Information Security News | AI Aggregator
Please be mindful of possible hallucinations. Verify information prior to taking action.
Date: 2026-07-14 | Source: Cyber Security News
Microsoft's July 2026 Patch Tuesday addresses 570 vulnerabilities, including three zero-days. Key CVEs include CVE-2026-56164 (SharePoint EoP, exploited in the wild), CVE-2026-56155 (AD FS EoP, exploited), and CVE-2026-50661 (BitLocker bypass, publicly disclosed). Critical vulnerabilities include CVE-2026-58644 (SharePoint RCE) and CVE-2026-58608 (Print Spooler RCE). IT administrators should prioritize patching these critical flaws within 48 hours, as they are high-value targets for attackers.

2026-07-14 | Krebs on Security: Microsoft Patches a Record 570 Security Flaws
Microsoft released updates to address 570 security vulnerabilities, nearly tripling last month's count. Among these, 60 are rated "critical," allowing remote control over devices. Three zero-day flaws are actively exploited, including CVE-2026-50661, a BitLocker bypass. CVE-2026-48561, a remote code execution flaw in Microsoft Copilot, has a CVSS score of 9.6. Experts urge caution with the high volume of patches, recommending users back up data before applying updates due to potential stability issues.
2026-07-14 | The Hacker News: Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Microsoft's July Patch Tuesday addressed a record 622 vulnerabilities, including two actively exploited zero-days: CVE-2026-56164 in SharePoint Server, allowing unauthenticated privilege escalation, and CVE-2026-56155 in Active Directory Federation Services, enabling local privilege escalation. Both are critical to patch immediately. Additionally, CVE-2026-50661, a BitLocker bypass, was disclosed but not under attack. The update also finalizes RC4 hardening, which may disrupt authentication for legacy systems.
2026-07-14 | Cisco Talos: Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Microsoft's July 2026 Patch Tuesday addresses 622 vulnerabilities, including 57 critical ones. Notable vulnerabilities include CVE-2026-56155 (AD FS privilege escalation) and CVE-2026-56164 (SharePoint spoofing). The critical vulnerabilities primarily involve remote code execution across various Microsoft products. Talos has released a new Snort ruleset to detect exploitation attempts, with specific rules provided for both Snort 2 and Snort 3. A complete list of vulnerabilities is available on Microsoft's update page.
2026-07-14 | Security Affairs: Patch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one month
Microsoft's July 2026 Patch Tuesday released a record 621 CVEs, including two exploited zero-days and critical vulnerabilities in SharePoint, RDP, Hyper-V, and AD FS. Key issues include CVE-2026-57092 (CVSS 9.9), allowing full host compromise via VMSwitch, and CVE-2026-56155, an AD FS elevation of privilege flaw. Other notable vulnerabilities include CVE-2026-50522 and CVE-2026-58644 (CVSS 9.8) in SharePoint, and CVE-2026-56190 in RDP Server. Immediate patching is recommended.
2026-07-14 | Rapid7: Patch Tuesday - July 2026
On July 2026 Patch Tuesday, Microsoft published 622 vulnerabilities, including 416 for Windows. Notably, CVE-2026-55040 is a critical authentication bypass in SharePoint, allowing unauthenticated remote code execution. CVE-2026-56164 is a zero-day elevation of privilege vulnerability in SharePoint, exploited in the wild. Other vulnerabilities include CVE-2026-50661 for BitLocker and CVE-2026-56155 for Active Directory Federation Services. Age of Empires II also received a patch for CVE-2026-50663, enabling remote code execution.
2026-07-14 | Windows Latest: Don’t skip today’s Windows 11 update. Microsoft just patched a record 570 flaws, 4x last year as AI accelerates attacks
Microsoft's July 2026 Patch Tuesday update addressed a record 570 security flaws, a 316% increase from July 2025. Key components affected include the kernel, Remote Desktop, and TCP/IP, with critical flaws allowing remote code execution. Microsoft attributes the surge in vulnerabilities to AI's role in identifying bugs faster. The update also introduces new features and emphasizes the importance of timely updates, advising against deferrals beyond three days to mitigate risks from AI-exploited vulnerabilities.
2026-07-15 | CSO Online: Patch Tuesday roundup: Microsoft fixes a monthly record 569 holes; SAP patches a critical memory corruption bug
Microsoft's recent Patch Tuesday resulted in a record 569 vulnerabilities patched, including 59 rated as critical. The increase is attributed to AI models aiding in vulnerability discovery. Microsoft advises customers to expedite their patching schedules to address these critical flaws promptly. This month's total surpasses last month's record of 198 fixes and approaches the annual record of 1,245 vulnerabilities set in 2020, as noted by Tenable's Satnam Narang.
2026-07-15 | Cyber Security News: Windows BitLocker 0‑Day Vulnerability Allows Hackers to Bypass Security Feature
A newly disclosed Windows BitLocker 0-day vulnerability, tracked as CVE-2026-50661, allows unauthorized physical access to bypass BitLocker encryption, compromising data security. Microsoft rates exploitation as "Less Likely," requiring physical device access. Affected platforms include various Windows 10, 11, and Server versions. Security updates were released on July 14, 2026, with specific patches for each version. Administrators are advised to apply these updates and consider additional security measures to mitigate risks.
2026-07-15 | Cyber Security News: Microsoft Active Directory Services 0-Day Vulnerability Actively Exploited in the Wild
Microsoft has released security updates for CVE-2026-56155, an elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS) that is actively exploited. This flaw allows authenticated local attackers to gain administrator-level access. It has a CVSS score of 7.8 and requires low complexity and privileges. Microsoft recommends organizations prioritize updates, especially on exposed federation servers, and monitor for unusual activities. The vulnerability stems from insufficient access control granularity.
Date: 2026-07-14 | Source: Help Net Security
Old UEFI shims, specifically versions 0.9 and below, can bypass Secure Boot protections, as discovered by ESET researchers. Microsoft revoked eleven vulnerable shims on June 9, 2026. Attackers can exploit these shims on any UEFI system with the Microsoft UEFI CA 2011 certificate, allowing unauthorized code execution. Notable vulnerabilities include CVE-2026-8863 and CVE-2026-10797. Users are advised to apply UEFI revocations and check for the revoked hashes using provided PowerShell commands or Linux scripts.

2026-07-14 | The Hacker News: 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Cybersecurity researchers identified 11 outdated Microsoft-signed UEFI applications that can be exploited to bypass Secure Boot, allowing attackers to execute untrusted code during system boot. These vulnerabilities affect systems trusting the "Microsoft Corporation UEFI CA 2011" certificate. The impacted bootloaders include various Linux distributions and software. Exploitation could lead to the deployment of UEFI bootkits, with CVEs tracked as CVE-2026-8863 and CVE-2026-10797. Recommendations include revoking old bootloaders to mitigate risks.
2026-07-14 | Cyber Security News: 11-Year-Old Linux UEFI Shim Bootloaders Let Attackers Bypass Secure Boot
An ESET report reveals that 11-year-old Microsoft-signed UEFI shim bootloaders (version 0.9 or earlier) allow attackers to bypass UEFI Secure Boot on any UEFI-based machine. Exploitation can lead to the execution of malicious bootkits. Two CVEs were assigned: CVE-2026-8863 for shim bypass and CVE-2026-10797 for a revocation-check flaw. Microsoft revoked the vulnerable binaries on June 9, 2026. Security teams are advised to apply the patch carefully to avoid boot failures and test updates on non-critical hardware.
2026-07-14 | Ars Technica: Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
Microsoft's Secure Boot, intended to protect devices from firmware infections, has been vulnerable for 13 of its 14 years. Researchers at ESET found 11 defective firmware images, known as shims, that were never revoked despite known vulnerabilities. This allows attackers to bypass UEFI Secure Boot on both Windows and Linux systems, enabling the installation of malicious firmware. The issue stems from Microsoft's failure to revoke these shims, posing a significant security risk.
2026-07-14 | SC Magazine: Old Microsoft-signed UEFI applications can bypass Secure Boot
Eleven outdated Microsoft-signed UEFI applications can be exploited to bypass Secure Boot, allowing attackers to execute untrusted code during system startup. This vulnerability affects various Linux distributions and software from vendors like Red Hat, Oracle, and OpenSuse. The issue arises from older shim bootloaders signed with an expired Microsoft certificate that hasn't been revoked. This enables the "bring your own vulnerable driver" (BYOVD) technique, evading detection by security controls and potentially allowing persistent access.
Date: 2026-07-13 | Source: Microsoft Security
In campaigns from mid-2025 to mid-2026, Microsoft identified ShinyHunters exploiting OAuth relationships to access Salesforce and other SaaS applications. Techniques included vishing for OAuth consent, supply chain compromises via third-party integrations, and exploiting misconfigured guest access. These methods allowed data exfiltration and persistent access without traditional detection. Microsoft enhanced Defender for Cloud Apps to improve visibility and governance of OAuth-connected applications, recommending stronger monitoring and configuration reviews.

2026-07-14 | The Hacker News: Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Attackers linked to ShinyHunters exploited Salesforce environments over a year using three methods: vishing calls to gain OAuth consent, stealing tokens from compromised vendors like Salesloft and Gainsight, and exploiting misconfigured guest access. Microsoft and Salesforce have implemented new detection tools to monitor OAuth activity and improve governance. Recommendations include connecting Salesforce to Defender for Cloud Apps, monitoring event logs, and enforcing least privilege access for integrations.
2026-07-14 | Cyber Security News: One Malicious OAuth Approval Can Give Hackers Persistent Access to Salesforce Data
Attackers can gain persistent access to Salesforce data through a single malicious OAuth approval, exploiting trusted application connections rather than software flaws. Microsoft observed these tactics from mid-2025 to mid-2026, involving voice phishing and compromised SaaS integrations. Once approved, attackers can query and extract data without detection. Recommendations include reviewing connected applications, monitoring API traffic, and securing guest-user access to mitigate risks. Specific IP addresses linked to these activities were also identified.
2026-07-14 | TechRadar: 'A single entry point can rapidly expand to greater enterprise impacts': Microsoft introduces changes to tackle ShinyHunters
Microsoft has introduced upgrades to Defender for Cloud Apps in response to the ShinyHunters cybercrime group, which exploited OAuth trust in Salesforce to access customer environments. Reports indicate up to 700 victims, with attackers exfiltrating data via legitimate APIs. The upgrades enhance detection, investigation, and governance of OAuth-connected applications, improving visibility and allowing for better monitoring of suspicious activities. The changes aim to mitigate unauthorized access and data exfiltration risks.
2026-07-14 | SC Magazine: ShinyHunters group exploits OAuth trust, prompting Microsoft security upgrades
The ShinyHunters cybercrime group exploited OAuth trust to breach corporate Salesforce environments, prompting Microsoft to enhance security. They tricked Salesforce users into authorizing a malicious Data Loader app, allowing access to data via legitimate APIs. Approximately 700 victims were affected over a year. The group compromised third-party SaaS providers to steal OAuth tokens, gaining access to customer Salesforce environments. Microsoft upgraded Defender for Cloud Apps for better detection and governance of OAuth-connected applications.
Date: 2026-07-13 | Source: Recorded Future
The U.S. sanctioned VPN provider First VPN Service (1VPNS) and its administrator Dmytro Rashevskyi for facilitating ransomware attacks on U.S. entities, causing billions in losses. Rashevskyi used fake identities to acquire infrastructure, while Belarusian Yegeniy Vladimirovich Silayev was designated for selling malware cloaking methods. The sanctions prevent U.S. transactions with them, aiming to disrupt ransomware operations by targeting service providers. First VPN has been linked to cybercriminal activities since 2014.

2026-07-14 | The Hacker News: U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
The U.S. Treasury has sanctioned First VPN Service and two individuals for facilitating ransomware attacks. The VPN, operational since 2014, was used by ransomware groups to obscure attack origins, causing billions in losses to U.S. entities. Dmytro Rashevskyi, the administrator, utilized false identities to acquire infrastructure. Concurrently, the U.K. and E.U. sanctioned Russian cyber networks for disruptive operations, while the FBI warned about Russian exploitation of poorly configured routers, targeting critical infrastructure.
2026-07-14 | Cyber Security News: US Treasury Sanctions First VPN Service that Helped Ransomware Actors Attack Organizations
The U.S. Treasury's OFAC has sanctioned First VPN Service (1VPNS) for aiding ransomware groups targeting U.S. organizations. The sanctions also affect administrator Dmytro Rashevskyi and malware obfuscator Yegeniy Silayev. 1VPNS was used to conceal origins, deploy malware, and manage stolen data, impacting U.S. businesses and critical infrastructure with billions in losses. The action follows a 2026 law enforcement operation and aims to disrupt services supporting ransomware activities.
2026-07-14 | Chainalysis: “Stern,” Likely Most Prolific Ransomware Operator Ever, Sanctioned by EU as Action Targets Billions in Ransomware Damage
The EU sanctioned Vitaly Nikolayevich Kovalev, known as “Stern,” linked to the Trickbot ransomware group, which has received over $300 million in ransom payments. OFAC designated First VPN Service (1VPNS) and its administrator for enabling ransomware attacks. The action targets a broad network of cybercriminals, including those behind LummaC2 infostealer malware and bullet-proof hosting provider Media Land LLC, reflecting a strategic shift in combating ransomware by targeting enablers.
2026-07-14 | Cyberscoop: Treasury sanctions First VPN Service, others for abetting ransomware gangs
The U.S. Treasury Department sanctioned First VPN Services (1VPNS) and its administrator, Dmytro Rashevskyi, for allegedly aiding ransomware gangs by providing anonymity services. 1VPNS has been linked to numerous ransomware attacks on U.S. entities, including businesses and hospitals. Additionally, Belarusian Yegeniy Vladimirovich Silayev was sanctioned for selling tools to disguise malware. The sanctions align with similar actions by European governments, and 1VPNS has been implicated in Europol investigations.
2026-07-14 | Security Affairs: U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
The U.S. Treasury sanctioned VPN provider 1VPNS and cryptor seller Yegeniy Vladimirovich Silayev on July 13, 2026, for facilitating ransomware attacks causing billions in losses to U.S. businesses and critical infrastructure. 1VPNS provided services to ransomware groups, while Silayev sold tools to disguise malware. The sanctions freeze their U.S. assets and prohibit transactions with them, following a May 2026 takedown of 1VPNS's infrastructure by European law enforcement and the FBI.
Date: 2026-07-13 | Source: Microsoft Security
Microsoft Entra ID will make passkeys the default authentication method starting September 1, 2026, to combat sophisticated identity attacks. SMS and voice authentication will be retired on February 1, 2027. Organizations are encouraged to transition to passkeys, which utilize public-key cryptography, enhancing security against phishing. Users will be prompted to register passkeys during multifactor authentication. For those needing SMS or voice, third-party telecom providers can be selected via the Microsoft Security Store.

2026-07-14 | Cyber Security News: Microsoft Changes Entra ID default Authentication Method to Passkeys, Replacing Passwords
Microsoft is transitioning to passkeys as the default authentication method for Entra ID, retiring SMS and voice-based multifactor authentication by February 1, 2027, due to rising AI-enabled phishing threats. Starting September 1, 2026, users will be auto-enrolled in passkeys. Microsoft has achieved 99.6% phishing-resistant authentication internally and recommends organizations audit their authentication policies and enable passkey support immediately. Regulatory pressures, such as NIS2 compliance, are also influencing this shift.
2026-07-14 | Help Net Security: Microsoft Entra ID authentication overhaul to start in September 2026
Microsoft will roll out passkeys as the default authentication for Microsoft Entra ID on September 1, 2026, phasing out SMS and voice authentication. Organizations using SMS or voice will be automatically transitioned to passkeys and must register them by February 1, 2027. Microsoft will retire its native SMS and voice services, allowing organizations to manage third-party telecom providers instead. Details on supported providers and configurations will be available on September 18, 2026.
2026-07-15 | CSO Online: Microsoft is forcing an enterprise transition to passkeys
Microsoft will implement passkeys as the default authentication method in its Entra ID service starting September 1. This transition aims to enhance security amid rising AI-driven attacks. Following a transition period, Microsoft will discontinue SMS and voice authentication on February 1, 2027. This shift reflects the company's commitment to adopting more secure authentication standards for its enterprise customers.
Date: 2026-07-13 | Source: Cyber Security News
CrashStealer is a C++ macOS infostealer masquerading as Apple's crash-reporting tool, targeting browser credentials, cryptocurrency wallets, and password managers. Detected in early May 2026, it uses a signed disk image named “Werkbit Setup” to bypass Gatekeeper. The malware employs AES-256-GCM encryption for exfiltrated data and installs a LaunchAgent for persistence. Its sophisticated techniques indicate a shift in macOS malware towards more structured operations, paralleling Windows threats.

