Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database…
A Broadcom lançou atualizações de segurança para corrigir diversas vulnerabilidades que afetam produtos VMware, incluindo ESX, vCenter, Workstation e Fusion. Entre elas, três falhas foram classificadas como críticas por permitirem desde o desvio do processo de autenticação até a execução remota de código e o comprometimento do host por meio de uma máquina…
Parceria entre startup australiana e plataforma brasileira promete pagamentos via Pix por vídeos de atividades rotineiras, como lavar louças ou dobrar roupas — executiva de cibersegurança questiona pontos preocupantes no modelo de negócio. E se você pudesse receber uma renda extra por simplesmente filmar atividades cotidianas que são indispensáveis para sua…
ESET West Africa Security Blog2026-07-29 23:00 UTC
The rise in malicious job offers is transforming Nigeria’s digital job market into a high-stakes cyber minefield. For millions of young, skilled Nigerians looking to land a career breakthrough or a remote global role, an innocent application can lead directly to financial loss or identity theft. Cybercriminals are actively weaponising the desperation of job…
La automatización industrial en España afronta un momento decisivo. Atraer inversiones y desarrollar fábricas inteligentes exige mucho más que incorporar maquinaria de última generación. A medida que los procesos productivos
Casi la totalidad de los ciberataques con éxito, el 98%, incluye algún componente de ingeniería social, y cada vez son menos los que se limitan a un único canal. Según CrowdStrike,
ThreatCluster - Threat Intelligence Feed2026-07-29 21:09 UTC
Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering tactics to compromise maintainers' accounts, allowing them to publish malicious updates that affected numerous organizations globally. The…
Amazon's threat intelligence team traced domain records from the open-source software hack to a smaller, earlier compromise by the same North Korean group. The post A little-known npm package was North Korea’s warm-up act for the axios hack appeared first on CyberScoop .
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been…
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious…
Brad Blakestad, director of the National Quantum Coordination Office, also said encryption and measuring progress would pose challenges. The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop .
La televisión de Digi TV añade una sección de vídeo bajo demanda , que se suma a los más de 120 canales estándar que ya ofrece. Es decir, series, películas y otros programas que podremos ver en cualquier momento, con un funcionamiento similar a Netflix o Disney+. Incluso operadores "pequeños" como Pepephone tienen una plataforma de televisión , así que…
Open Source Security Foundation2026-07-29 20:03 UTC
OpenSSF Community Day Europe 2026 (October 6 in Prague), focuses on open source software security, regulatory compliance like the EU CRA, and AI supply chain risks. The one-day event features technical sessions on tools like VEX, Gemara, and Sigstore, offering direct collaboration with maintainers and security experts.
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. [...]
A seller posting as Resolute, claiming to have acted alongside a group using the Lapsus$ name, is advertising data from a complete compromise of Mercor, the US platform that recruits domain experts to produce training data for AI laboratories.
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham's water plant went offline, and…
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer…
ThreatCluster - Threat Intelligence Feed2026-07-29 18:06 UTC
Guangdong Chanming, a covert Chinese company, has been linked to the sale of a spy botnet to the People's Liberation Army (PLA) and various hacking groups. This botnet serves as an anonymous relay network, facilitating global cyber intrusions while masking their origins. Research by Intrusion Truth revealed that Chanming's tools, including an 'Anonymous…
ThreatCluster - Threat Intelligence Feed2026-07-29 17:54 UTC
A drone struck the US-owned gas storage tanker Energos Winter at Egypt's Damietta port on July 29, causing a fire that spread to another vessel. The Egyptian cabinet confirmed the attack, marking a significant escalation in the ongoing Iran-US conflict. No casualties were reported, but the incident has raised concerns about regional security and the…
AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook…
Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. "No settings or additional user…
A forum user posting as cozypandas has published what they describe as the full customer database of IPRO, an eDiscovery platform used by law firms, corporations, and government agencies to manage data for litigation.
AI-generated phishing campaigns are rapidly evolving beyond traditional malware delivery, shifting the battleground directly into the web browser where attackers can hijack active sessions, bypass multi-factor authentication (MFA), and evade conventional endpoint security controls. This emerging threat model is forcing security operations centers (SOCs) to…
ThreatCluster - Threat Intelligence Feed2026-07-29 16:46 UTC
Ukrainian drone pilots are facing significant challenges due to pervasive electronic warfare (EW) tactics employed by both Ukrainian and Russian forces. Operators must negotiate safe flight paths through friendly jamming zones, often using group chats for coordination. The electronic warfare battle has become crucial in modern combat, complicating drone…
Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers…
The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal security agency said the instant messaging platform "failed to remove numerous channels, chats, and…
Broadcom has released emergency security updates for five vulnerabilities affecting VMware vCenter, ESX and ESXi, Workstation, Fusion, Cloud Foundation, vSphere Foundation, and several VMware Telco products.
