Tag: cyber
-
GhostApproval Attack Impacts Amazon Q, Claude Code, Cursor, Google Antigravity, and Windsurf
A newly disclosed vulnerability pattern known as >>GhostApproval<< is exposing significant flaws in the trust boundary of leading AI coding assistants, including Amazon Q Developer, Anthropic Claude Code, Cursor, Google Antigravity, Augment, and Windsurf. This issue demonstrates how attackers can exploit symbolic links (symlinks) to bypass workspace isolation and manipulate Human-in-the-Loop safeguards, potentially resulting in…
-
Foxit Patches Multiple UseFree Flaws Leading to Remote Code Execution
Foxit has released critical security updates to address multiple use-after-free vulnerabilities that could lead to remote code execution (RCE) in its widely used PDF Reader and PDF Editor products. The vulnerabilities, disclosed in Foxit’s July 8, 2026 security bulletin, affect Windows versions of Foxit PDF Reader and Foxit PDF Editor across multiple release branches, highlighting…
-
GitLab Patches 8 Vulnerabilities Affecting CE and EE Installations
GitLab has released critical security updates to address eight vulnerabilities in its Community Edition (CE) and Enterprise Edition (EE). Administrators are urged to upgrade immediately to versions 19.1.2, 19.0.4, or 18.11.7. The patch rollout on July 8, 2026, includes fixes for high-, medium-, and low-severity flaws affecting core functionalities such as wiki rendering, repository mirroring,…
-
Google Chrome Update Patches 27 Security Vulnerabilities Including Critical UseFree Flaws
Google has released a critical security update for Chrome, upgrading the Stable channel to version 150.0.7871.114/.115 on Windows and macOS, and to version 150.0.7871.114 on Linux. This update addresses 27 vulnerabilities, including several critical use-after-free flaws that could potentially enable remote code execution. The update will roll out gradually over the coming days and weeks,…
-
HalluSquatting Attack Lets Hackers Turn AI Coding Assistants Into Botnet Installers
A newly disclosed attack technique called “HalluSquatting” is raising serious concerns in the AI security landscape. This technique demonstrates how attackers can exploit large language model (LLM) hallucinations to covertly compromise systems and potentially create botnets on a large scale. The research introduces “adversarial hallucination squatting,” a novel method that exploits AI models that generate…
-
GitHub Copilot IDE Coding Agents Vulnerable to Workflow-Level Jailbreak Attacks
GitHub Copilot’s new coding agents, which are integrated into IDEs, are susceptible to a specific type of >>workflow-level<< jailbreak attacks. These attacks can bypass chat refusals, allowing agents to generate harmful code while performing standard software development tasks unwittingly. According to Arxiv, researchers who studied Copilot in Visual Studio Code discovered that models that successfully…
-
New AI Security Charter Backed by Over 70 Cyber Firms
Over 70 cybersecurity organizations have signed the CREST AI Charter detailing responsible use of AI for security First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/crest-ai-security-charter-cyber/
-
npm and PyPI Malware Campaign Exfiltrates CI/CD Secrets Through Fake Payment SDKs
A coordinated supply-chain campaign that pushed 17 malicious packages across npm and PyPI, masquerading as SDKs for well-known payment services including PaySafe, Skrill and Neteller. The campaign’s packages 17 npm modules published with four rapid versions each and four PyPI packages access with single malicious releases presented as convenient payment SDK facades but contained logic…
-
Cybercriminals Plant Malicious AI Agents in Open Source Tool Repositories
Cybersecurity researchers at ESET identify big rise in suspicious and malicious toolsets which put users at risk from cyber-attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cybercriminals-plant-ai-agents/
-
G DATA-Studie: Notfallpläne sind vorhanden, doch vielen Unternehmen fehlt die Übung für den Cyber-Ernstfall
Im Cyber-Ernstfall zählt nicht, ob ein Dokument existiert. Entscheidend ist, ob alle Beteiligten wissen, was zu tun ist und ob Technik, Prozesse und Partner schnell genug zusammenspielen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/g-data-studie-notfallplaene-sind-vorhanden-doch-vielen-unternehmen-fehlt-die-uebung-fuer-den-cyber-ernstfall/a45710/
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
SNOW Malware Ecosystem Uses Teams Phishing, WebSocket Tunnels, and Browser Extensions
Threat actors are increasingly chaining classic phishing with collaboration platforms and covert tunneling to create highly believable intrusion paths. A recent multi-stage campaign attributed to UNC6692 exposes how adversaries combine email bombardment, Microsoft Teams impersonation, malicious browser extensions, WebSocket tunnels, and Python backdoors into a single, resilient ecosystem known as SNOW. The campaign began with…
-
UK’s largest businesses dangerously exposed to cloud outages
British businesses, particularly those in the FTSE 100, are dangerously dependent on large cloud providers, with hypothetical large-scale outages at AWS or Azure regions likely to cause major economic damage, according to the Cyber Monitoring Centre First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645540/UKs-largest-businesses-dangerously-exposed-to-cloud-outages
-
Everest Ransomware Encryptor Uses ConfuserEx-Protected .NET Binary With Wake-on-LAN Capability
A recent technical analysis of an Everest ransomware encryptor reveals a purpose-built, ConfuserEx-protected .NET 4.0 binary that combines heavy obfuscation, misleading cryptographic declarations, and uncommon network tactics to maximize impact and impede response. The analyzed sample (hlntqyun.exe, SHA-256 1df92b…) is a 114 KB C# assembly compiled for .NET Framework 4.0 and protected with ConfuserEx anti-tamper,…
-
New Helix Extortion Group Targets Enterprises With MFA Abuse and SharePoint Exfiltration