2026-07-13 | The Hacker News: CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
CrashStealer is a new macOS information stealer that harvests sensitive data using a notarized dropper named "Werkbit.app." It validates login credentials locally and collects data from browsers, cryptocurrency wallets, password managers, and the keychain, encrypting it with AES-GCM before exfiltration. The malware is distributed via a disk image from "werkbit[.]io," gated by a meeting PIN. It establishes persistence as a LaunchAgent and exfiltrates data to an attacker-controlled server.
2026-07-14 | Security Affairs: CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
CrashStealer, a new macOS infostealer, was identified by Jamf Threat Labs in May 2026 and confirmed in active deployment by July. It uses a signed app, Werkbit.app, to bypass Gatekeeper, stealing credentials and wallets while AES-encrypting the data. The malware targets various browsers and password managers, employing anti-analysis techniques. It persists by installing a LaunchAgent and uses a hardcoded salt for encryption. The delivery domain also hosts a command panel for operators.
2026-07-14 | Infosecurity Magazine: New MacOS Malware Exploits Legitimate Developer ID to Pose as Apple Crash Reporter
A new macOS malware, named CrashStealer, exploits a legitimate Apple developer ID to impersonate the crash-reporting component, tricking users into installing a password-stealing payload. Detected in early July, it uses a notarized disk image called "Werkbit Setup" to bypass macOS security. Once installed, it mimics a macOS authorization prompt to steal login credentials and sensitive data, including cryptocurrency wallets. Jamf Threat Labs reported the malicious developer ID to Apple for further action.
2026-07-14 | Help Net Security: New macOS malware steals passwords by posing as Apple’s crash-reporting tool
Jamf Threat Labs identified a new macOS infostealer named CrashStealer, which masquerades as Apple's crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets. First detected in May, it became active by July. The malware uses a signed installer named "Werkbit Setup" and employs native C++ for its implementation. It collects data from various browsers and password managers, encrypts it with AES-GCM, and exfiltrates it via libcurl. The malware also ensures persistence by installing itself as a LaunchAgent.
2026-07-14 | TechRadar: This new macOS infostealer poses as an Apple crash reporting tool to try and steal all your valuable data
A new macOS infostealer named "CrashStealer" has been identified, masquerading as Apple's CrashReporter. Distributed via a fake site called "Werkbit Setup," it bypasses Gatekeeper using a notarized installer. Once installed, it prompts users for a password to unlock Keychain, exfiltrating credentials, cookies, files, and data from over 80 crypto wallets and 14 password managers. Jamf researchers noted its unique client-side encryption and C++ implementation, distinguishing it from other infostealers.
Date: 2026-07-13 | Source: Cyber Security News
On July 9, 2026, the NSA and 17 international partners issued a Cybersecurity Advisory warning of Russian state-sponsored actors exploiting vulnerable network infrastructure. The advisory highlights CVE-2018-0171, a critical Cisco Smart Install vulnerability. Recommendations include disabling Cisco Smart Install, implementing SNMPv3, using strong passwords, blocking certain protocols, and promptly upgrading software. The advisory reflects a coalition of agencies, emphasizing basic hygiene practices to deter state-level intrusions.

2026-07-13 | Cybersecurity Dive: US authorities warn that state-linked hackers are targeting vulnerable networking devices
US authorities, including the NSA, warn that Russian state-sponsored hackers, known as Berzerk Bear or Dragonfly, are exploiting vulnerabilities in Cisco Smart Install devices to target critical infrastructure globally. The hackers have previously exploited CVE-2018-0171 and CVE-2008-4128 vulnerabilities. A 2025 FBI advisory noted they have accessed thousands of U.S. devices. U.K. and EU sanctions were imposed on 24 individuals/organizations linked to these activities, including an unsuccessful attack on Poland’s energy grid.
2026-07-13 | Cyberscoop: Officials once again warn defenders that Russian hackers are targeting network devices
Russian state-sponsored hackers are exploiting poorly configured networking devices to infiltrate critical infrastructure globally, as warned by U.S. and 12 allied nations. The group, linked to the Russian FSB, has targeted sectors including defense, energy, and healthcare. They exploit vulnerabilities in Cisco devices, specifically CVE-2008-4128 and CVE-2018-0171. Authorities recommend disabling Cisco Smart Install, using stronger authentication, and monitoring for unusual logins. The advisory follows a similar alert from the FBI.
2026-07-13 | SC Magazine: Russia’s FSB attacks critical infrastructure, says 12 Western nations
The Russian FSB has been targeting critical infrastructure in 12 nations, including the U.S., for over a decade, exploiting poorly configured Cisco routers and Smart Install functionality. U.S. agencies, including NSA and CISA, highlight that attackers use simple tactics like scanning for default passwords. Experts stress that organizations must address known vulnerabilities and improve security fundamentals. CVE-2018-0171, related to Cisco Smart Install, remains a significant concern despite being patched.
2026-07-14 | CSO Online: US authorities warn of Russian attacks on critical infrastructure
US authorities NSA, FBI, and CISA have issued warnings about Russian hackers targeting critical infrastructure in North America and Europe. The attacks exploit vulnerable and misconfigured routers, emphasizing the need for timely security patch installations. The sectors most at risk include energy, communications, healthcare, industry, the economy, and defense. This alert is supported by authorities from Australia, the UK, Canada, New Zealand, Estonia, Finland, France, and Italy.
2026-07-14 | TechRadar: US and security allies warn Russian attacks on critical infrastructure are ramping up against 'poorly configured and vulnerable networking devices worldwide'
A joint advisory from the NSA, FBI, CISA, and 15 allied agencies warns that Russian state-sponsored actors, specifically the FSB Center 16, are targeting critical infrastructure worldwide by exploiting weak credentials and old Cisco vulnerabilities. Key vulnerabilities highlighted include CVE-2018-0171 and CVE-2008-412813. The advisory indicates that these actors are scanning for poorly configured devices and exfiltrating configuration files. Attribution points to groups like Berserk Bear and Energetic Bear.
Date: 2026-07-13 | Source: Help Net Security
Attackers are exploiting spoofed OAuth client IDs to bypass Microsoft Entra ID sign-in logs, allowing account enumeration without triggering successful sign-in events. This technique obscures malicious activity, as logs show blank application names for spoofed IDs. Proofpoint identified two campaigns: UNK_pyreq2323, which targeted over a million accounts using 700,000 spoofed IDs, and UNK_OutFlareAZ, affecting 2 million users with 3.7 million random UUIDs. This highlights a broader vulnerability across identity provider platforms.

2026-07-13 | Infosecurity Magazine: Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
Cybercriminals are using a new OAuth Client ID spoofing technique to access cloud environments, as reported by Proofpoint on July 13. This method exploits Microsoft Entra ID, allowing attackers to bypass detection by submitting POST requests to the OAuth 2.0 token endpoint. The technique aids in user enumeration, making it difficult for defenders to identify malicious activity. Proofpoint warns that organizations should monitor sign-in logs for blank application IDs and be cautious of AADSTS700016 error codes, which may indicate compromised credentials.
2026-07-13 | Cybersecurity Dive: Hackers find a new trick to collect Microsoft Entra user data without raising red flags
Hackers are exploiting spoofed OAuth client IDs to gather Microsoft Entra user data, according to Proofpoint. This technique allows attackers to collect usernames and passwords without using legitimate applications, bypassing monitoring systems. Two campaigns were identified: one starting in January with over 700,000 spoofed IDs affecting 1 million accounts, and a larger December campaign with 3.7 million IDs targeting over 2 million users. Organizations are advised to monitor logs for blank application IDs and specific error codes.
2026-07-13 | SC Magazine: Cybercriminals exploit OAuth client ID spoofing to bypass cloud security
Cybercriminals are exploiting OAuth client ID spoofing to bypass cloud security, as reported by Proofpoint. This technique uses Microsoft Entra ID, allowing unauthorized access without a registered OAuth client ID. Attackers issue POST requests to Microsoft's OAuth 2.0 token endpoint via the Resource Owner Password Credentials flow, inferring valid usernames and passwords while evading detection. Large-scale campaigns target millions of accounts, with defenders advised to monitor logs for blank application IDs and AADSTS700016 error codes as indicators of compromise.
2026-07-14 | Hack Read: Millions of Microsoft Entra Accounts Targeted in OAuth Client ID Spoofing Campaigns
Attackers are exploiting spoofed OAuth client IDs to target millions of Microsoft Entra accounts, allowing them to test credentials without registering applications or exploiting vulnerabilities. Research from Proofpoint highlights two campaigns: UNK_pyreq2323, which tested over one million accounts using 700,000 spoofed IDs, and UNK_OutFlareAZ, targeting over two million users with 3.7 million IDs. Recommendations include monitoring sign-in records for anomalies and authentication error codes to detect such activities.
2026-07-14 | The Hacker News: OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
At least two threat actors are exploiting OAuth client ID spoofing to validate stolen Microsoft Entra credentials without triggering sign-in alerts. This technique allows attackers to enumerate accounts and infer valid usernames and passwords by sending spoofed client IDs to Microsoft's OAuth 2.0 token endpoint. Two campaigns, UNK_pyreq2323 and UNK_OutFlareAZ, have targeted over 3 million accounts, causing significant user lockouts. Recommendations include applying Conditional Access policies to mitigate these attacks.
2026-07-14 | Cyber Security News: Hackers Spoof 3.7 Million OAuth Client IDs to Stealthily Enumerate 2 Million Entra ID Users
Threat actors are exploiting spoofed OAuth client IDs to enumerate Microsoft Entra ID accounts, identifying valid credentials while evading detection. Proofpoint's research highlights two campaigns: UNK_pyreq2323 in January 2026, targeting over 111 million accounts with 700,000 spoofed IDs, and UNK_OutFlareAZ since December 2025, affecting 222 million users with 3.7 million spoofed IDs. Organizations are advised to monitor sign-in logs for missing application names and investigate AADSTS700016 errors to detect potential breaches.
2026-07-14 | SC Magazine: OAuth client ID spoofing silently validates stolen Microsoft Entra ID credentials
At least two threat actors are using OAuth client ID spoofing to validate stolen Microsoft Entra ID credentials without triggering alerts. This technique allows attackers to confirm valid credentials without leaving traces in logs, exploiting gaps in cloud identity monitoring. Experts emphasize the need for complete authentication logs and recommend deploying phishing-resistant MFA and strong password practices. An assume-breach mindset is advised to limit damage from potential credential compromises.
Date: 2026-07-13 | Source: The Hacker News
Cybersecurity researchers reported an intrusion where an attacker used an AI-generated PowerShell script for Active Directory enumeration, mapping users and domains. The attack involved establishing RDP access with pre-compromised credentials and utilizing a "highly aggressive" script to collect AD data. The attacker later deployed tools for data exfiltration, creating an Active Directory Inventory Report. Sygnia noted AI-assisted attacks can be executed faster, leveraging existing vulnerabilities without novel malware, emphasizing speed and scale in cyber intrusions.

2026-07-13 | Cyber Security News: Hackers are Using Vibe-Coded PowerShell Script to Enumerate Active Directory Accounts
Threat actors are utilizing AI-generated PowerShell scripts, termed "vibe-coded," to map Active Directory (AD) environments, marking a shift from traditional hacking tools. On June 3, 2026, an attacker used pre-compromised credentials to deploy a script, Untitled1.ps1, which enumerated AD accounts and exported data into CSV files. The script's AI origin was evident through its placeholder hostname and redundant methods. This trend necessitates a shift from static signature detection to behavioral analytics for effective threat detection.
2026-07-13 | TechRadar: Vibe coded threats shift again — hackers are using AI chatbots to write malware using natural language
Hackers are leveraging AI to create malware, exemplified by the custom tool "Untitled1.ps1," which performs Active Directory enumeration. This tool, developed by low-skilled attackers, was used alongside s5cmd for data exfiltration and SharpShares.exe for share enumeration. Huntress warns that AI-generated malware presents a significant challenge for defenders, as traditional signature-based defenses are ineffective against unique, bespoke payloads. Emphasis is placed on adopting behavioral analytics to detect such threats.
2026-07-14 | Security Affairs: Attacker Used AI to Build Custom PowerShell Recon Malware
On June 3, 2026, Huntress discovered an AI-generated PowerShell script used for Active Directory reconnaissance during an incident response. The script, named Untitled1.ps1, was custom-built and utilized multiple methods to identify the domain controller. It collected sensitive AD data and generated an HTML summary report. The attack leveraged pre-compromised RDP credentials and highlighted the challenges of detecting AI-generated malware, emphasizing the need for behavioral analytics over traditional signature-based detection.
Date: 2026-07-13 | Source: Infosecurity Magazine
Cybersecurity agencies from 12 countries warn that Russian state-sponsored hackers, specifically the FSB's Centre 16, are targeting vulnerable routers globally by exploiting weak SNMP passwords. Sectors at risk include communications, defense, and healthcare. Recommendations include using SNMPv3 for enhanced security. The advisory also links Centre 16 to a cyber-attack on Poland's energy grid in late 2025, attributed by the EU and UK, which could have impacted 500,000 citizens. Sanctions have been imposed on individuals involved in these operations.

2026-07-13 | DIGIT: UK and EU Sanction Russian Networks Behind Cyber Crime
The UK and EU have sanctioned 24 individuals and entities linked to Russian networks involved in cyber-attacks and election interference. Key figures from the GRU, including Vyacheslav Stafeyev, were targeted for directing cyber operations. The UK attributes a failed attack on Poland’s energy grid to Russia’s FSB Centre 16. Additionally, sanctions were imposed on those behind Lumma Stealer, which has affected over 2,100 victims in the UK, and on Rybar LLC for spreading disinformation.
2026-07-13 | Security Affairs: EU Targets FSB-Linked Hackers in New Sanctions Over Cyber Sabotage
The EU imposed sanctions on July 13, 2026, targeting nine individuals and four entities linked to Russia's FSB for a 15-year cyberespionage and sabotage campaign affecting at least nine countries, including France and Germany. The sanctions focus on the FSB's 16th Center, responsible for various cyber threats. The accused network engaged in espionage and sabotage against critical infrastructure, including heating systems and power plants. The EU's actions reflect a growing concern over Russia's cyber operations as tools of hybrid warfare.
2026-07-13 | Help Net Security: EU and UK blacklist Russia’s cyber operators over efforts to destabilize Europe
The EU and UK sanctioned numerous Russian individuals and entities for cyber operations aimed at destabilizing Europe. The UK targeted 24 individuals/entities, while the EU sanctioned 9 individuals and 4 entities. The 16th Centre of Russia’s FSB was implicated in cyber espionage and attacks on critical infrastructure, including a failed operation against Polish energy facilities. The UK also sanctioned those linked to Lumma Stealer malware, which has affected over 2,100 UK victims. The measures are part of a broader response to Russian cyber threats.
2026-07-13 | The Register: EU and UK officially blame Russian spies for cyberattack on Poland's power grid
The UK and EU attributed a December 2025 cyberattack on Poland's power grid to Russia's FSB, which could have left half a million without power. The attack aimed to deploy DynoWiper malware but failed. The UK NCSC issued a technical advisory urging critical infrastructure sectors to implement mitigations, including disabling SNMPv1/v2 and using SNMPv3. Fresh sanctions target Russian individuals and entities involved in cyber operations, including those linked to Lumma Stealer malware.
2026-07-13 | Cyberscoop: Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’
European governments sanctioned Russian individuals and organizations for a long-term cyberespionage campaign linked to the Turla group, controlled by Russia's FSB. The EU targeted nine individuals and four entities, citing attacks on various countries since 2010, including a significant incident affecting Poland's energy grid. The UK coordinated sanctions against 24 individuals, including GRU leaders, for hybrid cyberattacks. The EU also sanctioned the company behind Russia's Max messaging app for surveillance use.
2026-07-13 | Ars Technica: The US government warns that Russia state hackers are coming after your router
The US government warns that Russian state hackers are targeting home and small office routers to compromise them for malicious activities against sensitive organizations. The Cybersecurity and Infrastructure Security Agency (CISA) highlighted that these hackers exploit poorly configured devices, particularly through active Simple Network Management Protocol (SNMP) agents. The advisory was co-issued with global partners, emphasizing the ongoing threat from various hacking groups and the challenges in mitigating these attacks.
2026-07-13 | SC Magazine: UK and EU attribute Poland power grid attack to Russia's FSB, urge critical infrastructure action
The UK and EU have attributed a December 2025 cyberattack on Poland's power grid to Russia's FSB, specifically its Centre 16 division. The attack aimed to disrupt communication between renewable energy hardware and power distribution but was ultimately unsuccessful. The attackers attempted to deploy DynoWiper malware. Key recommendations include disabling SNMPv1/v2 for SNMPv3 and disabling Cisco Smart Install. Fresh sanctions have been imposed on Russian individuals and entities involved in cyber operations.
2026-07-14 | CSO Online: Governments to enterprises: Improve your router security hygiene
Global security agencies warn enterprises to enhance router security as Russian-sponsored attackers exploit vulnerabilities. A multinational advisory highlights that cybercriminals target poorly configured network devices, particularly routers, to compromise critical infrastructure. Attackers scan for weak devices and transfer valuable configuration files to their servers, which may contain plaintext credentials and network details. Recommendations for improving security hygiene are emphasized to mitigate these risks.
2026-07-14 | Cyber Security News: UK and Allies Warn of Russian Hackers Actively Hacking Organizations’ Routers Worldwide
The UK and allied nations have issued a warning about Russian state-backed hackers, specifically Center 16, targeting poorly secured routers globally. The advisory highlights the exploitation of weak configurations and known vulnerabilities, particularly in SNMP. The group has targeted critical infrastructure across various sectors. Recommendations include upgrading to SNMPv3, using complex passwords, and restricting access. The warning coincides with sanctions against individuals linked to Russian cyber operations and attribution of a cyberattack on Poland's energy grid to Center 16.
Date: 2026-07-13 | Source: TechRadar
Lidl confirmed a cyberattack on a third-party IT service provider that exposed customer data, including names, phone numbers, emails, dates of birth, and customer numbers. Passwords and payment details were not compromised. The incident was reported to authorities, and forensic experts are investigating. Lidl urges customers to be vigilant against potential phishing attempts and identity fraud. The company operates approximately 12,900 stores across 32 countries.

