Tag: cyber
-
New Malicious Campaign Delivers Vidar Infostealer and Monero Crypto Miner
Cyber threat actors are infecting victims with the Vidar stealer and the XMRig cryptocurrency miner in a new malicious campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/new-campaign-vidar-stealer-monero/
-
Exposed Banana RAT Infrastructure Reveals Payload Generator and Obfuscator Tooling
A publicly indexed server at 198[.]245[.]53[.]26, discovered via Shodan, exposed more than simple staging files it revealed an active payload-generation backend and obfuscation tooling tied to two distinct Banana RAT branches. The host served static stages (st.txt, payload.php) and a FastAPI-based builder (servidor_completo_pool.py) plus an ofuscador.py helper. Enabling researchers to compare an older ETW-themed branch…
-
CrowdStrike Uncovers 5 New Prompt Injection Techniques Targeting AI Agents
CrowdStrike has identified five new techniques for prompt injection targeting AI agents, emphasizing the rapid evolution of adversarial methods as enterprises increasingly deploy autonomous AI systems. Detailed in a report published on July 7, 2026, by CrowdStrike’s AI security research team, these techniques expand the company’s prompt injection taxonomy to over 200 documented attack methods.…
-
AI-as-a-Service Botnet Routes Malicious Workloads Across Compromised Windows and Linux Hosts
The underground advertisement for the so-called Mycelium Framework reads like another feature”‘packed botnet sales pitch: cross”‘platform payloads, encrypted C2, persistence, exploit modules, credential theft, and lateral movement. Those building blocks are not new. What makes Mycelium notable is its advertised purpose to treat compromised endpoints not as disposable bots but as a capability”‘aware. AI compute…
-
Discord Confirms Bug That Incorrectly Banned 8,200 Users Since May 2026
Discord has confirmed a significant flaw in its automated moderation and enforcement pipeline that led to the wrongful banning of approximately 8,200 user accounts between May and early July 2026. This raises concerns about the reliability of AI-assisted trust and safety systems. The issue was disclosed via Discord’s official support channel on July 7 and…
-
NCSC Touts National Scale, AI-Powered “Cyber Shield” for Defense
The National Cyber Security Centre wants to work with AI partners to build a new “Cyber Shield” to defend the UK First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-national-cyber-sheild-ai/
-
CISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government Code
CISA is using Anthropic’s Mythos AI to scan federal code for vulnerabilities, aiming to find flaws before hackers and foreign intelligence services. Three sources familiar with the matter told Reuters that CISA, the U.S. government’s civilian cyber defense agency, is running Anthropic’s Mythos AI model against federal code repositories to find vulnerabilities before foreign intelligence…
-
Claude Code, Cursor, and OpenAI Codex Trigger Cyberattack-Like Telemetry Alerts
AI-powered coding assistants such as Claude Code, Cursor, and OpenAI Codex are increasingly triggering endpoint detection and response (EDR) alerts that resemble active cyberattacks, according to new research from Sophos X-Ops. This analysis, based on real-world telemetry collected in June 2026, highlights how autonomous AI behavior, while often benign, closely mirrors adversarial tactics, creating new…
-
CISA Warns of Actively Exploited Adobe ColdFusion Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Adobe ColdFusion, tracked as CVE-2026-48282, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability is actively being exploited in the wild. Disclosed on July 7, 2026, this vulnerability involves a path traversal weakness that could allow attackers to execute arbitrary code…
-
Over 70% of Public WordPress Sites Running Outdated PHP Exposed to Cyberattacks
A new analysis has revealed a significant security gap within the global web ecosystem. Over 70% of publicly accessible WordPress sites are running outdated, end-of-life (EOL) PHP versions, significantly increasing their vulnerability to cyberattacks. These findings highlight a systemic issue in how organizations manage their backend infrastructure, particularly given that WordPress remains the leading content…
