Experts share their insights on protecting against cyber threats and staying ahead of evolving security risks.
Recently active
Ravie Lakshmanan Jul 09, 2026 Malware / Endpoint Security Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy.According to a new report published by the Threat Hunter Team from Symantec, the ransomware was first publicly spotted in the wild on May 21, 2026. It's assessed to be a rebrand of the Beast ransomware, which, in turn, was an enhanced version of Monster, a Delphi-based ransomware that surfaced in March 2022. Broadcom's cybersecurity arm is tracing the developer behind these ransomware families under the moniker Hyadina.In one attack orchestrated by the ransomware operation in early June 2026, the threat actors are said to have leveraged AnyDesk for remote access and used a NirSoft-based credential harvesting toolkit before deploying the ransomware. The exact initial access vector is unknown. The credential harvester is designed to extract sen
The Hacker News Jul 09, 2026 AI Security / Application Security Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quietly months earlier, heads down, taking findings and shipping fixes, because customers kept asking us to. We only announced it now because everyone else started announcing theirs, and staying quiet started to look like something it wasn't. The others arrived louder and, as far as anyone outside the press releases could tell, didn't exist yet.Here's the part none of those announcements will tell you: the clearinghouse is the least important thing to build.When a project we'd deliberately kept private, a five-billion-dollar press release, and the White House all reach for the same word inside a few weeks, that's not a trend. Trends are optional. This is the shape of a problem changing under everyone at once.
The Hacker News Jul 09, 2026 AI Security / Zero Trust AI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the next host before your team clears the first alert.That is the gap, and it is not your fault. The tools and runbooks most teams run on were built for attackers who work at human speed. AI-driven attacks do not, and they run at scale. Save your seat for the free webinar, "Outpacing Mythos: How to Fight Back Against AI-Powered Attacks."In one hour, we take the attack apart. You see how AI-powered attacks get in, what they do once they are inside, and why network-based defenses keep landing a step behind. No slideware theory, just the mechanics, so the next campaign looks familiar instead of surprising.Full Article
CISA released three Industrial Control Systems (ICS) Advisories. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-26-190-01 OpenPLC v3 ICSA-26-190-02 Schneider Electric PowerChute Serial Shutdown ICSA-26-190-03 Schneider Electric Easergy MiCOM Px40 SeriesCISA encourages users and administrators to review these ICS Advisories for technical details and mitigations. https://www.cisa.gov/news-events/ics-advisories
July 8, 2026 By Bill Toulas Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications.The threat actor published at least 17 malicious packages simultaneously, each tasked to exfiltrate credentials and access tokens to a command-and-control server hosted on Amazon Web Services (AWS).All three payment platforms are popular, with Paysafe being mostly used by e-commerce sites and online marketplaces, gaming platforms, travel businesses, and financial services or software-as-a-service (SaaS) providers.Skrill and Neteller are digital wallets and money transfer services used in online betting, cryptocurrency exchanges, and on Forex trading platforms.Software developers working on such platforms integrate Paysafe’s SDKs into apps and websites to implement a secure payments and funds management system.According to application security company Socket, these deve
“HalluSquatting” weaponizes LLMs’ inability to say “I don’t know.” Dan Goodin – 8 Jul 2026 In the brief history of AI security, the prompt injection has quickly become the top threat. Large language models are inherently unable to distinguish between legitimate instructions provided by users and malicious ones sneaked into emails, source code, and other third-party content the models are processing. This makes it trivial to surreptitiously inject malicious commands that the LLM readily follows.With no way to enforce this crucial boundary between trusted and untrusted sources, AI engine developers are left to erect elaborate guardrails designed to mitigate the damage rather than solve the root cause.To date, most prompt injections have fallen into a class known as push, in which each potential victim is targeted. For example, the adversary injects malicious instructions into an individual email or calendar invitation. Because the injection must then be sent (or pushed) to each specific
