Tag: cybersecurity
-
New InfraTrust report reveals infrastructure flaws admins should patch first
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first/
-
CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, infrastructure, injection, kev, sql, vulnerability, wordpressThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified a critical SQL injection vulnerability in WordPress Core, tracked as CVE-2026-60137, as one of its Known Exploited Vulnerabilities (KEV) due to its active exploitation in real-world attacks. This vulnerability affects the core functionality of WordPress when themes or plugins fail to properly validate untrusted input…
-
Why Modern SOCs Need Multi-Layered Detections
The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely.The CrowdStrike Global Threat Report estimates around 79% of attacks are malware-free, as threat actors rely on First seen on thehackernews.com…
-
U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: The first issue added to the catalog…
-
CISA orders urgent action on actively exploited Langflow RCE flaw
Tags: ai, cisa, cybersecurity, exploit, flaw, framework, government, infrastructure, rce, remote-code-execution, update, vulnerabilityThe Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-langflow-rce-flaw/
-
AI models cheat on cybersecurity evaluations, then fail to admit it
Frontier AI models will take just about any route to finish a task, cheating included, according to new cybersecurity evaluations from the UK government’s AI Security … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/ai-models-cheating-behaviour-cybersecurity-evaluations/
-
Google Unveils Gemini 3.5 Flash Cyber to Find and Fix Software Vulnerabilities Faster
Google has introduced Gemini 3.5 Flash Cyber, a lightweight AI model designed to improve cybersecurity by helping defenders identify, validate, and patch software vulnerabilities more efficiently. Built on Gemini 3.5 Flash and optimized for security tasks, Flash Cyber aims to deliver a cost-effective alternative to larger AI models while supporting large-scale vulnerability analysis. First seen on thecyberexpress.com Jump to…
-
AccuKnox Wins Best AI Startup Award for Enterprise Agentic AI Security at BSides Bangalore
Bangalore, India, July 22nd, 2026, CyberNewswire AccuKnox announced it has won the number one Startup Award at Security BSides Bangalore 2026, marking the second consecutive year the company has topped the category after also winning in 2025. The back-to-back recognition affirms AccuKnox’s standing among the region’s leading cybersecurity startups. AI Security Adoption For AccuKnox, this award…
-
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain.The package, named “Newtonsoftt.Json.Net,” masquerades as the Newtonsoft.Json library and is a trojanized fork. Seven versions of the package have been published to the First seen on thehackernews.com…
-
AI can’t fix cybersecurity’s hiring problem
Organizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/cybersecurity-workforce-trends-report/
-
Audit reveals gaps in FAA and TSA cybersecurity strategies
First seen on scworld.com Jump to article: www.scworld.com/brief/audit-reveals-gaps-in-faa-and-tsa-cybersecurity-strategies
-
OpenAI Models Escaped Containment and Hacked Hugging Face
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack. First seen on wired.com Jump to article: www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
-
OpenAI Models Escaped Sandbox, Breached Hugging Face
Tags: ai, attack, breach, credentials, cybersecurity, exploit, infrastructure, openai, risk, zero-dayReduced Guardrails Enabled Advanced Models to Pursue Unrestricted Attack Paths. OpenAI said advanced frontier models escaped a constrained testing environment, exploited multiple zero-days and stolen credentials and breached Hugging Face infrastructure while attempting to obtain answers for an internal ExploitGym evaluation, highlighting the growing cybersecurity risks posed by autonomous AI agents. First seen on govinfosecurity.com…
-
OpenAI Models Escaped Containment and Hacked HuggingFace
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack. First seen on wired.com Jump to article: www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
-
CISA Report on US Election Cybersecurity Draws Plaudits
Apolitical Analysis Suggests Better Patching Practices. Amid the partisan clamor surrounding U.S. President Donald Trump’s false claims last week of widespread voter fraud in the 2020 presidential election, one little-noticed document is garnering widespread welcome, even from critics of the administration. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cisa-report-on-us-election-cybersecurity-draws-plaudits-a-32278
-
CMMC: 5 Things To Watch Amid Pause On Upcoming Requirements
The pause on the next phase of the Cybersecurity Maturity Model Certification (CMMC) program has prompted major questions about how the government plans to verify the protection of sensitive data by defense contractors. First seen on crn.com Jump to article: www.crn.com/news/security/2026/cmmc-5-things-to-watch-amid-pause-on-upcoming-requirements
-
Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack
The Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 million people worldwide. First seen on therecord.media Jump to article: therecord.media/spain-fines-23andme-3-million-cyber-failings-data-breach
-
Craneware Confirms Data Theft After Cyberattack, Investigations Underway
Healthcare software vendor Craneware confirmed attackers stole data during a cyberattack, underscoring growing cybersecurity risks facing healthcare suppliers. The post Craneware Confirms Data Theft After Cyberattack, Investigations Underway appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-craneware-cyberattack-data-theft-2026/
-
Trump’s AI Safety Agency Chief Resigns After Just Three Months Leading CAISI
Chris Fall, the director of the U.S. Center for AI Standards and Innovation (CAISI), has resigned just three months after being appointed to lead the Commerce Department agency. This departure raises new uncertainties regarding the Trump administration’s agenda on AI safety, model evaluation, and cybersecurity oversight. The Commerce Department confirmed his resignation on July 20,…
-
What the World Cup can teach us about cybersecurity resilience
Future major events can’t rely on yesterday’s playbook. Lessons from the World Cup show why true cyber resilience starts months before kickoff and extends far beyond stadium perimeters. First seen on cyberscoop.com Jump to article: cyberscoop.com/world-cup-2026-major-event-cybersecurity-resilience-op-ed/
-
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecurity company Arctic Wolf. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
-
PR3TACK preemptive framework maps threats before attackers use them
Defensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/first-pr3tack-preemptive-framework/
-
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit.”FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP First…
-
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/
-
Cybersecurity Keeps Events ‘Uneventful’
Tags: cybersecurityFrom the World Cup to the United States’ 250th celebration, this year’s event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cybersecurity-keeps-events-uneventful
-
Eco-Verband warnt vor Angriff auf digitale Freiheitsrechte
Mit einem neuen Eckpunktepapier zur aktuellen Cybersicherheits-Politik warnt der Eco-Verband der Internetwirtschaft e. V. vor einer zunehmenden Verschärfung sicherheitspolitischer Eingriffe in den digitalen Raum. Aus Sicht des Verbands werden die Regeln für Cybersicherheit derzeit nicht nur dichter, sondern auch eingriffsintensiver. NIS2, KRITIS Dachgesetz, Cyber-Re20260706_eco_inf_cyberregulierungsilience-Act, die Revision des Cybersecurity-Act, das Gesetz zur Stärkung der Cybersicherheit, neue…
-
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Tags: advisory, cctv, cybersecurity, intelligence, Internet, military, russia, service, spy, ukraineAt least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops.That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands’ civilian and military…
-
Weekly Cybersecurity Newsletter The 50 Biggest Cybersecurity Stories Microsoft Patch, AI Attack, Exploits Releases, Data Breaches More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 40 most important stories from July 1317, 2026. What a week: Microsoft shattered records with 570 vulnerabilities patched in a single Patch Tuesday, China-linked hackers weaponized Claude Code and DeepSeek against government networks, GPT-5.6 wrote a complete Chrome […]…