-
15-Year-Old GhostLock Linux Kernel Vulnerability Enables Root Access and Container Escape
A critical vulnerability in the Linux kernel, known as “GhostLock” (CVE-2026-43499), has been disclosed by researchers at Nebula Security. This vulnerability, which has existed for 15 years, allows for reliable privilege escalation and container escape across nearly all Linux distributions. The issue dates back to Linux kernel version 2.6.39, released in 2011, and remained undetected…
-
Lurking Lizard Uses Drop-Catch Domains and Lookalike Brands to Distribute Proxyware
Tags: cyberA sophisticated, long-running operation that converts consumer devices into rentable exit nodes for residential proxy services. The initial signal was a fake 7-Zip installer hosted at 7zip[.]com a domain that mimicked the legitimate 7-zip[.]org and benefitted from years of search-engine history due to a common misquote. That apparent one-off lure, however, proved to be the…
-
Plattform ‘Cyber Frame” – Acronis bringt eigene Infrastruktur für MSP
First seen on security-insider.de Jump to article: www.security-insider.de/acronis-bringt-eigene-infrastruktur-fuer-msp-a-ac651c4ba072638dc328fc1d7f28d611/
-
Indian Income Tax Department Phishing Lure Deploys Gh0st RAT and AsyncRAT Implants
A targeted phishing campaign impersonating the Indian Income Tax Department has been observed delivering a sophisticated, six-stage infection chain that culminates in two in-memory remote-access implants: a Gh0st RAT derivative and a Quasar/AsyncRAT-family .NET payload. Victims are funneled to fake government pages that mimic Ministry of Finance and Income Tax branding and are pressured with…
-
LONGLEASH Malware Adds Reverse Shell, Proxying, and Intermediate C2 Capabilities
A significant upgrade to malware maintained by the UAT-7810 actor: LONGLEASH, a successor to the previously reported SHORTLEASH implant, now sporting reverse-shell, multi-protocol proxying, and intermediate command-and-control (C2) forwarding capabilities. LONGLEASH retains SHORTLEASH’s ff-agent codebase but expands its operational scope. The implant, internally named “nz1.0,” splits into Base, Executor, and Core modules. The Base module…
-
China-Aligned UNK_MassTraction Exploits Roundcube Servers to Target Universities
A suspected China-aligned cluster dubbed UNK_MassTraction that is exploiting n-day flaws in Roundcube webmail to compromise physics and engineering departments at U.S. and Canadian universities. The operators use a two-stage browser-to-server infection chain that begins with a Cross-Site Scripting (XSS) exploit against CVE-2024-42009 to execute JavaScript in the victim’s browser. Escalate to a credential- and…
-
U.S. Government Reportedly Approves OpenAI’s GPT-5.6 Sol, Terra, and Luna Models
The Trump administration has reportedly lifted previous restrictions on the launch of OpenAI’s GPT-5.6, enabling a broader commercial rollout of this advanced model after weeks of government-mandated cybersecurity and national security vetting. This decision marks a significant turning point in U.S. AI governance, moving GPT-5.6 from a tightly controlled pilot program with Trump-approved partners to…
-
Anthropic Keeps Claude Fable 5 Available on Paid Plans Until July 12
Anthropic has announced an extension of access to its advanced AI model, Claude Fable 5, allowing users on all paid plans to continue using the system until July 12, 2026. This update, shared via the company’s official X account, comes as enterprises increasingly rely on generative AI models for security research, code analysis, and threat…
-
Google Dialogflow CX Flaw Lets Attackers Bypass VPC-SC and Steal Sensitive Chatbot Data
A critical vulnerability in Google Cloud’s Dialogflow CX platform allowed attackers to bypass VPC Service Controls (VPC-SC) and silently exfiltrate sensitive chatbot data, raising significant concerns about the security of enterprise AI deployments. Discovered by Varonis Threat Labs and dubbed “Rogue Agent,” the flaw exposed a serious design gap in how Dialogflow CX executes custom…
-
Accenture Data Breach Exposes 35GB Source Code and Azure DevOps Credentials