Unknown attackers broke into 92 unique SonicWall user accounts with legitimate credentials, researchers said. The post Huntress warns about attack spree that hit 30 SonicWall customers in 2 days appeared first on CyberScoop .
Dependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project. The post Tame Dependabot: Group your updates, slow the cadence, keep security fast appeared first on The GitHub Blog .
ThreatCluster - Threat Intelligence Feed2026-07-29 15:44 UTC
NVIDIA has disclosed a critical security vulnerability in its BlueField data processing units (DPUs) that enables virtual machine (VM) users to execute arbitrary code through specially crafted network messages. This vulnerability, identified as CVE-2026-65094, affects the VIRTIO-Net implementations on BlueField-3 platforms. The flaw poses a significant risk…
NVIDIA has disclosed a serious vulnerability affecting its BlueField DPUs and ConnectX networking platforms that could allow attackers to execute code on affected systems if successfully exploited. This vulnerability, tracked as CVE-2026-65094, impacts the VIRTIO-Net component and has a CVSS v3.1 score of 9.0, indicating a high-risk issue for enterprise and…
Mac users are being targeted by a ClickFix campaign that turns a fake verification prompt into a path for malware installation. Victims are persuaded to copy a command from a web page, open Terminal, paste it, and run it, believing they are completing a routine CAPTCHA check. The attack does not rely on a software […] The post macOS ClickFix Attack Deploys…
A critical security flaw in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to execute arbitrary commands and fully compromise AI agent environments. Assigned a maximum CVSS base score of 10.0, the vulnerability (tracked as CVE-2026-59726) was discovered by Noma Labs and affects Ruflo’s Model Context…
ESET West Africa Security Blog2026-07-29 15:18 UTC
Your digital footprint reveals personal data that puts your security and privacy at risk. Here’s how to audit your exposure, remove PII, and stop it from resurfacing. Today, few, if any of us, have zero internet footprint. But an extensive online profile of personally identifiable information (PII) can be a security and privacy risk. It gives fraudsters and…
Anthropic’s Claude Mythos Preview model has helped researchers discover ways to speed up attacks against two widely studied cryptographic algorithms. One of the targets is Hawk, a candidate for post-quantum digital signature algorithms currently being evaluated by NIST, while the other improves the best previously known attack against a weakened version of…
Sweet Security , the proactive runtime enforcement company for cloud and AI, today announced its further expansion into AI security with Agentic AI Blocking . Sweet now blocks rogue agent behavior in real time – extending Sweet’s runtime enforcement from the cloud to the AI agents that are acting alongside it. Eighty percent of the world’s businesses are…
Russian intelligence-linked hackers are trying to seize Signal accounts by posing as support staff and asking targets for backup recovery keys. The campaign targets people with access to sensitive conversations, including officials, military personnel, political figures, journalists, and Ukrainian leaders. It relies on deception, not a break in Signal’s…
ASEC Blog를 통해 한 주간의 ‘Ransom & Dark Web Issues’ – 2026년 7월 5주차를 게시한다. Termite, 미국 비영리 의료기관 대상 랜섬웨어 공격 ShinyHunters, 글로벌 회계 및 컨설팅 기업 대상 데이터 유출 주장 The Gentlemen, 한국 IT 소프트웨어 도매업 및 IT 인프라 구축 기업 대상 랜섬웨어 공격
이 기술분석보고서는 대한민국 국가정보원, 경찰청, 한국인터넷진흥원, 금융보안원 합동 사이버 보안 권고문 ‘국가배후 해킹조직의 우리 국민ㆍ기업 해킹 공격 주의 권고’의 일환으로 작성되었습니다. 개요 AhnLab SEcurity intelligence Center(ASEC)은 국가배후 해킹 그룹이 2025년부터 2026년 상반기까지 금융·기관 서비스 이용 과정에서 설치되는 국내 금융 보안 소프트웨어의 취약점을 악용하여 지속적으로 악성코드를 유포한 정황을 확인하였다. 공격자는 워터링 홀 또는 스피어 […]
ThreatCluster - Threat Intelligence Feed2026-07-29 14:56 UTC
A new book warns that China, Russia, Iran, and North Korea are collaborating as a bloc, posing a significant threat to the U.S. The cooperation includes military exercises, arms transfers, and intelligence sharing, with 616 documented instances from 2019 to 2025. Retired Rear Adm. Mark Montgomery highlights the 'simultaneity problem,' where the U.S. may…
ThreatCluster - Threat Intelligence Feed2026-07-29 14:44 UTC
In 2025, the University of Pennsylvania suffered a significant data breach due to a compromised single sign-on (SSO) account. Attackers accessed the PennKey SSO, infiltrating internal systems including VPN, Salesforce, Qlik, SAP, and SharePoint. This breach affected 1.2 million individuals, highlighting the risks associated with SSO authentication. While…