A previously unreported data extortion operation dubbed “Helix” that targets enterprises using identity-focused entry techniques and automated SharePoint exfiltration. The group’s playbook combines voice phishing (vishing), device-code phishing to capture session tokens and bypass Conditional Access controls, rapid MFA registration for persistence, and scripted enumeration and bulk download of SharePoint content all staged from shared…
-
New Helix Extortion Group Targets Enterprises With MFA Abuse and SharePoint Exfiltration
A previously unreported data extortion operation dubbed “Helix” that targets enterprises using identity-focused entry techniques and automated SharePoint exfiltration. The group’s playbook combines voice phishing (vishing), device-code phishing to capture session tokens and bypass Conditional Access controls, rapid MFA registration for persistence, and scripted enumeration and bulk download of SharePoint content all staged from shared…
-
Claude AI Prompt Injection Attack Turns Chatbot Into Stealthy C2 Agent to Achieve Remote Code Execution
Claude Desktop’s synced Personal Preferences feature can be exploited as a covert prompt-injection vector, transforming the AI assistant into a de facto command-and-control (C2) agent. This method allows for remote code execution on a compromised user workstation without the need for phishing emails or traditional malware delivery. In this attack chain, the initial access is…
-
DuckDuckGo Browser Blocks YouTube Ads Using uBlock Origin Filter Lists
DuckDuckGo has quietly expanded its privacy-first browser capabilities by introducing a YouTube ad-blocking feature. This feature uses community-driven uBlock Origin filter lists to detect and remove video ads. From a security and privacy standpoint, this approach is significant because it relies on open-source filtering rules maintained by an active community, rather than proprietary, closed heuristics.…
-
Mexico’s New Cyber Plan Faces Its First Real Test
The Latin American nation’s cybersecurity plan, still in the expansion phase, has to survive its own knockout round during the FIFA World Cup. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/mexicos-cyber-plan-first-real-test
-
French nonprofit starts global intelligence and research hub for AI cyber threats
One of the project’s top goals is stitching together an international, quick response coalition of governments, businesses and civil experts for AI-related threats. First seen on cyberscoop.com Jump to article: cyberscoop.com/paris-peace-forum-intaic-ai-cyber-threats/
-
OpenMatter Network Joins HOL Initiative to Help Define Standards for Verifiable AI Collaboration and Security
Melbourne, Florida, United States, July 8th, 2026, CyberNewswire OpenMatter Network today announced that it has joined the founding group of organizations participating in the Hashgraph Online (HOL) Partner Program, where the company will help develop standards, policies and verification frameworks for secure autonomous AI systems and agentic computing environments. As organizations increasingly deploy AI agents…
-
US enterprises incorporate cyber risk into larger strategic focus
The rapid adoption of AI and cloud is forcing significant shifts toward business resilience and financial impact. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/us-enterprises-cyber-risk-strategic-focus/824707/
-
Best Next-Generation Firewall (NGFW) Solutions Compared (2026): Features Pricing
Twelve firewalls, one question: which NGFW earns a place at your network edge in 2026? For mostenterprisesthe shortlist starts with Fortinet FortiGate (best price-performance) and Palo Alto Networks (deepest application control), but the right answer shifts with your size, region, and cloud strategy, and one of the twelve vendors hereisn’tan appliance at all. A […]…
-
Claude Cowork Expands to Web and Mobile With Background AI Agent Workflows
Claude Cowork was expanded beyond the desktop, rolling out web and mobile versions that let AI-driven task sessions persist across devices and continue running in the background without an active connection. The beta rollout begins with Max-tier subscribers over the coming weeks, with additional plan tiers to follow. Cowork operates as an agentic workspace where…
-
EU unveils cyber plan to reduce reliance on foreign AI systems
The communication, adopted in Strasbourg on July 7, is built around three pillars: making frontier AI “safe, accessible and deployable” for European cybersecurity, preparing the EU’s cyber ecosystem and scaling European AI capabilities. First seen on therecord.media Jump to article: therecord.media/eu-unveils-cyber-plan-to-reduce-reliance-on-foreign-ai
-
Attackers Can Generate Duplicate Verified GitHub Commits Using Signature Malleability
Attackers can silently clone “Verified” GitHub commits by abusing signature malleability in Git’s commit-signing formats, creating byte”‘different commits with identical content, valid signatures, and fresh “Verified” badges under new hashes. This breaks the long”‘standing assumption that a verified commit hash is a unique, immutable identifier for a specific piece of signed content and exposes hash”‘based…
-
IonStack Exploit Chain Lets Hackers Root Android 17 Phones With a Single URL Click
Nebula Security has revealed a significant exploit chain known as “IonStack,” demonstrating how attackers could gain full root access on Android 17 devices with just a single click on a malicious URL. This raises serious concerns about browser-to-kernel attack surfaces in today’s mobile ecosystems. The disclosure highlights a complex, multi-stage exploitation technique that combines two…
-
Fancy Bear Uses LSB Steganography and Reflective Loading to Run C# Remote-Control Trojan
A new intrusion campaign attributed to APT”‘C”‘20 (aka Fancy Bear, APT28) demonstrates the group’s continued refinement of stealthy, fileless techniques: weaponized Office documents that deploy a COM”‘hijacking DLL. Extract shellcode hidden via LSB steganography in a PNG, and use reflective loading to run an obfuscated C# remote”‘control Trojan that communicates through the legitimate cloud storage…