July 8, 2026 By Pierluigi Paganini RedWing: The Android Banking Trojan You Can Rent on Telegram for Less Than a Coffee SubscriptionZimperium’s zLabs team has uncovered RedWing, an Android spyware operation sold as a subscription service through Telegram, with links to Russian threat actors and apparent roots in the Oblivion malware family.It comes with documentation, tutorial videos, a referral discount program, and a bot that builds custom malicious apps on demand. No malware-writing skill required.“Far from being just another basic piece of malware sold online, RedWing is a fully developed, commercial-grade MaaS product with seller documentation, videos, and a bot-driven subscription model that provides a low entry barrier for novice attackers.” reads the report published by Zimperium. “As a proof of this, the APK customization/obfuscation/creation can be fully implemented through telegram.” >>Full Article<<
July 8, 2026 By Tushar Subhra Dutta A newly uncovered cybercriminal operation has been quietly turning ordinary computers into paid proxy servers for years, hiding behind a fake version of the popular 7-Zip file compression tool.Victims searching for the free archiving software were instead led to a lookalike site that installed hidden proxy software instead of the real program.Once running, the malware quietly rented out the victim’s internet connection to paying customers without their knowledge or consent.The campaign first drew attention in early 2026 when the fake installer was found hosted at 7zip[.]com rather than the genuine site, 7-zip[.]org.What looked like an isolated scam turned out to be part of a much larger and longer running scheme. Researchers traced the activity back to at least August 2022, revealing a coordinated network built around dozens of fake software brands. >>Full Article<<
The “Rogue Agent” vulnerability could have enabled attackers to silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same Google Cloud project. July 8, 2026 By Ionut Arghire A vulnerability in Google Cloud’s Dialogflow CX service could have allowed attackers to silently control agents, manipulate conversations, and exfiltrate sensitive information, Varonis reports.Dialogflow CX is an enterprise-grade conversational AI platform that allows organizations to build complex virtual agents and chatbots for customer support, financial services, healthcare assistance, and sensitive data-handling workflows within enterprise environments.For user conversation workflows, Dialogflow CX relies on Playbooks, which offer Code Blocks, to support embedding custom Python logic into conversation flows, enabling agents to process user input, call APIs, and manipulate data.Code Blocks are executed within an environment controlled by Google, namely the C
A financially motivated operation uses lures of cracked or pirated software to deliver a malware two-for-one combo for data theft and cryptomining. July 8, 2026 By Elizabeth Montalbano Source: Bits and Splits via ShutterstockThreat actors are targeting consumers and small to midsize businesses (SMBs) globally in a financially motivated malvertising campaign that delivers the Vidar infostealer and cryptomining malware with multifaceted delivery and evasion strategies.Researchers from Palo Alto Networks' Unit 42 uncovered the campaign in April; it lures victims to pages for downloading files that impersonate cracked versions of copyright-protected software, according to a report published July 7. The files delivered, however, are actually password-protected archives that hide a malware loader for dropping and executing both the Vidar infostealer and the open source XMRig cryptominer. Vidar targets browser credentials, cookies, and crypto wallets, while the XMRig mines Monero cryptocurren
July 8, 2026 By Pierluigi Paganini Accenture confirmed a breach after a hacker claimed to steal 35 GB of source code, keys, and Azure credentials now offered for sale.A threat actor using the handle “888” claimed on the cybercrime forum PwnForums this week to have stolen 35 gigabytes of data from Accenture in July and offered it for sale. “Today I am selling the Accenture Data Breach, thanks for reading and enjoy!” reads the post published by the threat actor.The company confirmed the breach; its statement was brief and didn’t address most of the specific claims.“We are aware of this isolated matter, and we have remediated its source. There is no impact to Accenture operations and service delivery,” an Accenture spokesperson told the media. >>Full Article<<