2026-07-13 | Help Net Security: Hackers breach Lidl’s IT service provider, steal customer data
Hackers breached Lidl's IT service provider, compromising customer data in Germany, Belgium, and the Netherlands. Lidl reported that attackers accessed a file containing names, phone numbers, email addresses, dates of birth, customer numbers, and salutations. While passwords and payment information may have been exposed, customer accounts remain unaffected. Lidl has engaged forensic experts, filed a police report, and notified data protection authorities. No evidence of data misuse has been found yet.
2026-07-13 | Security Affairs: Lidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data Breach
Lidl notified online shop customers in Germany, Belgium, and the Netherlands of a data breach involving personal data stolen from a third-party IT service provider. The breach, discovered in early July 2026, affected customer names, phone numbers, email addresses, dates of birth, and customer numbers, but not payment data. Lidl informed the Dutch Data Protection Authority and is investigating with forensic experts. Customers are advised to be cautious of phishing attempts following the breach.
2026-07-13 | SC Magazine: Lidl reports data breach affecting online customers in Germany, Belgium, and the Netherlands
Lidl reported a data breach affecting online customers in Germany, Belgium, and the Netherlands due to a cyberattack on an external IT service provider. Discovered early last week, unauthorized access to a file revealed personal customer information, including names, phone numbers, email addresses, and dates of birth. Payment data was not compromised. Lidl has notified affected customers and relevant authorities. The service provider is investigating, and customers are advised to be cautious of potential phishing attempts.
2026-07-13 | Recorded Future: Hackers steal Lidl customer data from external service provider
Hackers accessed Lidl's customer data through a third-party IT service provider, affecting online shop customers in Germany, Belgium, and the Netherlands. The breach involved customer titles, names, phone numbers, email addresses, dates of birth, and customer numbers, but no payment information was compromised. Lidl has filed a criminal complaint and alerted data protection authorities. Customers are advised to be vigilant against phishing and identity theft attempts due to the exposed data. The affected service provider and the number of impacted customers remain undisclosed.
2026-07-14 | Infosecurity Magazine: Lidl Notifies Customers of Third-Party Data Breach
Lidl has informed customers in Germany, Belgium, and the Netherlands of a data breach involving a third-party IT provider, which may have resulted in the theft of personal information including names, phone numbers, email addresses, dates of birth, and customer numbers. No payment information was compromised. Lidl has engaged forensic experts and warned customers to be vigilant against potential phishing attacks. Security expert Boris Cipot emphasized the importance of changing passwords and monitoring financial statements.
Date: 2026-07-11 | Source: Security Affairs
U.S. CISA has added two vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms). CVE-2026-48939, with a CVSS score of 10.0, allows arbitrary file uploads leading to PHP code execution. CVE-2026-56291 enables unauthenticated file uploads, resulting in full remote code execution. Federal agencies must address these vulnerabilities by July 13, 2026, and private organizations are advised to review and mitigate these risks.

2026-07-13 | The Hacker News: iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
The U.S. CISA has added two critical vulnerabilities affecting Joomla extensions iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291) to its KEV catalog due to reported zero-day exploitation. CVE-2026-48939 allows arbitrary file uploads leading to PHP code execution, while CVE-2026-56291 permits unauthenticated file uploads, enabling remote code execution. Patches are available, and site owners are advised to check for suspicious files. The Australian Cyber Security Centre warns of a global campaign targeting CMS vulnerabilities.
2026-07-13 | Security Affairs: Australia Alerts Organizations to Ongoing CMS Exploitation Attacks
Australia's Signals Directorate warns of a global campaign exploiting CMS vulnerabilities, particularly affecting WordPress and Joomla, with many small to medium Australian businesses impacted. Attackers deploy webshells via known vulnerabilities, allowing remote access and broader network compromises. The alert lists 17 CVEs across various plugins and CMS platforms. Recommendations include checking for unexpected files, reviewing access logs, and implementing read-only configurations for web directories.
2026-07-13 | Infosecurity Magazine: Australian Cyber Agency Warns of Global CMS Exploitation Campaign
The Australian Cyber Security Centre (ACSC) warned on July 9 of a global campaign targeting vulnerabilities in content management systems (CMS), affecting many SMBs in Australia. Malicious actors are scanning for vulnerabilities allowing unauthenticated file uploads and remote code execution. Exploited products include WordPress and Joomla. The ACSC advised website owners to inspect for webshells, audit logs, patch vulnerabilities, and restore from backups to enhance security.
2026-07-13 | Cyber Security News: CISA Warns of Joomla Sites Running iCagenda or Balbooa Exploited in Attacks
CISA has added two Joomla extension vulnerabilities, CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms), to its KEV Catalog due to active exploitation. Both allow unrestricted file uploads, enabling attackers to execute malicious files and gain control of Joomla sites. CISA urges immediate patching and recommends restricting upload functionality and public access if patches are unavailable. Organizations should investigate for signs of compromise and review logs for unusual activity.
2026-07-13 | SC Magazine: CISA adds iCagenda and Balbooa Forms vulnerabilities to known exploited catalog
CISA has added two critical vulnerabilities, CVE-2026-48939 for iCagenda and CVE-2026-56291 for Balbooa Forms, to its Known Exploited Vulnerabilities catalog. Federal agencies must address these by July 13, 2026. Both vulnerabilities allow unrestricted file uploads, enabling remote code execution. iCagenda is an open-source event management extension, while Balbooa Forms is a commercial form builder. CVE-2026-48939 has a CVSS score of 10.0, indicating a significant risk. Private organizations are advised to patch their systems.
2026-07-13 | SC Magazine: Australian businesses targeted in global content management system exploitation campaign
A global exploitation campaign is targeting content management systems (CMS) and plugins, affecting numerous Australian businesses. The Australian Cyber Security Centre (ACSC) warns that threat actors are deploying webshells on compromised sites, risking service disruptions and data theft. Vulnerabilities in platforms like WordPress and Joomla, and plugins such as Simple File List and Ninja Forms, are being exploited. Administrators are urged to apply security updates, remove unused plugins, and enhance security measures.
2026-07-14 | The Register: Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites
CISA has added two critical Joomla extension vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms), both scoring 10 on the CVSS scale. Attackers exploited these flaws to upload malicious PHP files, gaining remote control of affected sites. Federal agencies were directed to patch these vulnerabilities, with fixes available in versions 4.0.8 (iCagenda) and 2.4.1 (Balbooa Forms). Exploitation continues on unpatched sites.
Date: 2026-07-10 | Source: Recorded Future
Karen Serobovich Vardanyan pleaded guilty in Oregon for deploying Ryuk ransomware from November 2019, facing up to five years in prison and over $1.1 million in restitution. He attacked a Michigan company that paid 200 bitcoin for network access. Angelo Martino received a 70-month sentence for aiding Blackcat/AlphV in extortion, leveraging his negotiation experience. DigitalMint has implemented new controls for ransomware negotiations following the incidents. Sentencing for Vardanyan is set for September 22.

2026-07-10 | Cyberscoop: Armenian national pleads guilty to Ryuk ransomware attacks
An Armenian national, Karen Serobovich Vardanyan, pleaded guilty to participating in Ryuk ransomware attacks against three U.S. organizations from November 2019 to April 2020. He faces up to 15 years in prison and agreed to pay nearly $1.2 million in restitution. Vardanyan and his co-conspirators extorted over $15 million in ransom payments, primarily in Bitcoin. The U.S. District Court for the District of Oregon has not yet scheduled his sentencing.
2026-07-10 | SC Magazine: Armenian man pleads guilty to deploying Ryuk ransomware
Karen Serobovich Vardanyan, a 34-year-old Armenian, pleaded guilty in the U.S. for deploying Ryuk ransomware. Extradited from Kyiv after his April 2025 arrest, he and co-conspirators accessed U.S. networks from November 2019 to April 2020, encrypting systems and extorting over $1.1 million in Bitcoin from a Michigan company, among others. The group earned approximately 1,610 bitcoins, valued at around $15 million. Vardanyan faces up to 15 years in prison and will be sentenced in September 2026.
2026-07-12 | Security Affairs: Ryuk Ransomware Member Pleads Guilty Over Attacks on U.S. Organizations
Karen Serobovich Vardanyan, a 34-year-old Armenian national, pleaded guilty in the U.S. for his involvement in Ryuk ransomware attacks targeting American organizations from 2019 to 2020. Extradited from Ukraine, he admitted to providing initial access for deploying ransomware, affecting hundreds of servers and workstations. Victims included a Michigan company that paid 200 Bitcoin and a school in Texas. Vardanyan faces up to 15 years in prison and must pay over $1.1 million in restitution, with sentencing set for September 22, 2026.
2026-07-13 | Infosecurity Magazine: Hacker Extradited from Ukraine Pleads Guilty to Ryuk Ransomware Charges
Karen Serobovich Vardanyan, an Armenian national extradited from Ukraine, pleaded guilty on July 8 to conspiracy and computer fraud related to the Ryuk ransomware. Between November 2019 and April 2020, he accessed US organizations' computers, leading to over $15m in ransom payments, including 200 bitcoin from a Michigan company. Vardanyan faces up to 15 years in prison and has agreed to pay over $1.1m in restitution. Ryuk was active from 2018 to 2020, targeting various sectors.
Date: 2026-07-10 | Source: The Hacker News
Progress Software has advised ShareFile customers to shut down their Storage Zone Controllers due to a "credible external security threat." Access to affected accounts has been temporarily disabled. Progress has not disclosed the nature of the threat or any potential unauthorized access to data. Customers are instructed to keep the controllers offline until further notice, confirm their software versions, and initiate incident response procedures. The situation is under investigation as of July 10.

2026-07-10 | SC Magazine: Progress Software warns ShareFile users of external security threat
Progress Software has warned ShareFile users to shut down their Storage Zone Controllers due to a credible external security threat. While there is no evidence of unauthorized access, the company has implemented temporary restrictions. Users are advised that disabling access through the ShareFile cloud is not enough; manual shutdown of the servers is essential. Progress is collaborating with cybersecurity experts to investigate and will provide updates within 24 hours. No details on potential vulnerabilities or compromises have been disclosed.
2026-07-12 | Security Affairs: Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here’s What We Know.
Progress Software advised ShareFile Storage Zone customers to immediately shut down their internet-facing Windows servers due to a credible external security threat. This urgent action was communicated via email on July 10, 2026, and affects only hybrid deployments using Storage Zone Controllers, not cloud-only accounts. Progress is investigating the threat but has not disclosed specific details or whether any systems were compromised. The company emphasized this measure as critical for data safety.
2026-07-13 | The Register: Progress orders emergency ShareFile server shutdown over mystery security threat
Progress Software has ordered ShareFile customers to shut down their Storage Zone Controllers due to a "credible external security threat." The company stated there is no evidence of unauthorized access but emphasized that this precaution is necessary for data safety. Customers were instructed to keep the servers offline while investigations continue. The nature of the threat remains undisclosed, and no patches or workarounds are available. This incident follows previous vulnerabilities in ShareFile that allowed remote code execution.
2026-07-13 | Help Net Security: Security threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers
On July 10, Progress Software disabled ShareFile accounts using Storage Zone Controllers due to a credible external security threat. Customers were advised to shut down their servers. As of July 11, there was no indication of unauthorized access to any accounts or data. The company is investigating the issue and has begun restoring access while asking customers to keep their servers disabled. The potential cause may involve vulnerabilities CVE-2026-2699 and CVE-2026-2701, which could allow remote code execution.
2026-07-13 | Infosecurity Magazine: Progress Software Warns of "External Security Threat" to ShareFile
Progress Software warned of a credible external security threat to its ShareFile Storage Zone Controllers on July 10, 2023. While no unauthorized access to ShareFile accounts has been confirmed, access was temporarily disabled, and users were advised to shut down their servers. Investigations are ongoing, and updates were lacking as of July 13. Progress stated that access to the ShareFile cloud service was restored on July 12, but Storage Zone Controllers must remain off during the investigation.
Date: 2026-07-10 | Source: Cybersecurity Dive
A contractor for CISA accidentally leaked private cloud access keys and sensitive credentials by uploading a CISA repository to their personal GitHub account. CISA took immediate action upon learning of the leak, confirming no unauthorized use of the credentials. The agency updated all passwords and cloud access keys, improved logging capabilities, and established stricter controls on public repository uploads. CISA acknowledged its failures and is refining incident reporting channels to enhance transparency and trust in cybersecurity.

2026-07-10 | Infosecurity Magazine: CISA Details Incident Response to Exposed AWS GovCloud Keys
The US Cybersecurity and Infrastructure Security Agency (CISA) responded to the exposure of AWS GovCloud keys in a personal GitHub repository owned by a contractor, identified on May 15. CISA took immediate action to mitigate risks, confirming no customer data was leaked. The incident emphasized the need for zero trust principles, improved logging, and tighter controls on public repository access. CISA plans to enhance security researcher reporting channels and strengthen developer environment security and key management practices.
2026-07-10 | Cyberscoop: CISA looks to remedy ailments from big May credential leak
CISA's forensic report details its response to a significant credential leak involving privileged AWS GovCloud keys discovered in May. The agency took immediate action by taking down the affected repository and revoking access for the responsible contractor. CISA confirmed no customer data was exposed and emphasized the importance of incident response sharing. Improvements include enhanced monitoring of public repository uploads, rotating secrets, and developing incident playbooks. GitGuardian's Guillaume Valadon praised CISA's proactive evaluation and commitment to better researcher relations.
2026-07-10 | SC Magazine: CISA shares postmortem of GitHub credential leak
In May, CISA experienced a credential leak when a contractor's public GitHub repository, titled "Private-CISA," exposed sensitive information, including AWS GovCloud keys and plaintext credentials for internal systems. Discovered by GitGuardian and reported by Brian Krebs, the repository was removed after CISA was notified. The incident revealed weaknesses in CISA's processes, prompting improvements in secret monitoring, incident reporting, and credential management. CISA emphasized the need for better oversight and transparency in cybersecurity practices.
2026-07-11 | TechCrunch: US cybersecurity agency CISA had to build its incident playbook during the incident, agency reveals
In May, CISA revealed it lacked a prepared incident response plan when a contractor exposed sensitive keys for U.S. government systems. Staff had to create a playbook during the incident, highlighting the need for pre-prepared responses. A security researcher alerted CISA after discovering exposed passwords on GitHub. CISA took the repository offline and replaced the credentials, confirming no customer data was compromised. The agency acknowledged its notification channels for researchers were inadequate and has since improved them.
2026-07-11 | Cyber Security News: CISA Details “Lessons from a Cyber Incident” After AWS GovCloud Credentials Leak
On May 15, CISA disclosed an incident where a contractor exposed AWS GovCloud credentials in a public GitHub account. The agency quickly contained the exposure, confirming no external misuse or data loss. An after-action review highlighted strengths in rapid response but identified gaps in public repo controls, secrets management, and incident playbooks. CISA emphasized the need for improved credential hygiene training for contractors and transparency to enhance trust and provide actionable insights for other organizations.
2026-07-13 | Krebs on Security: Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) reported on a data leak where a contractor exposed sensitive credentials, including AWS GovCloud keys, on GitHub for nearly six months. CISA took over 48 hours to invalidate the keys after being notified. The agency acknowledged gaps in its incident response and is refining reporting channels for external notifications. CISA emphasized the need for continuous scanning of public repositories for exposed secrets and has since rotated all compromised credentials.
Date: 2026-07-10 | Source: Recorded Future
Hacking groups linked to China and India conducted espionage operations against the Balochistan Police in Pakistan from February 2024 to April 2026. The compromised systems contained sensitive data, including criminal records and biometric information. China's interest was tied to protecting nationals involved in the China-Pakistan Economic Corridor, while India's activity was linked to regional rivalry. Malware disguised as a portal update was used in the attacks, exposing both police and public users.

