uses an incorrect OR operator where an AND operator is required, enabling exploitation on any SSH or SFTP co
NVD CRITICAL: CVE-2026-60113 — AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 c...
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network c
NVD CRITICAL: CVE-2026-60112 — AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authenticatio...
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward ar
NVD HIGH: CVE-2026-16463 — A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force ...
A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8 . An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authent
Former CPA Sentenced for Laundering Stolen Children’s Healthcare of Atlanta Funds
A business email compromise (BEC) attack on a vendor of Children’s Healthcare of Atlanta in 2023 resulted in $5.3 million […] The post Former CPA Sentenced for Laundering Stolen Children’s Healthcare of Atlanta Funds appeared first on The HIPAA Journal .
Huntress warns about attack spree that hit 30 SonicWall customers in 2 days
Unknown attackers broke into 92 unique SonicWall user accounts with legitimate credentials, researchers said. The post Huntress warns about attack spree that hit 30 SonicWall customers in 2 days appeared first on CyberScoop .
OpenAI agent used exposed credentials at 4 services in Hugging Face breach
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. [...]
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
LogoKit now builds per-victim phishing pages using live screenshots of the target's real website
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter
Mythos takes its first shot at post-quantum cryptography
Anthropic’s Claude Mythos Preview model has helped researchers discover ways to speed up attacks against two widely studied cryptographic algorithms. One of the targets is Hawk, a candidate for post-quantum digital signature algorithms currently being evaluated by NIST, while the other improves the best previously known attack against a weakened version of the widely used Advanced Encryption Stand
Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities
Sweet Security , the proactive runtime enforcement company for cloud and AI, today announced its further expansion into AI security with Agentic AI Blocking . Sweet now blocks rogue agent behavior in real time – extending Sweet’s runtime enforcement from the cloud to the AI agents that are acting alongside it. Eighty percent of the world’s businesses are already AI enterprises, and their agents ta
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
ICE puts fixed income pricing data on leading AI platforms
Intercontinental Exchange, Inc. (NYSE: ICE), one of the world's leading providers of financial market technology and data powering global capital markets, today announced its fixed income data and methodologies are now available to be used on leading AI platforms by licensed users, using the Model Context Protocol (MCP).
Hackers target over 30 Minnesota water utilities in coordinated OT attack
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." [...]
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." [...]
Laundry Bear’s webmail hackers had more in store after February, report says
Researchers say the Russian state-linked hacking group tracked as Laundry Bear recently began exploiting a bug in Microsoft Outlook Web Access.
Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms
The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.
Alaskan bank Northrim selects Narmi for digital transformation project
Narmi, a leading provider of digital banking solutions for financial institutions, today announced that Northrim Bank, a $3.4 billion Alaska-based bank, has selected Narmi to modernize its digital banking ecosystem, unifying digital banking and account opening for the bank's customers across Alaska and the Pacific Northwest.
NVD HIGH: CVE-2026-67215 — cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack ex...
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON
Banner Health; LifeStance Health Group Settle Tracking Technology Lawsuits
Two healthcare providers have agreed to settle lawsuits over their use of pixels and other website tracking technologies. The tools […] The post Banner Health; LifeStance Health Group Settle Tracking Technology Lawsuits appeared first on The HIPAA Journal .
Your AI Agents Are Guessing at Scale: Permissions Decide the Damage
AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI. [...]
Windows 11 KB5101684 update released with 42 changes and fixes
Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system. [...]
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham's water plant went offline, and the city asked residents to minimize
Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies
ACI Worldwide and dLocal bring Latin American payment rails to global merchants
ACI Worldwide (NASDAQ: ACIW), an original innovator in global payments technology, and dLocal (NASDAQ: DLO), the leading payment platform connecting global merchants to emerging markets, today announced a strategic partnership that gives global merchants immediate and seamless access to leading local payment methods in Brazil and Mexico through the ACI Payments Orchestration Platform, with Argenti
PayPal and Amazon launch BNPL payments for customers in Germany and Austria
PayPal and Amazon today announced that starting in August eligible Amazon customers in Germany and Austria will be able to use PayPal Ratenzahlung on Amazon.de1 and in the Amazon app over the coming weeks, giving shoppers more flexibility to pay over time for eligible purchases.
US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security
The agency said imports of advanced robots pose cybersecurity and other national security risks. The post US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security appeared first on SecurityWeek .
How AI is Rewriting the Zero-Day Playbook for Preemptive Security
The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most difficult, question: "Are we exposed?” Answering questions like these when zero-days drop tends to trigge
Bloomberg to buy Canoe Intelligence for private markets push
Bloomberg has struck a deal to acquire AI-powered alternative investment data platform Canoe Intelligence. Financial terms were not disclosed.
OpenAI rogue AI agent’s attack expanded beyond Hugging Face
The autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet of one of the first publicly documented AI-driven intrusion chains. Hugging Face’s technical timeline identifies Modal
Mate Security Raises $35 Million for Agentic SOC
The startup will use the investment to expand its customer support, sales, and R&D teams. The post Mate Security Raises $35 Million for Agentic SOC appeared first on SecurityWeek .
Russia accuses Telegram founder of aiding terrorism, seeks international arrest
Russia is seeking to place Telegram founder Pavel Durov on an international wanted list, alleging that the app has been used by Ukrainian intelligence to organize terrorist attacks and conduct espionage inside Russia.
Soniva Dental Care Data Breach Affects At Least 30,000 Patients
Data breaches have been announced by Soniva Dental Care in Texas, Optalis Management Solutions in Michigan, CareCloud in New Jersey, […] The post Soniva Dental Care Data Breach Affects At Least 30,000 Patients appeared first on The HIPAA Journal .
ThreatLocker Raises $190 Million in Series F Funding
The company was previously valued at $1.6 billion, and the latest raise has significantly increased that valuation. The post ThreatLocker Raises $190 Million in Series F Funding appeared first on SecurityWeek .
NVD HIGH: CVE-2026-14270 — The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCom...
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings() function, which allows low-privileged authenticated users to modify the tc_eco_custom_file_types upload allowlist setting,
Mythos Asks the Right Question. It Doesn't Answer It.
AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change? The honest answer is
Operationalize AI Governance Across Shadow GenAI, MCP, and Agentic Workloads with Qualys TotalAI
Key Takeaways AI adoption has outpaced enterprise controls, with AI and LLM workloads appearing faster than security teams can inventory or approve them. AI governance has become an evidence problem. Policies, questionnaires, and risk registers cannot prove that AI systems are safe. Traditional security tools see only fragments of AI risk. They miss model behavior, […]
Cyberattack hits Angola’s largest telco hours before landmark stock debut
Angola’s largest telecommunications operator, Unitel, was hit by a cyberattack that has left millions of people nationwide without voice services, mobile data, and internet access.
Citi rolls out digital invoice processing tool
Citi has launched Citi Consolidate, a new invoice processing solution powered by Infor, the Industry Cloud Complete company.
2026 Minimum Elements for a Software Bill of Materials (SBOM)
<p>CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, <a href="https://www.cisa.gov/sites/default/files/2026-07/2026_cisa_sbom_minimum_elements_508c.pdf">2026 Minimum Elements for a Software Bill of Materials (SBOM)</a>, that updates and replaces the minimum elements for an SBOM published by the National Telecommunicati
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. "No settings or additional user interaction are required," Eten Zou,
Critical VM Escape Vulnerability Patched in VMware ESXi
A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion. The post Critical VM Escape Vulnerability Patched in VMware ESXi appeared first on SecurityWeek .
NVD HIGH: CVE-2026-18220 — An out-of-bounds write vulnerability was found in the BFD library's DLX ELF back...
An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation
NVD HIGH: CVE-2026-16655 — The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Fo...
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that
NVD HIGH: CVE-2026-16597 — The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPres...
The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.22.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses
NVD CRITICAL: CVE-2026-14900 — The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Cod...
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the orderDetails[*].originalValue field, which is injected verbatim into a calculator formula string passed to PHP eval() inside js_to_php(), with the regex allow-list in evaluateFormula() onl
NVD CRITICAL: CVE-2026-14488 — The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via...
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the handle_request() function routing the mbfs_delete action without any capability or ownership check, and the nonce verification in check_ajax() being gated behind is_ajax() which is false
Global Data Breach Costs Rise 12% to Almost $5 Million
The IBM 2026 Cost of a Data Breach Study shows data breach costs have risen by 12% in a year […] The post Global Data Breach Costs Rise 12% to Almost $5 Million appeared first on The HIPAA Journal .
Global Data Breach Cost Rises 12% to Almost $5 Million
The IBM 2026 Cost of a Data Breach Study shows data breach costs have risen by 12% in a year […] The post Global Data Breach Cost Rises 12% to Almost $5 Million appeared first on The HIPAA Journal .
73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by Vanson Bourne in January
These near-mint ASUS Chromebook refurbs are only $145
Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade "A" rating, but it still only costs $144.97 (reg. $369.99) on sale. [...]
Long-Lived Vulnerability in Microsoft Secure Boot
Microsoft’s Secure Boot has had a serious vulnerability for most of its existence. An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were
The Average Cost of a Data Breach Rises to $5 Million
IBM Cost of a Data Breach Report warns that the global average cost of a data breach has reached a record high of $4.99m – and AI-backed attacks have played a role
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal security agency said the instant messaging platform "failed to remove numerous channels, chats, and bots on the platform that are
US, Australia Release OT Isolation Guidance for Critical Infrastructure
The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period. The post US, Australia Release OT Isolation Guidance for Critical Infrastructure appeared first on SecurityWeek .
Oxane Partners secures strategic growth investment from TA Associates
Oxane Partners (“Oxane” or “the Company”), a leading technology-driven solutions provider to the private credit industry, today announced a strategic growth investment from TA Associates (“TA”), a leading global private equity firm.
Opetek launches AI reasoning platform for intstitutional trading desks
Opetek today announced the launch of ARIUS, its proprietary quantitative reasoning platform for institutional capital markets.
Private market fund accounting platform LemonEdge raises $21 million
LemonEdge, a fund accounting platform built for private markets, has completed a $21 million Series A investment round led by Blackstone Innovations Investments, and joined by BNY and Sidekick Partners.
NVD HIGH: CVE-2026-58187 — The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on...
The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
NVD CRITICAL: CVE-2026-58185 — The Apache Traffic Server intercept plugin has a use-after-free. This issue aff...
The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
NVD HIGH: CVE-2026-58184 — The Apache Traffic Server header_rewrite plugin can crash or corrupt memory duri...
The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
NVD HIGH: CVE-2026-58183 — The Apache Traffic Server prefetch plugin can crash when processing attacker-inf...
The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
NVD CRITICAL: CVE-2026-58179 — The Apache Traffic Server regex_remap plugin overflows the stack and integers fr...
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
NVD CRITICAL: CVE-2026-58177 — The Apache Traffic Server Cripts framework has out-of-bounds writes, path traver...
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.
NVD CRITICAL: CVE-2025-10656 — The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin f...
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user_filter function. This makes it possible for unauthenticated attackers to create admin accounts.
Singapore's central bank convenes AI-Driven Cyber and Technology Risk Taskforce
Singapore's central bank is establishing an AI-Driven Cyber and Technology Risk Taskforce in collaboration with the country's leadingg commercial banks and tech companies.
Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
For now, the use of AI benefits vulnerability research more than vulnerability exploitation, a VulnCheck researcher said
OpenAI’s Rogue AI Ventured Beyond Hugging Face
Hugging Face has published an anatomy of the attack and OpenAI has shared additional information from its investigation. The post OpenAI’s Rogue AI Ventured Beyond Hugging Face appeared first on SecurityWeek .
It’s easier to steal cargo than toothpaste
Our cybersecurity world can get quite interesting and even close to science fiction sometimes. No, it’s not AI this time, but something movie-worthy nevertheless. Picture scenes from known heist-themed movies such as “Ocean’s Eleven” or “Mission: Impossible”. Real-world equivalent scenarios like these are happening in front of your eyes and you might not even know when it’s happening. Cyber-enable
OpenAI’s rogue AI agent shows why we need federal rules for autonomous systems
The Hugging Face breach shows there is a gap in federal policy. The frameworks to govern autonomous AI already exist—there just needs to be the desire to apply them. The post OpenAI’s rogue AI agent shows why we need federal rules for autonomous systems appeared first on CyberScoop .
Researchers Warn of AI-Enhanced Phone Fraud Ecosystem
AI is dramatically reducing the barriers to entry for scam phone farm operators, Human Security warns
NVD HIGH: CVE-2026-13425 — The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scr...
The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by una
Specialist Hub selects OMS as CRM provider
One Mortgage System (OMS), the leading CRM and loan origination platform for intermediaries and lenders, has been chosen by Specialist Hub as its customer relationship management (CRM) provider.
WealthSimple to give Canadian customers access to US futures contracts via Plus500
Plus500, a global multi-asset fintech group operating proprietary technology-based trading platforms, today announces a strategic partnership with Wealthsimple, Canada's leading financial innovator, serving more than 4 million Canadians and holding C$150bn in assets under administration.
Spur Raises $200 Million for IP Intelligence Platform
The IP intelligence company will use the fresh investment to accelerate and scale its operations. The post Spur Raises $200 Million for IP Intelligence Platform appeared first on SecurityWeek .
BMLL appoints Brad Hunt as chairman
BMLL, the independent provider of harmonised, continually engineered historical Level 3, 2 and 1 data and analytics for Capital Markets, today announced the appointment of Brad Hunt as Chairman of the Board.
Risk-based patching is the future. AI made it table stakes
CISA’s new Binding Operational Directive (BOD) 26-04 marks one of the most important changes to federal vulnerability management in years. Rather than requiring agencies to patch every critical vulnerability on the same timetable, the directive prioritizes remediation based on risk, with patch deadlines ranging from three days for the highest-risk vulnerabilities to deferral for those posing minim
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek .
NCSC Publishes Guidance to Aid Incident Response and Recovery
The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery
NVD CRITICAL: CVE-2026-18191 — VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allo...
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device.
How MFA gets hacked — and strategies to prevent it
The security benefits of multifactor authentication (MFA) are well-known, yet MFA continues to be poorly, sporadically, and inconsistently implemented, undercutting its effectiveness as a security tool while often saddling users with an extra workflow burden — one of many obstacles to MFA’s success. Frequent news stories that describe innovative ways to circumvent MFA don’t help, such as evidence
Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks
State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities. The post Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks appeared first on SecurityWeek .
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The
Apple Patches Everything (July 2026), (Wed, Jul 29th)
I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 versions.
Ransomware report: VPNs in the crosshairs, AI attacks
Ransomware attacks were up year over year in June for the fourth consecutive month, according to the NCC Group, though attacks increased just 3% in Q2 2026 versus the previous quarter. VPNs and other network edge devices continue to be prime initial access targets. And an autonomous AI agent enters the fray. Here is a rundown of recent ransomware developments. Industries at risk NCC Group reports
Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment, and also hacked multiple third-party accounts and services as part of the attack. The latest disclosure shows that the security incident, which stemmed from an internal security test, was more extensive in scope than
ShinyHunters Claims Ernst & Young Hack
Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform. The post ShinyHunters Claims Ernst & Young Hack appeared first on SecurityWeek .
NVD CRITICAL: CVE-2026-18072 — The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick ...
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied t
Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.0.0-rc24-2773-beta.4 The two packages "contain an import-time JavaScript implant that resolves encrypted code
NVD HIGH: CVE-2026-12476 — The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File ...
The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in the edd_do_ajax_import_file_upload() function , which only checks the client-supplied $_FILES['edd-import-file']['type'] Content-Type header against an allow-list of CSV mime types, then uses raw move_uploaded_file() (bypa
Stadium Summer: The Snyk Connect Fan Zone Tour
Snyk’s Fan Zone tour brought AI security workshops, networking, and friendly competition to 8 cities and 3 virtual sessions. Attendees built skills, shared ideas, and leveled up together.
FTC sues Hims & Hers for allegedly sharing patient information with third-party platforms
Popular telehealth provider Hims & Hers "shared consumers’ sensitive health information with third-party advertising platforms such as Meta and Snap despite promising to protect patient privacy," the federal government alleges.
NVD HIGH: CVE-2026-12144 — The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Es...
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with no allowlist validation against permitted wholesale roles and no capability check
Measuring LLMs’ Ability to Perform Cryptanalysis
There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks. The benchmark: “ CryptanalysisBench: Can LLMs do Cryptanalysis? ” The idea is to benchmark the ability of LLMs to discover new mathematical cryptanalytic attacks against a series of historical algorithms. Abstract: Cryptanalysis
Fortinet’s new FortiGate platform converges firewall, SASE technologies
Fortinet has expanded its firewall family with new high-speed boxes that, when combined with the vendor’s FortiSASE Outpost software, extend cloud-based SASE (secure access service edge) capabilities and policy enforcement to on-premises environments. The new midrange FortiGate 1200G series supports 10G, 25G, and 100G connectivity options and delivers 397 Gbps firewall throughput. It’s aimed at se
A 13-year-old flaw is exposing tens of thousands of data center management systems
The ‘no man’s land’ beneath the OS on enterprise servers is becoming the malicious actors’ next target. Attackers are gaining a foothold into broader data center environments by exploiting Baseboard Management Controllers (BMCs) that are largely unprotected, still running decades-old protocols and susceptible to a vulnerability published 13 years ago, according to data center security company Lava
The CSO’s blind spot: Why platform engineering 2.0 is now a security imperative
Security leaders have spent the last decade building controls around people and code. Shift-left practices caught vulnerabilities earlier in the development cycle. Zero trust reduced lateral blast radius. Developer tooling added guardrails at the IDE. The architecture was sound — for an enterprise where humans wrote code and humans ran applications. That enterprise no longer exists. AI agents are
Arista patches maximum severity vulnerability that is already being exploited
Arista has patched a VeloCloud Orchestrator (VCO) security hole that has been actively leveraged in the wild, one that the vendor says “may allow a remote attacker to access privileged internal functionality and impact the VCO host.” The Arista security advisory added that the hole “may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestr
Ebanx and Pagaleve blend Pix and BNPL to expand access to instalment plans in Brazil
Brazilian commerce platform Ebanx has joined forces with local payments fintech Pagaleve to bring buy now, pay later to the country's Pix system.
SPP launches AI governance framework for pensions industry
The Society of Pension Professionals (SPP) has launched a practical framework to guide pension scheme trustees, advisers, and administrators through responsible AI leadership.
AI Lab Staffers Urge Government to Slow Frontier AI Race
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ai-lab-staffers-urge-government-to-slow-frontier-ai-race-image_small-6-a-32353.jpg" align=right hspace=4><b>More Than 1,000 Employees Back International Coordination on AI Safety</b><br>More than 1,000 employees from Anthropic, OpenAI, Google and Meta signed a letter urging governments to support international efforts to slow fron
US FCC Bans Sales of Foreign-Made Power Inverters and Robots
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/us-fcc-bans-sales-foreign-made-power-inverters-robots-image_small-7-a-32352.jpg" align=right hspace=4><b>Interagency Review Warns Internet-Connected Inverters Could Enable Grid Shutdowns</b><br>The U.S. federal government is banning new sales of foreign-made mobile robots and connected power inverters. Cybersecurity experts and ot
CISA KEV: Cisco Secure Firewall Management Center (FMC) — Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
Senate confirms Clayton as intel chief after delays
A party-line vote in the Senate installed Jay Clayton as director of national intelligence, a job that has drawn increasing scrutiny during Donald Trump's second term as president.
1Password CEO: AI Spending Needs Identity-Based Governance
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/1password-ceo-ai-spending-needs-identity-based-governance-image_small-6-a-32351.jpg" align=right hspace=4><b>Human Oversight Remains Essential as AI Spending Accelerates Across Enterprises</b><br>1Password CEO David Faugno says enterprises need identity-driven AI governance that connects users, models, spending and business outcom
Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
Security researcher Aleksandr Krasnov reveals dormant non-human identities can create security blind spots and releases NHI Hound, an open source tool to sniff out trust paths.
CubePilot drone software dev hit by DNS hijacking to intercept traffic
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. [...]
NVD HIGH: CVE-2026-15328 — IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv...
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling.
NVD HIGH: CVE-2026-15325 — IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv...
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.
NVD HIGH: CVE-2026-15280 — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collecti...
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism.
NVD HIGH: CVE-2026-15064 — IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv...
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
NVD HIGH: CVE-2026-15057 — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerab...
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
NVD HIGH: CVE-2026-14996 — IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related...
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
NVD HIGH: CVE-2026-14981 — IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv...
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
NVD HIGH: CVE-2026-14976 — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected...
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
NVD HIGH: CVE-2026-14974 — IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote a...
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
NVD CRITICAL: CVE-2026-14973 — IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow fil...
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
NVD CRITICAL: CVE-2026-14959 — IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated at...
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.
NVD CRITICAL: CVE-2026-14958 — IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated at...
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.
NVD HIGH: CVE-2026-14893 — IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana...
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.
NVD HIGH: CVE-2026-14528 — IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote a...
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
NVD CRITICAL: CVE-2026-14512 — IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-a...
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
NVD CRITICAL: CVE-2026-14446 — IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access con...
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.
NVD HIGH: CVE-2026-13463 — IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive in...
IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.
NVD HIGH: CVE-2026-13442 — IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another use...
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact through persistent poisoning of returned results.
Flaw From 2002 Exposes Data Centers to Server Takeover
Lots of Internet-exposed server management controllers are subject to offline password-cracking attacks — and adversaries have taken note.
Thousands of Data Center Controllers Open to Takeover
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks — and adversaries have taken note.
Here’s what Anthropic found when it turned Mythos loose on encryption algorithms
Claude Mythos exposed mathematical weaknesses in a post-quantum candidate and a simplified version of AES, marking a major breakthrough for AI-driven cryptanalysis. The post Here’s what Anthropic found when it turned Mythos loose on encryption algorithms appeared first on CyberScoop .
OpenAI models used Artifactory zero-days to escape to the internet
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. [...]
When AI Agents Escape Sandboxes, Old Security Rules Apply
OpenAI's recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log everything.
NVD HIGH: CVE-2026-57510 — SuperPlane before 0.27.0 contains a broken object-level authorization vulnerabil...
SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary canvas or queue UUIDs without organization scoping. Attackers can read cross-tenant execution history and event payloads contain
NVD HIGH: CVE-2026-16192 — IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected...
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled.
NVD HIGH: CVE-2026-16184 — IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to b...
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
Stronger AI Safety Requires Peeking Inside the 'Black Box'
Researchers propose focusing on identification of certain cognitive elements in LLMs that indicate when AI systems may take an unwanted action.
Claude's Shared Chats Surface on Google Search
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/claudes-shared-chats-surface-on-google-search-image_small-1-a-32348.jpg" align=right hspace=4><b>Nearly 11 Months After a Similar Exposure, Sharing Guide Omits Search Risk</b><br>An unknown number of shared Claude chats and published Artifacts surfaced in Google results, including pages that reportedly contained medical, personal
Medical Billing Vendor Hack Affects 1.3M Patients
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/third-party-medical-billing-vendor-hack-hits-13m-patients-image_small-10-a-32350.jpg" align=right hspace=4><b>Extortion Gang PEAR Claims Theft of 3.3TB of MCBS LLC's Client and Patient Data</b><br>A Georgia-based medical billing firm is notifying nearly 1.3 million patients of seven healthcare practices of a 2025 hack, ranking the
Conquest integrates Shaping Wealth’s Lydia agent into advisor workflow
Conquest Planning Inc. (“Conquest”), the AI-powered technology platform modernizing financial advice delivery across the full wealth spectrum, and Shaping Wealth, the leading provider of behavioral science-based learning and engagement solutions for the wealth management industry, today announced a new integration that brings Lydia, Shaping Wealth’s AI-powered behavioral intelligence agent, direct
NVD HIGH: CVE-2026-7769 — IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2...
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in t
NVD HIGH: CVE-2026-66745 — Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) con...
Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior to authentication. Attackers can pre-set a controlled session identifier and wait for a victim to authenticate through fw.login.php, after which the att
NVD HIGH: CVE-2026-48396 — Bridge is affected by an Incorrect Authorization vulnerability that could result...
Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
NVD HIGH: CVE-2026-48395 — Bridge is affected by an Untrusted Search Path vulnerability that could result i...
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
NVD HIGH: CVE-2026-48394 — Bridge is affected by an out-of-bounds write vulnerability that could result in ...
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
NVD HIGH: CVE-2026-48393 — Bridge is affected by an out-of-bounds write vulnerability that could result in ...
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
NVD HIGH: CVE-2026-48392 — Bridge is affected by an out-of-bounds write vulnerability that could result in ...
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
NVD HIGH: CVE-2026-48391 — Bridge is affected by an Untrusted Search Path vulnerability that could result i...
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
NVD HIGH: CVE-2026-48390 — Bridge is affected by an Incorrect Authorization vulnerability that could result...
Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
NVD HIGH: CVE-2026-48374 — Bridge is affected by an Improper Limitation of a Pathname to a Restricted Direc...
Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
NVD HIGH: CVE-2026-18107 — A flaw was found in CRIU's handling of restartable sequences (rseq) during check...
A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section that hijacks CRIU's parasite code injection during checkpoint, allowing it to spoof the process credentials saved in the checkpoint image. On restore, the container process gains elevated capabilities and zeroed UIDs/GIDs. The
NVD HIGH: CVE-2026-15992 — The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalatio...
The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally calls `WP_User::set_role()` with the attacker-supplied `role` parameter on any account resolved via `$_POST['user_login'
Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities
A cyberattack of undetermined origin disrupted water treatment plants in at least 30 communities in Minnesota, according to the state's technology bureau. The post Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities appeared first on CyberScoop .
IoT Sector Given Final EU Cyber Resilience Act Guidance
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/iot-sector-given-final-eu-cyber-resilience-act-guidance-image_small-3-a-32349.jpg" align=right hspace=4><b>Incident Reporting Starts Sept. 11, Other Mandates Wait Until Dec. 11, 2027</b><br>The European Commission published final guidance for complying with the Cyber Resilience Act, a 2024 law that aims to boost the cybersecurity
Many More Bugs But Exploits Stay Steady
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/so-far-post-mythos-bug-volume-surges-exploits-stay-flat-image_small-5-a-32346.jpg" align=right hspace=4><b>Data Shows Hackers Not Using More Exploits, But They Are Exploiting Flaws Quicker</b><br>The coming of the vulnocalypse - our artificial intelligence-instigated moment of drastically accelerating flaw discovery - has yet to b
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server
CISA shares advice on isolating vital systems during cyberattacks
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. [...]
Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
Overview On July 22, 2026, Check Point published a security advisory for CVE-2026-16232 , an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administra
Juniper Square launches AI agent to catch fund admin errors
Juniper Square, the operations partner to more than 2,300 private markets GPs, today announced its new Admin Oversight Agent, Fay. In June, Juniper Square introduced Headless GPX and opened its fund operating system to any AI a GP chooses to use.
NVD HIGH: CVE-2026-48388 — Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vu...
Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running t
NVD HIGH: CVE-2026-48372 — Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that co...
Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Tech jobs go as Visa cuts workforce by 7%
Visa is set to cut around 2600 jobs - seven per cent of its workforce - with technology and product roles taking the brunt of the hit as the payments giant reconfigures its operations for the AI era.
Ramp enters Canada
Ramp today announced its entry into the Canadian market, making its finance platform available to businesses in Canada. With Ramp, companies can manage spend across currencies in one place, including cards in CAD and USD, CAD bill payments and reimbursements, automated GST, HST, PST, and QST coding, and shared controls, approvals, and accounting workflows.
vBulletin fixes critical pre-auth RCE flaw with public exploit
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]
Rent payment fintech Flexible Finance applies for bank license
Flexible Finance, Inc. (“Flex”), the financial technology company behind Flex Rent, today announced it has submitted applications to the Federal Deposit Insurance Corporation (“FDIC”) and the Utah Department of Financial Institutions (“UDFI”) to charter Flex Bank, a Utah state-chartered industrial bank.
FBI sees Anthropic’s Mythos as a law enforcement challenge
The post FBI sees Anthropic’s Mythos as a law enforcement challenge appeared first on CyberScoop .
NVD HIGH: CVE-2026-67185 — TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauth...
TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which are concatenated directly to the configured web root in HttpBuilder::buildResponse() without normalization, dot-segment removal, or boundary checks. Attackers can craft a single request with ../ sequences that pass through th
NVD HIGH: CVE-2026-67184 — TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that all...
TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line with an invalid version string. The HttpParser::execute() function fails to allocate the Url object when version parsing fails, leaving the url pointer NULL, and buildResponse() subsequently dereferences this NULL po
NVD HIGH: CVE-2026-67183 — TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthent...
TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader instances via raw new expressions that are never freed due to missing destructors and unreachable delete calls, causing worke
NVD HIGH: CVE-2026-67182 — Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability tha...
Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) into client-supplied request header values that are copied verbatim to upstream connections without validation. Attackers can craft a header value containing a complete additional HTTP request that is interpreted as a sepa
NVD HIGH: CVE-2026-16313 — A flaw was found in sg3_utils. The sg_inq command, when invoked with the --expor...
A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitr
House Committee Advances Bill Preventing OSHA From Implementing Heat Standard
A bill that seeks to prohibit the Department of Labor’s Occupational Safety and Health Administration (OSHA) from issuing a standard […] The post House Committee Advances Bill Preventing OSHA From Implementing Heat Standard appeared first on The HIPAA Journal .
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.
NVD HIGH: CVE-2026-67181 — Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability tha...
Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation. The proxy in src/proxy.rs forwards the client's Transfer-Encoding header to upstream backends unchanged while transmitting a body already de-chunked by tiny_http, enabling CL.TE desyn
NVD HIGH: CVE-2026-66754 — Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the ...
Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request whose decoded path matches a configured prefix while the raw percent-encoded path does not, causing the assert! to fail and triggering either a 500 erro
NVD HIGH: CVE-2026-66752 — tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that a...
tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize request framing by sending a Transfer-Encoding header with any value, including non-chunked codings, which causes the library to unconditionally apply chunk-decoding and discard Content-Length. Attackers can exploit the discrepancy between tiny_http's improper Transfer-Encoding p
NVD HIGH: CVE-2026-66748 — Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code ...
Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers can store an attacker-controlled Ruby expression in the field options command parameter, which is evaluated via instance_
Disrupting supply chain attacks on npm and GitHub Actions
Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact. The post Disrupting supply chain attacks on npm and GitHub Actions appeared first on The GitHub Blog .
Corpay introduces agent card capability
Corpay, a global leader in corporate payments, today announced Agent Card, a new capability that enables secure virtual card creation for AI-driven commerce workflows.
NVD HIGH: CVE-2026-8164 — Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardwar...
Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026.
NVD HIGH: CVE-2026-63727 — Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper ...
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capable of modifying user permissions to gain access to additional resources and operations. It is not possible to grant the system-admin role, but a read onl
Apple partners Klarna for new hardware leasing programme
Klarna, the global digital bank and flexible payments provider, today announced it would be the leasing provider behind the Apple Upgrade program, a new hardware leasing option available from Apple in the United States.
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it
Fenergo launches Fen-AI to bring governed AI to client lifecycle management
Fenergo, the leading provider of digital solutions for Know Your Customer (KYC), Anti-Money Laundering (AML) and client lifecycle management (CLM), today announced the launch of Fen-AI, its agentic AI orchestration platform for financial institutions.
AI-assisted security tools are finding more bugs, but the threat level has not changed
Analysis from vulnerability intelligence firm VulnCheck shows AI-discovered flaws aren't being exploited any faster than traditional ones. The post AI-assisted security tools are finding more bugs, but the threat level has not changed appeared first on CyberScoop .
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force. Tengu supports 25 distributed denial-of-service (
Iwoca closes debt facility amid £1bn sale speculation
Amid reports it is planning a £1 billion sale later this year, British SME lender iwoca has closed a £250 million debt facility.
Cyera Acquiring Oasis Security in $1 Billion Deal
Oasis Security recently raised $120 million in Series B funding for its agentic access management platform. The post Cyera Acquiring Oasis Security in $1 Billion Deal appeared first on SecurityWeek .
India’s Bank of Baroda confirms cyber incident after hackers claim data theft
An employee's email account had been compromised, allowing unauthorized access to "certain data," Bank of Baroda reported.
AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched
AI-assisted research uncovered Linux kernel use-after-free allowing root escalation
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose password-derived authentication hashes before login due to
Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe
Apple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared first on SecurityWeek .
X Money starts US rollout
X Money is now available to US Premium and Premium Plus subscribers to Elon Musk's social media app.
Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813)
[object Object]
Is Your SSO Protected Against Modern Credential Attacks?
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. [...]
PEX secures $160m to scale payments, credit and finance automation platform
Corporate card and spend management platform PEX has secured $160 million in debt and equity financing led by Bluff Point Associates.
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud
Rothera implements Eventus platform for trade surveillance of event contract exchange
Eventus, a leading provider of comprehensive, at-scale trade surveillance and financial risk solutions, and Rothera, the U.S.-based CFTC regulated event contract market, today announced that Rothera has deployed and implemented Eventus’ Validus platform for trade surveillance of its fast-growing markets.