July 8, 2026 By Bill Toulas A China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware.The campaign has been observed since May and focuses on physics and engineering departments, administrators and professors, as well as organizations involved in astrophysics, particle physics, or national security-related research.Researchers at cybersecurity company Proofpoint are tracking the activity under the name ‘UNK_MassTraction’ and believe to be associated with a new threat cluster.The attack begins with a malicious email sent from compromised accounts or spoofed domains, using a generic lure.Sample emails from the campaignSource: ProofpointOpening the email in a vulnerable Roundcube webmail client triggers exploitation of a cross-site scripting flaw tracked as CVE-2024-42009, which executes JavaScript code inside the victim’s browser, loading a payload called IceCube.According to the resea
July 8, 2026 By Brian Krebs A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 followers since its creation in January 2025, posting frequently about security vulnerabilities, AI and software exploits. IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.The IRIS C2 website dangles the possibility of million-dollar payouts for exploits to attract talent.“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X. “Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/ext
Swati Khandelwal Jul 08, 2026 AI Security / Threat Detection Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders.The agents are not malicious. They just do a lot of things that, to a behavioral engine, look exactly like an attack.Decrypting browser credentials, listing what sits in Windows' credential store, pulling files down with built-in system tools, writing to the startup folder: these have long been high-signal to defenders.What has changed is who is generating it. On the machines Sophos watched, it was often a developer's AI assistant going about ordinary work.What set the alarms offThe analysis draws on seven days of telemetry from June 2026, taken from Sophos's behavioral engine on Windows and counted by unique machines, not raw event volume. It is a narrow window on one vendor's fleet, not an industry census.Sophos's charts put credentia
The Hacker News Jul 08, 2026A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser.For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365 access, sensitive data, and response time are already at stake.The Email Looks Safe. The Browser Tells a Different StoryA recent EvilTokens attack shows how a phishing link can appear harmless during initial inspection while still leading to Microsoft 365 account takeover.The kit uses Microsoft Device Code Phishing to convince victims to complete a legitimate Microsoft login flow and unknowingly authorize access to their accounts. It does not need to steal the password directly.The real attack remains hidden until the page opens in the browser. Its HTML is encrypted with AES-GCM and becomes visible only after th
Ravie Lakshmanan Jul 08, 2026 Cybercrime / AI Security A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures.The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed SCMBANKER. Some components of the malware date back to October 2025."Once installed, the operator can see when a victim opens a banking session, lock the screen behind a fake bank warning, push the victims towards live phone interaction, redirect the browser, or replace account numbers copied to the clipboard," security researchers Jia Yu Chan and Salim Bitam said. "For a full takeover, they can also deploy a commercial remote-access tool."SCMBANKER is specifically designed to go after Mexico's financial ecosystem, with evidence pointing to
Swati Khandelwal Jul 08, 2026 Vulnerability / Cloud Security Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched.The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network access; ordinary threading calls from any local program are enough.Nebula turned it into a working root exploit that is 97% reliable in its testing and also escapes containers, and says Google awarded the team $92,337 through its kernelCTF bug-bounty program.No one is known to be exploiting it in the wild, but Nebula has published working exploit code, so anyone can now run it. Patching is the priority.How the bug worksThe kernel has a system for keeping an urgent task from getting stuck behind a trivial one. Part of it is a cleanup step that tidies up after a
Ravie Lakshmanan Jul 08, 2026 AI Security / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerabilities are listed below -CVE-2026-48282 (CVSS score: 10.0) - A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the current user. CVE-2026-56290 (CVSS score: 10.0) - An improper access control vulnerability in Joomlack Page Builder that could allow for remote code execution via unauthenticated arbitrary file upload. CVE-2026-55255 (CVSS score: 6.1) - An authorization bypass through a user-controlled key vulnerability in Langflow that could allow an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. CVE-2026-48908 (CVSS score: 10.0) - An unrestricted upload of a file with a dangerous type vulnera
