The archive
391 dispatches · newest first · page 6 of 7
- 2026-07-27GitHub, PyPI add time-based defenses against supply chain attacks
- 2026-07-27Be careful downloading Windows 11 apps from Google, 70+ fake sites are pushing malware right now
- 2026-07-27'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure
- 2026-07-27Inside the growing residential proxy botnet threat
- 2026-07-27Vidar Malware: How the Multithreaded Windows Stealer Works
- 2026-07-27From /init to Code Execution with Opus-5 in Claude Code - An Indirect Prompt Injection Story
- 2026-07-27Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis
- 2026-07-27MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
- 2026-07-27Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
- 2026-07-27Really Muddy Waters — Refuting the Seedworm Attribution of Commodity MaaS
- 2026-07-27RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)CVE-2026-64600
- 2026-07-27Coca-Cola confirms data theft in Fairlife ransomware attack
- 2026-07-27Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles
- 2026-07-27BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms
- 2026-07-27Ernst & Young data breach claimed by ShinyHunters extortion gang
- 2026-07-27PTC Windchill Vulnerability Exploited in Ransomware Campaign
- 2026-07-27RT by @cyb3rops: Quick follow-up on the OceanLotus / APT-C-00 campaign from the recent 360 report - the one using disc-image delivery, Analyzer.exe DLL sideloading, and http://NTUSER.MAN persistence. We turned up more indicators tied to the same group, and both are barely detected: An ISO container (6/60) with the same anti-debug + long-sleep traits, seen via China on 2 Jun 2026. Billfish.rar (2/63), tagged persistence + anti-debug, seen via Japan on 24 Jul 2026 9130d7d2271e9cb118dd83907d9865cba547304a1f6c72743973efd59813df18 (ISO image) 0bae4acd83015b8447e90aec97efa2e81d136bfd512a69301d6187fed2e45c74 (Billfish.rar)
- 2026-07-27The SID that wasn’t there: bypassing KB5014754 to Domain Admin on a fully patched AD CS
- 2026-07-27Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
- 2026-07-27RDP bitmap cache artifacts revealed the threat actor opening the Veeam Backup & Replication console, reviewing backup jobs, tape & storage infrastructure — and removing backups from the configuration database. Full report 👇 https://thedfirreport.com/2025/12/17/cats-got-your-files-lynx-ransomware/
- 2026-07-27RT by @TheHackersNews: 🛑 WARNING - Public PoC released for a vBulletin flaw that turns one unauthenticated request into code execution. No login, no click. The request reaches PHP’s eval(). Self-hosted admins should update now. Details: https://thehackernews.com/2026/07/public-exploit-released-for-patched.html
- 2026-07-27New Certighost PoC exploit lets attackers hijack Windows domains
- 2026-07-27Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
- 2026-07-27[KEV] CVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection VulnerabilityKEVCVE-2026-16812
- 2026-07-27[KEV] CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor VulnKEVCVE-2025-68686
- 2026-07-27Java Spring Boot "heapdump" scans, (Mon, Jul 27th)
- 2026-07-27⚡ A poisoned package can land in a Dependabot update PR before registries remove it. GitHub is adding a 3-day cooldown for routine version updates, while security fixes will still move immediately. Why three days, and what the delay cannot stop: https://thehackernews.com/2026/07/github-adds-3-day-dependabot-cooldown.html
- 2026-07-27GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
- 2026-07-27Certighost and the Privilege Hiding in Your Certificate AuthorityCVE-2026-54121
- 2026-07-27Ransomware: ExfilSquad → Wesco International
- 2026-07-27MCBS Data Breach Affects 1.2 Million Individuals
- 2026-07-27Nono: Open-source sandbox for AI agents
- 2026-07-27From Google Ads to Terminal: Dissecting an Apple Support Impersonation Campaign Abusing Claude Share.
