Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git | Cybersecurity
Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June…
Read moreOpenAI’s agent escaped its sandbox during a security test | Malware
During an internal OpenAI security evaluation, a chain of AI models escaped its sandbox, reached the internet, and then accessed Hugging Face infrastructure to complete the test objective. OpenAI is…
Read moreCall of Duty Mobile scam uses fake free points to steal player accounts | Malware
Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway. Victims are asked to log in with their email…
Read moreDon’t get fooled by TikTok resin art scams | Malware
Resin art has become a popular corner of TikTok, with some videos attracting millions of views. But not every glossy, colorful post is what it claims to be. Scammers are…
Read moreBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery | Cybersecurity
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing…
Read moreHacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry | Cybersecurity
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand’s Ministry of…
Read moreWhatsApp Web chats exposed by Adobe’s Acrobat extension flaw | Malware
HermeticReader is the name given to a recently disclosed vulnerability in the Adobe Acrobat PDF extension for Chrome, tracked as CVE-2026-48294. Researchers discovered the issue in early June 2026 and…
Read moreRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes | Cybersecurity
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client. The payload goes after the last 90 days of email, the organization’s…
Read moreHow Synthetic Identity Fraud is Coming for Machine Identities | Cybersecurity
Most people understand identity theft as an attacker stealing a real person’s sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real…
Read moreMillions of cars could be tracked and unlocked by a hidden security flaw | Malware
A car alarm vendor’s coding mistake has left millions of vehicles vulnerable to theft and location tracking. Thanks to the way dealers sell car alarms, many affected drivers don’t even…
Read moreNine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs | Cybersecurity
RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root…
Read moreGitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier | Cybersecurity
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while…
Read moreUbuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs | Cybersecurity
Ravie LakshmananJul 22, 2026Linux / Vulnerability Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root…
Read moreChick-fil-A loyalty accounts hijacked using stolen passwords | Malware
Fast-food chain Chick-fil-A is warning customers after attackers hijacked loyalty accounts using stolen passwords in a credential stuffing attack. Chick-fil-A says it detected suspicious login activity against some Chick-fil-A One…
Read moreWhy Modern SOCs Need Multi-Layered Detections | Cybersecurity
The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass…
Read moreDon’t trust that “FBI agent” in your DMs | Malware
The Federal Bureau of Investigation’s (FBI) Internet Crime Complaint Center (IC3) is warning that scammers are impersonating the bureau on social media and on messaging apps, targeting people who’ve already…
Read morePolice Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA | Cybersecurity
Swati KhandelwalJul 22, 2026Law Enforcement / Cybercrime German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most…
Read morePaidwork breach exposes data of 23 million users: Check if you’re affected | Malware
A data breach at Paidwork, a platform that pays people small amounts to complete online microtasks, has exposed personal and financial information of more than 23 million users. According to…
Read moreNew ClickLock Stealer locks your Mac until you hand over your password | Malware
ClickLock Stealer is a new, modular macOS infostealer delivered via ClickFix-style phishing pages that can lock a victim’s Mac, steal their macOS password, browser and password manager data, cryptocurrency wallets,…
Read moreApple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs | Cybersecurity
Ravie LakshmananJul 21, 2026Vulnerability / Cloud Security Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked,…
Read moreWhat happens if you visit a WordPress site hacked through wp2shell? | Malware
WordPress has patched a serious core vulnerability chain known as wp2shell, and site owners are understandably focused on updating their own sites. But there’s another question worth asking: what happens…
Read moreAWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code | Cybersecurity
Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code on a developer’s machine, with…
Read moreOpen-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs | Cybersecurity
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will…
Read moreAI nudify apps spark legal scrutiny of Apple and Google’s profits | Malware
You expect all kinds of apps on Apple’s App Store and Google’s Play Store, from weather monitors to home automation apps and games. What you might not expect are apps…
Read moreCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution | Cybersecurity
Ravie LakshmananJul 21, 2026Vulnerability / Artificial Intelligence Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared…
Read moreHealthcare giant Abbott probes two cyber incidents amid extortion claims | Malware
Abbott Laboratories, one of the world’s largest healthcare and medical device companies, is investigating two apparently unrelated cyber incidents after confirming unauthorized access to internal systems. While Abbott says there…
Read moreFakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware | Cybersecurity
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a…
Read moreThe Odyssey piracy scams appear within hours of the movie’s release | Malware
Christopher Nolan’s The Odyssey is one of the biggest movie releases of the year and scammers wasted no time taking advantage of it. Within hours of the film’s release, we…
Read moreHollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 | Cybersecurity
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events…
Read moreFake games spread stealers with RenPy Loader, MSBuild and EtherHiding | Malware
We have detected several campaigns using fake downloads of games, mods, cracks, and software to spread RenPy Loader. Once installed, the loader starts a complex, multi-stage infection chain that abuses…
Read more