Experts share their insights on protecting against cyber threats and staying ahead of evolving security risks.
Recently active
Electronic signature platforms have become a routine part of business operations, making them an attractive lure for threat actors. While DocuSign remains the most commonly spoofed brand, attackers are increasingly abusing alternative document-signing services and trusted email infrastructure to make their campaigns appear legitimate.A recent campaign observed by our team illustrates this evolution. The attack impersonated PandaDoc and claimed that overdue invoices required review and signature, leveraging a workflow that many finance, procurement, and accounts payable employees encounter regularlyThe email was delivered through a compromised SendGrid account and legitimate SendGrid infrastructure. Rather than building trust from scratch, the attackers inherited credibility from an established business communications platform, increasing the likelihood that the message would reach inboxes and be viewed as authentic.Clicking "OPEN THE DOCUMENT" did not immediately direct users to a log
In the years since the Hyadina ransomware group was first identified, two distinct variants have been used in attacks: Monster in 2022 and Beast in 2024. Though now researchers have discovered a new variant, dubbed GodDamn, that retains much of the same code and use of AnyDesk to gain on-going remote access, but with the added upgrade of exploiting a Microsoft-signed kernel driver, PoisonX, to disable device security measures at the kernel level and add an extra layer of persistence during and after the attack.MacOS infostealer disguises as crash reporting toolResearchers have been tracking a new infostealer, dubbed CrashStealer, for several months that operates exclusively on Apple’s MacOS and disguises itself as Apple’s crash reporting tool to avoid detection and convince the user to input their credentials for administrator privileges on the device. CrashStealer’s main payload is downloaded via Apple’s notarized installer, Werkbit which allows it to bypass macOS internal security a
Thursday, July 16, 2026The Stable channel has been updated to 150.0.7871.128/.129 for Windows and Mac and 150.0.7871.128 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log Security Fixes and RewardsNote: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.This update includes 7 security fixes. Please see the Chrome Security Page for more information. https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html Webroot SecureAnywhere users make sure to re-add back to Privacy Protection!
Most ransomware stories end with a payment, an arrest, or another victim.This one starts with a question:What happens when the person negotiating on your behalf is secretly helping the ransomware gang instead?According to the U.S. Department of Justice, that's exactly what happened. Angelo Martino, a Florida ransomware negotiator, was recently sentenced to 70 months in federal prison after pleading guilty to conspiring with members of the BlackCat (ALPHV) ransomware operation.The conspiracy is the headline. The information is the real story. The attacker shouldn't know this...When organizations suffer a ransomware attack, negotiators often become trusted advisors. They're brought into executive calls. They work directly with legal teams, insurance carriers, incident responders, and executive leadership. Very quickly, they gain visibility into some of the organization's most sensitive business decisions.The Information the Attacker Was Never Supposed to HaveThey quickly learn things the
July 16, 2026 By Lawrence Abrams The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States.In a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), Coca-Cola said Fairlife detected unauthorized access to some of its systems, including its production-related systems, in connection with a ransomware attack."After detecting the issue, the Company promptly activated its incident response and business continuity protocols," Coca-Cola said in the filing."The Company's investigation and assessment of the impact of the incident is ongoing, with the assistance of outside advisors and cybersecurity experts. The Company has also notified law enforcement."The company said product quality and safety have not been affected by the ransomware attack. >>Full Article<<
The social-engineering technique has primarily been a tool of financially motivated criminals.Dan Goodin – 16 Jul 2026 One of the Russian government’s most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center is warning.Clickfix has emerged as an effective attack technique that attackers, primarily financially motivated criminals, began using in the last year or so. Websites under the control of the attackers display a CAPTCHA that requires the visitor to copy a jumble of text and paste it into the terminal. The text contains scripts that, once entered, perform malicious actions, typically by installing malware or exfiltrating sensitive data. Ukraine’s CERT said Wednesday that Sandworm, an advanced hacking unit inside the GRU, Russia’s military intelligence arm, is now using the technique.“GhettoVibe,” “ScoutCurl,” and many moreThe Clickfix attacks began in the spring and h
July 16, 2026 By Sinisa Markovic A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI)In more than 200 sessions between March 19 and April 21, 2026, the threat actor worked with Gemini to deploy and operate infrastructure that controlled eight computers inside a dental clinic and gain access to the clinic’s OpenDental database.Posing as an “authorized penetration tester,” he instructed Gemini to suppress safety disclaimers and automatically save any credentials it encountered. Both instructions were placed in Gemini’s memory file, which reloads at the start of each session, allowing them to persist across subsequent conversations. >>Full Article<<
July 16, 2026 By Pieter Arntz Flock-style ALPR systems carry serious privacy and civil-liberties risks, and the backlash is now starting to show up in agency decisions too.For those not yet familiar with Flock, Flock Safety operates an automated license plate recognition (ALPR) system that uses cameras and computer vision to identify and log vehicle license plates.According to ACLU.org, in the US there are currently:“80,000–100,000 Flock cameras in both urban and rural areas on highways, in neighborhoods, and outside your local hardware store.”Automated license plate readers were sold as a crime-fighting tool, but growing evidence suggests the privacy and accountability problems surrounding Flock are becoming increasingly difficult to dismiss. A growing number of incidents now show the same pattern: broad surveillance, shaky oversight, and enough operational risk to create real harm for ordinary people.ALPR systems create durable location records about people who are not suspected of a
