DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware | Cybersecurity
Ravie LakshmananJul 30, 2026Malvertising / Cryptocurrency Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages…
Read moreMalwarebytes for Windows, now available on the Microsoft Store | Malware
When you’re setting up a new PC or looking for an app you already know, the Microsoft Store is often the easiest place to start. It’s built into Windows and…
Read moreThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories | Cybersecurity
Ravie LakshmananJul 30, 2026Hacking News / Cybersecurity News A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an…
Read moreOpenAI explains how its AI agent breached Hugging Face | Malware
On July 28, OpenAI published an update on the agent that escaped its sandbox and hacked into Hugging Face during an internal cybersecurity evaluation. In the update, OpenAI reiterates that…
Read moreMicrosoft Copilot for Word Can Copy Hidden Prompts Into New Documents | Cybersecurity
Swati KhandelwalJul 30, 2026Vulnerability / AI Security Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the…
Read moreBuying TikTok views or followers? Here’s what you’re really getting | Malware
A whole industry has sprung up around selling TikTok “growth.” Cheap views by the hundred, pre-made ad accounts, and polished sales pages promising a repeatable path to serious revenue. None…
Read moreAmazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet | Cybersecurity
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft:…
Read moreApple accused of letting fake crypto app steal $1.8 million | Malware
Apple’s tagline for its App Store says, “The apps you love. From a place you can trust.” You might love the apps, but can you trust the store? A federal…
Read moreCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads | Cybersecurity
Swati KhandelwalJul 29, 2026Vulnerability / Software Security Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers…
Read moreAI robocalls: Why caller ID is still lying to you | Malware
If you feel like your phone has turned into a scam megaphone, you’re not alone. Robocalls have been a problem for years. Artificial intelligence (AI) is making them slicker, faster,…
Read moreRuflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory | Cybersecurity
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The…
Read moreRussia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity | Cybersecurity
Ravie LakshmananJul 29, 2026Cybercrime / Law Enforcement The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities…
Read moreVatican’s Click To Pray app exposed personal data from 700,000 users | Malware
A prayer app launched by Pope Francis in 2019 contained a security flaw that exposed the personal information of hundreds of thousands of users before it was finally fixed this…
Read moreTwo Compromised joyfill npm Packages Run RAT When Imported Into Node.js | Cybersecurity
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of…
Read moreShared Claude chats were searchable on Google | Malware
Reddit users found that by using a specific Google search query, it was possible to find Claude conversations that users had shared. This exposed sensitive material, including crypto wallet keys,…
Read moreWe rebuilt Malwarebytes Mobile Security for the scams of today | Malware
Nearly half of people encounter a scam on their phone every single day. Malwarebytes is doing something about it. That figure comes from a 2025 Malwarebytes survey of 1,300…
Read moreClaude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack | Cybersecurity
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a…
Read moreTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process | Cybersecurity
Swati KhandelwalJul 28, 2026Linux / Endpoint Security A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main…
Read moreMicrosoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost | Cybersecurity
Swati KhandelwalJul 28, 2026AI Security / Vulnerability Management Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash…
Read moreJuly Apple updates are especially important if you receive images | Malware
Apple has shipped a hefty round of July security patches, headlined by iOS/iPadOS 26.6, macOS Tahoe 26.6, and Safari 26.6, with dozens of vulnerabilities squashed across kernel, WebKit, media frameworks,…
Read moreAttackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw | Cybersecurity
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a…
Read moreAftercall ads are driving Android users crazy | Malware
Aftercall is a wave of deceptive Android apps on Google Play that pose as everyday tools while bombarding users with pop-up ads after every phone call. When an unexpected ad…
Read moreNVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework | Cybersecurity
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The…
Read moren8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process | Cybersecurity
Swati KhandelwalJul 27, 2026Vulnerability / Enterprise Security n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation…
Read moreWhat’s your data worth on the dark web? (Lock and Code S07E15) | Malware
This week on the Lock and Code podcast… Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data’s relationship with the entire global…
Read moreTELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments | Cybersecurity
Ravie LakshmananJul 27, 2026Cyber Attack / Threat Intelligence Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the…
Read moreMalvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable | Cybersecurity
A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file…
Read moreBeyond the Play Store: How Android threats really spread | Malware
You probably think of your phone’s security the way you think of your front door: as long as you’re downloading apps from the Play Store, you’re safe. And for the…
Read moreFastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available | Cybersecurity
Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot…
Read moreGoogle wants to store a selfie video of your face | Malware
Google has started rolling out a new way to recover access to your account if you’ve lost your phone or forgotten your password: a “selfie video” verification option. After recording…
Read more