The archive
391 dispatches · newest first · page 7 of 7
- 2026-07-25Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched AvailableCVE-2026-16723
- 2026-07-25DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
- 2026-07-25CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
- 2026-07-25A featured Chrome extension "Planet Search" (2M installs) routes every query to the nextgeeker[.]com hijacker network
- 2026-07-25Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
- 2026-07-25Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
- 2026-07-25Today Mandiant announced that they're a bunch of soft blooded cowards and need to make names more catchy, or something. They're abandoning their APT naming convention (i.e. APT29) and replacing it with codenames, like SANDWORM RELIC Weak bro https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/
- 2026-07-24Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
- 2026-07-24US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
- 2026-07-24Despite multiple takedowns, botnets continue to grow
- 2026-07-24Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
- 2026-07-24Data Breach Confirmed After Australian Energy Giant Origin Is Hacked
- 2026-07-24Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
- 2026-07-24OpenAI’s agent escaped its sandbox during a security test
- 2026-07-24In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
- 2026-07-24New Dolphin X malware uses AI to rank high-value targets
- 2026-07-24NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
- 2026-07-24Australian energy provider Origin says data breach exposes client data
- 2026-07-24Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
- 2026-07-24Fake Claude app promoted by Bing ads pushes SectopRAT malware
- 2026-07-24[KEV] CVE-2026-16232: Check Point SmartConsole Improper Authentication VulnerabilityKEVCVE-2026-16232
- 2026-07-24BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
- 2026-07-24Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
- 2026-07-24Vatican's Official Prayer App Leaks 700K+ Global Users' PII
- 2026-07-24Hermes AI agent used to automate attack on Thai Finance Ministry
- 2026-07-24Microsoft blames massive Microsoft 365 outage on maintenance bug
- 2026-07-24ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
- 2026-07-24Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
- 2026-07-24Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
- 2026-07-24Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's ServersCVE-2026-32194
- 2026-07-24Clop ransomware targets Windchill, FlexPLM in data theft attacks