Most of the headlines this week focused on the extradition of Peter Stokes, an alleged member of Scattered Spider. That's certainly newsworthy, but after reading the criminal complaint, I think the investigation itself is the more interesting story.Peter Stokes, alleged member of Scattered SpiderAccording to the complaint, Microsoft provided records associated with that Windows installation through its Global Device ID (GDID). Investigators then combined that information with timestamps, account activity, IP history, and other evidence to build their case.To me, this was the biggest operational security mistake described in the complaint.If the government's timeline is accurate, the alleged attacker wasn't separating operational activity from personal activity. They kept returning to the same Windows installation. Whether you're a threat actor, penetration tester, or security researcher, mixing personal and operational activity on the same endpoint creates opportunities for investigato
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.CVE-2026-48282 Adobe ColdFusion Path Traversal VulnerabilityThis type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether th
Attackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets. July 7, 2026 By Ionut Arghire Threat actors are exploiting a vulnerability in Gitea’s reverse-proxy authentication mechanism to access internet-accessible instances by supplying only a valid username.Specific to Gitea’s official Docker images, the critical-severity security defect is tracked as CVE-2026-20896 (CVSS score of 9.8) and can be exploited with a single HTTP header, Sysdig Sr. Director of Threat Research Michael Clark says.The issue exists because, in Gitea Docker images before 1.26.3, the default settings allow connections from any source IP address instead of enforcing an allowlist, security researcher Ali Mustafa, who was credited for finding the bug, explains.If placed behind a proxy, Gitea should trust only a header set by the proxy when reverse-proxy authentication is enabled. Because of the flaw, any
Dog-eat-dog world for credential-stealing attackers July 7, 2026 By Jessica Lyons EXCLUSIVE There's no honor among thieves as a new worm steals from other infectious software. It pilfers “multiple” victims’ credentials and mines for cryptocurrency while killing competitors’ processes, including similar secret-harvesting malware.It’s called Cloud AI Infrastructure Attack Framework (CAI), and it’s a centralized botnet that targets cloud-native developer tools like Docker, Kubernetes, Redis, etcd, Kubelet, and Ray for credential theft and cryptomining. The scripts “are heavily inspired” by the likes of other similar credential-stealing worms that have wreaked havoc across cloud environments and supply chains this year, “using code comments like ‘PCPJack-aligned,’” according to security researcher Michael R.“CAI explicitly seeks out and kills TeamPCP and PCPJack processes, to further monopolize on compromised targets,” he posted on X. TeamPCP is the malware-developing crew behind the mini
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability CVE-2026-56290 Joomlack Page Builder Improper Access Control VulnerabilityThese types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly
July 7, 2026 By Jordyn Alger KDDI Corporation, a prominent Japanese telecommunications organization, revealed a data breach may have impacted 12.2 million customer emails. Furthermore, 7.6 million passwords were compromised. The cyberattack reportedly leveraged vulnerabilities in a third-party software for the organization’s email system. >>Full Article<<
The 16-year-old Januscape flaw affects Linux’s KVM hypervisor, allowing attackers to escape virtual machines and potentially execute code on the underlying host. July 7, 2026 By Ionut Arghire A newly disclosed Linux kernel vulnerability can be exploited to escape virtual machines (VMs) and execute code on the underlying host, security researchers warn.Tracked as CVE-2026-53359 and referred to as Januscape, the security defect impacts the shadow MMU code in Linux Kernel-based Virtual Machine (KVM) hypervisor.The guest-to-host vulnerability poses a major threat to multi-tenant x86 public clouds running untrusted guests and exposing nested virtualization. It is known to be the first KVM exploit that can be triggered on both Intel and AMD architectures.The flaw was discovered by security researcher Hyunwoo Kim (@v4bel), who demonstrated it as a zero-day in Google kvmCTF, the bug bounty program that works like a CTF event and offers up to $250,000 for full VM escape weaknesses. >>Full
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.