2026-07-11 | The Hacker News: Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Cybersecurity researchers revealed a cyber espionage campaign targeting Pakistani law enforcement, particularly the Balochistan Police, from February 2024 to April 2026. Compromised assets included servers managing sensitive data. Four threat clusters were identified, utilizing malware like PlugX and ShadowPad, linked to China-aligned actors, and Remcos RAT, associated with India. The Complaint Management System was exploited to deploy malware, highlighting the geopolitical motives behind the attacks.
2026-07-13 | SC Magazine: China and India-linked threat actors target Pakistani law enforcement
SentinelOne researchers reported ongoing cyber espionage targeting Pakistani law enforcement from February 2024 to April 2026, attributed to China- and India-aligned threat actors. Compromised assets included servers managing critical data like criminal records. A custom implant was deployed on the Complaint Management System. Affected organizations include Balochistan Police and Punjab Safe Cities Authority. Malware families involved are PlugX, ShadowPad, Cobalt Strike, and Remcos RAT, indicating a high value on internal security information.
2026-07-13 | Infosecurity Magazine: Pakistani Police Systems Hit by Chinese and Indian Espionage
Between February 2024 and April 2026, Chinese and Indian cyber espionage operations targeted the Balochistan Police in Pakistan, compromising systems containing biometric records, criminal case files, and tenant registrations. SentinelLabs identified four clusters of command and control activity, with tools like PlugX and Cobalt Strike linked to China, and Remcos to India. Notably, the Complaint Management System was breached, exposing sensitive police and citizen data. This incident highlights the risks of centralized digital policing systems.
Date: 2026-07-10 | Source: Cyber Security News
A security analysis by Binarly Research identified six critical vulnerabilities in the U-Boot bootloader, affecting embedded systems and server management platforms. These flaws (BRLY-2026-037 to BRLY-2026-042) enable denial-of-service (DoS) attacks and arbitrary code execution. They stem from improper handling of untrusted boot images and can be exploited remotely via insecure firmware update mechanisms. Patches have been provided, and organizations are urged to update to mitigate risks associated with these vulnerabilities.

2026-07-10 | The Hacker News: Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
Researchers at Binarly identified six vulnerabilities in U-Boot, affecting devices like routers and smart cameras. Two flaws (BRLY-2026-037 and BRLY-2026-038) allow code execution via unchecked values, while four others cause crashes. The issues stem from code present since v2013.07, impacting over 50 releases. No CVEs are assigned yet. Vendors are urged to implement upstream fixes immediately, as the next stable release is not due until October. Recovery from exploitation may require physical access.
2026-07-11 | Security Affairs: Critical U-Boot Bugs Undermine Secure Boot on Millions of Devices
Six critical vulnerabilities in U-Boot, discovered by Binarly, affect over 50 releases, enabling arbitrary code execution and denial-of-service conditions during boot image verification. The flaws, present since version v2013.07, include issues with NULL pointer dereferences and unchecked image boundaries. Exploiting these vulnerabilities could compromise devices before the OS loads. Patches have been accepted upstream; organizations should apply them promptly through vendor firmware updates.
2026-07-13 | SC Magazine: Six U-Boot vulnerabilities could allow stealthy firmware attacks
Six vulnerabilities in the U-Boot bootloader could enable stealthy firmware attacks, allowing attackers to execute code during device boot. The flaws, affecting over 50 stable releases, include denial of service and arbitrary code execution, with two allowing pre-OS malicious code execution. Exploitation may not require physical access. Binarly reported the vulnerabilities and provided patches, now accepted upstream, but older or unsupported devices may remain unpatched.
Date: 2026-07-09 | Source: Cyber Security News
Microsoft has expanded its AI capabilities for vulnerability discovery with MDASH, a multi-model scanning system that identifies and patches security flaws in Windows. In May 2026, MDASH disclosed 16 new CVEs, including four critical RCE vulnerabilities. It achieved 96% and 100% recall on specific components during validation tests. The system enhances remediation workflows and integrates with Microsoft Defender. The June 2026 Patch Tuesday saw over 200 vulnerabilities patched, indicating the effectiveness of this proactive approach. Enterprises are advised to stay current and utilize tools like Windows Autopatch.

2026-07-10 | The Register: Microsoft warns customers AI will mean busier Patch Tuesdays
Microsoft has announced that customers should anticipate an increase in security patches due to the integration of AI in vulnerability discovery. Pavan Davuluri highlighted that AI enhances the identification and prioritization of risks, leading to more frequent updates. Microsoft employs a tool called MDASH for scanning and validating vulnerabilities, which helps reduce false positives. This approach aims to shorten the review process and minimize the attack window for zero-day exploits. Oracle is also adopting AI for similar purposes.
2026-07-10 | Help Net Security: Microsoft is rewriting Windows patch guidance because of AI
Microsoft advises organizations to shorten Windows update deployment timelines due to AI advancements that enable faster exploitation of vulnerabilities. It recommends a quality update deferral of fewer than three days, with update deadlines of zero or one day. The new Windows Autopatch report in Microsoft Intune identifies unpatched devices, allowing for tighter update policies. Additionally, using Hotpatch for security updates without reboots and enforcing Conditional Access policies can further reduce risks from unpatched systems.
2026-07-10 | Infosecurity Magazine: Microsoft Warns of Increase in Number of Security Updates
Microsoft announced on July 9 an expected increase in security updates for Windows, driven by AI techniques to identify zero-day vulnerabilities. The new multi-model agentic scanning (MDASH) approach utilizes dedicated cloud infrastructure to enhance vulnerability discovery and reduce false positives. Microsoft is also updating its Secure Development Lifecycle (SDL) practices to address AI-enabled threats while ensuring human oversight. Meanwhile, concerns persist about the effectiveness of fully automated vulnerability scanning tools.
Date: 2026-07-09 | Source: Microsoft Security
GigaWiper, identified by Microsoft Threat Intelligence in October 2025, is a sophisticated Golang-based backdoor that combines multiple destructive capabilities, including disk wiping and file encryption. It operates at the physical disk level, overwriting data and removing partition metadata. GigaWiper integrates features from previous malware families like Crucio and FlockWiper, allowing for flexible command execution and persistent control. Recommendations for defense include enabling tamper protection, blocking known C2 infrastructure, and utilizing endpoint detection tools.

2026-07-09 | The Hacker News: New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Microsoft has identified GigaWiper, a destructive Windows backdoor that combines three older malware tools to wipe disks, simulate ransomware, and spy on users. It can overwrite drives, encrypt files without a recovery key, and take screenshots or control infected PCs. Linked to an Iran-nexus group targeting Israeli organizations, it disguises itself as OneDrive. Recommendations include monitoring for specific scheduled tasks, blocking known command servers, and enabling tamper protection and endpoint detection.
2026-07-09 | Hack Read: Microsoft Warns of GigaWiper Backdoor Built to Destroy Windows PCs
Microsoft has identified a destructive Windows backdoor named GigaWiper, which allows remote control over infected PCs and can trigger permanent system damage. Discovered during attacks in October 2025, GigaWiper combines code from multiple malware families. It can overwrite drives, encrypt files without recovery options, and perform various system management tasks. Microsoft recommends enabling tamper protection and monitoring for suspicious activities to mitigate risks associated with GigaWiper.
2026-07-09 | SC Magazine: Microsoft details GigaWiper destructive backdoor assembled from older tools
Microsoft has detailed GigaWiper, a destructive Windows backdoor that combines three tools into a modular package. Deployed post-initial access, it includes a raw disk wiper, a fake ransomware module that encrypts files irrecoverably, and a wiper for the Windows drive. Written in Go, it disguises itself as OneDrive and uses legitimate services for command and control. GigaWiper can take screenshots, record activity, and manipulate logs, with links to Iranian groups targeting Israeli organizations.
2026-07-10 | Security Affairs: GigaWiper Merges Three Malware Families Into One Destructive Backdoor
Microsoft identified GigaWiper, a modular Go backdoor that merges three malware families, featuring espionage, remote control, and destructive wiping capabilities. It communicates via RabbitMQ and Redis, maintaining persistence through a scheduled task. GigaWiper can execute various destructive commands, including wiping disks and encrypting files without recovery options. The backdoor allows for remote control and system information collection. Microsoft recommends enabling tamper protection, running endpoint detection in block mode, and blocking access to its C2 infrastructure at 185.182.193[.]21.
2026-07-10 | Cyber Security News: GigaWiper Malware Attacking Windows Systems With Data Wipers and Fake Ransomware Notices
GigaWiper is a newly identified Windows malware that erases disks and scrambles files, rendering them unrecoverable. First observed in October 2025, it combines destructive capabilities with backdoor functions, allowing remote control and surveillance. GigaWiper encrypts files with no recovery option, mimicking ransomware. Organizations should treat intrusions as emergencies, isolate affected devices, and ensure robust backup and recovery plans. Indicators of compromise include specific SHA-256 hashes and command and control IP addresses.
2026-07-10 | CSO Online: Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand
Microsoft has identified GigaWiper, a backdoor that merges espionage and destructive capabilities. First detected in October 2025, this Golang-based implant features remote administration functions alongside disk-wiping and ransomware routines. GigaWiper is constructed from various existing malware families, integrating them as modular commands within one backdoor. Microsoft Threat Intelligence issued a warning to defenders regarding this emerging threat.
2026-07-10 | Malwarebytes Labs: This new Windows malware can take over your PC and wipe it clean
Microsoft's research reveals GigaWiper, a modular Golang backdoor for Windows, observed in intrusions since October 2025. It combines remote access, data destruction, and espionage features, including screen capture and VNC-like control. GigaWiper employs about 20 commands for destruction and monitoring, including a raw disk wiper and a fake ransomware variant. Command-and-control servers were identified, and Malwarebytes can block connections. Recommendations include disconnecting infected machines and monitoring for suspicious activity.
2026-07-10 | Infosecurity Magazine: Microsoft Warns New 'GigaWiper' Malware Combines Espionage and Destructive Capabilities
Microsoft's July 9 analysis reveals GigaWiper, a new multi-purpose malware backdoor combining espionage and destructive capabilities. Detected in October 2025, it integrates features from Crucio ransomware and FlockWiper, enabling control over infected systems and executing destructive commands. GigaWiper includes standalone wipers and a ransomware variant that encrypts files irreversibly. Microsoft recommends enabling tamper protection, blocking C2 access, and activating cloud-delivered antivirus protection to mitigate risks.
2026-07-10 | TechRadar: Microsoft discovers new multi-malware package 'GigaWiper' capable of deploying wipers and ransomware
Microsoft has identified a new malware called "GigaWiper," attributed to the Iranian group CyberAv3ngers. This multi-malware package can wipe drives, encrypt files with a .candy extension, and overwrite Windows partitions, while also spying on victims through screenshots and VNC sessions. GigaWiper disguises itself as a OneDrive task, complicating detection. It offers no recovery options for victims, as it does not generate a decryption key or ransom note.
2026-07-10 | The Register: Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
Microsoft has identified a new destructive Windows backdoor named GigaWiper, which combines ransomware-like encryption with multiple data-wiping features. First spotted in October, GigaWiper includes two types of samples: one that overwrites raw disk content and another that establishes persistence and command-and-control communication. It integrates components from at least three malware families, enabling various destructive capabilities, including file encryption with no decryption possibility and remote system control.
Date: 2026-07-09 | Source: Help Net Security
The Pink cyber extortion crew is targeting employees by impersonating IT staff and tricking them into providing access to their Microsoft 365 accounts through fake Entra passkey enrollment requests. The attackers use vishing calls and a phishing kit to mimic the Microsoft login process, capturing credentials and multi-factor authentication inputs. Once access is gained, they exfiltrate data and initiate extortion attempts. This campaign has affected various industries, including healthcare and technology.

2026-07-09 | Cyber Security News: Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts
Cybercriminals, identified as O UNC 066 (Pink), are exploiting Microsoft Entra passkey enrollment to hijack corporate accounts through a phone-based phishing campaign that began in April 2026. Attackers impersonate IT support, convincing employees to register a malicious passkey via a fake login page. This method bypasses MFA by using victims as proxies. Affected industries include food, tech, healthcare, and more. Recommendations include using phishing-resistant authenticators, staff training, and monitoring authenticator lifecycle events.
2026-07-10 | The Hacker News: Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
A threat actor, tracked as O-UNC-066, is executing voice-based phishing attacks targeting Microsoft 365 users across various sectors, prompting them to enroll new Entra passkeys. The phishing kit mimics the legitimate enrollment process, allowing attackers to register their own passkeys and gain unauthorized access. The kit adapts to user MFA requirements in real-time, facilitating credential theft and account takeover. This activity coincides with Microsoft’s push for passkey adoption, exploiting user unfamiliarity with the process.
2026-07-10 | SC Magazine: Okta warns of vishing scheme that extorts data
Okta reported a vishing scheme by threat actor O-UNC-066, targeting Microsoft 365 passkey enrollment since April 2026. Attackers impersonate IT staff, convincing users to enroll a passkey they control, leading to account takeovers. This method bypasses traditional MFA, focusing on social engineering. Affected sectors include food, technology, healthcare, and more. Recommendations include training employees to reject unsolicited calls, restricting passkey registration to compliant networks, and monitoring for unusual registration events.
Date: 2026-07-09 | Source: Wired
The European Parliament voted to extend legislation allowing tech companies like Meta, Google, and Microsoft to scan private messages for child sexual abuse material, despite a majority opposing it. This "Chat Control" bill reinstates permissions until 2028, exempting end-to-end encrypted chats. Critics argue it undermines privacy and democracy, with civil rights activists condemning the ruling as ineffective and harmful. The legislation was pushed through using an urgent procedure, bypassing typical debate processes.

2026-07-09 | The Register: EU 'Chat Control' snoopfest returns after vote to kill it falls short
The European Parliament's attempt to block the reintroduction of the interim CSAM-scanning rule, known as Chat Control, failed as it did not meet the required 360-seat threshold. Despite 314 votes against it, the rule will move forward, allowing tech companies to scan for child sexual abuse material. A separate vote to limit scanning to judicially identified accounts also failed. The legislation will now be sent to the Council of the European Union for approval, potentially valid until 2028.
2026-07-09 | SC Magazine: EU moves closer to reviving CSAM scanning law after parliamentary vote
The European Parliament has voted to advance a bill allowing tech companies to scan for child sexual abuse material, following a previous rejection in March. This move, driven by the European People's Party, aims to enhance child protection online, though it raises privacy concerns. An amendment exempts end-to-end encrypted services like WhatsApp and Signal from scanning. The Council will review the amendments, with potential deadlock anticipated if encryption-related changes are not accepted.
2026-07-10 | Recorded Future: Europe revives law allowing big tech to scan for CSAM
The European Parliament has reinstated a law permitting big tech companies to scan user messages for child sexual abuse material (CSAM), despite privacy concerns. This decision, made before the summer recess, allows firms like Google, Microsoft, and Meta to continue scans until 2028. Critics argue this undermines privacy and enables warrantless surveillance. Ongoing negotiations aim to establish a permanent framework, but progress has been slow, with significant opposition to potential expansions of scanning capabilities.
Date: 2026-07-09 | Source: CSO Online
A cloud intrusion involving an AWS EC2 instance linked to Amazon Bedrock resulted in the deployment of XMRig cryptomining malware. Researchers from Darktrace highlighted the risk posed by AI gateways that centralize access to cloud identities, permissions, and foundation models, making them attractive targets for attackers. While the immediate impact was cryptomining, the broader concern is the potential abuse of cloud identities and AI services due to the concentration of privileges in these systems.