Researchers from ZeroBEC disclosed details of the phishing campaign Operation BlueDash, in which attackers use fake Microsoft Teams update pages to deliver legitimate remote monitoring and management (RMM) tools. Victims are redirected via compromised web infrastructure to a counterfeit Microsoft Store page, where they are told they must update Teams before…
A fresh supply chain scare hit software teams after attackers slipped malware into trusted open source libraries. On July 28, 2026, malicious beta builds of two Joyfill packages appeared on the npm registry. The libraries, @joyfill/components and @joyfill/layouts, are used for forms and layout work in many web apps. Anyone who imported those beta builds […]…
The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass…
Las Vegas, USA, July 29th, 2026, CyberNewswire Catches rogue AI agents – and stops them in live production before they cause damage Sweet Security, the proactive runtime enforcement company for cloud and AI, today announced its further expansion into AI security with Agentic AI Blocking. Sweet now blocks rogue agent behavior in real time – […] The post…
We’re packing up for Las Vegas to take over at BSides LV, Black Hat USA, and DEF CON! Don’t miss out on our DEF CON kickoff with an exclusive dual-session evening: join offensive security expert Jason Haddix and Anthropic’s Rob Bair for a candid breakdown of AI guardrails, and then test your dark web monitoring […] The post Flare’s Heading to Hacker Week…
The CEO of Mercurius Cybersecurity examines the dual challenge created by AI adoption within organizations, with incidents stemming from unsupervised use and increasingly sophisticated attacks such as personalized phishing and voice cloning, in a landscape where Gartner estimates that 34% of companies using generative AI have already experienced unintended…
Health-ISAC is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters, which are using social engineering to compromise single sign-on accounts and steal data from cloud services. [...]
ThreatCluster - Threat Intelligence Feed2026-07-29 13:51 UTC
Noma Labs has disclosed a critical vulnerability (CVE-2026-59726) in the Ruflo AI hosting platform, allowing unauthenticated attackers to execute arbitrary commands and take full control of AI agent environments. The flaw, known as 'RufRoot', has a maximum CVSS score of 10.0 and enables attackers to exploit a Model Context Protocol (MCP) bridge that is open…
Nach einem kurzen Rückgang steigen die Kosten für Datenlecks in Deutschland erneut. Laut dem aktuellen "Cost of a Data Breach Report" von IBM liegt der Schaden pro Vorfall im Schnitt bei 4,25 Millionen Euro – ein Anstieg gegenüber dem Vorjahreswert von 3,87 Millionen Euro. Als Treiber gilt vor allem der zunehmende Einsatz künstlicher Intelligenz auf Seiten…
A single malicious webpage is enough to compromise Tor Browser users running an unpatched build, following newly disclosed research into CVE-2026-10702. The flaw, a high-severity Firefox JavaScript engine bug, was successfully exploited against Tor Browser by researchers at Nebula Security. Mozilla resolved the vulnerability in Firefox 151.0.3 on June 2,…
The agency said imports of advanced robots pose cybersecurity and other national security risks. The post US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security appeared first on SecurityWeek .
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment also hacked multiple third-party accounts and services as part of the attack. The latest disclosure shows that the security incident, which stemmed from an internal security test, was…
Revolut is currently under scrutiny after hackers claimed to be selling a database containing records of more than 75 million users. However, the company asserts that it has found no evidence of a new breach at this time. A threat actor has advertised what they describe as a Revolut customer database on a cybercrime forum, […] The post Revolut Alleged Data…
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before…
Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize. Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users…
Vultr informa que se encuentra entre los primeros proveedores cloud en ofrecer la nueva GPU AMD Instinct MI455X y soporte para la solución AMD Helios rackscale. Vultr ya está aceptando pedidos anticipados disponibles en el cuarto
The autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet of one of the first publicly documented AI-driven intrusion chains. Hugging…
The startup will use the investment to expand its customer support, sales, and R&D teams. The post Mate Security Raises $35 Million for Agentic SOC appeared first on SecurityWeek .
Russia is seeking to place Telegram founder Pavel Durov on an international wanted list, alleging that the app has been used by Ukrainian intelligence to organize terrorist attacks and conduct espionage inside Russia.
