Tag: cyber
-
Linux Kernel Team Publishes 440 CVE Security Advisories Within 24 Hours
The Linux kernel security team published approximately 440,440 CVE advisories over 24 hours, reflecting a significant release of vulnerability records linked to fixes already incorporated into the upstream kernel tree. These notices were distributed through the linux-cve-announce mailing list between July 19 and July 20, 2026, and cover a wide range of kernel subsystems, including…
-
AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware
AgentBaiting is the clearest sign yet that AI agents and their capability ecosystems have become a first”‘class malware delivery surface, with FakeGit’s 7,600″‘repo operation pushing SmartLoader and StealC directly into AI Skills and MCP workflows. By turning agent”‘readable READMEs, public AI registries, and GitHub trust signals into a weaponized “AI capability supply chain,” attackers now…
-
Critical Gitea Flaw Lets Public-Only Tokens Write to Private Repositories and Trigger Actions Workflows
Gitea administrators are strongly encouraged to upgrade their systems following the discovery of a critical authorization vulnerability. This flaw allows public-only API tokens to modify private pull request branches and potentially trigger Gitea Actions workflows. The vulnerability, tracked as CVE-2026-58443 and GHSA-xxjv-752h-3vp2, affects Gitea versions up to and including 1.26.4. The issue has been resolved…
-
Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical pre-authentication remote code execution vulnerability, tracked as CVE-2026-6875, in the ServiceNow AI Platform on July 14. The same day, ServiceNow released patches for self-hosted instances. Since July 17, attackers have started exploiting it in…
-
Fileless Stealer and PureRAT Raid Browser Passwords, Telegram Sessions, and Crypto Wallets
Fileless stealer and PureRAT operators are abusing a WebDAV”‘backed “malware delivery lab” to raid browser passwords, Telegram sessions, and cryptocurrency wallets in a campaign that blends fileless info”‘stealing with a modular .NET RAT. The incident began with an MDR alert tied to a user executing content retrieved from a WebDAV server via rundll32.exe, with telemetry…
-
European Password Manager Passwork Shares Codebase and Updates With FSTEC-Certified Russian Firm
Passwork Europe, a Spain-based password manager used by European public sector bodies, universities, and private organizations, is facing scrutiny after an investigation led by OCCRP uncovered technical and historical connections to a Russian counterpart certified by Russian state agencies. The investigation found that Passwork Europe S.L. and Russia’s Passwork LLC share a common codebase origin,…
-
Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids
Bit2Watt is a newly disclosed cyber”‘physical attack class that weaponizes AI and GPU workloads in modern data centers to destabilize nearby power grids, turning compute infrastructure itself into a grid”‘scale threat surface. Measurements on NVIDIA accelerators show sub”‘millisecond power ramps where a single Volta V100 or RTX”‘series GPU swings from low-load phases to near”‘TDP draw,…
-
Paidwork Data Breach Exposes 23.3 Million Accounts, Banking Data and bcrypt Password Hashes
Gig-economy platform Paidwork has been linked to a significant data breach that affects 23.3 million accounts. This breach, involving an approximately 11GB dataset, was publicly released in July 2026. The incident was added to the Have I Been Pwned (HIBP) breach database on July 19, with the compromise reportedly occurring in March 2026. Paidwork Data…
-
HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert CommandControl Channels
HOLLOWGRAPH, a Windows malware implant that transforms Microsoft 365 calendar events into a covert command-and-control channel. This malware, which is highly likely linked to the Cavern modular backdoor framework, utilizes the Microsoft Graph API to retrieve tasks from operators and to exfiltrate stolen data via a compromised Microsoft 365 mailbox. This technique enables malicious communications…
-
Hackers Hide C2 Traffic Inside Telegram While Targeting Middle East Governments
Hackers are increasingly blending malicious traffic with legitimate services, and a newly uncovered campaign shows how far this tactic has evolved. The activity has been attributed to a threat actor with links to East Asia, with researchers uncovering a previously undocumented malware suite comprising TELESHIM, MIXEDKEY, and a final-stage implant dubbed BINDCLOAK. The campaign demonstrates…
-
Hackers Hide C2 Traffic Inside Telegram While Targeting Middle East Governments
Hackers are increasingly blending malicious traffic with legitimate services, and a newly uncovered campaign shows how far this tactic has evolved. The activity has been attributed to a threat actor with links to East Asia, with researchers uncovering a previously undocumented malware suite comprising TELESHIM, MIXEDKEY, and a final-stage implant dubbed BINDCLOAK. The campaign demonstrates…
-
Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware
Tags: access, attack, authentication, corporate, cve, cyber, encryption, exploit, flaw, hacker, network, ransomware, vpn, vulnerabilityHackers are exploiting a high-severity vulnerability in Palo Alto Networks’ PAN-OS to gain initial access to corporate networks and deploy Qilin ransomware. Multiple intrusions investigated in June 2026 began with the exploitation of CVE-2026-0257, an authentication bypass flaw affecting GlobalProtect portal and gateway deployments. The attacks evolved from external VPN compromises to domain-wide encryption, with…
-
The 12 Best Identity Threat Detection Response (ITDR) Solutions, Compared and Priced (2026)
Identity is where breaches start, and ITDR pricing is where budgets get confused platform modules, IdP SKUs, E5 bundles, and managed services all claim the same acronym. The value verdict up front: Huntress is the best published-price ITDR for SMBs and MSPs, Microsoft Defender for Identity is effectively the bundled default inside E5 estates, Sophos…
-
Banks and Telecoms Are Struggling to Share Scam Data
Canadian Cyber Exchange’s Jennifer Quaid on Privacy Hurdles, Real-Time Fraud Intel. Banks, telecoms and tech platforms all want to share scam data faster, but privacy rules and regulatory limits are standing in the way, said Jennifer Quaid at the Canadian Cyber Threat Exchange. AI-driven fraud could make matters even worse in the next 12 to…
-
Why blocking AI models won’t stop the cyber threats they create
AI companies can find vulnerabilities and write patches. But only the government can build the long-term defense strategy America needs. First seen on cyberscoop.com Jump to article: cyberscoop.com/why-blocking-ai-models-wont-stop-cyber-threats-op-ed/
-
What Does the Cyber Industry Want to See From the New UK Government?
Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed ‘Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including plans for a dedicated AI Minister, the scrapping of the hotly debated digital ID programme,…
-
New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience
Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve.…
-
GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE
Tags: authentication, cyber, exploit, flaw, injection, rce, remote-code-execution, sql, vulnerability, wordpressA critical vulnerability chain in WordPress, called wp2shell, that allegedly allows unauthenticated attackers to exploit a pre-authentication SQL injection flaw to achieve remote code execution (RCE) on typical WordPress installations running MySQL. Security researcher Adam Kues discovered this vulnerability chain using GPT-5.6 Sol Ultra during a multi-agent audit of the WordPress source code. GPT-5.6 Sol…
-
Eco-Verband warnt vor Angriff auf digitale Freiheitsrechte
Mit einem neuen Eckpunktepapier zur aktuellen Cybersicherheits-Politik warnt der Eco-Verband der Internetwirtschaft e. V. vor einer zunehmenden Verschärfung sicherheitspolitischer Eingriffe in den digitalen Raum. Aus Sicht des Verbands werden die Regeln für Cybersicherheit derzeit nicht nur dichter, sondern auch eingriffsintensiver. NIS2, KRITIS Dachgesetz, Cyber-Re20260706_eco_inf_cyberregulierungsilience-Act, die Revision des Cybersecurity-Act, das Gesetz zur Stärkung der Cybersicherheit, neue…
-
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier
Microsoft will stop delivering feature updates, bug fixes, and security patches for the OneDrive sync app on systems running Windows version 21H2 and earlier on August 15, 2026. This change was announced in the Microsoft 365 Message Center notification MC1426708 and leaves organizations with older Windows endpoints exposed to an increasingly unsupported file synchronization client,…
-
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor
Tags: advisory, backdoor, cisa, cyber, data-breach, exploit, malicious, microsoft, remote-code-execution, update, vulnerabilityA newly disclosed cluster of Microsoft SharePoint Server vulnerabilities is actively being exploited in the wild, allowing attackers to convert a single crafted web request into full remote code execution and long-term persistence across enterprise environments. Security updates released in July 2026, alongside a CISA advisory, confirm that multiple vulnerabilities are already being weaponized against…
-
LG Monitors Silently Install McAfee Adware on Windows PCs With Full System Access
Concerns have arisen regarding LG monitors that reportedly trigger the silent installation of an LG companion application on Windows PCs. This installation is followed by promotional prompts for a McAfee security trial, raising issues related to device-software delivery mechanisms, user consent, and the permissions granted to automatically installed applications. Gamers Nexus, a YouTube hardware-testing outlet,…
-
Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues
Microsoft has released KB5121767, an out-of-band (OOB) cumulative update for Windows 11 versions 22H2 and 21H2. This update addresses a system performance issue related to the Intel Innovation Platform Framework (Intel IPF) drivers. The update was made available on July 18, 2023, specifically for devices affected by this issue, which arose after installing recent Windows…
-
Weekly Cybersecurity Newsletter The 50 Biggest Cybersecurity Stories Microsoft Patch, AI Attack, Exploits Releases, Data Breaches More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 40 most important stories from July 1317, 2026. What a week: Microsoft shattered records with 570 vulnerabilities patched in a single Patch Tuesday, China-linked hackers weaponized Claude Code and DeepSeek against government networks, GPT-5.6 wrote a complete Chrome […]…
-
GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack
GoldenEyeDog, a Chinese cybercrime group increasingly tracked as an advanced threat cluster, has been linked to a sophisticated intrusion into DigiCert that enabled the theft and abuse of legitimate code-signing certificates. The group has been active since at least 2015 and, since 2024, has consistently leveraged stolen or abused code-signing certificates to bypass Windows SmartScreen…
-
Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover
Kimai users who are running the official Docker image are strongly urged to update their installations after a critical vulnerability, tracked as CVE-2026-52824 and GHSA-jr9p-4h4j-6c58, was discovered. This vulnerability exposes installations to the risk of account takeover due to a publicly known application secret. The flaw affects Kimai versions 2.57.0 and earlier, and it has…
-
U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million
U.S. federal prosecutors have unsealed a sweeping indictment charging three Russian nationals and two St. Petersburgbased companies for operating a global “bulletproof hosting” infrastructure. That enabled widespread cyberattacks against critical sectors, causing losses exceeding $62 million across at least 21 U.S. states and multiple countries. The defendants Alexander Alexandrovich Volosovik, 43, Kirill Andreevich Zatolokin, 34,…
-
PENTDEM AI Pentesting Daemon Uses 34 Security Tools to Automate WAF Bypass and Attack Chains
Tags: ai, attack, bug-bounty, cyber, firewall, LLM, open-source, penetration-testing, tool, vulnerability, wafPENTDEM is an open-source autonomous AI pentesting daemon that integrates 34 security tools with LLM-directed analysis to automate various tasks, including reconnaissance, vulnerability discovery, evidence validation, Web Application Firewall (WAF) fingerprinting, and multi-stage attack-path modeling. This Python-based project is designed for authorized security testing and bug-bounty workflows, offering both an autonomous agent mode and a…

