Tag: cyber
-
US Space Cybersecurity: ‘No One Is in Charge’
Cyber Defense Falters Without Cabinet Agency or White House Champion for Security. No single senior official is in charge of U.S. efforts to help secure commercial satellites and their land-based infrastructure. That leadership void has hampered the ability to impose security standards on space vendors providing critical services to the U.S. government over the past…
-
Microsoft unveils MAI1-Flash, promises cybersecurity AI at half the cost
Microsoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/microsoft-mai-cyber-1-flash-ai-model/
-
Bank of Baroda Breach Tests Disclosure Readiness
Email Compromise Exposes Sensitive Data, Raising DPDP Act Compliance Questions. A Bank of Baroda employee email compromise exposed customer and internal data allegedly leaked by the Triple X ransomware group. The incident shows how India’s new DPDP Act breach notification rules test banks’ readiness to disclose cyber incidents quickly and transparently. First seen on govinfosecurity.com…
-
Nvidia pushes ahead with security alliance for AI openness
Nvidia and several businesses have formed a cross-industry alliance to promote open, secure AI to improve cyber defences First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646293/Nvidia-pushes-ahead-with-security-alliance-for-AI-openness
-
Security Risk Advisors Named a Finalist in CRN’s 2026 Best of the Channel Awards
Philadelphia, Pennsylvania, July 27th, 2026, CyberNewswire Security Risk Advisors is proud to share that CRN, a brand of The Channel Company, has recognized Joe Cicero as a finalist in the second annual CRN Best of the Channel Awards in the Best Channel Visionary of the Year category. As a finalist, Joe is being spotlighted for…
-
Tech giants form alliance to put open AI in cyber defenders’ hands
NVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/nvidia-open-secure-ai-alliance/
-
NVIDIA, Microsoft, and CrowdStrike Launch Alliance for Open-Source AI Security
Tags: ai, crowdstrike, cyber, cybersecurity, linux, microsoft, nvidia, open-source, technology, toolNVIDIA, Microsoft, and CrowdStrike have joined a broad coalition of technology, cybersecurity, and open-source organizations to launch the Open Secure AI Alliance. This initiative focuses on developing open tools, models, agent harnesses, and security techniques to defend AI-enabled infrastructure. The alliance builds on the groundwork laid by the Linux Foundation’s Akrites initiative and the Open…
-
Google changes how it names cyber threat actors
Google Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/google-threat-actors-naming-system/
-
Anyone With a Browser Could Access 700,000 Vatican Prayer App Accounts
A critical access control vulnerability in the Vatican’s official “Click to Pray” platform has exposed the personal data of more than 700,000 users, highlighting once again how basic web security misconfigurations continue to put large-scale user bases at risk. The service, operated by the Pope’s Worldwide Prayer Network, is widely used across the globe to…
-
Hackers used autonomous AI agent to spy on Thailand’s finance ministry
Hackers used an autonomous artificial intelligence agent to carry out a cyber-espionage campaign against Thailand’s Ministry of Finance, researchers discovered. First seen on therecord.media Jump to article: therecord.media/thailand-hackers-ai-finance-ministry
-
Claude Opus 5 Finds Software Vulnerabilities While Blocking Exploit Generation
Claude Opus 5, the latest flagship AI model from Anthropic, represents a significant shift in how advanced systems can be safely utilized in cybersecurity. This model can proactively identify software vulnerabilities while specifically preventing the generation of exploits and offensive usage. Announced on July 24, 2026, Opus 5 is positioned as a high-end, general-purpose intelligence…
-
Europol Launches Project COMPASS to Disrupt ‘The Com’ Cybercrime Network Targeting Minors
Europol has launched Project COMPASS, a coordinated transnational initiative aimed at disrupting >>The Com,<< a highly dangerous cybercrime and nihilistic extremist network that systematically targets minors and vulnerable young people across digital platforms. The Com operates as a sprawling transnational virtual network (TVN), utilizing social media, messaging apps, music platforms, and online games to recruit,…
-
vBulletin Pre-Auth RCE Flaw Allows Remote PHP Code Execution
A critical pre-authentication remote code execution vulnerability in vBulletin, tracked as CVE-2026-61511, could allow unauthenticated attackers to execute arbitrary PHP code on vulnerable forum servers. This issue affects vBulletin versions 6.2.1 and earlier, as well as 6.1.6 and earlier, according to a July 27, 2026, disclosure from SSD Secure Disclosure. If exploited successfully, this vulnerability…
-
Over 70 Fake Windows App Sites Could Turn Trusted Downloads Into Malware
A newly uncovered cluster of more than 70 impersonation domains targeting popular Windows applications is raising fresh concerns about a scalable malware distribution campaign that leverages trust in legitimate software ecosystems. The discovery, triggered by a developer investigating unusual search results for their own application, reveals a coordinated infrastructure designed to mimic well-known tools while…
-
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies as soon as they are released. This change comes in response to a rise in supply chain attacks where attackers publish trojanized package versions to public registries, relying on automated update…
-
Crypto Criminals Use Social Media Profiling to Select Victims for Violent Wrench Attacks
Crypto criminals are increasingly weaponizing social media intelligence to identify and target high-value individuals in a surge of violent “wrench attacks,” marking a shift from purely digital exploitation to coordinated physical coercion campaigns. Recent threat intelligence indicates that attackers are systematically profiling cryptocurrency holders using publicly available data across platforms such as Instagram, TikTok, X,…
-
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East.The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. The cybersecurity firm said it detected the campaign earlier this month.…
