Cybercrime Law Enforcement3 Min Read July 29, 2026 Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terroris…
2 Min Read July 29, 2026 Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass Cybersecurity researchers have shared additional technical details about… Enterprise Security Vulnerability
5 Min Read July 29, 2026 OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent… Artificial Intelligence Vulnerability
3 Min Read July 29, 2026 New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands Gitea, the self-hosted Git platform, has patched a critical remote code… DevOps Vulnerability
Enterprise Security Vulnerability2 Min Read July 28, 2026 Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical…
Linux Vulnerability3 Min Read July 28, 2026 Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw,…
AI Security Vulnerability Management3 Min Read July 28, 2026 Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation…
Threat Intelligence Vulnerability3 Min Read July 28, 2026 Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in…
AI Security Software Security5 Min Read July 27, 2026 NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for…
Botnet IoT Security3 Min Read July 27, 2026 Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device…
Vulnerability Website Security3 Min Read July 27, 2026 Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute…
Cybersecurity Hacking10 Min Read July 27, 2026 ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old…
Cyber Attack Threat Intelligence3 Min Read July 27, 2026 TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities…
DevSecOps Software Supply Chain2 Min Read July 27, 2026 GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before…
Browser Security Malvertising3 Min Read July 25, 2026 Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun…
Application Security Vulnerability3 Min Read July 25, 2026 Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected…
Cybercrime Phishing6 Min Read July 25, 2026 CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and…
Vulnerability2 Min Read July 25, 2026 Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in…
Cybercrime Ransomware5 Min Read July 25, 2026 DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability…
Application Security Vulnerability3 Min Read July 25, 2026 Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June…
Artificial Intelligence Malware5 Min Read July 24, 2026 BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found…
Enterprise Security Vulnerability3 Min Read July 24, 2026 Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a…
Enterprise Security Vulnerability4 Min Read July 24, 2026 ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single…
Vulnerability Web Security4 Min Read July 24, 2026 Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITYSYSTEM on Microsoft's production image-processing workers, and as…
AI Security Enterprise Security7 Min Read July 24, 2026 Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively…
Artificial Intelligence Threat Intelligence5 Min Read July 24, 2026 Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky…
Browser Security Threat Intelligence3 Min Read July 24, 2026 Golden Chickens Resurfaces With Four New Malware Families and Modular Implants The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating…
Vulnerability Web Security4 Min Read July 24, 2026 NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity…
Database Security Vulnerability3 Min Read July 24, 2026 Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and…
Cyber Espionage Web Security4 Min Read July 24, 2026 Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's…
Email Security Vulnerability5 Min Read July 23, 2026 Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The…
Cybersecurity News Hacking News9 Min Read July 23, 2026 ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became…
Application Security Vulnerability3 Min Read July 23, 2026 Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of…
Network Security Ransomware4 Min Read July 23, 2026 Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust…
Malware Threat Intelligence3 Min Read July 23, 2026 China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government,…
Cloud Security Identity Security6 Min Read July 23, 2026 How Synthetic Identity Fraud is Coming for Machine Identities Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity…
Vulnerability Web Security3 Min Read July 23, 2026 Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack…
Authentication Data Protection3 Min Read July 23, 2026 Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per…
Linux Vulnerability5 Min Read July 23, 2026 Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs RefluXFS, a Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files…
DevSecOps Vulnerability4 Min Read July 22, 2026 GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from…
Linux Vulnerability3 Min Read July 22, 2026 Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged…
Browser Security Vulnerability3 Min Read July 22, 2026 Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314…
Vulnerability Web Security3 Min Read July 22, 2026 Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.…
AI Security Shadow IT3 Min Read July 22, 2026 The Fastest Path to AI Adoption Runs Through Security Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done…
Artificial Intelligence Network Security5 Min Read July 22, 2026 Why Modern SOCs Need Multi-Layered Detections The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth…
Cybercrime Law Enforcement3 Min Read July 22, 2026 Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most…