Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw | Cybersecurity
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a…
Read moreAftercall ads are driving Android users crazy | Malware
Aftercall is a wave of deceptive Android apps on Google Play that pose as everyday tools while bombarding users with pop-up ads after every phone call. When an unexpected ad…
Read moreNVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework | Cybersecurity
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The…
Read moren8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process | Cybersecurity
Swati KhandelwalJul 27, 2026Vulnerability / Enterprise Security n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation…
Read moreWhat’s your data worth on the dark web? (Lock and Code S07E15) | Malware
This week on the Lock and Code podcast… Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data’s relationship with the entire global…
Read moreTELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments | Cybersecurity
Ravie LakshmananJul 27, 2026Cyber Attack / Threat Intelligence Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the…
Read moreMalvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable | Cybersecurity
A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file…
Read moreBeyond the Play Store: How Android threats really spread | Malware
You probably think of your phone’s security the way you think of your front door: as long as you’re downloading apps from the Play Store, you’re safe. And for the…
Read moreFastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available | Cybersecurity
Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot…
Read moreGoogle wants to store a selfie video of your face | Malware
Google has started rolling out a new way to recover access to your account if you’ve lost your phone or forgotten your password: a “selfie video” verification option. After recording…
Read moreResearcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git | Cybersecurity
Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June…
Read moreOpenAI’s agent escaped its sandbox during a security test | Malware
During an internal OpenAI security evaluation, a chain of AI models escaped its sandbox, reached the internet, and then accessed Hugging Face infrastructure to complete the test objective. OpenAI is…
Read moreCall of Duty Mobile scam uses fake free points to steal player accounts | Malware
Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway. Victims are asked to log in with their email…
Read moreDon’t get fooled by TikTok resin art scams | Malware
Resin art has become a popular corner of TikTok, with some videos attracting millions of views. But not every glossy, colorful post is what it claims to be. Scammers are…
Read moreBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery | Cybersecurity
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing…
Read moreHacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry | Cybersecurity
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand’s Ministry of…
Read moreWhatsApp Web chats exposed by Adobe’s Acrobat extension flaw | Malware
HermeticReader is the name given to a recently disclosed vulnerability in the Adobe Acrobat PDF extension for Chrome, tracked as CVE-2026-48294. Researchers discovered the issue in early June 2026 and…
Read moreRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes | Cybersecurity
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client. The payload goes after the last 90 days of email, the organization’s…
Read moreHow Synthetic Identity Fraud is Coming for Machine Identities | Cybersecurity
Most people understand identity theft as an attacker stealing a real person’s sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real…
Read moreMillions of cars could be tracked and unlocked by a hidden security flaw | Malware
A car alarm vendor’s coding mistake has left millions of vehicles vulnerable to theft and location tracking. Thanks to the way dealers sell car alarms, many affected drivers don’t even…
Read moreNine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs | Cybersecurity
RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root…
Read moreGitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier | Cybersecurity
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while…
Read moreUbuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs | Cybersecurity
Ravie LakshmananJul 22, 2026Linux / Vulnerability Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root…
Read moreChick-fil-A loyalty accounts hijacked using stolen passwords | Malware
Fast-food chain Chick-fil-A is warning customers after attackers hijacked loyalty accounts using stolen passwords in a credential stuffing attack. Chick-fil-A says it detected suspicious login activity against some Chick-fil-A One…
Read moreWhy Modern SOCs Need Multi-Layered Detections | Cybersecurity
The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass…
Read moreDon’t trust that “FBI agent” in your DMs | Malware
The Federal Bureau of Investigation’s (FBI) Internet Crime Complaint Center (IC3) is warning that scammers are impersonating the bureau on social media and on messaging apps, targeting people who’ve already…
Read morePolice Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA | Cybersecurity
Swati KhandelwalJul 22, 2026Law Enforcement / Cybercrime German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most…
Read morePaidwork breach exposes data of 23 million users: Check if you’re affected | Malware
A data breach at Paidwork, a platform that pays people small amounts to complete online microtasks, has exposed personal and financial information of more than 23 million users. According to…
Read moreNew ClickLock Stealer locks your Mac until you hand over your password | Malware
ClickLock Stealer is a new, modular macOS infostealer delivered via ClickFix-style phishing pages that can lock a victim’s Mac, steal their macOS password, browser and password manager data, cryptocurrency wallets,…
Read moreApple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs | Cybersecurity
Ravie LakshmananJul 21, 2026Vulnerability / Cloud Security Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked,…
Read more