July 16, 2026 By Lawrence Abrams A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.The issue was discovered by Ax Sharma of Manifold Security, who says it stems from how the Claude extension determines whether a user intentionally requested one of its built-in tasks.Chrome extensions with permission to run on a website can inject JavaScript into the page, allowing them to read and modify its contents. This includes changing page elements, reading information displayed on a site, and generating click and keyboard events programmatically.According to Manifold's report, the Claude extension listens for click events on a specific page element that launches one of its built-in AI workflows. These workflows are predefined tasks that allow Claude to perform action
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency. July 16, 2026 By Eduard Kovacs A new macOS malware named ClickLock Stealer leverages social engineering and process killing to bypass the operating system’s protections and obtain valuable information from victims. Cybersecurity firm Group-IB came across ClickLock Stealer in early June, and the malware appears to have been around since at least late May. Researchers say it has targeted at least 100 users across 33 countries, more than half in Europe.The stealer is designed to collect various types of data from compromised systems, including web browsers, cryptocurrency wallets and wallet extensions, and password manager extensions. It can also harvest blockchain addresses from six chains and target the macOS Keychain, FTP credentials, and shell history. The stolen data is added to an archive file and exfiltrated to a Telegram bot.While Group-IB researchers could not definitively determin
Iberian hackers carried out a variety of cyberattacks and laundered the winnings through complex financial networks. July 16, 2026 By Nate Nelson Source: Gwengoat via Getty ImagesLaw enforcement agents across three countries and one ocean have disrupted a Spanish cybercrime network and its sophisticated money laundering apparatus.On July 13, Spain's national police revealed a World Cup semifinal-level takedown of an Iberian criminal gang. The gang employed more than 70 known individuals, in possession of 19 registered companies and nearly 1,000 financial accounts.Most of those individuals were used to launder cybercrime profits. The hackers at the heart of this operation worked out of two "nerve centers," perpetrating man-in-the-middle (MitM) attacks, CEO impersonation scams, social engineering attacks involving fake invoices, and scams built off fake investment platforms. In all, they managed to steal at least €140 million ($161 million). Authorities tied €61 million of their take to
July 16, 2026 By Pierluigi Paganini TuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed.Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes with an unusual detail: the developer used a large language model to write significant portions of the code, and the LLM’s safety disclaimer ended up in every compiled binary. Sixty-one C source files each carry an identical header warning that “this code is for educational and authorized security research only.” The developer shipped it without removing a single line.“The malware authors leveraged an LLM to assist in their code development, yielding mixed results. While the AI complied with their request to generate botnet code, it included a safety disclaimer that the developer failed to remove before shipping.” reads the Unit 42’s report. “Although the LLM clearly aided in constructing
July 16, 2026 By Bill Toulas A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data.OkoBot reaches victims through ClickFix attacks or malicious GitHub repositories pretending to host legitimate software tools.In one case, a repository claimed to offer SQL Server Management Studio (SSMS) but dropped a trojanized version of the Audacity audio editing tool.Researchers at cybersecurity company Kaspersky say that the OkoBot campaign has been ongoing for more than a year and evolved from the activity that delivered the malicious PowerShell script TookPS.However, the infection chain has been completely changed, with multiple attack stages and TookPS being used in the first phase to install and configure an SSH bot that delivered the other malicious components.The OkoBot infection chainSource: Kaspersky >>Full Article<<
How threat actors use disguised .ttf files and low-detection Lua loaders to deliver RATs and infostealers By Yurren Wan | July 16, 2026Affected Platforms: Microsoft WindowsImpacted Users: Any organizationImpact: Attackers gain control of the infected systems or stolen data may be leveraged for follow-on attacksSeverity Level: High Since late March, 2026, we have been observing large-scale campaigns that use a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private LOGGER.Figure 1: Lua-based loader on VirusTotalIn these attack campaigns, the threat actor impersonates several well-known companies, using the guise of business cooperation to launch phishing attacks. To evade detection, the actor employs multi-layered, highly obfuscated stages, including extensive junk code and an AutoIt/Lua loader masquerading as a TrueType Font (.ttf) file.Figure 2: Attack flow Initial Acce
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data VulnerabilityThese types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total contr
Ravie Lakshmanan Jul 16, 2026 Cybercrime / Endpoint Security Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026."The malware is full-featured, lightweight, and modular," Elastic Security Labs researcher Cyril François said in a technical report. "While the number of C2 [command-and-control] domains is currently small, the daily volume of builds uploaded to VirusTotal and the rapid pace of updates indicate active development and likely further growth."The disclosure makes it the second new threat actor after SCMBANKER to be propagated via ClickFix, a pervasive social engineering attack that tricks users into manually running malicious commands by disguising them as innocent fixes for fake browser errors, software updates, or CAPTCHA verifications.Underpinning the technique is an approach called clipboard hijacking. Because web pages using ClickFix inject malicious