Russia’s Federal Security Service (FSB) has formally charged Telegram founder and CEO Pavel Durov with aiding terrorism and issued a warrant for his arrest, escalating a long-running clash between the Kremlin and one of the world’s most widely used encrypted messaging platforms. The move, announced on July 29, 2026, centers on allegations that Telegram…
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in…
Houston City College has experienced a serious data breach that exposed sensitive personal information of approximately 832,000 unique students and alums. This incident is linked to a cyber extortion campaign by the ShinyHunters threat group. The breach, which came to light in June 2026, is part of a larger trend of attacks on educational institutions […]…
La Sociedad Española para la Transformación Tecnológica (SETT), adscrita al Ministerio para la Transformación Digital y de la Función Pública, ha hecho pública una inversión de 1,47 millones de euros
La tienda online de Amazon añade una nueva complicación: la entrega segura con una contraseña temporal (OTP) . No basta con firmar en la entrega del paquete o facilitar el número de DNI, porque Amazon no se fía de sus propios repartidores. Hace tiempo que pensamos que Amazon Prime no es ningún "chollo" , y que la tienda online se aprovecha de una…
The company was previously valued at $1.6 billion, and the latest raise has significantly increased that valuation. The post ThreatLocker Raises $190 Million in Series F Funding appeared first on SecurityWeek .
Angola’s largest telecommunications operator, Unitel, was hit by a cyberattack that has left millions of people nationwide without voice services, mobile data, and internet access.
No pierdas la oportunidad de conseguir este pack de cámaras de Tapo por casi la mitad de su precio . No es una, sino dos cámaras con las que podrás reforzar la seguridad de tu hogar con muy poco dinero, es un chollo irrepetible que no debes desaprovechar. Lo cierto es que Tapo cuenta con un amplio ecosistema de cámaras de seguridad para todas las…
A new wave of job scams is hitting Web3 developers who are simply looking for their next role. Attackers pose as recruiters, start friendly chats about interviews, and then steer candidates toward a fake meeting tool that feels completely normal for remote hiring. The lure looks polished. Victims are told to install “Relay,” billed as […] The post Fake…
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. [...]
Según el nuevo estudio titulado Informe sobre IA de Netskope: 2026, las vulneraciones de las políticas de datos descendentes ya son la segunda infracción de IA más frecuente en las empresas,
ThreatCluster - Threat Intelligence Feed2026-07-29 11:51 UTC
OpenWrt has released updates for versions 24.10.8 and 25.12.5 to address critical security vulnerabilities. The most severe issue is a buffer overflow in the odhcpd DHCP server, allowing unauthenticated attackers to execute code remotely (CVE-2026-53921, CVSS 9.8). Another vulnerability allows for stored XSS through manipulated FQDN hostnames…
A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion. The post Critical VM Escape Vulnerability Patched in VMware ESXi appeared first on SecurityWeek .
The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period. The post US, Australia Release OT Isolation Guidance for Critical Infrastructure appeared first on SecurityWeek .
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." [...]
Two beta releases of joyfill npm Packages have been found distributing a malware implant capable of delivering the DEV#POPPER remote access trojan (RAT) . The compromised Node.js packages use an import-time loader that retrieves encrypted payloads through blockchain transactions instead of traditional command-and-control infrastructure. The affected…
Malicious cyber actors routinely target critical infrastructure to conduct espionage, extort victims, or establish access for disruptive and destructive attacks. The new CI Fortify Guide advises owners and operators to strengthen their ability to isolate vital systems from other networks, helping contain incidents and maintain critical services during a…
The Have I Been Pwned service has added to its database data stolen in the breach of Suno, a popular AI music generator. According to HIBP, the dump contains 55.3 million unique email addresses, phone numbers and tens of thousands of records from the Stripe payment system, including partial bank card details. All Suno users ... Read more
Hugging Face has published an anatomy of the attack and OpenAI has shared additional information from its investigation. The post OpenAI’s Rogue AI Ventured Beyond Hugging Face appeared first on SecurityWeek .
ThreatCluster - Threat Intelligence Feed2026-07-29 10:04 UTC
On July 29, 2026, Russia's Federal Security Service (FSB) charged Pavel Durov, founder of Telegram, with aiding terrorism, alleging that his platform was used by Ukrainian intelligence to coordinate sabotage and terrorist activities within Russia. The FSB claims Telegram failed to remove channels and bots facilitating these actions, leading to the issuance…
AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI. [...]
Our cybersecurity world can get quite interesting and even close to science fiction sometimes. No, it’s not AI this time, but something movie-worthy nevertheless. Picture scenes from known heist-themed movies such as “Ocean’s Eleven” or “Mission: Impossible”. Real-world equivalent scenarios like these are happening in front of your eyes and you might not…
Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system. [...]
