DevSecOps Vulnerability4 Min Read July 22, 2026 GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,…
3 Min Read July 22, 2026 Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Cybersecurity researchers have disclosed details of a new local… Linux Vulnerability
3 Min Read July 22, 2026 Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Cybersecurity researchers have disclosed details of a now-patched… Browser Security Vulnerability
3 Min Read July 22, 2026 Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication A high-severity security flaw impacting open-source developer platform… Vulnerability Web Security
AI Security Shadow IT3 Min Read July 22, 2026 The Fastest Path to AI Adoption Runs Through Security Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done…
Artificial Intelligence Network Security5 Min Read July 22, 2026 Why Modern SOCs Need Multi-Layered Detections The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth…
Cybercrime Law Enforcement3 Min Read July 22, 2026 Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most…
Malware Supply Chain Attack3 Min Read July 22, 2026 Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package…
AI Security DevSecOps5 Min Read July 22, 2026 Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects…
AI Security Cloud Security2 Min Read July 22, 2026 OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release…
Cloud Security Vulnerability2 Min Read July 21, 2026 Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively…
AI Security Vulnerability5 Min Read July 21, 2026 AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on…
Artificial Intelligence Software Security3 Min Read July 21, 2026 Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5…
Vulnerability Web Security2 Min Read July 21, 2026 Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per…
Network Security Vulnerability2 Min Read July 21, 2026 Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy…
Cyber Attacks Vulnerability4 Min Read July 21, 2026 WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code…
Threat Intelligence Vulnerability5 Min Read July 21, 2026 New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented…
Artificial Intelligence Vulnerability1 Min Read July 21, 2026 Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In…
Artificial Intelligence Malware3 Min Read July 20, 2026 FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial…
Malware Vulnerability4 Min Read July 20, 2026 Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates,…
Cyber Espionage SaaS Security3 Min Read July 20, 2026 HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions…
Cybersecurity Hacking11 Min Read July 20, 2026 ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled…
Cyber Espionage IoT Security4 Min Read July 20, 2026 Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the…
Exposure Management Security Operations5 Min Read July 20, 2026 Mythos Didn't Break Your Security Program. Your Exposure Window Could. The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an…
Endpoint Security Vulnerability2 Min Read July 20, 2026 New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow…
Artificial Intelligence Cybercrime4 Min Read July 20, 2026 Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI…
AI Security Vulnerability2 Min Read July 20, 2026 World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an…
Application Security Malware3 Min Read July 20, 2026 SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three…
Server Security Vulnerability4 Min Read July 19, 2026 Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker…
Cyber Warfare Malware2 Min Read July 19, 2026 UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting…
Network Security Vulnerability4 Min Read July 19, 2026 SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000…
Vulnerability Web Security3 Min Read July 17, 2026 New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9…
Server Security Vulnerability4 Min Read July 17, 2026 OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems…
Malware Software Supply Chain2 Min Read July 17, 2026 Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a…
AI Security Botnet5 Min Read July 17, 2026 New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.…
Malware Threat Intelligence4 Min Read July 17, 2026 GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.…
Malware Social Engineering3 Min Read July 17, 2026 Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to…
Artificial Intelligence Regulation7 Min Read July 17, 2026 E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the…
Artificial Intelligence National Security4 Min Read July 17, 2026 The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace? Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new…
Law Enforcement Ransomware4 Min Read July 17, 2026 Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil…
Malware Windows Security5 Min Read July 17, 2026 ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session…
Cyber Espionage Threat Intelligence4 Min Read July 17, 2026 New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks…
Enterprise Security Vulnerability2 Min Read July 17, 2026 CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft…
Cybercrime Identity Security4 Min Read July 16, 2026 Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for…
Cybersecurity News Hacking News10 Min Read July 16, 2026 ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync…
Vulnerability Web Security3 Min Read July 16, 2026 n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one…