Accenture is currently investigating a potential data breach after a threat actor using the alias “888” claimed to be selling approximately 35GB of stolen data, including source code and sensitive credentials, on a cybercrime forum. This listing, posted on July 6, 2026, alleges that the breach resulted in the exfiltration of proprietary assets, including source…
-
GitLost Vulnerability Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos
A critical vulnerability known as >>GitLost<< has been discovered in GitHub's newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to exfiltrate sensitive data from private repositories. It demonstrates how AI-driven automation within development pipelines can be manipulated to bypass conventional access controls and leak confidential information across repository boundaries. GitLost Vulnerability…
-
CISA to finalize critical infrastructure cyber incident reporting rule in September
First seen on scworld.com Jump to article: www.scworld.com/brief/cisa-to-finalize-critical-infrastructure-cyber-incident-reporting-rule-in-september
-
Spain arrests suspected hacker linked to Russian hacktivist campaign
Authorities didn’t name the man or file formal charges, but accuse him of participating in attacks linked to Cyber Army of Russia Reborn and NoName. First seen on cyberscoop.com Jump to article: cyberscoop.com/spain-arrests-alleged-cyber-army-of-russia-reborn-member/
-
UK Govt Pairs Agentic AI Initiative With Cyber Resilience Pledge
NCSC Launches AI Research, Governance and Resilience Measures. The U.K. government unveiled an AI-driven Cyber Shield initiative alongside a Cyber Resilience Pledge signed by 60 organizations, seeking to automate vulnerability management, strengthen governance and improve national resilience as ransomware and AI-enabled threats escalate. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/uk-govt-pairs-agentic-ai-initiative-cyber-resilience-pledge-a-32172
-
Selling Cyber: Anthropic’s Fable 5 Raises Security Tradeoffs
Panel Examines Costs, Security Limits, Enterprise Adoption of Fable 5 and Mythos 5. Anthropic’s Claude Fable 5 and Mythos 5 demonstrate major advances in coding and reasoning while raising new questions about exploit generation, enterprise AI spending, data governance and the growing urgency of faster vulnerability remediation, according to the panelists on Selling Cyber. First…
-
Spain Arrests Suspected Russian Hacktivist After FBI Tip
Investigators Say Suspect Supported CARR, Z-Pentest and NoName057(16). Spanish authorities, acting on FBI intelligence, arrested a man accused of supporting Cyber Army of Russia Reborn, Z-Pentest and NoName057(16), underscoring international efforts to dismantle Russian state-linked hacktivist networks targeting critical infrastructure. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/spain-arrests-suspected-russian-hacktivist-after-fbi-tip-a-32169
-
Spain Arrests Suspected Russian Hacktivist After FBI Tip
Investigators Say Suspect Supported CARR, Z-Pentest and NoName057(16). Spanish authorities, acting on FBI intelligence, arrested a man accused of supporting Cyber Army of Russia Reborn, Z-Pentest and NoName057(16), underscoring international efforts to dismantle Russian state-linked hacktivist networks targeting critical infrastructure. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/spain-arrests-suspected-russian-hacktivist-after-fbi-tip-a-32169
-
Britain plans to build autonomous AI ‘Cyber Shield’ to defend nation
The capability, called Cyber Shield, is designed to counter a threat the National Cyber Security Centre (NCSC) said could see attackers “move at machine speed and greater scale, reducing opportunities for detection and response.” First seen on therecord.media Jump to article: therecord.media/britain-plans-autonomous-ai-cyber-shield
-
Britain plans to build autonomous AI ‘Cyber Shield’ to defend nation
The capability, called Cyber Shield, is designed to counter a threat the National Cyber Security Centre (NCSC) said could see attackers “move at machine speed and greater scale, reducing opportunities for detection and response.” First seen on therecord.media Jump to article: therecord.media/britain-plans-autonomous-ai-cyber-shield

