Tag: cyber
-
Mexico’s New Cyber Plan Faces Its First Real Test
The Latin American nation’s cybersecurity plan, still in the expansion phase, has to survive its own knockout round during the FIFA World Cup. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/mexicos-cyber-plan-first-real-test
-
French nonprofit starts global intelligence and research hub for AI cyber threats
One of the project’s top goals is stitching together an international, quick response coalition of governments, businesses and civil experts for AI-related threats. First seen on cyberscoop.com Jump to article: cyberscoop.com/paris-peace-forum-intaic-ai-cyber-threats/
-
OpenMatter Network Joins HOL Initiative to Help Define Standards for Verifiable AI Collaboration and Security
Melbourne, Florida, United States, July 8th, 2026, CyberNewswire OpenMatter Network today announced that it has joined the founding group of organizations participating in the Hashgraph Online (HOL) Partner Program, where the company will help develop standards, policies and verification frameworks for secure autonomous AI systems and agentic computing environments. As organizations increasingly deploy AI agents…
-
US enterprises incorporate cyber risk into larger strategic focus
The rapid adoption of AI and cloud is forcing significant shifts toward business resilience and financial impact. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/us-enterprises-cyber-risk-strategic-focus/824707/
-
Best Next-Generation Firewall (NGFW) Solutions Compared (2026): Features Pricing
Twelve firewalls, one question: which NGFW earns a place at your network edge in 2026? For mostenterprisesthe shortlist starts with Fortinet FortiGate (best price-performance) and Palo Alto Networks (deepest application control), but the right answer shifts with your size, region, and cloud strategy, and one of the twelve vendors hereisn’tan appliance at all. A […]…
-
Claude Cowork Expands to Web and Mobile With Background AI Agent Workflows
Claude Cowork was expanded beyond the desktop, rolling out web and mobile versions that let AI-driven task sessions persist across devices and continue running in the background without an active connection. The beta rollout begins with Max-tier subscribers over the coming weeks, with additional plan tiers to follow. Cowork operates as an agentic workspace where…
-
EU unveils cyber plan to reduce reliance on foreign AI systems
The communication, adopted in Strasbourg on July 7, is built around three pillars: making frontier AI “safe, accessible and deployable” for European cybersecurity, preparing the EU’s cyber ecosystem and scaling European AI capabilities. First seen on therecord.media Jump to article: therecord.media/eu-unveils-cyber-plan-to-reduce-reliance-on-foreign-ai
-
Attackers Can Generate Duplicate Verified GitHub Commits Using Signature Malleability
Attackers can silently clone “Verified” GitHub commits by abusing signature malleability in Git’s commit-signing formats, creating byte”‘different commits with identical content, valid signatures, and fresh “Verified” badges under new hashes. This breaks the long”‘standing assumption that a verified commit hash is a unique, immutable identifier for a specific piece of signed content and exposes hash”‘based…
-
IonStack Exploit Chain Lets Hackers Root Android 17 Phones With a Single URL Click
Nebula Security has revealed a significant exploit chain known as “IonStack,” demonstrating how attackers could gain full root access on Android 17 devices with just a single click on a malicious URL. This raises serious concerns about browser-to-kernel attack surfaces in today’s mobile ecosystems. The disclosure highlights a complex, multi-stage exploitation technique that combines two…
-
Fancy Bear Uses LSB Steganography and Reflective Loading to Run C# Remote-Control Trojan
A new intrusion campaign attributed to APT”‘C”‘20 (aka Fancy Bear, APT28) demonstrates the group’s continued refinement of stealthy, fileless techniques: weaponized Office documents that deploy a COM”‘hijacking DLL. Extract shellcode hidden via LSB steganography in a PNG, and use reflective loading to run an obfuscated C# remote”‘control Trojan that communicates through the legitimate cloud storage…
-
New Malicious Campaign Delivers Vidar Infostealer and Monero Crypto Miner
Cyber threat actors are infecting victims with the Vidar stealer and the XMRig cryptocurrency miner in a new malicious campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/new-campaign-vidar-stealer-monero/
-
Exposed Banana RAT Infrastructure Reveals Payload Generator and Obfuscator Tooling
A publicly indexed server at 198[.]245[.]53[.]26, discovered via Shodan, exposed more than simple staging files it revealed an active payload-generation backend and obfuscation tooling tied to two distinct Banana RAT branches. The host served static stages (st.txt, payload.php) and a FastAPI-based builder (servidor_completo_pool.py) plus an ofuscador.py helper. Enabling researchers to compare an older ETW-themed branch…
-
CrowdStrike Uncovers 5 New Prompt Injection Techniques Targeting AI Agents
CrowdStrike has identified five new techniques for prompt injection targeting AI agents, emphasizing the rapid evolution of adversarial methods as enterprises increasingly deploy autonomous AI systems. Detailed in a report published on July 7, 2026, by CrowdStrike’s AI security research team, these techniques expand the company’s prompt injection taxonomy to over 200 documented attack methods.…
-
AI-as-a-Service Botnet Routes Malicious Workloads Across Compromised Windows and Linux Hosts
The underground advertisement for the so-called Mycelium Framework reads like another feature”‘packed botnet sales pitch: cross”‘platform payloads, encrypted C2, persistence, exploit modules, credential theft, and lateral movement. Those building blocks are not new. What makes Mycelium notable is its advertised purpose to treat compromised endpoints not as disposable bots but as a capability”‘aware. AI compute…
-
Discord Confirms Bug That Incorrectly Banned 8,200 Users Since May 2026
