Tag: cybersecurity
-
Weekly Cybersecurity Newsletter The 50 Biggest Cybersecurity Stories Microsoft Patch, AI Attack, Exploits Releases, Data Breaches More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 40 most important stories from July 1317, 2026. What a week: Microsoft shattered records with 570 vulnerabilities patched in a single Patch Tuesday, China-linked hackers weaponized Claude Code and DeepSeek against government networks, GPT-5.6 wrote a complete Chrome […]…
-
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.The rogue gems are listed below – git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) – Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) –…
-
SoftBank leverages OpenAI for AI-driven cybersecurity patching service
First seen on scworld.com Jump to article: www.scworld.com/brief/softbank-leverages-openai-for-ai-driven-cybersecurity-patching-service
-
U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, cybersecurity, exploit, flaw, fortinet, infrastructure, kev, microsoft, remote-code-execution, update, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities (KEV) catalog. This week, Microsoft’s July 2026 Patch Tuesday addressed the SharePoint remote code execution bug…
-
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an “unprecedented” four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron, First seen on thehackernews.com Jump…
-
The Real AI Threat Is Blind Trust
AI models left to both interpret and execute commands eliminate critical cybersecurity oversight. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/real-ai-threat-blind-trust
-
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using…
-
Lessons Learned: US Cybersecurity Agency Leaked Secrets
CISA Lauded for Fast Response, Transparency and Detailing Security Recommendations. Secure developers’ use of public code repositories, monitor them for secrets and if they get exposed, have a well-tested incident response playbook at the ready. The U.S. Cybersecurity and Infrastructure Security Agency has shared these and other lessons learned after suffering a data leak. First…
-
Zero-Days, AI Governance Gaps, and Global Cybercrime Define This Week’s Security Landscape in July 2026
Weekly summary of Cybersecurity Insider newsletters in July 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/
-
Zero-Days, AI Governance Gaps, and Global Cybercrime Define This Week’s Security Landscape in July 2026
Weekly summary of Cybersecurity Insider newsletters in July 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/
-
The Cyber Express Weekly Roundup: TikTok Age Verification Probe, Healthcare Data Breach, Qantas Ruling, and Major Cyberattacks
Tags: breach, cyber, cyberattack, cybersecurity, data, data-breach, healthcare, risk, supply-chain, threat, vulnerabilityThis week’s cybersecurity roundup highlights growing concerns around online child safety, healthcare data protection, supply chain risks, and cyber threats affecting organizations worldwide. From regulatory scrutiny of digital platforms to large-scale vulnerabilities and operational disruptions, recent incidents show how cyber risks continue expanding across industries. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cybersecurity-weekly-roundup-tce/
-
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering.Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities…
-
U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, oracle, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KEV) catalog. The flaws added to the catalog are: The vulnerability CVE-2023-4346 (CVSS…
-
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, rce, remote-code-execution, vulnerability, zero-dayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization First seen…
-
HHS Wants Input on Cyber, AI for Regulations on Clinical Labs
Experts Say Clinical Laboratory Improvement Amendments Are Seriously Outdated. The Department of Health and Human Services is seeking public feedback pertaining to cybersecurity matters and the use of artificial intelligence for potentially updating decades-old, rules-of-the-road regulations for U.S. clinical laboratories that test human specimens for health conditions. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hhs-wants-input-on-cyber-ai-for-regulations-on-clinical-labs-a-32246
-
Gaps in network security, oversight strategy hamper US’s aviation cybersecurity regulators
A new government audit identified several weaknesses at the two agencies that protect air travel from hackers. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/aviation-cybersecurity-faa-tsa-gao-report/825416/
-
Top 10 Firewall Solutions Setting New Cybersecurity Standards in 2026
Thefirewallcategory is reinventing itself faster than at any point since NGFW arrived and2026’sleadersaren’tjust shipping betterboxes,they’reredefining what”firewall”means. Palo Alto Networks is setting the bar for AI-driven inline prevention, Fortinet for hybrid mesh execution, and HPE Juniper for the quantum-safe era, while Zscaler and Cloudflare are proving the most consequentialfirewallof all might be no appliance whatsoever. Here…
-
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that’s been spreading via websites infected with ClickFix lures since late April 2026.”The malware is full-featured, lightweight, and modular,” Elastic Security Labs researcher Cyril François said in a technical report. “While the number of C2 [command-and-control] domains is currently small, the daily First…
-
Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers Claim
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities and the results showed how effective a frontier LLM can be for hackers First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chatgpt55-to-execute-full/
-
CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance
On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/16/cisa-coordinated-vulnerability-disclosure-guidance/
-
CISA Warns of Actively Exploited Oracle E-Business Suite Flaw
Tags: business, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting CVE-2026-46817, an improper privilege management vulnerability in Oracle E-Business Suite that can lead to a takeover of Oracle Payments. The agency added the issue to its Known Exploited Vulnerabilities Catalog on July 15, 2026, and directed affected federal civilian executive…
-
Cribl Acquires CardinalOps In Move To Expand Into Security Operations
Cribl acquires CardinalOps in move to strengthen its presence in the cybersecurity space for threat detection, providing an alternative to legacy SIEM products. First seen on crn.com Jump to article: www.crn.com/news/security/2026/cribl-acquires-cardinalops-in-move-to-expand-into-security-operations
-
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments.”LabubaRAT creates a reusable foothold for hands-on activity,” Blackpoint Cyber researchers Sam Decker and Nevan Beal said in an analysis published today. “Once deployed, it can profile the host, First seen on…
-
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments.”LabubaRAT creates a reusable foothold for hands-on activity,” Blackpoint Cyber researchers Sam Decker and Nevan Beal said in an analysis published today. “Once deployed, it can profile the host, First seen on…
-
CMMC Is ‘Not Dead’ Despite Pause On Next Phase Of Requirements: MSP Execs
The move by the U.S. Department of War to pause the next phase of requirements around the Cybersecurity Maturity Model Certification (CMMC) program does not mean the program’s underlying data security obligations are being relaxed for U.S. defense contractors, MSP executives told CRN. First seen on crn.com Jump to article: www.crn.com/news/security/2026/cmmc-is-not-dead-despite-pause-on-next-phase-of-requirements-msp-execs
-
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries.Miggo’s security team, which discovered and reported the flaws, said one “leaks the broker’s confidential OAuth First seen on thehackernews.com…
-
Künstliche Intelligenz verändert Cybersecurity-Berufe und stärkt die Bedeutung menschlicher Kontrolle
ISC2, die weltweit führende gemeinnützige Mitgliederorganisation für Cybersecurity-Fachleute, veröffentlicht die Ergebnisse ihres aktuellen Berichts ‘Rethinking AI’s Impact on Cybersecurity Roles”. Die Studie zeigt, dass künstliche Intelligenz die Aufgaben, Arbeitsabläufe und Entscheidungsprozesse in der Cybersecurity grundlegend verändert und gleichzeitig die Bedeutung menschlicher Urteilsfähigkeit, sorgfältiger Validierung und klarer Governance-Strukturen weiter zunimmt. Rund zwei Drittel der Befragten geben…