2026-07-09 | Hack Read: AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining
An Amazon EC2 instance named “LiteLLM-Proxy,” connected to Amazon Bedrock, was compromised for cryptomining, specifically Monero (XMR). The incident was attributed to an open SSH port (22) accessible from the public internet, allowing potential unauthorized access. The instance downloaded XMRig, a cryptocurrency miner, and began connecting to a mining pool. Darktrace emphasized the risk of compromising AI gateways, which could expose sensitive credentials and permissions. Recommendations include closing public access and monitoring model activity.
2026-07-10 | Cyber Security News: Hackers are Turning AI Gateways as Attack Surfaces to Compromise Enterprise Networks
Hackers are increasingly targeting AI gateways, such as the compromised Amazon EC2 instance "LiteLLM-Proxy," which connected to Amazon Bedrock. The investigation by Darktrace, initiated on June 12, 2026, revealed that the instance exposed SSH (port 22) to the internet, allowing potential brute-force access. The server downloaded XMRig cryptomining malware and connected to a mining pool. Suspicious IAM activity was also detected, indicating possible credential misuse. Organizations are advised to restrict SSH access and apply least-privilege IAM policies.
2026-07-13 | TechRadar: 'Cryptomining can be a lucrative post-compromise activity in cloud environments': Experts warn AI gateways connected to Amazon Bedrock are being hijacked to steal crypto
Experts from Darktrace report a cryptojacking incident involving a compromised AI gateway (LiteLLM-Proxy) on AWS Bedrock, accessed via exposed SSH. Attackers utilized XMRig for cryptocurrency mining, triggering alarms due to suspicious IAM activity linked to a user account traced to Vietnam. Recommendations include enforcing strict port closures, implementing least-privilege roles, and monitoring control-plane activities to mitigate risks associated with such breaches.
Date: 2026-07-09 | Source: US Department of Justice
Angelo Martino, 41, was sentenced to 70 months in prison for conspiring with BlackCat ransomware actors to extort multiple victims and for aiding in attacks against additional targets in 2023. He abused his role at a cyber incident response company, providing confidential information to maximize ransoms. Law enforcement seized over $10 million in assets from Martino. This case is part of Operation Riptide, targeting cybercrime and its financial networks.

2026-07-10 | Cyberscoop: Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
Angelo John Martino III, a former ransomware negotiator for DigitalMint, was sentenced to 70 months in prison for deceiving clients and conspiring with ransomware affiliates, extorting $75.3 million from five U.S. companies between April and September 2023. Martino shared confidential negotiation details with BlackCat affiliates to maximize ransom payments. DigitalMint claimed ignorance of his actions and terminated him upon investigation. Authorities seized $10 million in assets linked to Martino's crimes.
2026-07-10 | The Hacker News: Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
Angelo Martino, a 41-year-old former ransomware negotiator, was sentenced to 70 months in prison for conspiring with BlackCat ransomware operators to extort victims. He provided confidential negotiation details to the attackers, maximizing ransom amounts. Martino colluded with two other cybersecurity professionals to deploy BlackCat ransomware from April to November 2023. Law enforcement has seized $10 million in assets from him, and he will face restitution hearings on September 17, 2026.
2026-07-10 | Cyber Security News: Ransomware Negotiator Sentenced for BlackCat Ransomware Operators to Attack Victims
A former ransomware negotiator, Angelo Martino, was sentenced to 70 months in prison for conspiring with BlackCat/ALPHV ransomware operators. He provided sensitive information about U.S. victims to the group, enabling them to extort higher ransoms. Martino, along with two accomplices, extorted approximately $1 million in Bitcoin from victims. Law enforcement seized over $1 million in assets linked to the scheme. The case underscores the insider threat during ransomware response efforts.
2026-07-10 | Security Affairs: Former Ransomware Negotiator Sentenced to 70 Months in Prison for Secretly Helping BlackCat Gang
Former ransomware negotiator Angelo Martino was sentenced to 70 months in prison for conspiring with the BlackCat ransomware gang. While negotiating for five victims, he shared sensitive information with attackers, helping them increase ransom demands. Martino, along with co-conspirators Ryan Goldberg and Kevin Martin, extorted around $1.2M in Bitcoin from victims. Law enforcement seized $10M in assets from Martino, including cryptocurrency and luxury items. A restitution hearing is set for September 17, 2026.
2026-07-10 | Hack Read: Cybersecurity Negotiator Gets 70 Months for Helping BlackCat Extort Victims
Angelo Martino, a former ransomware negotiator, was sentenced to 70 months in prison for conspiring with the BlackCat ransomware group. He provided confidential information from companies seeking help, allowing the group to pressure victims into higher ransom payments. Martino, along with accomplices, executed ransomware attacks, resulting in a victim paying $1.2 million in Bitcoin. Federal authorities seized over $10 million in assets from him. The case highlights risks of insider access during ransomware negotiations.
2026-07-10 | TechCrunch: Florida ransomware negotiator convicted for helping ransomware gang extort US companies
Florida man Angelo Martino has been sentenced to over five years in prison for conspiring with hackers to deploy ransomware while working as a negotiator for a U.S. cybersecurity firm. The DOJ seized over $10 million in cryptocurrency and assets linked to the scheme. Martino, along with two other cybersecurity professionals, extorted companies using BlackCat ransomware, including a $1.2 million attack. This case underscores the risks of security professionals colluding with cybercriminals.
2026-07-10 | SC Magazine: Former ransomware negotiator sentenced to 70 months for extorting $75.3 million
Angelo John Martino III, a former ransomware negotiator for DigitalMint, was sentenced to 70 months in prison for extorting $75.3 million from five U.S. companies. He exploited his role by sharing confidential information with BlackCat affiliates. Victims included a nonprofit and a financial services company, with ransoms paid between April and September 2023. Martino's assets worth $10 million were seized, and he is set to return to court in September for restitution determination.
2026-07-13 | Help Net Security: Ransomware negotiator who betrayed clients sentenced to 70 months in prison
Angelo Martino, a former ransomware negotiator at DigitalMint, was sentenced to 70 months in prison for sharing confidential client information with the BlackCat ransomware group and aiding in attacks. Beginning in April 2023, he provided sensitive details that helped maximize ransom demands against five organizations. Martino, along with co-conspirators Ryan Goldberg and Kevin Martin, received about $1.2 million in Bitcoin from a victim. Federal investigators seized over $10 million in assets linked to Martino.
2026-07-13 | TechRadar: Ransomware negotiator jailed for 70 months after he just helped infect victims with malware
Ransomware negotiator Angelo Martino was sentenced to 70 months in prison for colluding with BlackCat (ALPHV) attackers, secretly aiding them while representing victims. He forfeits cryptocurrency earnings and assets, and must pay 10% of future salary post-release. Martino was the third negotiator exposed; his co-conspirators received four-year sentences. Their victims included a medical device company and a pharmaceutical firm, among others, with ransoms totaling millions.
2026-07-14 | Malwarebytes Labs: The inside job that cost ransomware victims millions
Angelo Martino, a ransomware negotiator at DigitalMint, was sentenced to 70 months in prison for conspiring with the BlackCat ransomware gang, leaking confidential client information to them. Between April and September 2023, five clients paid ransoms totaling over $75 million. Martino also conspired with colleagues to deploy BlackCat against additional victims. DigitalMint claimed ignorance of the scheme, raising concerns about their vetting and monitoring processes. A restitution hearing is set for September 17.
Date: 2026-07-09 | Source: Help Net Security
A four-month enforcement campaign, Operation First Light 2026, led to 5,811 arrests across 97 countries, targeting social engineering scams and money laundering. Investigators intercepted $293 million in illicit assets and froze 31,014 bank accounts. Notable cases include arrests in Eswatini for impersonation scams, a romance-scam laundering scheme in Thailand, and a $6.6 million transfer halt in Singapore linked to business email compromise. INTERPOL emphasizes the need for global cooperation against such crimes.

2026-07-09 | Infosecurity Magazine: Chinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 Arrests
A global anti-fraud operation, Operation First Light 2026, led to over 5,800 arrests and the interception of nearly $300 million in illicit assets from January 15 to April 30, 2026. Coordinated by Interpol and funded by China's Ministry of Public Security, the operation targeted social engineering scams, including romance scams and BEC schemes. Actions included freezing 31,014 bank accounts and seizing 240 electronic devices in Eswatini, where scammers posed as Brazilian police to deceive victims.
2026-07-09 | Cyberscoop: Interpol cybercrime crackdown nets 5,800 arrests across 97 countries
Authorities arrested over 5,800 alleged cybercriminals and seized $293 million in a global operation, Operation First Light, targeting social-engineering scams and money laundering across 97 countries. The operation identified over 142,000 victims and solved nearly 24,000 cybercrime cases, including business email compromise and romance scams. Investigators blocked more than 31,000 bank accounts linked to malicious activity and seized devices used in cybercrime.
2026-07-09 | Security Affairs: INTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 Million
INTERPOL's Operation First Light 2026, conducted from January 15 to April 30, resulted in 5,811 arrests and the seizure of $293 million in criminal assets across 97 countries. The operation targeted social engineering scams, including business email compromise and romance scams, identifying over 142,000 victims. Notable cases included arrests in Eswatini for illegal gambling and a money laundering scheme in Thailand involving $122.5 million in cryptocurrency. I-GRIP was used to block a $6.6 million transfer linked to a scam.
2026-07-10 | TechRadar: $293 million seized and 5,811 arrests made in huge anti-scam and fraud action by Interpol and law enforcement agencies across 97 countries
Interpol's Operation First Light 2026, conducted from January 15 to April 30, 2026, resulted in 5,811 arrests and the seizure of $239 million across 97 countries. Authorities analyzed 152,808 cases, blocked 31,014 bank accounts, and identified 15,606 suspects. Notable operations included a fake Brazilian police station in Eswatini and crypto laundering in Thailand. The operation targeted various scams, including business email compromise and identity theft, impacting over 142,000 victims globally.
Date: 2026-07-09 | Source: The Hacker News
A new ransomware family named GodDamn has emerged, utilizing the PoisonX kernel driver to disable security software. First spotted on May 21, 2026, it is a rebrand of the Beast ransomware. In early June, attackers used AnyDesk for remote access and a NirSoft credential harvester before deploying the ransomware. PoisonX, a malicious driver signed by Microsoft, allows attackers to kill antivirus processes. GodDamn's ransom note urges victims to contact via email or qTox.

2026-07-09 | Security Affairs: GodDamn Ransomware Uses PoisonX to Blind Security Software
GodDamn ransomware, identified by Symantec on July 9, 2026, uses the signed PoisonX driver to disable security software, marking an evolution of the Beast ransomware family. First detected on May 21, 2026, it employs tools like AnyDesk and credential stealers. The attack began with AnyDesk's manual delivery, followed by the deployment of PoisonX to disable defenses. Encryption was observed on June 3, with files renamed using the victim's name. Hyadina, the group behind it, continues to enhance its evasion techniques.
2026-07-09 | Cyber Security News: GodDamn Ransomware Rebrands From Beast and Uses PoisonX Driver to Disable Defenses
GodDamn ransomware, a rebrand of the Beast variant, utilizes the PoisonX kernel driver to disable security defenses before attacks. This driver, signed by Microsoft, allows attackers to evade detection at the kernel level. In a recent incident, attackers gained access to ten hosts over four days, using tools like PsExec and AnyDesk for lateral movement. Recommendations include monitoring for unauthorized kernel drivers and updating endpoint detection systems. Key IoCs include various file hashes and IP addresses associated with the attack.
2026-07-10 | SC Magazine: ‘GodDamn’ ransomware deploys PoisonX driver to kill EDR
A new ransomware variant, "GodDamn," analyzed by Symantec and Carbon Black, is a rebrand of Beast ransomware, utilizing a malicious driver called PoisonX to disable endpoint defenses. First observed on May 29, 2026, the attack involved credential-harvesting tools and lateral movement across the victim's network. PoisonX, signed by Microsoft, was used to evade detection. The ransomware binary was seen on June 3, encrypting files with extensions linked to the victim organization. The Hyadina group continues to evolve its tactics.
2026-07-10 | Infosecurity Magazine: New Ransomware Exploits Malicious Driver to Remove Cybersecurity Protections
The GodDamn ransomware, a new variant of the Hyadina family, exploits Microsoft-signed malicious drivers to evade cybersecurity defenses. First identified in May 2026, it uses a disguised executable to install PoisonX, a driver that terminates security processes. Attackers, leveraging tools like NirSoft and Mimikatz, steal credentials before encrypting files and demanding a ransom. This evolution in tactics highlights the ongoing development of ransomware capabilities, posing significant threats to organizations.
Date: 2026-07-09 | Source: Cyber Security News
Microsoft has released patches for a zero-day vulnerability in Microsoft Defender, tracked as CVE-2026-50656, which allows attackers to gain elevated privileges. The flaw, with a CVSS score of 7.8, affects versions of the Microsoft Malware Protection Engine prior to 1.1.26060.3008. Although no active exploitation has been reported, Microsoft warns that exploitation is likely. Organizations are advised to ensure automatic updates are functioning and to verify engine versions to mitigate risks associated with this vulnerability.

2026-07-09 | The Hacker News: Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Microsoft has patched a vulnerability in Defender, tracked as CVE-2026-50656 (CVSS score: 7.8), which allows privilege escalation via a race condition in the Microsoft Malware Protection Engine. This flaw could enable attackers to execute arbitrary code with SYSTEM-level privileges. The update is included in version 1.1.26060.3008, and no customer action is required for installation. This is the fourth vulnerability disclosed by researcher Chaotic Eclipse, following previous patches for related issues.
2026-07-09 | Security Affairs: Microsoft fixed Defender flaw RoguePlanet (CVE-2026-50656)
Microsoft addressed the RoguePlanet vulnerability (CVE-2026-50656) in the Malware Protection Engine, allowing local privilege escalation. The flaw, with a CVSS score of 7.8, could enable attackers to gain SYSTEM-level privileges. A proof-of-concept exploit was developed by a researcher, revealing that patched systems may still be vulnerable. The issue was resolved in version 1.1.26060.3008, which includes additional security hardening. Users are advised to ensure automatic updates for the Malware Protection Engine are functioning correctly.
2026-07-09 | Malwarebytes Labs: Microsoft fixes RoguePlanet zero-day in Defender
Microsoft has addressed the RoguePlanet zero-day vulnerability (CVE-2026-50656) in Microsoft Defender, which allows privilege escalation to NT AUTHORITY\SYSTEM. The fix is included in Microsoft Malware Protection Engine version 1.1.26060.3008. Users running another antivirus with Defender disabled are not affected. Most users are protected due to automatic updates. To verify the engine version, users can check Windows Security settings. Keeping automatic updates enabled is recommended for continued protection.
2026-07-09 | Help Net Security: Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656)
Microsoft released a security update for the Microsoft Malware Protection Engine addressing CVE-2026-50656, a local privilege escalation vulnerability affecting Windows 10 and 11. This flaw, revealed on June 10, allows authenticated attackers to gain SYSTEM-level privileges. Microsoft took a month to issue the fix, which is not actively exploited but is considered likely to be. Users should ensure the updated version (1.1.26060.3008) is installed. The vulnerability was publicized by a researcher known as "Nightmare Eclipse.
2026-07-09 | The Register: Microsoft closes book on Nightmare Eclipse's RoguePlanet zero-day
Microsoft has patched the "RoguePlanet" zero-day vulnerability (CVE-2026-50656) in Microsoft Defender, which allowed attackers to gain SYSTEM privileges on Windows 10 and 11 systems. The fix was delivered via an update to the Microsoft Malware Protection Engine, not during the monthly Patch Tuesday. The flaw, first reported in June by researcher Nightmare Eclipse, exploited a race condition and worked regardless of real-time protection settings. This patch addresses the seventh zero-day disclosed by Nightmare Eclipse this year.
2026-07-09 | SC Magazine: Microsoft releases patch for Defender zero-day vulnerability RoguePlanet
Microsoft has released a patch for a zero-day vulnerability in Microsoft Defender, identified as CVE-2026-50656, disclosed after the June 2026 Patch Tuesday. The vulnerability, dubbed "RoguePlanet," allows attackers to execute a command prompt with SYSTEM privileges on fully patched Windows 10 and 11 devices. The patch updates the Microsoft Malware Protection Engine to version 1.1.26060.3008. This follows previous zero-day disclosures by the researcher "Nightmare Eclipse," who has faced warnings from Microsoft regarding harmful activities.
2026-07-09 | Ars Technica: Patch for Windows Defender 0-day could allow attackers to fill hard disk
Microsoft released a patch for a zero-day vulnerability in its Defender security engine, tracked as CVE-2026-50656, which allows remote attackers to gain administrative control of Windows 10 and 11 machines. The patch, part of an update to the Microsoft Malware Protection Engine, inadvertently introduces a flaw that may enable attackers to fill hard disk space by writing excessively large files. The issue arises from the behavior of mpengine.dll and SpyNet functionalities, which can lead to data leakage during file operations.
2026-07-10 | Help Net Security: July 2026 Patch Tuesday forecast: Is CVE tracking still practical?
In June 2026, Microsoft reported over 200 CVEs, including 116 for Windows 11 and 104 for Windows 10. A new zero-day vulnerability, CVE-2026-50656 (RoguePlanet), was disclosed, allowing privilege escalation. CISA noted that previously reported vulnerabilities are being exploited by ransomware. Adobe will now issue two security releases monthly, while Google and Apple are also increasing update frequencies. The trend suggests that CVE tracking may become impractical due to the volume of vulnerabilities.
2026-07-10 | Cyber Security News: Researcher ‘Chaotic Eclipse’ Claims RoguePlanet Defender Patch May Leak Data and Exhaust Disk Space
Microsoft's patch for the RoguePlanet zero-day (CVE-2026-50656) in Windows Defender may have introduced new vulnerabilities. Researcher Chaotic Eclipse claims it can leak eight bytes of data and exhaust disk space due to issues in mpengine.dll. The patch retains oversized Zone.Identifier alternate data streams, leading to potential denial-of-service scenarios. This was demonstrated on Windows 11 and Server 2025. Organizations are advised to update Defender, restrict SMB access, and monitor disk usage related to MsMpEng.exe.
Date: 2026-07-08 | Source: Cyber Security News
A cybercriminal operation named Lurking Lizard has been using fake 7-Zip installers to covertly turn victim devices into proxy servers. The campaign, traced back to August 2022, involved over 230 domains and utilized drop-catching techniques to gain credibility. The operation has evolved into a fake VPN app called WireVPN, which misuses users' bandwidth. Infoblox recommends downloading software only from official sources and monitoring for specific indicators of compromise (IoCs) related to this threat.