Um grupo de 25 empresas de tecnologia, organizações do setor e fundos de investimento publicou uma carta aberta pedindo que o governo dos Estados Unidos apoie modelos de inteligência artificial de pesos abertos (open weight), argumentando que eles são fundamentais para manter a concorrência, impulsionar a inovação e fortalecer a segurança do ecossistema de…
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.0.0-rc24-2773-beta.4 The two packages "contain an import-time JavaScript…
La vulnerabilidad CVE-2026-60004 abre la puerta a la ejecución remota de comandos en Gitea si un atacante cuenta con permisos de escritura en un repositorio. La corrección pasa por actualizar, se cita Gitea 1.27.1 como versión con parche, y por auditar de inmediato el uso de hooks de Git y los permisos de colaboradores. Un […] La entrada Un fallo crítico en…
ThreatCluster - Threat Intelligence Feed2026-07-29 09:31 UTC
On July 22, 2026, Check Point disclosed CVE-2026-16232, a critical authentication bypass vulnerability in SmartConsole affecting Security Management Server and Multi-Domain Security Management Server (MDS). This flaw allows unauthenticated attackers to gain full administrative access by exploiting the SmartConsole login process. The vulnerability is…
A equipe responsável pelo kernel Linux publicou 432 novos identificadores de vulnerabilidades (CVEs) entre domingo e segunda-feira, provocando preocupação entre administradores de sistemas e profissionais de segurança pela dificuldade de analisar e priorizar um volume tão elevado de falhas em um curto período. O aumento chamou a atenção da comunidade após…
The IP intelligence company will use the fresh investment to accelerate and scale its operations. The post Spur Raises $200 Million for IP Intelligence Platform appeared first on SecurityWeek .
ThreatCluster - Threat Intelligence Feed2026-07-29 09:06 UTC
A severe supply chain compromise in the Advanced Responsive Video Embedder WordPress plugin has been identified, allowing unauthenticated attackers to gain complete administrator access. The malicious version, 10.8.7, impacts around 20,000 active installations and is tracked as CVE-2026-18072, with a CVSS score of 9.8. The backdoor enables attackers to…
We work so hard to have freedom and leverage and choice. And then, as soon as a social network, boss or cultural force instructs us to do something, we fold our tents and go along. Responsibility is scary. Sometimes it’s easier to find someone (or something) to blame. Just because AI tells you to put […]
ThreatCluster - Threat Intelligence Feed2026-07-29 09:00 UTC
Recent research revealed that a significant number of Model Context Protocol (MCP) servers are exposed to the Internet without proper authentication, affecting many organizations, including Fortune 500 companies. Wiz found that 1 in 6 cloud environments expose at least one MCP server, with 70% returning their full tool catalog to anonymous callers.…
The IT Engineer Teammate brings agentic triage to infrastructure health—autonomous investigation, chat support, and firewall review. Read the breakdown.
CISA’s new Binding Operational Directive (BOD) 26-04 marks one of the most important changes to federal vulnerability management in years. Rather than requiring agencies to patch every critical vulnerability on the same timetable, the directive prioritizes remediation based on risk, with patch deadlines ranging from three days for the highest-risk…
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek .
ThreatCluster - Threat Intelligence Feed2026-07-29 08:20 UTC
The Flying Eagle Android remote access trojan (RAT) is being distributed via fraudulent applications impersonating China's Public Security Bureau. Researchers from Hunt.io and NetAskari identified 170 servers linked to this malware, which captures sensitive information such as payment passwords and keystrokes. The malware utilizes Android Accessibility…
Most OT security spending goes to defending networks after equipment is installed. The presentations at S4x26 in Miami made a different case: the highest-impact moment to address supply chain risk is before the purchase order is signed. Asset owners who attach cybersecurity acceptance testing to existing procurement instruments, retainage clauses, and…
The security benefits of multifactor authentication (MFA) are well-known, yet MFA continues to be poorly, sporadically, and inconsistently implemented, undercutting its effectiveness as a security tool while often saddling users with an extra workflow burden — one of many obstacles to MFA’s success. Frequent news stories that describe innovative ways to…
State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities. The post Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks appeared first on SecurityWeek .
Tampa International Airport will privatize most Transportation Security Administration operations just months after President Donald Trump unveiled a 2027 budget proposal that called for handing more airport security over to private companies. In a statement to CNN on Monday, Tampa International Airport said it “opted in” to the TSA Gold+ program, a new…
Link to the Room: https://tryhackme.com/room/publisher Title: Test your enumeration skills on this boot-to-root machine Description: The “ Publisher ” CTF machine is a simulated environment hosting some services. Through a series of enumeration techniques, including directory fuzzing and version identification, a vulnerability is discovered, allowing for…
I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 versions.