-
Microsoft Introduces KMS Hardware-Secured for Windows Server Activation
Microsoft has introduced KMS Hardware-Secured, an upcoming enhancement to Windows Server activation that utilizes Trusted Platform Module (TPM)-based attestation to validate Key Management Service (KMS) hosts before they can activate Windows devices. Announced in a July 2022 Windows IT Pro Blog post, this initiative addresses risks related to spoofed, cloned, or otherwise untrusted KMS infrastructure.…
-
Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure
Tags: advisory, automation, cisa, cyber, cybersecurity, exploit, hacker, infrastructure, Internet, iran, technology, threatIranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected programmable logic controllers (PLCs) from major industrial vendors, including Rockwell Automation, Schneider Electric, and Siemens, targeting U.S. critical infrastructure sectors. A joint cybersecurity advisory (AA26-097A) released by the FBI, CISA, NSA, DOE, EPA, Treasury, and U.S. Cyber Command highlights sustained exploitation activity against operational technology…
-
Windows WalletService Flaw Lets Standard Users Gain SYSTEM Privileges
Microsoft Windows WalletService is affected by a local privilege escalation vulnerability tracked as CVE-2026-49176. This flaw could allow a standard authenticated user to obtain SYSTEM-level privileges. The vulnerability arises from WalletService’s handling of user-controlled file paths during initialization. An attacker can exploit this by redirecting the service to a maliciously crafted Extensible Storage Engine (ESE)…
-
New usbliter8 SecureROM Exploit Enables iOS 27 Jailbreak on iPhone 11 Pro
A new developer-focused project, usbliter8-fun, showcases an iOS 27 jailbreak workflow specifically for the iPhone 11 Pro. It combines the usbliter8 SecureROM exploit with a custom firmware restoration process. This proof of concept targets Apple’s A13-based iPhone 11 Pro. It is labeled as experimental, destructive, and unsuitable for use on primary devices. New usbliter8 SecureROM…
-
AWS Launches Claude Opus 5 With Advanced Agentic Coding and Cybersecurity Capabilities
AWS has launched Anthropic’s Claude Opus 5 on Amazon Bedrock and the Claude Platform, introducing a groundbreaking model designed for agentic coding, complex enterprise workflows, visual understanding, and long-running autonomous tasks. Released on July 24, 2026, Claude Opus 5 is Anthropic’s first fifth-generation Opus model. According to AWS, it offers significant improvements in production-grade reasoning,…
-
Apple Biome Data Reveals Safari Activity, Wallet Transactions and Location Visits
Apple’s internal Biome framework is rapidly emerging as one of the most valuable sources of forensic intelligence on iOS, with newly analyzed data revealing detailed records of Safari browsing activity, Wallet transactions. Originally misunderstood due to its name, Biome is not مرتبط with biometrics but instead powers Apple’s predictive intelligence ecosystem, including Siri suggestions, personalization,…
-
Claude Code Symlink Flaw Exfiltrates Sensitive Files Without User Approval
Claude Code has a flaw in its startup memory loader related to handling symbolic links (symlinks) that can unintentionally expose readable files from outside a cloned repository, without requiring explicit user approval. The issue arises not from the tool following symlinks, something that is standard behavior in filesystems, but from a mismatch in how its…
-
SparkKitty Monitors Mobile Photo Galleries and Exfiltrates Sensitive Images to C2 Servers
SparkKitty is a cross”‘platform mobile stealer that weaponizes users’ photo galleries, using OCR to extract sensitive text from images and silently exfiltrating it to attacker”‘controlled C2 servers on both Android and iOS. Built as an apparent successor to SparkCat, the malware is tuned to hunt cryptocurrency wallet seed phrases, but its indiscriminate photo theft dramatically…
-
PyPI Blocks New File Uploads to Old Releases to Prevent Package Poisoning Attacks
PyPI has introduced a new supply-chain security control that prevents publishers from uploading additional files to package releases older than 14 days, reducing the risk of attackers poisoning previously trusted versions after compromising project credentials, automation workflows, or publishing tokens. The Python Package Index (PyPI) has begun rejecting new distribution files uploaded to releases that…
-
BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials
BlueNoroff, a financially motivated threat cluster linked to the Lazarus Group, has been observed deploying a highly sophisticated “fake meeting” phishing kit. That goes far beyond traditional lures, enabling webcam capture, Microsoft Defender evasion, and targeted cryptocurrency credential theft. New research from JUMPSEC provides rare source-level visibility into the operation after attackers mistakenly exposed JavaScript…
-
Google Indexed Claude AI Shared Chats Exposing Sensitive User Conversations
Anthropic’s Claude includes a share feature that creates a publicly accessible URL for conversations, allowing users to share AI chats with colleagues, clients, or friends. However, this convenience also brings exposure risks when shared URLs are posted in public forums, on social media platforms, web pages, or other crawlable locations. Claude AI Shared Chats Exposed…
-
GitLab RCE Flaws Allow Attackers to Execute Commands via Malicious Jupyter Notebooks
A critical remote code execution (RCE) vulnerability chain in GitLab’s Jupyter Notebook diff renderer. This issue is rooted in two long-standing memory safety vulnerabilities within the Oj Ruby JSON parser. The vulnerabilities impact both GitLab Community Edition and Enterprise Edition releases from version 15.2.0 through 19.0.1. They allow an authenticated project member to execute commands…
-
Claude Opus 5 sharpens coding and cybersecurity work on AWS
Claude Opus 5 went live on Amazon Bedrock and Claude Platform on AWS. Anthropic says the model improves on Claude Opus 4.8’s cyber capabilities, coding through … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/claude-opus-5-aws-coding-cybersecurity-work/