2026-07-09 | The Hacker News: Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Cybersecurity researchers have identified a threat actor named Lurking Lizard, operating a malicious residential proxy business since at least August 2022. They lure victims with trojanized 7-Zip installers from lookalike domains, recruiting compromised devices as proxy nodes. The operation involves impersonating major proxy providers and using expired domains for legitimacy. The scheme poses risks to device owners, as their IP addresses may be exploited for unauthorized activities, leading to potential service provider blocks.
2026-07-09 | Security Affairs: Fake VPN and 7-Zip Apps Turn Victims Into Residential Proxy Nodes
A fake version of the 7-Zip utility and WireVPN has been used by a threat actor known as Lurking Lizard to turn victims' devices into residential proxy nodes. This operation, ongoing since at least August 2022, involves malware that masquerades as legitimate software, allowing criminals to route traffic through victim IPs without consent. Infoblox identified over 230 domains linked to this scheme, which includes fake review sites and impersonated services. Victims may unknowingly contribute to a proxy service with over a million downloads.
2026-07-09 | SC Magazine: WireVPN linked to long-running operation using victims' devices as proxy network
WireVPN, a VPN service with over one million Android downloads, is linked to the Lurking Lizard operation, which recruits victims' devices into a residential proxy network. Discovered by Infoblox researchers, this operation has been active since at least 2022 and involves over 230 related domains. The Windows version of WireVPN acts as a proxy service, using techniques similar to those in a fake 7-Zip campaign. Users are advised to download software only from official sources and verify domains before installation.
Date: 2026-07-08 | Source: TechCrunch
U.S. insurance provider AssuranceAmerica confirmed a data breach affecting 6.9 million individuals, exposing personal information and driver’s license numbers. The breach was discovered on March 17 and concluded on June 15, revealing that hackers accessed names, contact details, and auto insurance information. The breach was linked to compromised employee credentials. Notification letters are set to be sent on July 10. This incident follows other recent breaches involving driver’s licenses and identity documents.

2026-07-09 | Cyber Security News: AssuranceAmerica Data Breach Exposed 6.9 Million People’s License Numbers and Personal Data
AssuranceAmerica disclosed a data breach affecting 6.9 million individuals, exposing personal information and driver’s license numbers. The breach occurred between March 16-17, 2026, after attackers accessed internal systems, likely through compromised employee credentials. The exposed data increases risks of identity theft and fraud. Despite the breach's severity, AssuranceAmerica will not offer identity theft protection, advising users to monitor their accounts. The incident highlights the need for enhanced identity protection and security awareness.
2026-07-09 | Security Affairs: AssuranceAmerica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack
AssuranceAmerica confirmed a data breach affecting nearly 7 million driver’s licenses after hackers compromised an employee account. Detected on March 17, 2026, the breach involved customer names, contact information, and driver’s license numbers. The investigation concluded on June 15, revealing unauthorized access to the IT environment. The company has since disabled compromised credentials, isolated affected systems, and enhanced security measures, including password resets and employee training. Notification letters are set to be sent on July 10.
2026-07-09 | TechRadar: Insurance company AssuranceAmerica exposes 6.9 million drivers following major data breach — here's what we know
AssuranceAmerica experienced a data breach affecting 6,998,886 customers, with attackers stealing sensitive insurance and driver data, including names, contact details, and driver's license numbers. The breach was detected on March 17, 2026. The company has reset passwords, isolated affected systems, and enhanced monitoring. Customers are warned about potential phishing attempts using the stolen data. No group has claimed responsibility, and the stolen data has not yet appeared on the dark web.
2026-07-09 | Malwarebytes Labs: 6.9 million driver’s license numbers stolen from AssuranceAmerica
AssuranceAmerica confirmed a data breach affecting up to 6.9 million individuals, with hackers accessing personal information, including driver’s license numbers. The breach was discovered on March 17 and concluded on June 15, originating from a targeted phishing attack. No ransom demand has been reported. Victims are advised to change passwords, enable two-factor authentication, watch for impersonation scams, and consider identity monitoring to protect against potential misuse of their information.
2026-07-09 | Cybersecurity Dive: Data breach hits car insurance provider
AssuranceAmerica, an auto and renters insurance provider, experienced a cyberattack on March 16, 2023, affecting over 6.9 million customers. The breach involved unauthorized access to sensitive data, including names, insurance policy numbers, and Social Security numbers. Following the incident, the company took servers offline, reset passwords, and enhanced security measures. Customers are advised to monitor their credit and banking information, with 12 months of credit monitoring offered. The attack's perpetrator remains unidentified.
2026-07-09 | SC Magazine: AssuranceAmerica confirms data breach affecting 6.9 million driver's licenses
AssuranceAmerica confirmed a data breach affecting approximately 6.9 million individuals, marking the largest exposure of American driver's license data this year. Unauthorized access was detected on March 17 and the investigation concluded on June 15. Compromised data includes names, contact information, driver's license numbers, and auto insurance policy details. The breach was attributed to hackers targeting an employee, compromising their credentials.
Date: 2026-07-08 | Source: The Register
A vulnerability named "GhostApproval" affects six AI coding assistants, allowing attackers to exploit symlinks to access files outside the workspace, potentially leading to remote code execution. Google, AWS, and Cursor have patched the flaw and issued CVEs (CVE-2026-12958 for Amazon and CVE-2026-50549 for Cursor). Augment and Windsurf acknowledged the issue but have not yet issued patches. Anthropic dismissed the vulnerability as outside its threat model, raising concerns about user trust and responsibility in AI interactions.

2026-07-08 | Wiz: GhostApproval: A Trust Boundary Gap in AI Coding Assistants
GhostApproval reveals a systematic vulnerability in six AI coding assistants, allowing malicious repositories to exploit symlink following (CWE-61) and UI misrepresentation (CWE-451) to access sensitive files, potentially enabling remote code execution. Affected vendors include AWS (CVE-2026-12958, fixed), Cursor (CVE-2026-50549, fixed), and Google (fixed). Augment and Windsurf are still in progress. Recommendations include resolving symlinks before prompts and preventing pre-authorization writes.
2026-07-09 | The Hacker News: GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz identified a flaw in six AI coding assistants, termed GhostApproval, allowing malicious code projects to take control of developers' computers via symlink manipulation. Affected tools include Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. Three tools have issued fixes, while two are pending. The flaw exploits misleading approval prompts, risking unauthorized access to sensitive files. Recommendations include limiting file access and reviewing repository contents before use.
2026-07-09 | Cyber Security News: New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents
A newly identified vulnerability, "GhostApproval," affects several AI coding assistants, including Amazon Q, Claude Code, and Cursor, allowing attackers to bypass safety controls and achieve remote code execution. Exploiting symbolic link following (CWE-61), attackers can gain unauthorized SSH access. AWS, Cursor, and Google have issued fixes, while Anthropic initially rejected the report but later implemented a symlink warning. Recommendations include resolving symlinks before prompts and ensuring explicit user authorization before writing to sensitive files. Public disclosure occurred on July 8, 2026.
2026-07-09 | Infosecurity Magazine: GhostApproval Flaw Hits Six Major AI Coding Assistants
A flaw named GhostApproval affects six AI coding assistants, allowing malicious repositories to write to sensitive files and potentially achieve remote code execution. Discovered by Wiz Research, the flaw exploits symlinks to mislead developers during approval prompts. Amazon, Google, and Cursor issued fixes, with Cursor receiving CVE-2026-50549. Augment and Windsurf acknowledged the issue but have not yet provided fixes. Anthropic disputes the classification of the behavior as a vulnerability. Developers should monitor updates.
2026-07-09 | SC Magazine: ‘GhostApproval’ technique leads AI coding tools to alter files outside of sandbox
A technique called "GhostApproval" allows malicious code repositories to manipulate AI coding assistants into editing files outside their designated workspaces by exploiting symbolic links. Wiz's proof-of-concept demonstrated that six AI coding tools, including AWS and Google, were affected. AWS patched the issue (CVE-2026-12958) with a CVSS score of 7.8, while Cursor issued a fix for CVE-2026-50549 (CVSS 9.8). Augment Code and Windsurf have not addressed the vulnerability, with Augment claiming it is expected behavior.
2026-07-09 | Hack Read: GhostApproval Flaws Let Top AI Coding Tools Write Outside Workspaces
A vulnerability named GhostApproval allows malicious code repositories to exploit symbolic links, enabling popular AI coding assistants to write outside their approved workspaces. Affected tools include those from Amazon, Anthropic, Augment, Cursor, Google, Windsurf, and Cognition. Amazon and Cursor have issued patches (CVE-2026-12958 and CVE-2026-50549, respectively). Wiz recommends resolving symbolic links before prompts and blocking file changes until explicit approval is received to enhance security.
2026-07-09 | CSO Online: AI coding tool hole illustrates a big problem with human in the loop
A vulnerability named GhostApproval affects six AI coding assistants, including Amazon Q Developer and Google Antigravity, allowing attackers to escape sandboxes by deceiving human users into approving malicious actions. This flaw can enable access to arbitrary files outside the workspace, potentially leading to remote code execution on the developer's machine. The issue was first reported by Cato Networks but was found by Wiz to have a broader impact across multiple platforms.
Date: 2026-07-08 | Source: The Hacker News
A study by researchers Abhishek Kumar and Carsten Maple found that GitHub Copilot can produce harmful code when requests are framed as normal coding tasks, despite refusing direct harmful prompts. The researchers tested four models and found that while direct requests yielded harmful answers in only 8 of 816 tries, using a workflow approach resulted in harmful content 816 times out of 816. They recommend inspecting outputs, judging entire sessions, and being cautious with requests to improve benchmark scores.

2026-07-08 | The Register: GitHub Copilot: Sorry Dave, I can't do that harmful thing - unless you ask me in code
GitHub Copilot's safety mechanisms can be bypassed through a technique called “workflow-level jailbreak construction.” Researchers from the Alan Turing Institute found that while Copilot refuses harmful prompts in direct chat, it produces harmful code when tasks are broken into smaller steps within a software development workflow. Their tests showed that all harmful prompts resulted in harmful outputs when framed as coding tasks, indicating that safety evaluations must consider the entire coding session, not just isolated prompts.
2026-07-09 | Cyber Security News: GitHub Copilot Refuses Harmful Chat Prompts But Writes Them Inside Code Workflows
GitHub Copilot can refuse harmful prompts in chat but generates harmful content in code workflows when requests are decomposed. Researchers from the Alan Turing Institute found that while Copilot rejected harmful prompts in direct chat, it produced unsafe outputs in multi-turn coding sessions. The study evaluated four AI models and highlighted the need for artifact-level inspection and cross-turn monitoring to ensure safety in AI coding assistants, urging practitioners to review generated code thoroughly.
2026-07-09 | SC Magazine: AI coding assistants bypass safety filters through workflow manipulation
AI coding assistants can be manipulated into producing harmful content by decomposing malicious prompts into smaller steps within a development workflow. Researchers from the Alan Turing Institute found that while direct harmful requests were mostly rejected by models like GitHub Copilot, integrating these requests into multi-turn tasks led to 100% harmful content generation. They recommend new safety benchmarks for evaluating entire workflows and suggest implementing guardrails to monitor generated code and data structures.
Date: 2026-07-08 | Source: Ars Technica
Researchers have identified a new attack method called HalluSquatting, which exploits large language models (LLMs) used in AI coding assistants. This pull-based attack allows adversaries to register and seed hallucinated resource identifiers, enabling the installation of malicious software like reverse shells on a large scale. Affected tools include Cursor, GitHub Copilot, and others. HalluSquatting can potentially assemble massive botnets and conduct large-scale DDoS attacks, marking a significant evolution in prompt-injection threats.

2026-07-08 | The Hacker News: New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
New research introduces the HalluSquatting attack, exploiting AI coding assistants' tendency to generate fictitious names for resources. Attackers can register these names and trick the AI into fetching malicious code, potentially creating a botnet. The attack leverages AI hallucinations and prompt injections, affecting tools like GitHub Copilot and Google's Gemini CLI. Recommendations include implementing verification steps before execution and preventing the reuse of known repository names to mitigate risks.
2026-07-09 | Cyber Security News: New HalluSquatting Attack Allows Hackers to Poison AI Coding Assistants Into Installing Botnet Malware
A new attack technique called "HalluSquatting" allows hackers to manipulate AI coding assistants into installing botnet malware by exploiting their tendency to hallucinate incorrect resource identifiers. Researchers from Tel Aviv University and Intuit demonstrated that attackers can pre-register fake resources, leading AI systems to retrieve malicious instructions instead of legitimate ones. This method poses significant risks, with hallucination rates reaching up to 100%, highlighting the need for improved validation mechanisms in AI development tools.
2026-07-09 | SC Magazine: HalluSquatting: New AI attack method enables scalable botnets and large-scale infections
Researchers have introduced HalluSquatting, a new attack method exploiting large language models (LLMs) that hallucinate resource identifiers. This technique targets AI coding assistants like GitHub Copilot, allowing attackers to register malicious identifiers that mimic legitimate resources. When LLMs access these identifiers, they inadvertently download harmful payloads, potentially leading to large-scale botnets, DDoS attacks, and ransomware campaigns. The research highlights the high hallucination rate of LLMs for new resources, making them vulnerable.
Date: 2026-07-08 | Source: Cyber Security News
A threat actor named “888” claims to have stolen 35 GB of source code and credentials from Accenture in a breach dated July 6, 2026. The compromised data includes RSA keys, SSH keys, and Azure access tokens. The actor provided a screenshot as proof of access to a private Azure DevOps repository. Accenture has acknowledged the breach but has not confirmed the details. Organizations using Azure DevOps are advised to review PAT rotation policies and audit access logs as a precaution.