Discord has confirmed a significant flaw in its automated moderation and enforcement pipeline that led to the wrongful banning of approximately 8,200 user accounts between May and early July 2026. This raises concerns about the reliability of AI-assisted trust and safety systems. The issue was disclosed via Discord’s official support channel on July 7 and…
-
NCSC Touts National Scale, AI-Powered “Cyber Shield” for Defense
The National Cyber Security Centre wants to work with AI partners to build a new “Cyber Shield” to defend the UK First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-national-cyber-sheild-ai/
-
CISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government Code
CISA is using Anthropic’s Mythos AI to scan federal code for vulnerabilities, aiming to find flaws before hackers and foreign intelligence services. Three sources familiar with the matter told Reuters that CISA, the U.S. government’s civilian cyber defense agency, is running Anthropic’s Mythos AI model against federal code repositories to find vulnerabilities before foreign intelligence…
-
Claude Code, Cursor, and OpenAI Codex Trigger Cyberattack-Like Telemetry Alerts
AI-powered coding assistants such as Claude Code, Cursor, and OpenAI Codex are increasingly triggering endpoint detection and response (EDR) alerts that resemble active cyberattacks, according to new research from Sophos X-Ops. This analysis, based on real-world telemetry collected in June 2026, highlights how autonomous AI behavior, while often benign, closely mirrors adversarial tactics, creating new…
-
CISA Warns of Actively Exploited Adobe ColdFusion Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Adobe ColdFusion, tracked as CVE-2026-48282, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability is actively being exploited in the wild. Disclosed on July 7, 2026, this vulnerability involves a path traversal weakness that could allow attackers to execute arbitrary code…
-
Over 70% of Public WordPress Sites Running Outdated PHP Exposed to Cyberattacks
A new analysis has revealed a significant security gap within the global web ecosystem. Over 70% of publicly accessible WordPress sites are running outdated, end-of-life (EOL) PHP versions, significantly increasing their vulnerability to cyberattacks. These findings highlight a systemic issue in how organizations manage their backend infrastructure, particularly given that WordPress remains the leading content…
-
15-Year-Old GhostLock Linux Kernel Vulnerability Enables Root Access and Container Escape
A critical vulnerability in the Linux kernel, known as “GhostLock” (CVE-2026-43499), has been disclosed by researchers at Nebula Security. This vulnerability, which has existed for 15 years, allows for reliable privilege escalation and container escape across nearly all Linux distributions. The issue dates back to Linux kernel version 2.6.39, released in 2011, and remained undetected…
-
Lurking Lizard Uses Drop-Catch Domains and Lookalike Brands to Distribute Proxyware
Tags: cyberA sophisticated, long-running operation that converts consumer devices into rentable exit nodes for residential proxy services. The initial signal was a fake 7-Zip installer hosted at 7zip[.]com a domain that mimicked the legitimate 7-zip[.]org and benefitted from years of search-engine history due to a common misquote. That apparent one-off lure, however, proved to be the…
-
Plattform ‘Cyber Frame” – Acronis bringt eigene Infrastruktur für MSP
First seen on security-insider.de Jump to article: www.security-insider.de/acronis-bringt-eigene-infrastruktur-fuer-msp-a-ac651c4ba072638dc328fc1d7f28d611/
-
Indian Income Tax Department Phishing Lure Deploys Gh0st RAT and AsyncRAT Implants
A targeted phishing campaign impersonating the Indian Income Tax Department has been observed delivering a sophisticated, six-stage infection chain that culminates in two in-memory remote-access implants: a Gh0st RAT derivative and a Quasar/AsyncRAT-family .NET payload. Victims are funneled to fake government pages that mimic Ministry of Finance and Income Tax branding and are pressured with…
-
LONGLEASH Malware Adds Reverse Shell, Proxying, and Intermediate C2 Capabilities
A significant upgrade to malware maintained by the UAT-7810 actor: LONGLEASH, a successor to the previously reported SHORTLEASH implant, now sporting reverse-shell, multi-protocol proxying, and intermediate command-and-control (C2) forwarding capabilities. LONGLEASH retains SHORTLEASH’s ff-agent codebase but expands its operational scope. The implant, internally named “nz1.0,” splits into Base, Executor, and Core modules. The Base module…
-
China-Aligned UNK_MassTraction Exploits Roundcube Servers to Target Universities
A suspected China-aligned cluster dubbed UNK_MassTraction that is exploiting n-day flaws in Roundcube webmail to compromise physics and engineering departments at U.S. and Canadian universities. The operators use a two-stage browser-to-server infection chain that begins with a Cross-Site Scripting (XSS) exploit against CVE-2024-42009 to execute JavaScript in the victim’s browser. Escalate to a credential- and…
-
U.S. Government Reportedly Approves OpenAI’s GPT-5.6 Sol, Terra, and Luna Models
The Trump administration has reportedly lifted previous restrictions on the launch of OpenAI’s GPT-5.6, enabling a broader commercial rollout of this advanced model after weeks of government-mandated cybersecurity and national security vetting. This decision marks a significant turning point in U.S. AI governance, moving GPT-5.6 from a tightly controlled pilot program with Trump-approved partners to…
-
Anthropic Keeps Claude Fable 5 Available on Paid Plans Until July 12
Anthropic has announced an extension of access to its advanced AI model, Claude Fable 5, allowing users on all paid plans to continue using the system until July 12, 2026. This update, shared via the company’s official X account, comes as enterprises increasingly rely on generative AI models for security research, code analysis, and threat…