Difficulty: Very Easy Category: Web / Information Disclosure Target Room: https://tryhackme.com/room/hh-room404-804573bf Executive Summary During web application security assessments, misconfigurations in version control systems can lead to catastrophic source code disclosure. In this challenge, an exposed .git directory allowed us to reconstruct the target…
Table of Contents Choosing the Target Reading the Code A Small Test Building a Test Environment Testing the Application It Wasn’t Just File Read Understanding the Root Cause Responsible Disclosure Final Thoughts Every security researcher has a different way of finding vulnerabilities. Some start with automated scanners. Some begin by fuzzing endpoints. For…
HTTP Request Smuggling is one of those vulnerabilities that sounds complicated, but the core idea is actually simple. Let’s Understand it in simplest way possible. When your browser sends a request to a server there are generally two types of servers through which your request goes through - 1. Front end server (like a load balancer, reverse proxy, or CDN)…
You have confirmed SQL injection against a Snowflake backend. The injected expression executes . The behavior is repeatable. The database is clearly processing your input. But you cannot extract a single value. Every normal error-based extraction technique returns the same thing: HTTP 200, followed by an empty array. Only malformed payloads, such as an…
Static malware analysis is typically the first line of investigation when dealing with a suspicious executable. Before a sample ever touches a sandbox, analysts can extract meaningful intelligence by examining its structure, metadata, embedded strings, imported APIs, and behavioral indicators — all without running a single line of code. In this…
In this blog, I am going to share an account takeover vulnerability in a third-party provider widely used by many bug bounty programs. I discovered this issue during a bug bounty engagement in October 2025. I discovered an IDOR leading to Account Takeover (ATO) in a third-party provider that works with many organizations. before this Let me clear the…
Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade "A" rating, but it still only costs $144.97 (reg. $369.99) on sale. [...]
Eine aktuelle Auswertung zeigt, wie stark Unternehmen hinter bekannten KI-Produkten von bereits ausgenutzten Sicherheitslücken betroffen sind. Seit 2021 wurden bei 16 Anbietern insgesamt 828 sogenannte CVEs registriert, die nachweislich für reale Angriffe genutzt wurden. Mit Abstand am häufigsten betroffen ist Microsoft. Der Beitrag KI-Branche: Microsoft…
AI assistants, automation and digital workplace platforms are reshaping work, boosting productivity and creating a more intelligent employee experience
Trans-Tasman wholesale internet and network service provider Devoli is adding to its reach in Australia with the appointment of Kent Plummer as channel manager for the country. Based on the Gold Coast, Plummer will work with Devoli partners in Australia to help them reduce operational complexity and make the most of the provider’s platform. He joins Devoli…
The critical vulnerability CVE-2026-12569 in the PTC Windchill product is being actively exploited as part of a data-theft campaign allegedly linked to the Cl0p group. The attackers are combining this vulnerability with a separate information disclosure defect in PTC FlexPLM, which allows unauthenticated arbitrary code execution on systems exposed to the…
Enhancing digital security infrastructure, setting up new central prisons, and maintaining a repository of sharp-edged tools kept in prison workshops to avoid misuse by inmates were some of the major recommendations made by a panel that looked into the safety lacunae in prisons in the state, highly placed sources say. Phasing out physical production of […]…
Neue gemeinsame Leitlinien von CISA, dem australischen ACSC und dem FBI zeigen Betreibern wichtiger Infrastruktureinrichtungen, wie sie ihre Betriebstechnologie im Ernstfall vom Netz trennen können, ohne den laufenden Betrieb zu gefährden. Der Beitrag CISA und internationale Partner veröffentlichen Leitfaden zur Isolierung von Betriebstechnologie erschien…
Consultancy dx1 is focusing on data and AI with the launch of subsidiary Innablr AI as a means of meeting demand for data foundations and enterprise AI capabilities. The subsidiary adapts the brand of Innablr, the cloud engineering firm that the business acquired in October last year . In a statement, the consultancy, which was formerly known as DevOps1…
Organizations today face increasingly sophisticated cyberattacks that abuse trusted infrastructure instead of suspicious domains. One recent example involves the PhantomEnigma malware campaign, where attackers compromise legitimate government websites to distribute malicious payloads. This tactic makes attacks significantly harder to detect because users…
Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform. The post ShinyHunters Claims Ernst & Young Hack appeared first on SecurityWeek .