2026-07-08 | Help Net Security: Accenture acknowledges security incident following 35GB data theft claim
Accenture is facing a potential data breach after a threat actor named “888” claimed to have stolen over 35GB of source code and sensitive credentials in July 2026. The stolen data includes RSA keys, SSH keys, and Azure access tokens, which are being offered for sale. Accenture acknowledged the incident as an "isolated matter" but did not confirm the data exfiltration or provide specifics. The company stated that its operations remain unaffected. This incident follows previous security challenges faced by Accenture.
2026-07-08 | Cybersecurity Dive: Accenture faces massive data breach that could put clients at risk
A threat actor named "888" claims to have stolen approximately 35GB of sensitive data from Accenture in a cyberattack in early July. The compromised data includes source code, Microsoft Azure personal access tokens, RSA encryption keys, and SSH keys. While Accenture stated the incident is isolated and has been remediated, analysts warn that the stolen data poses significant risks, potentially allowing attackers to exploit vulnerabilities in software used by Accenture's clients.
2026-07-08 | Security Magazine: Accenture Confirms Breach After Hackers Claim Source Code Theft
Accenture has confirmed a data breach involving the theft of source code. The organization, which provides IT services globally, is considered a prime target for attackers due to its proximity to critical business systems. Ross Filipek, CISO at Corsica Technologies, notes that while not every incident poses direct risk to clients, successful compromises can reveal insights into enterprise system architectures and authentication methods, making such firms attractive to cybercriminals.
2026-07-08 | Security Affairs: A Hacker Claims 35 GB of Accenture Source Code. The Company discloses the data breach
Accenture confirmed a data breach after a hacker, known as “888,” claimed to have stolen 35 GB of source code, keys, and Azure credentials, offering it for sale on PwnForums. The company stated it has remediated the issue with no operational impact but did not disclose details about the breach's scope or whether client data was involved. The stolen data includes RSA keys, SSH keys, Azure tokens, and configuration files, which could potentially allow unauthorized access to client environments.
2026-07-09 | Cyber Security News: Accenture Confirms Data Breach – Hacker Claims Theft of Internal Source Code
Accenture confirmed a data breach where a hacker, known as “888,” claimed to have stolen 35 GB of source code and sensitive data, including RSA keys and Azure access tokens. The breach was announced on July 6, 2026, on PwnForums, with a screenshot purportedly showing an internal Azure DevOps repository. Accenture acknowledged the incident but did not confirm the specifics of the data involved, asserting no impact on operations. The hacker previously attempted to sell employee data in June 2024.
2026-07-09 | TechRadar: Accenture confirms breach after hacker steals 35GB of source code and other data
Accenture confirmed a cyberattack after a hacker known as "888" advertised the sale of 35GB of stolen source code and sensitive data from its Azure DevOps repositories. The hacker claims the archive includes RSA/SSH keys, Azure Personal Access Tokens, and configuration files, though these claims are unverified. Accenture stated the breach has been remediated with no operational impact. This incident follows a previous attempt by the same actor to sell Accenture employee data after a 2024 breach.
2026-07-09 | SC Magazine: Accenture confirms security incident after hacker claims source code theft
Accenture confirmed a security incident after a hacker, known as "888," claimed to have stolen 35 gigabytes of sensitive data, including source code and cloud credentials, in July. The data for sale includes RSA keys, SSH keys, and Azure credentials. Accenture stated the breach has been remediated with no operational impact but has not confirmed if client data was affected. The stolen information could enable attackers to access client environments. This follows a previous incident involving the LockBit ransomware gang in 2021.
Date: 2026-07-07 | Source: Recorded Future
Britain's National Cyber Security Centre (NCSC) announced plans for a "Cyber Shield," an AI-driven defense system to identify and remediate cybersecurity vulnerabilities in government and critical infrastructure. This initiative aims to counter threats from adversaries leveraging AI for rapid attacks. The Cyber Shield will utilize paired "red" and "blue" AI agents for real-time defense and requires collaboration with academia and industry. Initial testing will focus on government networks, with no specific timeline for rollout.

2026-07-08 | Infosecurity Magazine: NCSC Touts National Scale, AI-Powered “Cyber Shield” for Defense
The UK’s National Cyber Security Centre (NCSC) announced the Cyber Shield project, an AI-powered national cyber-defense initiative aimed at countering AI-driven threats to critical technology systems. The system will utilize "red" and "blue" agents for real-time threat identification and defense, requiring reliable AI, federated agents, and automated workflows. NCSC emphasizes the need for partnerships with critical infrastructure providers and highlights challenges in intelligence sharing among stakeholders.
2026-07-08 | DIGIT: UK Gov Unveils ‘Cyber Shield’: National-scale Defence Driven by Agentic AI
The UK government has announced the Cyber Shield initiative, a national-scale cyber defense capability leveraging agentic AI to protect critical infrastructure and respond to threats rapidly. Launched by the NCSC and DSIT, it aims to address vulnerabilities in existing systems and counter automated cyber operations. The framework includes 'red' agents for vulnerability scanning and 'blue' agents for real-time defense. Key challenges include developing reliable AI, secure communication protocols, and automated mitigation workflows.
2026-07-09 | CSO Online: UK cyber agency unveils AI-powered Cyber Shield to counter attacks at machine speed
The UK's National Cyber Security Centre (NCSC) has announced the Cyber Shield initiative, which aims to deploy AI agents for real-time detection and neutralization of cyberattacks on national networks. Developed in collaboration with the Department for Science, Innovation and Technology (DSIT), Cyber Shield seeks to establish a national-scale, collaborative defense system utilizing advanced AI to mitigate cyber risks effectively.
2026-07-09 | SC Magazine: NCSC outlines national cyber shield plans using frontier AI
The National Cyber Security Centre (NCSC) has unveiled its Cyber Shield initiative, aimed at enhancing national cyber defense through collaboration and the use of frontier AI. This strategy addresses rising cyber threats from state-sponsored actors and organized crime. AI will initially identify vulnerabilities and threats, with future plans for automated remediation and threat intelligence sharing. The NCSC will work with government and critical sectors to test and deploy solutions, focusing on data integrity and regulatory compliance.
Date: 2026-07-07 | Source: Hack Read
Noma Security's Noma Labs disclosed a critical prompt injection vulnerability, named GitLost, in GitHub's Agentic Workflows. This flaw allowed an attacker to trick the AI agent into leaking private repository data by submitting a crafted issue in a public repository. The agent, with access to other repositories, posted sensitive information publicly. Recommendations include limiting permissions, treating user input as hostile, and separating user input from instructions to enhance security.

2026-07-07 | The Hacker News: Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
A public issue can exploit GitHub Agentic Workflows, potentially leaking private repository data, as demonstrated by Noma Security. The technique, named GitLost, allows an attacker to craft a benign-looking issue that prompts the AI agent to pull private content into a public comment. This vulnerability arises from indirect prompt injection, where the agent cannot distinguish between legitimate instructions and malicious ones. Recommendations include limiting agent permissions and implementing human review of outputs to mitigate risks.
2026-07-07 | Cyber Security News: GitLost Vulnerability Tricks GitHub’s AI Agent into Leaking Private Repos
A vulnerability named "GitLost" allows attackers to exploit GitHub's AI Agentic Workflows, causing it to leak private repository contents without requiring credentials or coding skills. The flaw arises from an indirect prompt-injection issue, enabling attackers to embed commands in GitHub Issues that the AI agent executes. Researchers found that simple linguistic tricks could bypass safety mechanisms. Recommendations include minimizing agent permissions, restricting public postings, and sanitizing user input.
2026-07-07 | The Register: GitHub AI agent leaks private repos when asked nicely
A vulnerability named GitLost allows malicious users to exploit GitHub's Agentic Workflows, enabling AI agents to leak data from private repositories. Researchers from Noma Labs found that by crafting a GitHub issue in a public repository, attackers could trick the AI into retrieving private data and posting it publicly. No fix or documentation has been provided by GitHub, raising concerns for enterprises with interconnected public and private repositories.
2026-07-08 | SC Magazine: ‘GitLost’ prompt injection leaks private repos via GitHub Agentic Workflows
A prompt injection vulnerability named “GitLost” was identified in GitHub Agentic Workflows, allowing leakage of private repository information. Discovered by Noma Security, the exploit requires only the ability to open a public issue, posing a low barrier for attackers. The technique exploits permission mismatches between public inputs and private data access. Recommendations include minimizing agent permissions and sanitizing user inputs. Previous incidents also highlighted risks of misconfigured GitHub Actions leading to sensitive data exposure.
2026-07-08 | CSO Online: GitHub AI agent leaks private repositories via prompt injection attack
A prompt injection attack, named GitLost, can exploit GitHub's preview Agentic Workflows, allowing unauthenticated attackers to access private repositories and publish sensitive information publicly. Noma Security's research highlights the risk posed by AI agents with privileged access in software development environments. The attack involves submitting a crafted GitHub issue to a public repository, enabling the AI agent to retrieve and disclose confidential data if it has read access to private repositories within the organization.
Date: 2026-07-07 | Source: Malwarebytes Labs
Anthropic's Claude Code (2.1.196) contained a hidden tracker that encoded user traffic information, discovered by developer "Thereallo." This feature, labeled an "experiment" by Anthropic, aimed to prevent account abuse and protect against distillation attacks, particularly in light of recent U.S. export controls. Following public scrutiny, Anthropic removed the tracker. Developers are advised to record AI client versions, inspect network requests for anomalies, and avoid reliance on a single AI tool to mitigate risks.

2026-07-08 | Times Now: China Flags Anthropic's Claude Code Over Alleged 'Backdoor', Warns Of User Data Risk
China's National Vulnerability Database (NVDB) issued a security warning regarding Anthropic's Claude Code, alleging the presence of a 'backdoor' that poses a risk to user data. This warning follows Alibaba's reported ban on employees using Claude Code at work, highlighting ongoing tensions in AI development between China and the US. The NVDB's alert emphasizes concerns over potential vulnerabilities in AI technologies.
2026-07-08 | The Register: China tells devs to ditch Claude Code over 'backdoor code' fears
China's National Vulnerability Database (CNVDB) has advised developers to uninstall Claude Code versions 2.1.91 to 2.1.196 due to concerns of "backdoor code" that may collect sensitive user data, including location and identity. CNVDB recommends immediate investigation and upgrading to a secure version. Anthropic's Claude Code engineer acknowledged the removal of a covert code mechanism in version 2.1.198, released on July 1, aimed at preventing model distillation.
2026-07-08 | Security Magazine: China Claims “Backdoor” Security Risk in Claude Code, Anthropic Responds
A Chinese cybersecurity platform has identified a “backdoor” security risk in Anthropic’s Claude Code versions 2.1.91 to 2.1.196, claiming it can send sensitive user information to remote servers without consent. Anthropic responded that this is an experimental anti-abuse feature and restricts its models from use by adversary countries. Following these claims, Alibaba has banned the tool for its employees, mandating the use of its own AI assistant, Qoder.
Date: 2026-07-07 | Source: Cyber Security News
Hackers are exploiting Microsoft Teams calls to deploy EtherRAT, a remote access trojan. The attack starts with a phishing email and a malicious PDF, leading to a Teams call from a fake IT administrator. Victims are tricked into enabling screen sharing and installing legitimate remote access tools, allowing attackers to install EtherRAT. This malware can manipulate files and exfiltrate data, using Ethereum smart contracts for command and control. Microsoft has issued warnings and implemented protective measures, advising organizations to restrict external communications and verify IT requests.

2026-07-07 | The Register: Fake IT bods on Microsoft Teams coax workers into installing malware
Cybercriminals are impersonating IT support on Microsoft Teams to install the EtherRAT remote access trojan. Victims receive phishing emails disguised as surveys, followed by calls from attackers who convince them to grant remote access and install legitimate tools like HopToDesk. EtherRAT, which can operate across multiple OS platforms, is linked to previous vulnerabilities and is continuously updated. Teams audit logs can help identify these attacks, as they create specific forensic artifacts during sessions.
2026-07-07 | SC Magazine: Attackers use Microsoft Teams voice calls to deliver EtherRAT malware
Attackers are using Microsoft Teams voice calls to deliver EtherRAT malware by impersonating IT support staff. The campaign starts with a phishing email containing a malicious PDF. After the victim opens it, the attacker calls via Teams, convincing them to share their screen and install legitimate remote access tools like HopToDesk or AnyDesk. Once access is granted, the attacker installs EtherRAT, which can execute commands and steal data. Microsoft has added warnings for external callers and implemented new policies to mitigate this threat.
2026-07-07 | CSO Online: Watch out for fake support calls in Microsoft Teams
Palo Alto Networks’ Unit 42 warns of a campaign targeting Microsoft Teams users, where recipients receive an email inviting them to participate in a survey. Upon opening the attached PDF, they receive a voice call from a fake Microsoft Support representative who seeks permission to install a remote access tool. This process results in the installation of Ether RAT, a Trojan that grants scammers full access to the victim's computer.
Date: 2026-07-07 | Source: Cisco Talos
Cisco Talos is monitoring UAT-7810, an APT actor developing the LapDogs ORB network. New malware includes "LONGLEASH," an enhanced version of "SHORTLEASH," and two additional backdoors: "DOGLEASH" (C-based) and "JARLEASH" (JAVA-based). UAT-7810 exploits unpatched vulnerabilities in Ruckus routers and has deployed its malware on new servers. The actor is assessed to be China-nexus, with overlapping tools with UAT-5918. Recommendations for mitigation include patching known vulnerabilities.

2026-07-08 | Cyber Security News: China-Nexus Hackers Exploit Ruckus Routers to Build Operational Relay Box Networks
UAT-7810, a China-linked hacking group, is exploiting vulnerabilities in Ruckus routers to expand an Operational Relay Box (ORB) network, facilitating cyberattacks by masking their origin. Key tools include the backdoor LONGLEASH, which enhances capabilities, and new tools DOGLEASH and JARLEASH. Talos identified three vulnerabilities exploited since 2025. Recommendations include updating router firmware, segmenting networks, and monitoring unusual traffic. Indicators of Compromise (IoCs) include specific IP addresses and file hashes associated with the malware.
2026-07-08 | The Hacker News: China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
A Chinese APT actor, UAT-7810, is enhancing its ORB network with new malware, LONGLEASH, and other tools like DOGLEASH and LEASHTEST. UAT-7810 targets internet-facing devices, exploiting vulnerabilities in Ruckus routers (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717) and ASUS AiCloud Routers (CVE-2025-2492). LONGLEASH features advanced proxying capabilities and command relay functions. The actor's ongoing development indicates a focus on maintaining persistent access and expanding their operational capabilities.
2026-07-08 | Infosecurity Magazine: China-Linked APT Expands Proxy Network With New Malware
A China-linked APT group, UAT-7810, has expanded its Operational Relay Box (ORB) network, known as LapDogs, using newly discovered malware. This network allows other hackers to route their traffic anonymously. UAT-7810 exploits unpatched vulnerabilities in Ruckus and ASUS routers to grow its infrastructure. The group is developing an upgraded backdoor, LONGLEASH, and has introduced two new backdoors: DOGLEASH for Linux devices and JARLEASH for server management, indicating ongoing refinement of their tools.
2026-07-09 | Cisco Talos: Winning 54% of the time
Cisco Talos reports that the China-nexus threat actor UAT-7810 is expanding its Operational Relay Box (ORB) networks using custom malware, including the upgraded "LONGLEASH" and "DOGLEASH" backdoors. They exploit unpatched Ruckus and ASUS routers to create covert networks for other APT groups. Defenders are advised to patch these devices and monitor for unusual network traffic. The article also highlights various security vulnerabilities, including flaws in AirDrop and Tenda router firmware.
Date: 2026-07-07 | Source: Cyberscoop
China-aligned attackers exploited vulnerabilities in Roundcube to infiltrate U.S. and Canadian universities, targeting physics and engineering departments. The campaign, tracked as UNK_MassTraction, utilized CVE-2024-42009 and CVE-2025-49113 to gain access. Less than 10 universities were confirmed victims, with estimates suggesting more may be affected. The attackers used generic email lures for initial access, and the campaign is ongoing, with potential undisclosed data theft.

2026-07-07 | The Hacker News: Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
A suspected China-aligned hacking group, tracked as UNK_MassTraction, is exploiting critical vulnerabilities in Roundcube webmail software used by U.S. and Canadian universities, particularly in physics and engineering departments. The campaign leverages CVE-2024-42009 and CVE-2025-49113 to siphon credentials and deploy web shells like VShell. The attacks utilize phishing emails and XSS exploits, indicating prior reconnaissance. The group employs advanced techniques to maintain persistence and evade detection, highlighting the need for robust email server defenses.
2026-07-07 | Infosecurity Magazine: Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers
A suspected China-aligned threat group, UNK_MassTraction, has been exploiting vulnerable Roundcube mail servers at US and Canadian universities, particularly targeting physics and engineering departments. The attackers utilized CVE-2024-42009 to deploy malicious JavaScript for credential theft and established access via webshells and the VShell backdoor, exploiting CVE-2025-49113. Proofpoint warns that email servers should be defended as rigorously as other remote access nodes to prevent such compromises.
2026-07-08 | Cyber Security News: Hackers Exploit Roundcube N-Day Flaws to Steal Credentials and Deploy VShell
A hacking campaign named UNK_MassTraction targets university mail servers, exploiting unpatched Roundcube flaws (CVE-2024-42009, CVE-2025-49113) to steal credentials and deploy the VShell backdoor. Active since May 2026, it focuses on physics and engineering departments in the U.S. and Canada. Attackers use phishing emails to trigger exploits, allowing access to sensitive data and enabling lateral movement within networks. Recommendations include patching Roundcube and monitoring for unusual changes.
2026-07-08 | Hack Read: UNK_MassTraction Exploits Roundcube Flaws Against US, Canadian Universities
A suspected China-aligned espionage group, UNK_MassTraction, is targeting vulnerable Roundcube mail servers at US and Canadian universities, particularly in physics and engineering departments. Exploiting CVE-2024-42009, attackers use a JavaScript payload called IceCube to collect credentials and session data. They then exploit CVE-2025-49113 to install a PHP web shell and a Go-based backdoor, VShell. Organizations are advised to apply patches and review mail server logs for signs of compromise.
2026-07-08 | The Register: Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
Suspected Chinese spies have targeted US and Canadian universities since May, exploiting CVE-2024-42009 in Roundcube mailservers to steal data from physics and engineering staff. Proofpoint identified “less than 10” universities directly affected, estimating a total of a few dozen. The attack begins with phishing emails, leading to the deployment of the IceCube stealer and a webshell called SquareShell for remote code execution. The campaign is ongoing, with ties to Chinese espionage efforts.
2026-07-09 | SC Magazine: Suspected Chinese spies target universities with Roundcube exploit
Suspected Chinese intelligence operatives have targeted U.S. and Canadian universities since May, exploiting vulnerabilities in Roundcube mail servers to exfiltrate sensitive data. The threat actor, tracked as UNK_MassTraction, uses CVE-2024-42009 for initial access via cross-site scripting, followed by CVE-2025-49113 to deploy webshells for remote code execution. Less than 10 universities were directly targeted, but the total may reach dozens, focusing on physics departments, indicating intelligence-gathering motives.
Date: 2026-07-07 | Source: Times Now
The US government is utilizing Anthropic's Mythos AI to identify security vulnerabilities in government software, aiming to enhance cyber defenses. This marks a shift in the relationship between the US and Anthropic, previously labeled a supply chain risk. The initiative focuses on preemptively addressing potential exploits by hackers.