- 2026-07-27GitHub delays version updates so malware gets caught first
- 2026-07-27Marathon Petroleum’s CISO on OT security automation, supply chain risk
- 2026-07-26RT by @cyb3rops: Hackers use DNS poisoning on hotel Wi‑Fi to steal Microsoft 365 accounts https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/
- 2026-07-26CVE-2026-12877: The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does CVE-2026-12877
- 2026-07-26Ransomware: Deadlock → Caspian One
- 2026-07-26RT by @cyb3rops: France Exposes Russia's Secret Cyber Espionage Network https://www.unredacted.info/russia/france-exposes-russias-secret-cyber-espionage-network/
- 2026-07-26> free time today > what was bro doing with a torrent movie .exe > download > 1gb .exe > lmfao binary inflation > bonk bonk > remove junk > deflate binary > 500kb > bonk bonk > no imports > crt stripped > position independent > checks language > kills self if in belarus or russia > runs 2000 random functions in random order > trying to stall to evade VMs > decrypts .exe from inside itself > runs mystery .exe in memory > .exe steals goop off machine > bonk bonk > yara flags as lumma stealer overall this wasnt the greatest goop ive ever seen, but i was a big fan of free_movie.exe. its a certified limewire 2002 classic. inflated binary: e25ae92b95809ee42f61810a0253ead29b3a6aa8adf91f785c80c9bec5f38bd8 stripped binary: 732d7a945163a3f31eae25028562bd5d9a352c31eb90c777042bceeeb1c6b3ec in-memory payload (partially reconstructed): 3e561eecde0071766626d80d6ce3cf1626fb2dbed0ef437948f622c283a0e91e c2: overcjo(.)cyou betavmt(.)cyou hiatuft(.)cyou auditva(.)cyou
- 2026-07-26Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
- 2026-07-26GitHub, PyPI add time-based defenses against supply chain attacks
- 2026-07-26Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials
- 2026-07-26Can a cloud tenant really black out the power grid? We asked the Bit2Watt researchers. Their answer 🠒 the scariest result only works if thousands of GPUs spike their power at the same instant, and in reality they never line up that cleanly, which blunts the attack. Also notable: they didn't warn any cloud provider first, because there's no product bug to patch. Read: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html
- 2026-07-26Ransomware: ExfilSquad → Microsoft
- 2026-07-26🚨 UPDATE - Public PoC exploit released for CVE-2026-42533, chaining an #nginx memory leak and heap overflow to bypass ASLR and achieve unauthenticated command execution. Read: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.htmlCVE-2026-42533
- 2026-07-26RT by @TheHackersNews: 🚨 A public GitLab RCE PoC lets an authenticated user run commands as the git user on an unpatched 18.11.3 server. No admin rights, CI runner access, victim interaction, or access to another user’s project. See how the notebook-diff chain works: https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html
- 2026-07-26Rockwell Patches Code Execution Flaws in Arena Simulation Software
- 2026-07-26Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
- 2026-07-26⚠️ DevMan RaaS now runs a full affiliate portal. Experts (tracking it as Funky Mantis) say the platform handles payload builds, victim records, chat, teams, support, and payouts in one place. Affiliates get structured workflows, deadlines, and an 80/20 cut. 184 victims claimed so far. Read: https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html
- 2026-07-26RT by @TheHackersNews: 🚨 The malware arrives in pieces. The victim’s browser puts it together. SourTrade malvertising delivers a legitimate Bun runtime, malicious bytecode, and PE components separately, then uses the browser to build the final Windows executable with a different hash each session. See how the browser-assembled malware chain works: https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html
- 2026-07-26RT by @cyb3rops: We successfully achieved an RCE on GitLab in its default configuration. Historically, most GitLab RCEs have lived in the web or application-logic layers. This time, guided by the @depthfirstlabs spirit, we went deeper: into the low-level gem dependency chain beneath GitLab. The result? By sending crafted JSON data, we could exploit memory-corruption vulnerabilities buried deep in that chain and take control of the GitLab application server. @depthfirstlabs brings together some of the smartest people, and is building the best security AI agent. Follow our work, and come join us! Read more about this in the comment...
- 2026-07-26🚨 Insurance phishing kits are now hijacking accounts while victims are still logging in. InsureOTP relays stolen credentials and one-time passwords to legitimate insurance portals in real time, letting attackers complete authentication within the same browsing session. Read how the operation works: https://thehackernews.com/2026/07/ctm360-research-reveals-how-insurance.html
- 2026-07-26Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems
- 2026-07-26Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
- 2026-07-265 months …CVE-2025-66376
- 2026-07-26RT by @TheHackersNews: 🛑 ALERT - A malicious JSON request can become unauthenticated RCE on affected Spring Boot fat-JAR apps running Fastjson 1.x. Fastjson 1.x has no patched release, and ThreatBook and Imperva report attacks targeting the flaw. Learn how it works and who’s exposed: https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html
- 2026-07-26🚨 Cl0p-linked attackers are actively exploiting a critical unauthenticated RCE in internet-exposed PTC Windchill and FlexPLM systems. They chain two flaws, drop hex-named JSP webshells, and steal engineering data for double extortion. Manufacturing, automotive, aerospace, and retail firms are the main targets. Full details → https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html
- 2026-07-26Steam forum ClickFix attacks infect gamers with XMRig cryptominers
- 2026-07-25Malicious sites use JavaScript to build malware in browser memory