Forschende von Anthropic haben mithilfe des KI-Modells Claude Mythos Preview zwei bemerkenswerte Ergebnisse in der Kryptoanalyse erzielt: Ein Angriff schwächt das für die Post-Quanten-Ära entwickelte Signaturverfahren HAWK spürbar, ein zweiter verbessert bekannte Angriffe auf eine reduzierte Version der weitverbreiteten Verschlüsselung AES. Auf produktive…
ThreatCluster - Threat Intelligence Feed2026-07-29 06:13 UTC
The FCC has added foreign-produced power inverters and advanced robotic devices to its Covered List, effectively banning new models from receiving FCC equipment authorization. This decision follows national security assessments indicating these devices pose unacceptable risks to critical infrastructure and supply chains. Concerns center on the remote…
Discover how Wi-Fi jamming disrupts your connectivity and learn how to protect your network from both intentional attacks and unintentional interference.
Master the art of identifying hidden vulnerabilities by learning how attackers bypass filters using alternate syntax to execute malicious scripts in your users' browsers.
Snowflake, the AI Data Cloud company, today introduced Cortex AI Gateway2 and several AI security innovations that establish the foundation for trusted agent interoperability, enabling organisations to securely scale their agentic enterprises. Cortex AI Gateway addresses two of the biggest barriers to enterprise AI adoption today by helping organisations…
AhnLab SEcurity intelligence Center(ASEC)은 MS-SQL 서버에 대한 공격 사례를 모니터링하던 중 Larva-26009 공격자가 XMRig 코인 마이너를 설치하는 사례를 확인하였다. MS-SQL 서버를 대상으로 한 공격 사례들 중 코인 마이너를 설치하는 사례는 흔하지만 이번에 확인된 공격에서는 VShell, GotoHTTP를 설치하여 감염 시스템에 대한 제어를 탈취하였으며 SoftEther를 설치해 VPN 서버로 사용하기도 하였다. 1. 초기 침투 과정 (MS-SQL) 최초 […]
In some tech circles, insulting colleagues and belittling anyone slower to understand is treated as a sign of confidence, and the next generation of leaders are learning from it.
As the UAE moves closer to universal digital adoption, new research suggests the priority is no longer encouraging people to use online services, but ensuring every digital interaction is secure and trusted. The post UAE digital users call for stronger security appeared first on Security Middle East Magazine .
Popular telehealth provider Hims & Hers "shared consumers’ sensitive health information with third-party advertising platforms such as Meta and Snap despite promising to protect patient privacy," the federal government alleges.
Infoblox, the leading platform for pre-emptive security and critical network services, today announced its entry into the external attack surface management (EASM) market. Together with the introduction of Supply Chain Intelligence, the launch expands the Infoblox Exposure Management portfolio, helping organisations identify, prioritise, and reduce…
OpenAI has open-sourced Codex Security, a command-line tool and TypeScript SDK designed to help developers find, validate, and fix security vulnerabilities in their codebases. The release marks a notable step in bringing AI-driven security analysis into everyday development workflows, allowing teams to scan repositories, review pull requests, and embed…
Between July 9 and July 13, 2026, security researchers documented what is being called the first fully autonomous AI agent cyberattack to chain zero-day flaws across multiple organizations. An AI agent running inside OpenAI’s ExploitGym cyber-capability evaluation harness escaped its test environment, rooted a third-party code sandbox, and then infiltrated…
TAIPEI, July 29, 2026 /PRNewswire/ — TPIsoftware has signed a global reseller agreement with Juxta, a US-based tech innovator specializing in Universal Positioning System (UPS), to deliver geospatial tracking applications to customers across regions. Through this agreement, TPIsoftware will help […]
Australian Cyber Security Magazine2026-07-29 01:45 UTC
Small and midsize businesses (SMEs) across Australia and New Zealand are adopting artificial intelligence at high rates, but many remain reluctant to trust it for autonomous cybersecurity decisions, according to [...]
Cisco New Zealand country leader Jess McFadden has taken on the role of east managing director at Cisco Australia and New Zealand (A/NZ), expanding her remit to include New South Wales in Australia and the Pacific Islands. Announcing the new position in a LinkedIn post, McFadden said the role will see her moving back to Sydney but added that she is still…
A threat actor claims to have breached Groomit, publishing a dataset containing customer information that BreachNews reviewed but could not independently attribute to the company. This article was first published by BreachNews . Original source: Groomit Allegedly Breached With Customer Data Claimed Exposed
A threat actor claims to have breached workforce management platform ZoomShift, alleging theft of employee information, event logs, and GPS clock-in data. This article was first published by BreachNews . Original source: ZoomShift Allegedly Breached With Employee and GPS Clock-In Data Exposed
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three…
Nature, Published online: 29 July 2026; doi:10.1038/s41586-026-10754-7 A silicon quantum processing unit executes high-fidelity multiqubit circuits, with all time-varying control signals generated by a digitally programmed cryogenic complementary metal–oxide–semiconductor controller and delivered to the low-noise, exchange-only qubit device through a…
Nature, Published online: 29 July 2026; doi:10.1038/s41586-026-10834-8 Pathways to previously undescribed polyenes, including unusual enzymes that introduce more sugars onto polyene scaffolds, are discovered, and their accessibility through clean and efficient fermentation and potential for safe use as antifungal treatments is described.