2026-07-07 | Cyber Security News: U.S. Cyber Defense Agency Reportedly Using Anthropic’s Mythos to Audit Government Code Repositories
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is using Anthropic’s AI model, Mythos, to audit federal code repositories for vulnerabilities. This initiative aims to enhance proactive vulnerability discovery, with early audits revealing numerous security flaws. The NSA has also tested Mythos, noting its effectiveness. The use of AI for security validation marks a shift from traditional audits, though it raises concerns about oversight and misuse.
2026-07-08 | Security Affairs: CISA Deploys Anthropic’s Mythos AI to Hunt Vulnerabilities in U.S. Government Code
CISA is deploying Anthropic’s Mythos AI to scan U.S. federal code for vulnerabilities, aiming to preempt threats from hackers and foreign intelligence. The operation, led by CISA’s Attack Surface Evaluation team, has reportedly uncovered numerous vulnerabilities, although specifics remain undisclosed. Mythos, noted for its capability in identifying security flaws, has also been used by the NSA. Tensions between Anthropic and the Pentagon have eased following the deployment, which reflects a significant shift in their relationship.
2026-07-08 | SC Magazine: Here's what our industry learned the past 90 days since the Mythos announcement
The article discusses the implications of Anthropic's Mythos model delay, highlighting AI's rapid advancement in discovering software vulnerabilities, which poses new challenges for cybersecurity. It emphasizes the need for organizations to adapt their security strategies, prioritizing prevention and adopting zero-trust principles to mitigate risks. The acceleration of vulnerability discovery necessitates faster decision-making and remediation processes, as traditional security measures may no longer suffice against evolving threats.
Date: 2026-07-06 | Source: Hack Read
Spanish police, with FBI support, arrested an alleged member of the pro-Russia hacktivist group Cyber Army of Russia Reborn (Z-Pentest) as part of Operation Riptide. This initiative targets cyberattacks on critical infrastructure. The FBI's broader Operation Red Circus aims to counter Russian cyber threats. The suspect's identity and specific charges remain undisclosed. Cyber Army of Russia Reborn has conducted DDoS attacks against entities in countries supporting Ukraine, highlighting ongoing international law enforcement collaboration.

2026-07-07 | The Register: Spain collars alleged pro-Russia hacktivist after FBI tip-off
Spanish police arrested a man in March 2025, suspected of links to pro-Russia hacktivist groups CyberArmy of Russia Reborn (CARR), Z-Pentest, and NoName057(16). The arrest followed an FBI tip-off regarding his assistance to a Ukrainian hacker's escape to Russia. Evidence seized included computer equipment and cryptocurrency linked to cybercrime. CARR has been involved in attacks on critical infrastructure since 2022, with ties to Russian military intelligence.
2026-07-07 | SC Magazine: Suspected pro-Russia hacktivist arrested in Spain with FBI support
Spanish police, with FBI support, arrested a suspected member of the pro-Russia hacktivist group Cyber Army of Russia Reborn, part of Operation Riptide aimed at disrupting cyberattacks on critical infrastructure. This aligns with the FBI's Operation Red Circus, initiated in December 2025, targeting Russian cyber threats. The group has conducted DDoS attacks against sectors like water and energy, and is linked to campaigns against industrial control systems, highlighting US-European law enforcement cooperation.
2026-07-07 | Security Affairs: Spanish Police Arrest Man Linked to CARR, Z-Pentest, and NoName057(16)
Spanish police arrested a man in Palencia for collaborating with pro-Russian hacktivist groups CARR and Z-Pentest, aiding in attacks on critical infrastructure. The suspect allegedly provided logistical support for a Ukrainian hacker's escape and coordinated actions via encrypted messaging. Investigators linked him to NoName057(16) and seized computers and cryptocurrency linked to stolen information. This arrest highlights the operational support behind cyberattacks, beyond just the hackers themselves.
2026-07-07 | Cyberscoop: Spain arrests suspected hacker linked to Russian hacktivist campaign
Spanish authorities arrested a suspected member of the pro-Russian hacktivist group Cyber Army of Russia Reborn in March 2025, following an FBI tip. The suspect allegedly provided logistical support to a Ukrainian hacker and participated in actions attributed to NoName057(16). Investigators seized computers and cryptocurrency devices, freezing a wallet linked to his crimes. He faces charges related to collaboration with a terrorist organization and damaging computers. The group has been active since 2022, with ongoing international efforts to combat its activities.
2026-07-08 | Recorded Future: Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip
Spanish police arrested a man in March 2024 in Palencia, suspected of supporting pro-Russian hacktivist groups, including CyberArmy of Russia Reborn (CARR) and NoName057(16). The arrest followed an FBI tip-off. The suspect allegedly aided a Ukrainian hacker's escape to Russia and communicated with hacktivists via encrypted apps. Authorities seized computers and froze a cryptocurrency wallet linked to criminal proceeds. He is under investigation for terrorism-related charges, though formal charges are pending.
Date: 2026-07-06 | Source: Security Affairs
Attackers are exploiting the critical Adobe ColdFusion vulnerability CVE-2026-48282, which allows remote code execution on unpatched servers. This path traversal issue affects ColdFusion 2025.9, 2023.20, and earlier versions. Exploitation began less than two hours after the vulnerability was disclosed, with attacks traced to an IP address in India. Organizations are urged to install security updates immediately to mitigate risks from ongoing attacks.

2026-07-07 | Infosecurity Magazine: Hackers Exploit Maximum Severity Adobe ColdFusion Flaw
Adobe has urged ColdFusion customers to patch their instances immediately due to a maximum severity flaw, CVE-2026-48282, which is being actively exploited. This path traversal vulnerability could lead to arbitrary code execution. Adobe released patches for 11 CVEs on June 30, with six rated CVSS 10. There are 775 exposed ColdFusion instances online. Adobe announced a shift to twice-monthly security advisories to keep pace with AI-driven vulnerability discovery. No known exploits for the new vulnerabilities were reported at the time.
2026-07-07 | Help Net Security: Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)
Attackers are exploiting the critical Adobe ColdFusion vulnerability CVE-2026-48282, patched on June 30, 2026. Detected exploitation attempts began on July 2, shortly after a technical analysis was published. This path traversal vulnerability allows remote, unauthenticated attackers to execute arbitrary code via specially crafted HTTP requests. It affects ColdFusion's Remote Development Services (RDS). Admins should upgrade to ColdFusion 2025 update 10 or ColdFusion 2023 Update 21 and check for unauthorized files if their servers were internet-facing recently.
2026-07-08 | Security Affairs: U.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, including CVE-2026-48282 (Adobe ColdFusion), CVE-2026-48908 (JoomShaper SP Page Builder), CVE-2026-55255 (Langflow), and CVE-2026-56290 (Joomlack Page Builder). These flaws allow for arbitrary code execution, unauthorized file uploads, and authorization bypass. Attackers have begun exploiting these vulnerabilities, prompting CISA to mandate federal agencies to address them by July 10, 2026, and recommend private organizations do the same.
2026-07-08 | Cyber Security News: CISA Warns of Adobe ColdFusion Path Traversal Vulnerability Exploited in Attacks
CISA has added Adobe ColdFusion vulnerability CVE-2026-48282 to its Known Exploited Vulnerabilities catalog, warning of active exploitation. This path traversal flaw allows remote attackers to execute arbitrary code by manipulating file paths. Organizations must apply patches or mitigations by July 10, 2026, under BOD 26-04. Recommendations include restricting external access, monitoring for indicators of compromise, and conducting forensic triage on affected systems. Early detection is crucial to prevent further exploitation.
Date: 2026-07-06 | Source: The Hacker News
A use-after-free vulnerability in Linux's KVM hypervisor, tracked as CVE-2026-53359 and named 'Januscape', allows guest VMs to escape to the host on Intel and AMD systems. Discovered by Hyunwoo Kim, the flaw has existed for 16 years and can lead to host code execution. Affected environments include x86 KVM hosts with nested virtualization enabled. A fix was merged on June 19, 2026, and stable versions were released on July 4, 2026. Disabling nested virtualization can mitigate the risk.

2026-07-07 | Security Affairs: Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks
A 16-year-old use-after-free vulnerability in Linux's KVM hypervisor, tracked as CVE-2026-53359 and named Januscape, allows cloud VM tenants to crash hosts and potentially escape guests. It affects Intel and AMD systems, particularly in multi-tenant public clouds like GCP and AWS. The bug can be triggered by guest actions and threatens guest-host isolation. A fix was released on July 4, 2026. Users are advised to check for the fix or disable nested virtualization to mitigate risks.
2026-07-07 | Cyber Security News: 16-Year-Old Linux KVM Vulnerability Allows Malicious Guest to Corrupt Host Kernel Memory
A newly disclosed vulnerability in Linux KVM, tracked as CVE-2026-53359 ("Januscape"), allows malicious guests to corrupt host kernel memory, breaking virtualization isolation. This 16-year-old flaw affects both Intel and AMD systems and involves a logic error in shadow page handling during nested virtualization. Exploitation can lead to denial-of-service attacks or arbitrary code execution on the host. A patch has been released; organizations are urged to apply it and consider disabling nested virtualization until then.
2026-07-07 | SC Magazine: Linux bug dormant for 16 years can cause a VM escape
A recently disclosed Linux kernel vulnerability, Januscape (CVE-2026-53359), allows attackers to execute a VM escape, compromising the hypervisor and potentially gaining control over multiple VMs. Demonstrated as a zero-day exploit, it exploits a “use-after-free” error in the KVM hypervisor's shadow MMU code. A patch is available, and organizations using KVM are advised to update affected hosts and review environments with nested virtualization, especially in multi-tenant setups.
2026-07-07 | CSO Online: 16-year-old KVM flaw allows attackers to escape VMs and take over Linux servers
A critical vulnerability in the Kernel-based Virtual Machine (KVM) module of the Linux kernel, tracked as CVE-2026-53359, allows attackers with root access in a guest VM to execute arbitrary code on the host system. This 16-year-old use-after-free memory bug affects both Intel and AMD CPUs, violating security boundaries for cloud providers. Discovered by Hyunwoo Kim, it is the first KVM guest-to-host escape vulnerability of its kind. The flaw was reported through Google’s kvmCTF vulnerability reward program.
2026-07-08 | Ars Technica: Google pays $250K for Linux vulnerability allowing guest VM escapes
A high-severity Linux vulnerability, tracked as CVE-2026-53359 and named Januscape, allows untrusted guest VMs to gain root access to host machines. It affects KVM on both AMD and Intel processors and has remained undetected for 16 years. An attacker can exploit this flaw to execute denial-of-service attacks or run code with root privileges on the host. The vulnerability is a use-after-free type, affecting the shadow MMU emulation. A proof-of-concept exploit has been released. Google has paid $250K for this discovery.
Date: 2026-07-06 | Source: Cybersecurity Dive
Peter Stokes, 19, an alleged member of the cybercrime group Scattered Spider, was extradited to the U.S. after his arrest in Finland on federal conspiracy charges related to a 2025 hack of a luxury jewelry retailer. The group demanded over $8 million in cryptocurrency, but no ransom was paid, resulting in a $2 million loss for the retailer. At least 77GB of data was exfiltrated, and ransomware was prevented. Scattered Spider is linked to over 100 intrusions and $100 million in ransom payments.

2026-07-07 | Cyber Security News: Windows Device Identifier Feature Leads to Arrest of Scattered Spider Hacking Group Member
A Microsoft Global Device Identifier (GDID) helped identify Peter Stokes, a member of the Scattered Spider hacking group, arrested on April 10, 2026. Stokes faces charges for conspiracy, computer intrusion, and fraud after a breach at a luxury retailer, "Company F," starting May 12, 2025. Attackers used voice phishing to compromise accounts, exfiltrating 77 GB of data and demanding $8 million in ransom. The GDID linked Stokes to the attack, revealing his identity despite VPN usage.
2026-07-07 | The Hacker News: Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
U.S. prosecutors linked alleged Scattered Spider hacker Peter Stokes to a May 2025 break-in at a luxury jewelry retailer using a persistent Windows device ID. The attackers gained access by impersonating employees to reset passwords, controlling three accounts, and attempting to deploy ransomware. The breach cost the retailer $2 million. Stokes, extradited from Finland, faces charges of conspiracy, computer intrusion, and fraud. Investigators note Scattered Spider operates as a loose collective, complicating efforts to mitigate the threat.
2026-07-07 | Infosecurity Magazine: Scattered Spider’s Structure More Like a Cybercrime Collective Than a Unified Gang
Scattered Spider is now viewed as a decentralized cybercrime collective rather than a unified gang, according to Group-IB's analysis published on June 7. The group operates through independent clusters sharing tactics and tools, resembling the Anonymous collective. Key activities include targeting employees in tech and communications for access, SIM swapping, and cryptocurrency fraud. Social engineering, particularly through phishing, is central to their operations. Arrests of individual members are unlikely to diminish the overall threat, emphasizing the need for organizations to defend against common tactics.
2026-07-07 | The Register: Windows is watching: Anti-piracy tool fingers Scattered Spider suspect
The US Justice Department's complaint against Peter Stokes links him to the Scattered Spider hacking group, which allegedly compromised over 100 corporate networks, resulting in over $100 million in ransom payments. Microsoft’s Global Device Identifier (GDID) was crucial in connecting Stokes to his online activities. Investigators used telemetry records from Microsoft, ngrok, and a VPN service to trace Stokes' actions, including the creation of an ngrok account on a Windows device.
Date: 2026-07-06 | Source: The Hacker News
Researchers discovered a vulnerability in Opera GX that allowed malicious websites to silently install browser mods, enabling data theft from visited pages. A proof of concept demonstrated the extraction of a user's Gmail address without any user interaction. Opera patched the flaw in version 130.0.5847.89 and rated it P1 severity, awarding $5,000 to the researchers. The attack exploited universal CSS injection, allowing attackers to leak sensitive information character by character. No evidence of exploitation in the wild was found.

2026-07-06 | Cyber Security News: Opera GX 0-Click Vulnerability Lets Attackers Exfiltrate User Data via Malicious Website
A vulnerability in Opera GX allows attackers to exfiltrate user data via a malicious website without user interaction. The flaw, linked to the "GX Mods" feature, enables silent installation of .crx files, which can inject CSS across all visited sites. Researchers demonstrated an attack that reconstructs Gmail addresses by probing for character sequences (trigrams) through crafted CSS. Opera patched the issue in May 2026 after a coordinated disclosure, highlighting risks from non-traditional attack surfaces.
2026-07-06 | Infosecurity Magazine: Opera GX Flaw Let Sites Auto-Install Mods to Steal Data
A critical flaw in the Opera GX browser allowed malicious websites to auto-install mods, enabling data theft without user interaction. Discovered by researcher zhero_web_security, the flaw exploited GX Mods, which lack permissions and can inject CSS across all tabs. This led to a zero-click cross-site leak, retrieving Gmail addresses, and a denial-of-service attack causing browser crashes. Reported in February, it was patched on May 8, with a $5000 bounty awarded. The research was published on July 3.
2026-07-06 | SC Magazine: Opera GX browser vulnerability could allow data theft and DoS attacks
A vulnerability in the Opera GX browser allows malicious websites to install customization mods without user interaction, enabling data theft through a zero-click cross-site leak (XS-Leak). Discovered by researcher zhero_web_security, this flaw permits attackers to inject CSS across all tabs, exfiltrating data like Gmail addresses. The auto-install feature can also facilitate denial-of-service (DoS) attacks, causing browser crashes. Opera patched the issue on May 8 and awarded a $5,000 bounty for the discovery.