Singapore's MAS and ABS set up taskforce to boost cyber resiliance against AI-driven threats
The Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) today announced the establishment of the AI-Driven Cyber and Technology Risk Taskforce (ACT), an industry-wide initiative to strengthen collective cyber and technology resilience in response to the emerging risks posed by frontier artificial intelligence (AI) models.
Goldwise taps Integral for 24/7 institutional precious metals trading
Goldwise, the UK-based precious metals fintech, has partnered with Integral, a leading currency technology provider, to launch 24/7 institutional trading for physical gold, silver, platinum, and palladium.
NVD HIGH: CVE-2026-7187 — Missing authentication for critical function vulnerability in Universal Software...
Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKBS: through 28072026. NOTE: The vendor was contacted and it was learned that the product is not supported.
NVD HIGH: CVE-2026-49332 — A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity...
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate
OT Security Startup Frenos Raises $1.52 Million
The company will use the fresh investment to grow its customer success and AI R&D teams. The post OT Security Startup Frenos Raises $1.52 Million appeared first on SecurityWeek .
AI Changes the Software Supply Chain and How We Secure It
<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/ai-changes-the-software-supply-chain-and-how-we-secure-it" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/blog_gartner_secure_ai_supply_chain.jpg" alt="Image with a hexagon shape at center containing the text "AI" with multiple offshoots connecting to circles containing software icons
Rapid7 Cyber GRC is now available: Turn security action into compliance proof
Compliance has become one of the biggest operational drains on modern security teams. CISOs are being asked to manage a growing sprawl of frameworks, prove control effectiveness more often, respond to more customer assurance requests, track risk across a growing web of third parties, and give executives and the board a clearer answer on whether cyber risk is actually going down. Most of that press
The Next Evolution of MDR: Preemptive Defense and Agentic Investigation
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next. In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise
Infoblox joins crowded EASM market with DNS-centric approach
With AI compressing reconnaissance and exploit development from weeks to hours, security vendors are racing to help enterprises identify exposures long before an incident happens. Infoblox is the latest to make that move, announcing its entry into the External Attack Surface Management ( EASM ) market alongside a new Supply Chain Intelligence capability that broadens its exposure management portfo
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6
Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model
IMF issues crypto asset warning to Brazil
The International Monetary Fund (IMF) has called for closer oversight of Brazil's rapidly developing digital assets market.
Former Citigroup CISO Blauner on What Makes A Great Security Leader
The cybersecurity pioneer discusses the evolution of the CISO role, AI's impact on careers, and why operational resilience is the profession's next frontier.
Standard Chartered names CTO for India and South Asia
UK bank Standard Chartered has bolstered its executive team in Asia after appointing Kavita Kulkami as chief technology and operations officer for India and South Asia
NVD HIGH: CVE-2026-15025 — The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builde...
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and automator_mautic_render_contact_fields AJAX actions due to a missing capability check and missing nonce v
NVD HIGH: CVE-2026-13440 — The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Che...
The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message_popup' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. [...]
Pemo secures approval in UAE to expand payments offering
Pemo, the UAE's leading all-in-one spend management platform built for small and medium-sized businesses (SMEs), today announced that it has received in-principle approval from the Central Bank of the UAE (CBUAE) for a Stored Value Facilities (SVF) licence.
Multiple water facilities in Minnesota attacked; Iranian hackers may be responsible
On June 16, media reported that Iran-linked Handala had attacked Cal Water. There was no evidence that they tampered with the water supply, but the group warned it would be increasing attacks on U.S. critical infrastructure. On July 23, the Iran-linked WANA News reported: Following a cyberattack by the hacking group “Handala” on Maryland’s Operational... Source
Multiple water facilities in Minnesota attacked; Iranian hackers may be responsible (UPDATED)
UPDATE: More than 30 Minnesota community water systems were attacked between Sunday and Monday. Original post: On June 16, media reported that Iran-linked Handala had attacked Cal Water. There was no evidence that they tampered with the water supply, but the group warned it would be increasing attacks on U.S. critical infrastructure. On July 23,... Source
Siemens Mendix Runtime
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead appl
MikroTik RouterOS and Cloud Hosted Router
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-05.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access.</strong></p> <p>The following versions of MikroTik RouterOS and Cloud Hosted Router are affected:</p>
Siemens SIMATIC S7-PLCSIM Advanced
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or no
Siemens Desigo CC
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommend
ABB KNX Update Tool
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-07.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in re
igloohome Smart Lock Mobile Application
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-06.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services.</strong></p> <p>The following versions of igloohome Smart Lock Mobile Application are affected:</p> <ul> <li>Smar
CI Fortify – Advice for isolating vital systems
<div class="c-page-title__buttons"><a class="c-button" href="https://www.cyber.gov.au/business-government/secure-design/operational-technology-environments/ci-fortify/ci-fortify-advice-for-isolating-vital-systems" target="_blank">CI Fortify – Advice for isolating vital systems</a><br><br>CISA and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration w
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,
Trulioo launches AI agent for beneficial ownership registry
Trulioo, a global risk intelligence platform, today announced the UBO Discovery Agent, the newest layer in Trulioo’s UBO Discovery capability inside its business risk and Know Your Business (KYB) verification workflow.
Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model
The company claims MAI-Cyber-1-Flash tops Anthropic’s Mythos and OpenAI’s GPT-5.6 Sol in CyberGym testing. The post Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model appeared first on SecurityWeek .
Axon Is Another License Plate Surveillance Company
Governments are switching, but I’m not sure it makes a difference : …some municipalities, including Denver, Colorado, are ditching their Flock arrays. But keep in mind that if they’re only switching from Flock to another brand of license-plate readers, like Axon, it’s like a gambling addict trying to kick the habit by switching from FanDuel to DraftKings. […] Despite
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack
Act Security Emerges from Stealth to Fight the Patch Problem
Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. The post Act Security Emerges from Stealth to Fight the Patch Problem appeared first on SecurityWeek .
How we use /goal to find bugs in Patch the Planet
<p>Codex’s <code>/goal</code> feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For <a href="https://trailofbits.com/patch-the-planet">Patch the Planet</a>, our joint initiative with OpenAI to find and fix bugs in open-source software, we pointed Codex at some of the most widely used, heavily audited codeba
PNC Financial Services appoints CISO
The PNC Financial Services Group, Inc. (NYSE: PNC) announced today that Christian Winward has been named chief information security officer.
Hush Security Raises $30 Million for AI Agent Governance
The startup will invest in expanding engineering and sales teams, accelerating ecosystem support, and expanding corporate partnerships. The post Hush Security Raises $30 Million for AI Agent Governance appeared first on SecurityWeek .
NVD CRITICAL: CVE-2026-16462 — In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a...
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
NVD HIGH: CVE-2026-14785 — The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injecti...
The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that ca
NVD HIGH: CVE-2026-14328 — The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plug...
The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the `wp_ajax_pos_get_option` AJAX handler, which verifies only a nonce that is localized to every logged-in admin-area user via `admin_enqueue_scripts` — without any capabilit
NVD HIGH: CVE-2026-10207 — The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Inject...
The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id' GET parameter in the user profile template combined with the use of wp_unslash() which removes WordPress's magic quotes protection, followed by direct concatenation into a SQL query without proper es
Florida SUD Treatment Provider Announces 145,700-record Data Breach
Operation PAR, a Florida-based SUD treatment provider, has announced a data breach affecting more than 145,700 individuals. Data breaches have […] The post Florida SUD Treatment Provider Announces 145,700-record Data Breach appeared first on The HIPAA Journal .
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.
NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names
NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”
Bank of Baroda hit by cyberattack
India-based Bank of Baroda (BoB) has confirmed a data breach as a result of an employee's compromised email account.
NVD HIGH: CVE-2026-14516 — The Online Scheduling and Appointment Booking System – Bookly plugin for WordPre...
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL qu
NVD HIGH: CVE-2026-14169 — Due to incorrect behavior order a low privileged remote attacker could trigger a...
Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.
NVD HIGH: CVE-2026-14168 — A low privileged remote attacker can gain administrator privileges due to missin...
A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.
NVD HIGH: CVE-2026-14167 — A low privileged remote attacker can perform privileged configuration changes re...
A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.
NVD HIGH: CVE-2026-13161 — The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress i...
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addition
NVD HIGH: CVE-2026-12800 — The Premium Packages – Sell Digital Products Securely plugin for WordPress is vu...
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint in versions up to, and including, 6.2.0. This is due to insufficient escaping on the user-supplied parameter, which is interpolated directly into a raw SQL query string in the CouponCodes::find() method witho
Data breach at medical billing firm MCBS affects 1.26 million people
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. [...]
Zimbabwe regulator approves seven fintechs for sandbox
The Securities and Exchange Commission of Zimbabwe has given the green light to a number of fintechs seeking to participate in its regulatory sandbox.
Why your AI safety certificates are worthless at runtime
Every week, another enterprise technology vendor issues a glossy press release announcing their new autonomous AI agent architecture, complete with a SOC 2 Type II report, an ISO 42001 certification, and an ironclad safety guarantee. On paper, the enterprise security battle looks won. In production, the trap is just snapping shut. The core mistake modern enterprise leaders are making is treating A
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
CREST’s new AI standards are optional add-on requirements for cybersecurity service providers wishing to demonstrate responsible AI usage
Google Adopts New Threat Actor Naming System
The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. The post Google Adopts New Threat Actor Naming System appeared first on SecurityWeek .
NVD CRITICAL: CVE-2026-15014 — The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart ...
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the `processRegistration()` function using a phone-unbound `$_SESSION['sa_mobile_verified']` boolean flag as the sole gate before
NVD HIGH: CVE-2026-12741 — The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is v...
The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queri
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and speed up exploit development. This is local
Mirage Kitten targets Middle East and Africa region with new malware
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Hugging Face breach shows why incident response needs a multi-model AI strategy
The recent breach of Hugging Face’s platform was the latest in a string of AI-assisted intrusions to come to light in recent weeks , showing that attackers can now use LLMs to automate entire attack chains. But it also exposed a limitation for defenders trying to use AI to respond at similar machine speed: Increasingly conservative safety controls on frontier models can block attempts to analyze m
Rapid7 and Exclusive Networks expand partnership to modernize security operations and accelerate customer success
Claudia Zoon is Senior Manager, Channel Sales at Rapid7. Across Belgium, the Netherlands, and Luxembourg, organizations are accelerating digital transformation through AI, cloud adoption, and increasingly connected business operations. These investments are creating new opportunities for innovation, but also reshaping the cybersecurity landscape. In this dynamic environment, Rapid7 is excited to a
AutoIT Payload Injector , (Tue, Jul 28th)
For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you'll see below.
Unpatched Fastjson Vulnerability Exploited in Attacks
The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek .
NVD HIGH: CVE-2026-16585 — The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots pl...
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which
NVD HIGH: CVE-2026-14490 — The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPres...
The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as dotfiles inside a publicly accessible subdirectory of the WordPress uploads folder — without any `.htaccess` or index file pr
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved
Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved
Origin Energy Data Breach Affects 900,000 Australians
The hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems. The post Origin Energy Data Breach Affects 900,000 Australians appeared first on SecurityWeek .
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution. "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue
How to Become HIPAA Compliant
When considering how to become HIPAA compliant, one of the simplest approaches is to adopt HHS’s “Seven Fundamental Elements of an Effective Compliance Program.” This will help you address compliance challenges identified in a HIPAA risk assessment. The post How to Become HIPAA Compliant appeared first on The HIPAA Journal .
Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts
Traveling enterprise employees beware: Think twice before you log onto that oh-so-convenient public Wi-Fi. Since at least June, threat actors have been compromising “captive” Wi-Fi gateways and other portal appliances at hotels, conference centers, and similar shared venues to hijack users’ Microsoft 365 accounts, according to the ReliaQuest Threat Research team. Once a threat actor controls a gat
For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup
Decades after it appeared in “The Terminator,” Skynet looks more like a forecast of the cyber incident in which a rogue AI system hacked into another AI company on its own. The post For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup appeared first on SecurityWeek .
Microsoft unveils multi-model agentic cyber stack for security operations
Microsoft announced a new AI-powered service that enables enterprise security teams to continuously evaluate and update their organization’s security posture through a series of AI agents that can find vulnerabilities, simulate attacks, detect and triage potential threats, and develop remediations. Dubbed Project Perception , the new service will enter public preview on Aug. 3, and takes a multi-m
Samsung’s entry into AI-powered glasses forces CISOs to again consider corporate risk
Now that Samsung has jumped into the crowded AI-powered glasses arena alongside Apple , Google , Meta , and others, CISOs and IT leaders are again having to think through whether it makes sense to establish enterprise restrictions on such devices, given the likely data leakage and privacy and compliance issues. And even if those tech leaders decide that such policies might make sense, the logistic
Samsung’s AI-powered glasses could be looking at enterprise data
Now that Samsung has jumped into the crowded AI-powered glasses arena alongside Apple , Google , Meta , and others, CISOs and IT leaders are having to think through whether it makes sense to establish enterprise restrictions on such devices, given the likely data leakage and compliance issues. And even if those tech leaders decide that such policies might make sense, the logistical hurdles to univ
Samsung’s AI-powered glasses could be looking at your data
Now that Samsung has jumped into the crowded AI-powered glasses arena alongside Apple , Google , Meta , and others, CISOs and IT leaders are having to think through whether it makes sense to establish enterprise restrictions on such devices, given the likely data leakage and compliance issues. And even if those tech leaders decide that such policies might make sense, the logistical hurdles to univ
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Attackers used Hermes, an autonomous open source tool, in unrestricted "YOLO mode" to conduct espionage against Thailand's Ministry of Finance.
Circle buys IBM's blockchain patent portfolio
Stablecoin issuer Circle Internet Finance has acquired nearly 1000 blockchain-related patents from IBM.
Wyden Calls for Edge Device Annihilation in US Government
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/wyden-calls-for-edge-device-annihilation-in-us-government-image_small-6-a-32344.jpg" align=right hspace=4><b>US Senator Says Zero Trust Must Replace Legacy Edge Devices in 2028</b><br>Network devices conversion into nation-state hackers' favorite initial access vector has a U.S. senator urging the federal government to phase out l
The Generator Can't Be the Validator: What OpenAI's Hugging Face Incident Proves About AI Security
OpenAI’s Hugging Face incident is a wake-up call: AI systems can escape their own test harnesses, and vendors can’t be the only ones validating safety.
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]
Microsoft Unveils AI Security Stack, Low-Cost Cyber Model
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/microsoft-unveils-ai-security-stack-low-cost-cyber-model-image_small-3-a-32343.jpg" align=right hspace=4><b>Project Perception Combines AI Agents With New MAI-Cyber-1-Flash Model</b><br>Microsoft introduced Project Perception, an AI-powered security platform that coordinates specialized agents to detect, investigate and remediate
US Space Cybersecurity: 'No One Is in Charge'
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/us-space-cybersecurity-no-one-in-charge-image_small-6-a-32342.jpg" align=right hspace=4><b>Cyber Defense Falters Without Cabinet Agency or White House Champion for Security</b><br>No single senior official is in charge of U.S. efforts to help secure commercial satellites and their land-based infrastructure. That leadership void ha
Nvidia Launches Open-Source AI Security Alliance
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/nvidia-launches-open-source-ai-security-alliance-image_small-4-a-32339.jpg" align=right hspace=4><b>Anthropic, OpenAI and Google Absent as 37 Firms Back Open AI Security Tools</b><br>Nvidia and 36 other technology giants launched the Open Secure AI Alliance to build and share open-source AI security tools, arguing open models are
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]
Microsoft debuts AI cybersecurity offerings as competition heats up
It includes the new agentic model MAI-Cyber-1-Flash and the Project Perception platform, with the tech giant claiming it’ll do a better job than its rivals at half the cost. The post Microsoft debuts AI cybersecurity offerings as competition heats up appeared first on CyberScoop .
Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms
In a Monday filing, the Justice Department said states sued before agencies even decided how the order would work. The post Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms appeared first on CyberScoop .
NVD HIGH: CVE-2026-55685 — React Router is a router for React. In versions 7.0.0 through 7.17.0, the manife...
React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<Router
Anthropic and DOD Set to Face Off Thursday Over Blacklisting
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/anthropic-dod-set-to-faceoff-thursday-over-blacklisting-image_small-7-a-32341.jpg" align=right hspace=4><b>Both Sides Ask San Francisco Federal Judge for Summary Judgment</b><br>Anthropic and the U.S. Department of Defense are set to face off Thursday in San Francisco federal court before a judge who already called the Pentagon's
CPA Gets Prison Time in $5.3M Healthcare Fraud Case
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cpa-gets-prison-time-in-53m-healthcare-fraud-case-image_small-3-a-32338.jpg" align=right hspace=4><b>Vendor Email Compromise Scam Diverted Children's Healthcare of Atlanta Payment</b><br>A former certified public accountant will serve four years in federal prison following his recent conviction in a money laundering scheme in whic
Agentic Browsers Rewind Web Security by 20 years
PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin requests.
New Dysphoria DDoS botnet spreads to 200k devices worldwide
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]
New Certighost PoC exploit lets attackers hijack Windows domains
A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]
Malware Attack Forces AnMed to Close Care Facilities
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/anmed-closes-care-facilities-as-deals-malware-attack-image_small-4-a-32336.jpg" align=right hspace=4><b>Nonprofit Health System in SC and Georgia Says Email, Phones and Portal Are Down</b><br>AnMed, a nonprofit healthcare system that serves upstate South Carolina and Northeast Georgia, has temporarily closed dozens of its medical
Bank of Baroda Breach Tests Disclosure Readiness
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/bank-baroda-breach-tests-disclosure-readiness-image_small-6-a-32335.png" align=right hspace=4><b>Email Compromise Exposes Sensitive Data, Raising DPDP Act Compliance Questions</b><br>A Bank of Baroda employee email compromise exposed customer and internal data allegedly leaked by the Triple X ransomware group. The incident shows h
'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls.
Outdated VPNs should be purged from federal agencies, senator says
Intelligence Committee member Ron Wyden wants CISA, OMB and NIST to lead a federal effort to rout out obsolete VPNs from the U.S. government.
FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.
ESMA picks EuroCTP to operate consolidated tape for shares and ETFs
The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, has authorised EuroCTP B.V. (EuroCTP) to operate as the Consolidated Tape Provider (CTP) for shares and exchange-traded funds (ETFs).
NVD CRITICAL: CVE-2026-66014 — JFrog Artifactory contains an authentication handling weakness in internal reque...
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
NVD HIGH: CVE-2026-42016 — JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a pri...
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too.
Three times may be a charm for some things, but not for data security incidents. Frontier Airlines allegedly has had a third data security incident this year. First, it was BobDaHacker publishing a blog post on June 16 titled “Your Boarding Pass Is a Skeleton Key.” Frontier Airlines Doesn’t Care. According to the post, Frontier... Source
Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too. (Corrected)
Three times may be a charm for some things, but not for data security incidents. Frontier Airlines allegedly has had a third data security incident this year. First, it was BobDaHacker publishing a blog post on June 16 titled “Your Boarding Pass Is a Skeleton Key.” Frontier Airlines Doesn’t Care. According to the post, Frontier... Source
NVD HIGH: CVE-2026-66759 — A flaw was found in the file-icns plugin in GIMP. When applying a decompressed m...
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability resu
NVD HIGH: CVE-2026-66758 — A flaw was found in the file-fits plugin in GIMP. When processing a FITS image f...
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based buffer allocation. This integer overflow issue results in a heap-based buffer overflow
NVD HIGH: CVE-2026-12383 — A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStre...
A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]) and relies solely on the Subject HTTP header value for mTLS authentication without verifying that the header originated from a trusted proxy. Additionally, the expected certificate Distinguished Name is leaked in the 40
Clop Tied to PTC Product Lifecycle Management Software Hits
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/clop-tied-to-ptc-product-lifecycle-management-software-hits-image_small-8-a-32333.jpg" align=right hspace=4><b>Signs Point to Cl0p Extortion Group Again Stealing Data and Holding It to Ransom</b><br>Digital extortion group Clop, aka Cl0p, has been tied to a fresh spate of supply-chain attacks, this time targeting users of popular
Why Resetting Passwords No Longer Stops Attackers
As attackers shift from password theft to session and token theft to bypass multifactor authentication controls, organizations must move beyond login security and protect authenticated sessions.
NVD HIGH: CVE-2026-64642 — Next.js is a React framework for building full-stack web applications. In versio...
Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has been fixed in version 16.2.11.
NVD HIGH: CVE-2026-64641 — Next.js is a React framework for building full-stack web applications. In versio...
Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process. This issue has been fixed in versions 15.5.21 and 16.2.11.
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux
UK court rejects Bahrain immunity claim in spyware case
The alleged hacking by officials in Bahrain “allowed access to and exfiltration of information on the computers, interception of communications conducted using the computers and use of the computers’ microphones and cameras to surveil the respondents,” according to the court opinion.
Outage leaves UK bank customers unable to make payments
Customers of several UK banks, including Lloyds and Barclays, reported problems with making online payments on Monday.
Detection Opportunities for Certighost (CVE-2026-54121)
[object Object]
Health system in South Carolina, Georgia closes offices after malware affects networks
On Sunday, AnMed published a statement online saying they were “experiencing a cybersecurity disruption involving malware” and were working to restore systems and determine the scope of the incident.
Adversaries Don't Need a Zero-Day — They Read Your Rulebook
Confidence in autonomous security tools is declining, and here's why.
Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin
Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. [...]
Google’s solution to hacker name confusion? Yet another naming system
APT-number conventions are out, cryptonyms are in, and security teams now have one more naming system to keep straight. The post Google’s solution to hacker name confusion? Yet another naming system appeared first on CyberScoop .
NVD HIGH: CVE-2026-66731 — facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the H...
facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single POST request with a Transfer-Encoding: chunked header containing a leading minus sign in the chunk size field, causing the parser in http1_parser.
NVD HIGH: CVE-2026-66730 — facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the m...
facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial closing boundary. The missing progress guard in the parser loop causes http_mime_parse to return 0 bytes consumed without setting done or error f
NVD HIGH: CVE-2026-66729 — facil.io through 0.7.6 contains an integer underflow vulnerability in the multip...
facil.io through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a uint32_t wraparound in http_mime_parser.h causing an out-of-bounds memory read past the name pointer, resulting in a bus fault t
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt. CNCERT, China's national computer emergency response team, and XLab, the threat-intelligence lab of Chinese
Qualys Expands Serverless Security with Vulnerability Scanning for AWS Lambda
Key Takeaways Serverless functions have become a core building block for modern cloud and AI-native applications. With AWS Lambda, developers build and scale applications faster without managing underlying infrastructure. But as Lambda functions increasingly process sensitive data, connect to APIs, invoke AI services, and power critical workflows, securing the code and dependencies running inside
NVD HIGH: CVE-2026-66396 — SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List val...
SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary code in the Electron renderer with full Node.js access when victims open affected documents.
NVD CRITICAL: CVE-2026-66395 — SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerabi...
SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering in an insecurely configured Electron renderer.
NVD HIGH: CVE-2026-66394 — SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerab...
SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements which the HTML parser treats as raw text but browsers interpret as executable SVG content when served as image/svg+xml, e
Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis
Researchers have uncovered a highly personalized phishing campaign that used Telegram to try to hijack the account of an exiled Belarusian activist, as well as users in Russia and Kazakhstan.
Coca-Cola confirms data theft in Fairlife ransomware attack
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]
NVD HIGH: CVE-2026-66050 — NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its ...
NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit the lack of path validation to write files outside the transfer root directory to a
Ernst & Young data breach claimed by ShinyHunters extortion gang
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. [...]
Orion integrates co-developed account opening tool with Goldman Sachs
Orion announced today the launch of its Dynamic New Account Opening tool to support digital account opening within the Orion Advisor Portal.
Keyfactor Expands Into AI Agent Identity With Cofide Deal
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/keyfactor-expands-into-ai-agent-identity-cofide-deal-image_small-9-a-32331.jpg" align=right hspace=4><b>Deal Extends Certificate-Based Trust Framework to AI Agents and Software Workloads</b><br>Cleveland-based Keyfactor plans to acquire London-based startup Cofide to expand its trust platform into software workloads and autonomous
The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches
Key Takeaways Two real-world cloud attacks reached meaningful impact in less than ten minutes despite pursuing entirely different objectives. Both attackers treated the environment as a connected system, using existing permissions and relationships to expand their reach. Reconnaissance increasingly focuses on understanding access and capability rather than discovering vulnerable assets. AI is comp
RefluXFS: Local Privilege Escalation via XFS reflink direct-I/O race (CVE-2026-64600)
[object Object]
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version
New GitHub, PyPI Policies Boost Supply Chain Security
Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, PyPI Policies Boost Supply Chain Security appeared first on SecurityWeek .
GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is shortly due to issue a final rule implementing the Cyber Incident […] The post GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure appeared first on The HIPAA Journal .
HSBC to open Singapore AI centre of excellence
HSBC is set to open a global artificial intelligence centre of excellence in Singapore, hiring around 100 specialists to work under new chief AI officer David Rice.
NVD CRITICAL: CVE-2026-61511 — vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul...
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped. That is the mood. Here is the full recap. ⚡ Threat of the Week OpenAI Says Its AI Agent Went Rogue
Shadow AI agents are multiplying. Here's how to find and secure them.
Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous actions create security risks. [...]
PTC Windchill Vulnerability Exploited in Ransomware Campaign
The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek .
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another bypass. The affected ranges are <2.31.5 and >=2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and
MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek .
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
In a letter first reported by CyberScoop, Ron Wyden, D-Ore., said ‘devastating’ attacks on the federal government have accumulated due to the tech. The post Sen. Wyden urges feds to discard older, insecure, public-facing VPNs appeared first on CyberScoop .
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools. "The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened," ZeroBEC said in
Nvidia and Tech Giants Launch AI Security Alliance
The Nvidia-led coalition aims to give defenders more open tools for testing, auditing and protecting AI models and agents. The post Nvidia and Tech Giants Launch AI Security Alliance appeared first on SecurityWeek .
NVD CRITICAL: CVE-2026-58662 — Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerabi...
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
NVD HIGH: CVE-2026-58389 — Allocation of Resources Without Limits or Throttling vulnerability in Apache Thr...
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
NVD CRITICAL: CVE-2026-58023 — Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue a...
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
NVD CRITICAL: CVE-2026-55971 — Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This is...
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
NVD HIGH: CVE-2026-55969 — Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, n...
Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
NVD HIGH: CVE-2026-55968 — Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Th...
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
NVD HIGH: CVE-2026-48586 — Improper Handling of Highly Compressed Data (Data Amplification) vulnerability i...
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
NVD HIGH: CVE-2026-48145 — Improper Validation of Certificate with Host Mismatch vulnerability in Apache Th...
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
NVD CRITICAL: CVE-2026-48144 — Improper Validation of Certificate with Host Mismatch vulnerability in Apache Th...
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
NVD HIGH: CVE-2026-45112 — Allocation of Resources Without Limits or Throttling vulnerability in Apache Thr...
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
NVD HIGH: CVE-2026-43871 — Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache T...
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
NVD HIGH: CVE-2026-41608 — Improper Handling of Highly Compressed Data (Data Amplification) vulnerability i...
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
AnMed Closes Almost 80 Facilities While it Grapples with Cyberattack
AnMed, formerly AnMed Health, a nonprofit health system serving patients in upstate South Carolina and Northeast Georgia, has been forced […] The post AnMed Closes Almost 80 Facilities While it Grapples with Cyberattack appeared first on The HIPAA Journal .
Hackers used autonomous AI agent to spy on Thailand's finance ministry
Hackers used an autonomous artificial intelligence agent to carry out a cyber-espionage campaign against Thailand's Ministry of Finance, researchers discovered.
MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals
MCBS, LLC, an Augusta, Georgia-based healthcare management and revenue cycle management company, has announced a major data incident involving the […] The post MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals appeared first on The HIPAA Journal .
Bitmart becomes latest crypto exchange to wind down operations
Bitmart has become the second major crypto exchange to wind down its operations, following in the footsteps last week of crypto perpetuals venue BitMEX.
Embat expands into global banking
Embat, the AI-powered fintech specialising in treasury management, has launched a new banking product to harmonise cash management, international payments and collections, FX hedging, account reconciliation and more into a single workflow - creating a comprehensive one-stop solution for finance professionals.
Certighost haunts Microsoft Active Directory Certificate Services
A vulnerability in Microsoft’s Active Directory Certificate Services (AD CS) could allow a low-privilege domain user to impersonate a Domain Controller, security researchers have warned. Dubbed Certighost, the flaw stems from an enrollment fallback mechanism known as a “chase,” which the Certification Authority (CA) uses during directory-object resolution. This mechanism could be used to trick the
SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims
Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
The Anubis cybercrime group has taken credit for the attack and is threatening to leak data. The post Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack appeared first on SecurityWeek .
Accountant laundered $5.3 million stolen from Children’s Healthcare of Atlanta by hacker, prosecutors say
Dan Raby provides this morning’s example of the insider threat: A former accountant has been sentenced to years in federal prison after he was convicted for taking part in a scheme to laundering more than $5.3 million stolen from Children’s Healthcare of Atlanta. Ronald Deabler, a 66-year-old Atlanta business owner and former Certified Public Accountant,... Source
Accountant laundered $5.3 million stolen from Children’s Healthcare of Atlanta by hacker, prosecutors say (1)
Dan Raby reports: A former accountant has been sentenced to years in federal prison after he was convicted for taking part in a scheme to laundering more than $5.3 million stolen from Children’s Healthcare of Atlanta. Ronald Deabler, a 66-year-old Atlanta business owner and former Certified Public Accountant, was found guilty by a jury earlier... Source
UK: Council worker who snooped on records handed a suspended sentence
From the Information Commissioner’s Office: A council worker who unlawfully accessed hundreds of personal records has been handed a suspended sentence. Geoffrey Smith, 31, from Ledbury, Herefordshire, was a new employee at Herefordshire Council working in the Children and Young People directorate. His unlawful conduct was discovered after concerns were raised within the council about... Sour
OpenAI not part of the new Open Secure AI Alliance
OpenAI is noticeably absent from the list of initial supporters of a new industry initiative to promote the creation of strong, safe, defensive AI cybersecurity tools built on open-source platforms. The Open Secure AI Alliance is an initiative of Nvidia with the backing of over 30 major AI makers and users, including Cisco, Databricks, Dell Technologies, HPE, IBM, Microsoft, OpenClaw, Palantir, Sa
Beelzebub Raises $3.4 Million for Hacker-Trapping Platform
The company plans to expand its research team, open new offices in Rome and San Francisco, and acquire new clients. The post Beelzebub Raises $3.4 Million for Hacker-Trapping Platform appeared first on SecurityWeek .
Cognyte Sells a Mobile Cell Surveillance Van
Yet another Israeli mass surveillance company : Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity whether they’re owned by a suspect in a case or not. Cognyte’s contract with the state of Texas reveals that the simulator, called FalcoNet, can be concealed
What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out
The new Mobile Security Exposure Center creates SBOMs for enterprise mobile apps to uncover vulnerable components, dependencies and hidden risks. The post What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out appeared first on SecurityWeek .
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra. According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote
Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees. The post Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials appeared first on SecurityWeek .
NVD HIGH: CVE-2026-17527 — In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view Cluste...
In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC the caller can name, without requiring write access to the source n
NVD HIGH: CVE-2026-17523 — A flaw was found in the kernel. An unprivileged local user can exploit this vuln...
A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.
Java Spring Boot "heapdump" scans, (Mon, Jul 27th)
Spring Boot exposes the endpoint "/actuator/heapdump" to collect debug information. By default, the endpoint will return a file heapdump.hprof, which includes a binary heapdump that can be used to analyze the current state of the application. Non-Java readers may be familiar with a similar concept, core dumps, which are produced by binaries to expose a memory image at the time the software crashes
Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits
Binary-based vulnerability scanning, penetration testing, and exploit generation are blocked in Opus 5. The post Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits appeared first on SecurityWeek .
Ransomware Groups Increasingly Deploy EDR Kill Techniques
Halcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight against
Data Breaches Announced by Four Hospitals and Surgery Centers
Data breaches have been reported by Wildwood Surgical Center, Michigan Surgical Center, Penobscot Valley Hospital, and Whitfield Regional Hospital. Wildwood […] The post Data Breaches Announced by Four Hospitals and Surgery Centers appeared first on The HIPAA Journal .
The containment paradox: Why your ransomware playbook has the wrong people in charge
I have sat in on a version of the same incident post-mortem in three sectors over the past two years. The script does not vary much. At 4:47 a.m. on a Saturday, an on-duty SOC analyst sees a ransomware payload spreading across three servers in the data center. The playbook says isolate. They hit the switch. Sixteen minutes later the CFO is on the phone: Those three servers were the production paym
DentaQuest Data Breach Potentially Impacts Over 23 Million People
In May 2026, hackers stole personal and dental health information from DentaQuest’s computer network. The post DentaQuest Data Breach Potentially Impacts Over 23 Million People appeared first on SecurityWeek .
Objectway enters negotiations to acquire BNP Paribas and Natixis joint venture Slib
Italian wealth management technology provider Objectway is to buy capital markets IT firm Slib from BNP Paribas and Natixis.
Upstart wins preliminary approval to establish US bank
US lending marketplace Upstart has been granted provisional approval from the Office of the Comptroller of the Currency to establish Upstart Bank.