Nature, Published online: 29 July 2026; doi:10.1038/s41586-026-10766-3 A silicon spin-qubit device comprising a shuttling bus for transporting qubits is used to achieve parity checks up to weight four, highlighting the feasibility and benefits of incorporating shuttling into semiconductor quantum processors.
Nature, Published online: 29 July 2026; doi:10.1038/s41586-026-10850-8 New data on homebuying loan records around the Second World War in the USA, linked to race and immigration status, show that Black borrowers were disproportionally excluded from mortgage programmes.
Nature, Published online: 29 July 2026; doi:10.1038/s41586-026-10839-3 Perpendicular switching of the polarization state in the layered ferroelectric Bi4Ti3O12 is demonstrated by means of trilinear coupling, allowing manipulation of the in-plane polarization component with an out-of-plane electric field.
Nature, Published online: 29 July 2026; doi:10.1038/s41586-026-10881-1 A nanopore-based ‘chop and measure’ method sequences peptides at single-amino-acid resolution by using enzymatic digestion to progressively shorten the N terminus one residue at a time, together with repetitive N-terminus re-reading.
Nature, Published online: 29 July 2026; doi:10.1038/s41586-026-10862-4 Operando optical microscopy shows avalanche-like lithium deintercalation (intercalation) processes as the dilute stages of graphite are emptied (filled), showing how local disorder governs phase-transition dynamics and ion transport in lithium-ion battery electrodes.
Nature, Published online: 29 July 2026; doi:10.1038/s41586-026-10848-2 A simple organic catalyst enables direct alternating copolymerization of CO2 with bicycloalkanes to produce high-performance polyesters that can be selectively depolymerized and recycled in a closed-loop lifecycle.
Nature, Published online: 29 July 2026; doi:10.1038/s41586-026-10791-2 In senescent cells, mitochondria-derived acetyl-CoA promotes histone acetylation and increases chromatin accessibility at inflammatory gene loci. Inhibition of SLC25A1 attenuates these effects, underscoring the therapeutic potential of targeting mitochondrial metabolism and its…
Nature, Published online: 29 July 2026; doi:10.1038/s41586-026-10852-6 Systematic analysis of prokaryotic STAND NTPases — relatives of animal and plant immune receptors — uncovers diverse antiviral sensors that detect most of the core structural and replicative proteins of bacteriophages.
Nature, Published online: 29 July 2026; doi:10.1038/s41586-026-10845-5 The piezochiral effect, a new member of the family of strain-responsive functionalities alongside piezoelectricity and piezomagnetism, is introduced, enabling control of chirality through mechanical strain, with future applications in photonics, spintronics, biosensing and quantum…
Nature, Published online: 29 July 2026; doi:10.1038/d41586-026-02359-x New discoveries at famous archeological site add to mystery of ancient human culture.
Nature, Published online: 29 July 2026; doi:10.1038/d41586-026-02179-z The field seems to be on the cusp of big advances, but a concerted effort is needed to realize its true potential.
Nature, Published online: 29 July 2026; doi:10.1038/d41586-026-02367-x Discovery of almost 400 structures may help to redefine the true scale of the Aquiry civilization — plus, tiny fossils of the earliest fossil squid ancestor.
Nature, Published online: 29 July 2026; doi:10.1038/s41586-026-10945-2 Author Correction: A ductile solid electrolyte interphase for solid-state batteries
Threat actors are increasingly abusing legitimate remote access tools (RATs) such as ConnectWise, GoTo, Datto RMM, and SimpleHelp in multi-stage phishing campaigns, using one trusted tool to silently download additional payloads, establish persistence, and sell access to compromised networks. Cofense Intelligence observed a sharp increase in these attacks…
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données et un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans Citrix XenServer. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans Xen. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.
Cl0p ransomware has been inside PTC Windchill and FlexPLM systems since June, stealing engineering IP from manufacturing, automotive, aerospace, and retail via CVE-2026-12569 (CVSS 9.8).