Tag: attack
-
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/
-
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Attackers used Hermes, an autonomous open source tool, in unrestricted YOLO mode to conduct espionage against Thailand’s Ministry of Finance. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ai-agent-espionage-attack-thai-ministry-finance
-
New Dysphoria DDoS botnet spreads to 200k devices worldwide
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/
-
Malware Attack Forces AnMed to Close Care Facilities
Nonprofit Health System in SC and Georgia Says Email, Phones and Portal Are Down. AnMed, a nonprofit healthcare system that serves upstate South Carolina and Northeast Georgia, has temporarily closed dozens of its medical offices and other care facilities as the organization responds to a weekend ransomware attack. Email, phones and patient portals are among…
-
Bahrain cannot claim sovereign immunity for spyware attack against UK dissidents, top UK court rules
The UK’s Supreme Court rules that Bahrain cannot claim sovereign immunity for infecting the computers of two UK-based dissidents with German-made FinFisher spyware. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646130/Bahrain-cannot-claim-sovereign-immunity-for-spyware-attack-against-UK-dissidents-top-UK-court-rules
-
Clop Tied to PTC Product Lifecycle Management Software Hits
Signs Point to Cl0p Extortion Group Again Stealing Data and Holding It to Ransom. Digital extortion group Clop, aka Cl0p, has been tied to a fresh spate of supply-chain attacks, this time targeting users of popular Windchill and FlexPLM product lifecycle management software from PTC. Victims appear to at least span the aerospace, automotive, manufacturing…
-
Coca-Cola restores most production capacity at dairy unit after ransomware attack
The company said it does not expect the Fairlife disruption to have a material impact on financial performance or operations.; First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/coca-cola-restores-most-production-capacity-at-dairy-unit-after-ransomware/826250/
-
27th July Threat Intelligence Report
Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/27th-july-threat-intelligence-report/
-
Coca-Cola confirms data theft in Fairlife ransomware attack
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/
-
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
Public exploit details released on July 27 show how an unauthenticated request can reach PHP’s eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user.SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not…
-
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
In a letter first reported by CyberScoop, Ron Wyden, D-Ore., said ‘devastating’ attacks on the federal government have accumulated due to the tech. First seen on cyberscoop.com Jump to article: cyberscoop.com/wyden-calls-for-federal-legacy-vpn-purge-zero-trust/
-
ChatGPT joins the most impersonated brands in phishing attacks
Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/check-point-brand-phishing-trends-report/
-
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies as soon as they are released. This change comes in response to a rise in supply chain attacks where attackers publish trojanized package versions to public registries, relying on automated update…
-
Crypto Criminals Use Social Media Profiling to Select Victims for Violent Wrench Attacks
Crypto criminals are increasingly weaponizing social media intelligence to identify and target high-value individuals in a surge of violent “wrench attacks,” marking a shift from purely digital exploitation to coordinated physical coercion campaigns. Recent threat intelligence indicates that attackers are systematically profiling cryptocurrency holders using publicly available data across platforms such as Instagram, TikTok, X,…
-
Ransomware Groups Increasingly Deploy EDR Kill Techniques
Halcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight against First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-q2-2026-edr-kill/
-
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East.The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. The cybersecurity firm said it detected the campaign earlier this month.…
-
LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations
A new report links 148 ransomware attacks to Italian organizations in H1 2026, with manufacturing the most targeted sector. Six months, 148 confirmed ransomware claims against Italian targets, and one sector taking the brunt of it. That’s the headline number from a new semi-annual tracker compiled by ransomNews under its RedACT project, which pulls together…
-
How the Gentlemen Ransomware Group Built a Multi-Region Attack Machine in H1 2026
Ransomware’s biggest story in the first half of 2026 was not only about established names maintaining dominance. A newer player, The Gentlemen ransomware group, emerged as one of the most geographically active operators, expanding its reach across Europe, Asia-Pacific, the Middle East & Africa, and the Americas. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/the-gentlemen-ransomware-group/
-
What the identity attack surface looks like when trust becomes the target
In this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/identity-attack-surface-video/
-
PyPI Blocks New File Uploads to Old Releases to Prevent Package Poisoning Attacks
PyPI has introduced a new supply-chain security control that prevents publishers from uploading additional files to package releases older than 14 days, reducing the risk of attackers poisoning previously trusted versions after compromising project credentials, automation workflows, or publishing tokens. The Python Package Index (PyPI) has begun rejecting new distribution files uploaded to releases that…
-
What Attack Surface Management Actually Controls
First seen on scworld.com Jump to article: www.scworld.com/tech-explainer/what-attack-surface-management-actually-controls
-
GitHub, PyPI add time-based defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/
-
Weekly Cybersecurity Newsletter Top 50 Biggest Cybersecurity Stories SonicWall Zero-Day, Cl0p Windchill Attack, AI-Weaponized Threats, Data Breaches More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from July 2024, 2026. It was a heavy week: Cl0p turned internet-exposed Windchill servers into a global data-theft campaign, attackers rode SonicWall SMA zero-days to root, a Bluetooth flaw put 2 million cars at […]…
-
GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/
-
Why Attack Surface Reporting Should Change for Executives
Tags: attackFirst seen on scworld.com Jump to article: www.scworld.com/tech-explainer/what-attack-surface-reporting-should-change-for-executives
-
US warns of Iran-linked attacks on critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/news/us-warns-of-iran-linked-attacks-on-critical-infrastructure
-
How to Evaluate Attack Surface Reduction and Remediation Workflows
Tags: attackFirst seen on scworld.com Jump to article: www.scworld.com/buyers-guide/how-to-evaluate-attack-surface-reduction-and-remediation-workflows
-
UK issues alert over Russian zero-click email attacks
First seen on scworld.com Jump to article: www.scworld.com/brief/uk-issues-alert-over-russian-zero-click-email-attacks
-
How to Build an Attack Surface Management Operating Model
Tags: attackFirst seen on scworld.com Jump to article: www.scworld.com/implementation-guides/how-to-build-an-attack-surface-management-operating-model
-
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers/