When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk
In cybersecurity, defenders sometimes naively assume that threat actors operate from secure, resilient infrastructures insulated from the very chaos they inflict on others. The 2026 compromise of Klue challenges that assumption. What began as a software-as-a-service supply chain breach evolved into an exceptional case in which a second criminal group claimed to have compromised the first extortion
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. The cybersecurity firm said it detected the campaign earlier this month.
NVD HIGH: CVE-2026-14837 — Multiple Lenze products are affected by an improper signature verification vulne...
Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. "The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project," the Microsoft-owned subsidiary said. According to GitHub, the
How CISOs can rise to the business resilience challenge
CISOs have quietly become their organizations’ de facto chief resilience officers as the role has evolved from its primary prevention roots to now include greater emphasis on incident response and business resiliency and recovery. “Any experienced CISO who’s come up through the ranks of IT has that operational mindset, which is about uptime,” says John Bruggeman , consulting CISO to OnX and CBTS.
MCBS Data Breach Affects 1.2 Million Individuals
The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company. The post MCBS Data Breach Affects 1.2 Million Individuals appeared first on SecurityWeek .
Insurtech Corgi hits $4 billion valuation on latest raise
Corgi, an AI-powered full-stack insurance platform, has reportedly hit a $4 billion valuation after raising money from investors for the fourth time this year.
CISA KEV: Fortinet FortiOS — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
CISA KEV: Arista VeloCloud Orchestrator — Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
What Is AI Pentesting and How Does It Works?
AI pentesting uses reasoning-capable models to continuously find and validate the flaws scanners miss, especially broken authorization and business-logic abuse.
What Is AI Pentesting and How Does It Work?
AI pentesting uses reasoning-capable models to continuously find and validate the flaws scanners miss, especially broken authorization and business-logic abuse.
NVD HIGH: CVE-2026-57990 — Files or directories accessible to external parties in Microsoft Edge (Chromium-...
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
NVD HIGH: CVE-2026-57989 — Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize...
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
ESAFENET&#;x26;#;39;s CDG showed up in our data before. The company focused on secure document management and data leakage prevention solutions. The "CDG" stands for "Content Data Guard", and the product appears to be mostly targeting the Chinese market [1]. Sadly, like so many security products, it suffers from basic security vulnerabilities like SQL Injectio
GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]
GitHub, PyPI add time-based defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]
Developing: AnMed reports phone and internet outage impacting all hospital locations; ERs remain open
Media outlets are reporting that all AnMed hospital locations are experiencing a phone and internet outage, but patients are being seen in the emergency rooms. AnMed is an independent, not-for-profit health system serving Upstate South Carolina and northeast Georgia with four hospitals: AnMed Medical Center, AnMed Cannon, AnMed Rehabilitation Hospital, and Regency Hospital – Upstate.... Source
A-list directors, actors and celebrities exposed in Tribeca film festival data leak
Researcher Jeremiah Fowler provides today’s entry in the “No Need to Hack When It’s Leaking” files: I recently discovered a publicly accessible database that was not password-protected or encrypted and contained what appeared to be records associated with the Tribeca Film Festival. Upon further investigation I uncovered an additional three separate unsecured databases: “dev
Why You Don’t Need to Understand HIPAA to Make Your Practice HIPAA Compliant
A fit-for-purpose compliance program encodes what HIPAA requires, translating a practice owner’s knowledge of their practice into a correct and complete compliance record. However, an owner does not need to become a compliance expert, because a structured HIPAA program can be built specifically for the practice with inexpensive, purpose-built HIPAA compliance software. The post Why You Don’t
Weekly Update 514: This Week in Data Breaches
The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted. You've got them leading with "don't worry, your credit card is fine", the hacker leading with "they didn&
NVD HIGH: CVE-2026-63720 — datamodel-code-generator prior to version 0.70.0 contains a code injection vulne...
datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The crafted value is emitted verbatim into a generated 'from ... import ...' statement without identifier validation, cau
NVD HIGH: CVE-2026-15962 — The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Objec...
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over a
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and
Malicious sites use JavaScript to build malware in browser memory
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. [...]
AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’
Caitlin Powell reports: A male registered nurse from northern Sydney has been charged after allegedly downloading the data of multiple patients. Police received a report on Wednesday, July 22, that a NSW Health employee had allegedly accessed and downloaded patient information without authorisation. Detectives launched an investigation under Strike Force Civic and, after inquiries, searched a home
No Need to Hack When It’s Leaking: Click to Pray edition
Jessica Lyons reports on today’s entry in the “No Need to Hack When It’s Leaking” files: Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked people’s names and email addresses for months – or longer – according to an ethical hacker who said she found... Source
ShinyHunters data leaks fuel $2,000 sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires
NVD CRITICAL: CVE-2026-66012 — SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST ...
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publis
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recent investigations into insurance-focused phishing operations reveal a more immediate approach. Instead of harvesting
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis. "The portal combined build generation, finance,
OpenAI confirms ChatGPT is down worldwide
ChatGPT, the famous artificial intelligence chatbot that allows users to converse with various personalities and topics, has connectivity issues worldwide. [...]
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their diff. The chain needs no administrator rights, continuous integration (CI) runner access, victim interaction
Rockwell Patches Code Execution Flaws in Arena Simulation Software
A researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations. The post Rockwell Patches Code Execution Flaws in Arena Simulation Software appeared first on SecurityWeek .
NVD HIGH: CVE-2026-10818 — The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in a...
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not being deleted upon validation failure. This makes it possible for unauthenticated
US House Votes to Extend Cyber Sharing Law for 10 Years
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/us-house-votes-to-extend-cyber-sharing-law-for-10-years-image_small-7-a-32329.jpg" align=right hspace=4><b>Lawmakers Advance 10-Year Renewal of Key Cyber Law, Setting Up Looming Senate Fight</b><br>The U.S. House of Representatives passed a fiscal year 2027 defense authorization bill with a provision extending the Cybersecurity In
NVD HIGH: CVE-2025-71408 — NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection ...
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or san
Anthropic Launches Opus 5 at Half the Price of Fable 5
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/anthropic-launches-opus-5-at-half-price-fable-5-image_small-8-a-32328.jpg" align=right hspace=4><b>Lower-Cost AI Model Challenges Need for Premium Frontier Models</b><br>Anthropic released Opus 5, a new flagship model priced at half the cost of Fable 5 while outperforming it on several internal benchmarks for coding, search and kn
Europol Flags 4,340 URLs Tied to The Com Network
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/europol-flags-4340-urls-tied-to-com-network-image_small-8-a-32325.jpg" align=right hspace=4><b>9 Countries Referred Thousands of URLs Tied to Grooming and Violent Content</b><br>European law enforcement notified hosting providers of 4,340 URLs containing nihilistic violent extremism in a weeks-long international crackdown on propa
CISOs vs. Boards: Myth or Misunderstanding?
Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide.
Friday Squid Blogging: Illex Squid Catch in the Falklands
Lower catch this year . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
When the Sandbox Won't Hold: Lessons From Hugging Face
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/when-sandbox-wont-hold-lessons-from-hugging-face-image_small-7-a-32327.jpg" align=right hspace=4><b>Experts Call for Hard Stops at Every New Privilege and Network Boundary</b><br>Barriers meant to stop artificial intelligence from escaping a sandboxed testing environment and not subject an unprepared third party to an onslaught of
Patient Sues Abbott Labs, Exact Sciences in Data Theft
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/patient-sues-abbott-labs-exact-sciences-in-data-theft-image_small-1-a-32326.jpg" align=right hspace=4><b>Class Action Suit Claims Labs Failed to Safeguard Data in ShinyHunters Hack</b><br>The first of what could be many more proposed class action lawsuits has been filed against clinical testing laboratory and medical device maker
Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks
The administration set a target date of September for CISA to finalize the rule, but where the agency is headed remains a mystery to some. The post Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks appeared first on CyberScoop .
NVD HIGH: CVE-2026-66040 — FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds wri...
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output
NVD HIGH: CVE-2026-66039 — FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflo...
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_fra
NVD HIGH: CVE-2026-66036 — FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds wri...
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() a
NVD CRITICAL: CVE-2026-62835 — Improper authorization in Azure Portal allows an unauthorized attacker to disclo...
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
OnTrac notifies customers of data breach after network hack
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. [...]
Despite multiple takedowns, botnets continue to grow
Roughly 1 in 4 of those compromised IPs are based in the United States, Lumen’s Black Lotus Labs said. Botnets like IPIDEA have also rebounded quickly, surpassing their pre-disruption footprint. The post Despite multiple takedowns, botnets continue to grow appeared first on CyberScoop .
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best.
NVD HIGH: CVE-2026-17107 — A flaw was found in the cluster-proxy service-proxy component used in Red Hat Ad...
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]
Russian Espionage Hackers Hit Zimbra With Half-Click Attacks
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/russian-espionage-hackers-hit-zimbra-half-click-attacks-image_small-7-a-32322.jpg" align=right hspace=4><b>Viewing Malicious Email in Vulnerable Webmail Client Triggers Data-Stealing Attack</b><br>Russian cyberespionage hackers are targeting a vulnerability in Zimbra Collaboration Suite - a patch is available - that enables them t
ISMG Editors: Oops! AI Just Escaped the Sandbox
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ismg-editors-oops-ai-just-escaped-sandbox-image_small-10-a-32324.jpg" align=right hspace=4><b>Also: Lessons From Scattered Spider Sentencing, Controlling Enterprise AI Costs</b><br>In this week's panel, four ISMG editors discussed the implications of OpenAI's sandbox escape and Hugging Face hack, the sentencing of two Scattered Sp
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]
NVD HIGH: CVE-2026-66033 — libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication i...
libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to
Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry
The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.
'Wrench' attacks against crypto holders appear to be on the rise
There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.
Marqeta and zerohash make stablecoins spendable on cards
zerohash, a leading infrastructure platform powering crypto, stablecoin, and tokenized asset capabilities for financial institutions, and Marqeta, Inc. (NASDAQ: MQ), the modern card issuing platform, today announced they will collaborate to integrate zerohash’s stablecoin infrastructure into Marqeta’s flexible card issuing capabilities.
Microsoft blames massive Microsoft 365 outage on maintenance bug
Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]
Microsoft, tech companies throw weight behind spread of open-source AI
Other signatories of the letter include Meta, Palantir, Perplexity, Mistral, NVIDIA, Mozilla, The Linux Foundation, Hugging Face, Dell Technologies and IBM. The post Microsoft, tech companies throw weight behind spread of open-source AI appeared first on CyberScoop .
Swiss private bank invests into Mbanq's new note listed on Düsseldorf Stock Exchange
Mbanq, a U.S.-based provider of banking infrastructure and embedded finance technology, today announced that its newly established institutional funding program has received its inaugural investment from a leading Swiss private bank.
NVD CRITICAL: CVE-2026-58630 — Improper access control in Azure App Service allows an unauthorized attacker to ...
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. "BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet
Wise US national trust bank charter application rejected
Shares in Wise tumbled after US regulators rejected the fintech's national bank charter application, citing compliance concerns.
In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws appeared first on SecurityWeek .
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.
Chick-fil-A data breach affects more than 13,000 customers
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline. [...]