Ravie Lakshmanan Jul 16, 2026 Hacking News / Cybersecurity News A lot of this week’s trouble starts with something that looks close enough.A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation.Old bugs are back, weak defaults are earning their keep, and some attack paths are so plain they barely feel like research. Here’s the mess.Full Article
CISA released nine Industrial Control Systems (ICS) Advisories. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-26-197-01 Rockwell Automation Arena ICSA-26-197-02 Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT ICSA-26-197-03 NASA Core Flight System (cFS) Health & Safety (HS) Application ICSA-26-197-04 AutomationDirect Productivity Suite ICSA 26-197-05 Siemens SICAM 8 ICSA-26-197-06 Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix ICSA-26-197-07 SALTO ProAccess Space ICSA-26-197-08 Rockwell Automation Flex 5000 Adapter ICSA-26-197-09 Rockwell Automation FactoryTalk DataMosaixCISA encourages users and administrators to review these ICS Advisories for technical details and mitigations. https://www.cisa.gov/news-events/ics-advisories
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the ass
Researchers have been tracking a new ransomware group that is trailblazing the path towards fully automating ransomware attacks using solely AI agents. The JadePuffer ransomware group was recently attributed to an attack that used AI to identify prospective targets, gain access to their systems, enhance local privileges during the intrusion, and finally deploy the encryption payload. By exploiting a known remote code execution vulnerability in the Langflow AI framework, CVE-2025-3248, JadePuffer was able to gather significant data on potential victim systems and carry out the remainder of the attack, even pivoting for system obstacles in a similar fashion that a human attacker would perform.Accenture suffers 35GB data breachAt the beginning of the week, a hacker known as “888” posted a 35GB data trove to PwnForums, a known cybercrime marketplace, claiming to have compromised source code and other critical files from Accenture, a tech consultancy firm. Officials for Accenture have confi
July 15, 2026 By Bill Toulas Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts.Discovered internally, the security issue is tracked as CVE-2026-53412 and received a severity score of 9.8 out of 10.In an advisory this week, the messaging platform says that the flaw affects Zoom Workplace for Windows before version 7.0.0, the Windows VDI Client before versions 7.0.10, 6.6.15, and 6.5.18, and the Meeting SDK for Windows before version 7.0.0. >>Full Article<<
July 15, 2026 By Pierluigi Paganini LegacyHive PoC exposes a Windows Privilege Escalation flaw affecting fully patched Windows desktop and server systems.Just hours after Microsoft’s July 2026 Patch Tuesday, security researcher Nightmare Eclipse, also known as Chaotic Eclipse, published a new Windows zero-day proof-of-concept called LegacyHive. This time, the target is the Windows User Profile Service (ProfSvc), and unlike the hundreds of vulnerabilities Microsoft fixed this month, this one currently has no CVE, no advisory, and no security update.LegacyHive is a local privilege escalation vulnerability. An attacker who already has code execution as a standard user can abuse the User Profile Service to load another user’s registry hive, potentially that of a local administrator, under their own profile.That opens the door to accessing registry data that should remain protected and may help elevate privileges under the right conditions. While it isn’t a remote code execution bug, privil
July 15, 2026 By Bill Toulas Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities.The threat actor exploited a misconfigured GitHub Actions workflow and pushed trojanized packages in the @asyncapi namespace that had a cummulative weekly download count of more than 2.25 million.Multiple security companies confirmed that on July 14, an attacker compromised two AsyncAPI GitHub repositories and injected malware into project files.“Both attacks are CI/CD pipeline compromises, not stolen npm tokens or malicious maintainers,” reads a report from Step Security.The researchers explain that "the attacker pushed commits under a placeholder git identity and let each repository's real release workflow do the publishing via npm's GitHub OIDC trusted-publisher integration."In doing so, the attacker ensured that the resulting packages had the legitimate SLSA provenanc
Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a coordinated vulnerability disclosure (CVD) program for working with external security researchers that includes a clear vulnerability disclosure policy (VDP) and process for triaging, remediating and assigning Common Vulnerabilities and Exposures (CVE) identifiers to reported vulnerabilities. The guidance also provides considerations for leveraging third-party intermediaries, like CISA or other national computer security incident response teams, to substitute or supplement a CVD program. By implementing a robust CVD program aligned with this guidance, organizations can work transparently and collaboratively with security researchers to remediate vulnerabilities, build constructive relationships, enhance product security while improving vulnerability management processes, and demons
Swati Khandelwal Jul 14, 2026 Vulnerability / Enterprise Security Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 200.Those two live bugs are the ones to grab first. Microsoft credits incident responders for both. Both are elevation-of-privilege flaws in identity and collaboration infrastructure: CVE-2026-56164 in on-premises SharePoint Server and CVE-2026-56155 in Active Directory Federation Services.Neither is one of the splashy remote code execution criticals. They are privilege bugs in two systems that matter more than their scores suggest: the company document store, and the box that signs its logins.The two zero-days to patch firstCVE-2026-56164, a SharePoint Server flaw Microsoft says is being exploited in attacks, lets an unauthenticated attacker escalate privilege
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.