Suspect arrested in investigation into sadistic “764” group
From the Dutch Police: In an investigation into so-called online sadistic COM networks, a suspect from North Holland was arrested on Monday, July 20. As a member of the group ‘764’, the suspect allegedly asked girls to cut themselves and write his online username on surfaces such as walls with their blood—known as ‘bloodsigns’. He... Source
Monetary Authority of Singapore and the Bank of Thailand ink cybersecurity MoU
The Monetary Authority of Singapore (MAS) and the Bank of Thailand (BOT) signed a Memorandum of Understanding (MoU) on Cybersecurity Cooperation and Digital Fraud Protection.
IDenfy launches bank card verification platform
iDenfy, the global identity verification, compliance, and fraud prevention solution platform, has announced the launch of a Bank Card Verification platform within its software dashboard.
Billtrust launches AR Intelligence connection for Claude and Microsoft Copilot
Beginning today, finance teams can query their live invoice-to-cash data directly from inside Microsoft Copilot and Claude, using plain language.
Mastercard expands virtual card programme
Mastercard today announced a series of enhancements to Mastercard In Control – the industry-leading virtual card number (VCN) platform according to Kaiser Associates – reinforcing its position as a global leader in secure, scalable B2B payments.
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
A porous API endpoint exposes, names, email addresses, location, and site status, all of which can be easily gleaned by anyone with a browser.
Europol flags 4,340 URLs for removal in 'The Com' crackdown
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups. [...]
Crime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.
Previous reporting about the Navigate360 breach focused on tips submitted by students, teachers, and parents. In this article, we focus on tips submitted to Crime Stoppers and law enforcement-related programs that use Navigate360’s software. Links to previous articles on this breach are at the end of this article. Background In 1976, an Albuquerque detective had... Source
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation which could have let attackers seize another tenant's identity and access other tenants' data, credentials, and cloud workloads.
Stripe becomes worldwide partner for Ryder Cup Europe
Ryder Cup Europe and the PGA of America today announced that Stripe has signed a new agreement to become a Worldwide Partner and the Official Financial and Payments Infrastructure Partner to golf’s greatest team contest—the Ryder Cup.
Commerzbank relents, enters talks with UniCredit for takeover
After months of resistance, Commerzbank has agreed to enter talks with Italy’s UniCredit that has been pushing to buy the bank.
Origin silent on settlement as alleged fired employee breach detail emerges
Roxanne Libatique reports: Origin Energy has declined to comment on a public claim that it privately resolved a cyber extortion threat – a posture that, as of July 24, leaves the company managing simultaneous obligations to regulators, the ASX, and an insurance market now aware that the alleged access point was a fired former employee’s... Source
T-Mobile violated WA data breach notification law, judge rules
Mirandah Davis-Powell reports: T-Mobile failed to properly notify customers of a data breach in which 40 million people had sensitive personal information stolen and sold on the dark web, a King County Superior Court judge ruled Friday. The Washington attorney general’s office filed the civil lawsuit against the Bellevue-based company in January 2025. The lawsuit alleged that T-Mobile... Source
Furious KPMG boss expels senior partner over confidential documents in locker
Colin Kruger provides today’s reminder of the insider threat: The most serious whistleblower claim from the KPMG scandal, that senior partners had illicitly accessed sensitive Lendlease board documents and kept them in a work locker, has been confirmed and led to the immediate expulsion of former chief operating officer, Eileen Hoggett. “I can confirm that... Source
IL: Weeks after cyberattack, ETHS students receive phishing scam emails
Bob Chiarito reports: Six weeks after a cyberattack shut down the campus for two days, several Evanston Township High School students received phishing emails this week. The emails offered students part-time jobs paying $550 for two to three hours of work, three times a week and came from a student’s ETHS email account. The emails were signed by “Human Resource”... Source
Millions of California-bought cars can be hijacked via Bluetooth
Brandon Vigliarolo reports: At least 2.2 million vehicles fitted with dealer-installed KARR and SWDS security systems are vulnerable to nearby Bluetooth attacks that can unlock doors or prevent a stopped vehicle from starting, according to researchers at the University of California San Diego. An advance look at the research published by UCSD this week (the full writeup won’t be... Source
Clop gang targets Windchill, FlexPLM in data theft attacks
Sergiu Gatlan reports: The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecur
AegisAI Raises $36 Million for AI-Powered Email Security
The company has raised a total of $49 million in funding, including from Battery Ventures, Accel and Foundation Capital. The post AegisAI Raises $36 Million for AI-Powered Email Security appeared first on SecurityWeek .
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization. The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of June 8,
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine. Microsoft issued two critical CVEs, CVE-2026-32194 and
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to identity-layer access controls. Where we've collectively landed is that understanding the intent of
Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday
Industry professionals debate whether it represents a lab containment failure or an unprecedented agentic capability milestone. The post Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday appeared first on SecurityWeek .
Man gets six years for hacking 750 women's Snapchat accounts
An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos. [...]
Leading digital assets firms pledge $15 million to establish Bitcoin Security Consortium
Financial institutions and Bitcoin companies have pledged $15 million over the next three years to form the Bitcoin Security Consortium.
ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check Point
OpenAI’s chatbot tool ChatGPT ranked among the top 10 most impersonated brands in phishing attacks for the first time
Why AI Needs a “Genie Coefficient”
This essay was written with Barath Raghavan, and originally appeared in The Guardian . Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to do it. We propose a new metric: the Genie coefficient. There’s often a gap between one person’s request and anot
Top AIs invent same fake PyPl and npm package names
Enterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent libraries and hackers create malicious packages in response. The top AI coding tools are remarkably consistent in their hallucinations: Researcher Aleksandr Churilov found the same 127 fake package names generated by five different LLMs. Slopsqu
Alipay+ partners with Hong Kong's Hang Seng Bank for cross-border QR code payments
Ant International’s Alipay+ has partnered with Hang Seng Bank to enable QR code payments in Hong Kong.
Tycoon2FA takedown reshapes the phishing landscape
Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform , Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”. “Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the c
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection. The agent then worked through the ministry's network on its own, checking hosts for ways to gain root access, hunting through file systems, and
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential
Visa and Lianlian enable China's first B2B agentic transaction
Visa, a global leader in digital payments, and Lianlian DigiTech Co., Ltd., an AI-native global financial infrastructure provider, today announced the first live B2B agentic transaction completed using LoopXPay, Lianlian’s AI agent.
Tennessee Pathology Group Announces 170K-record Data Breach
Anatomic and Clinical Laboratory Associates is notifying almost 170,000 patients about a recent cybersecurity incident. Data breaches have also been […] The post Tennessee Pathology Group Announces 170K-record Data Breach appeared first on The HIPAA Journal .
Co-operative Bank introduces £300 switching incentive to open Charity and Community Accounts
The Co-operative Bank has announced a new £300 switching incentive for eligible organisations opening a Charity and Community Account and removed the previous £2m turnover limit on the account.
Ransomware Attacks Targeting Universities on the Rise
Comparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher education
How to Choose HIPAA Compliance Software
At smaller organizations with under 100 employees, responsibility for HIPAA compliance normally falls to an administrator or practice manager who usually won’t have deep knowledge of compliance matters. For these multitasking individuals, the best HIPAA compliance software reduces the administrative burden and lessens the likelihood of an expensive HIPAA breach. In this article we discuss how to c
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators should be on 4.14.2. The simplest one takes a settings change. A
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. [...]
Ransomware groups are hammering your vulnerable VPNs
Cybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin ransomware strain. A critical authentication bypass flaw ( CVE-2026-0257 ) in Palo Alto GlobalProtect portal and gateway was the common link in a series of intrusions in June, Arctic Wolf Labs warns. Exploitation of the vulnerability came within days of d
Europe's Multilingual Reality Exposes AI Security Gaps
The AI security layer and guardrails for many AI products don't evenly protect against jailbreaking and unsafe actions in every single language.
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution. Redis 6.2.23, 7.2.15, and 7.4.10
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed weaponizing security flaws in WinRAR software to
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331
[object Object]
Data Breach Confirmed After Australian Energy Giant Origin Is Hacked
A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it. The post Data Breach Confirmed After Australian Energy Giant Origin Is Hacked appeared first on SecurityWeek .
NVD CRITICAL: CVE-2026-56191 — Improper authentication in Microsoft Exchange Online allows an unauthorized atta...
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
NVD HIGH: CVE-2026-56167 — Server-side request forgery (ssrf) in Azure AI Search allows an authorized attac...
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
AgentForger proves AI agents can become persistent insider threats
A new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to install. Its researchers have discovered AgentForger , a phishing-based attack that silently creates and launches a fully autonomous AI agent within OpenAI workspaces. Once running, the agent has full access to apps like Outlook, Slack, Share
Verifone patents tech that lets payment terminals detect tampering
Verifone has been granted a US patent for security technology that allows terminals to continuously monitor themselves for physical tampering, including threats invisible to the human eye.
CISA Again Sounds Warning Over Exposed PLCs
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cisa-again-sounds-warning-over-exposed-plcs-image_small-4-a-32319.jpg" align=right hspace=4><b>Internet-Exposed Programmable Logic Controllers 'An Easy Target'</b><br>Thousands of vulnerable industrial devices, accessible from the public internet, are being targeted by Iran-linked hackers, U.S. authorities said this week. The warn
NVD CRITICAL: CVE-2026-63732 — 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcode...
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn() when registering MCP plugins. A remote, unauthenticated attacker can log in with the default credential, spoof the Host head
NVD CRITICAL: CVE-2025-71389 — Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote co...
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interacti
IBM Bets on Multi-Billion-Dollar Open-Source Patch Business
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ibm-bets-on-multi-billion-dollar-open-source-patch-business-image_small-6-a-32317.jpg" align=right hspace=4><b>IBM Charges Enterprises $1M Annually for Validated Legacy Open-Source Patches</b><br>IBM is betting that AI can transform legacy open-source vulnerability remediation into a multibillion-dollar business by delivering vali
Cloudflare CEO: How AI Commerce Is Upending the Web Economy
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cloudflare-ceo-how-ai-commerce-upending-web-economy-image_small-2-a-32315.jpg" align=right hspace=4><b>Matthew Prince: AI Assistants Are Replacing Traditional Search and Commerce Models</b><br>Cloudflare's CEO said AI assistants are replacing traditional search and advertising-driven internet models, arguing that AI firms and sear
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.
New Dolphin X malware uses AI to rank high-value targets
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. [...]
NVD CRITICAL: CVE-2026-15981 — The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authen...
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful sign
NVD CRITICAL: CVE-2026-15967 — Insufficient session expiration vulnerability in Progress MOVEit Transfer. This...
Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
NVD CRITICAL: CVE-2026-15966 — Permissive cross-domain security policy with untrusted domains vulnerability in ...
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
NVD CRITICAL: CVE-2026-10697 — Improper Authentication vulnerability in Progress MOVEit Transfer. This issue a...
Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
Breach Roundup: Zelle Must Face NY Lawsuit Over Fraud
<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/breach-roundup-zelle-must-face-ny-lawsuit-over-fraud-image_small-10-a-32313.jpg" align=right hspace=4><b>Also, Spain Fines 23andMe Over 2023 Data Breach</b><br>This week: Zelle can't transfer out of a New York state lawsuit alleging poor controls over rampant fraud, a hack wiped Romania's land registry, Spain fined 23andMe, Austra