TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development | Cybersecurity

Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model…

Read more

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws | Cybersecurity

Ravie LakshmananJul 15, 2026Vulnerability / Browser Security Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities…

Read more

July 2026 Patch Tuesday fixes 622 Microsoft CVEs, including three zero-days | Malware

Just one month ago, June 2026 Patch Tuesday broke Microsoft’s previous record with 206 CVEs and three zero‑days. July now triples that count, reinforcing that the era of “small” Patch…

Read more

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware | Cybersecurity

Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are…

Read more

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands | Cybersecurity

Ravie LakshmananJul 15, 2026Vulnerability / Enterprise Security SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be…

Read more

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts | Cybersecurity

Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. “LabubaRAT creates a reusable foothold for…

Read more

Warning: Scammers are using FaceTime to empty bank accounts | Malware

Apple is urging users to treat any suspicious FaceTime call or message as untrusted, especially if it involves payments, refunds, password resets, or requests for personal information. This warning appears…

Read more

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata | Cybersecurity

Ravie LakshmananJul 14, 2026Vulnerability / Network Security Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth…

Read more

The inside job that cost ransomware victims millions | Malware

When a ransomware crew locks up your servers, the outside negotiator you hire has to know everything about you so that they can negotiate a smaller ransom payment. You tell…

Read more

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read | Cybersecurity

xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding…

Read more

A week in security (July 6; July 12) | Malware

Last week on Malwarebytes Labs: This new Windows malware can take over your PC and wipe it clean How mule betting scams recruit ordinary people Two Chrome updates in two…

Read more

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack | Cybersecurity

Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft’s own CVEs by…

Read more

Ghostcommit attack hides malicious AI instructions in images | Malware

Ghostcommit is a proof of concept that shows how AI assistants used to review software code can be tricked by hidden instructions embedded in images. The academic ASSET Research Group…

Read more

Trusting your kids online isn’t enough (Lock and Code S07E14) | Malware

This week on the Lock and Code podcast… There is a lot going on right now regarding the safety of kids online. In the United States, the majority of state…

Read more

⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More | Cybersecurity

Ravie LakshmananJul 13, 2026Cybersecurity / Hacking Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That’s supposed to be the good news….

Read more

Fake crypto gift card sites are getting harder to spot | Malware

You want to turn some crypto into a gift card. You search, click a promising result, and land on a site that looks polished and legitimate: a dark theme, trust…

Read more

Meta Files Patent for AI That Can Listen All Day and Track How You’re Feeling | Cybersecurity

Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound,…

Read more

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 | Cybersecurity

An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3…

Read more

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install | Cybersecurity

The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook that drops and executes…

Read more

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions | Cybersecurity

Ravie LakshmananJul 11, 2026Vulnerability / Email Security Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary…

Read more

Two Chrome updates in two days fix critical vulnerabilities | Malware

Updating Chrome is becoming an almost daily task lately. But it’s too important to ignore. On Wednesday, July 8, Google released another Chrome update, just one day later after the…

Read more

How mule betting scams recruit ordinary people | Malware

Mule betting or third-party betting account scams are a form of money mule scam where criminals recruit or coerce people into opening gambling accounts in their own name. The criminals…

Read more

Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat | Cybersecurity

Swati KhandelwalJul 10, 2026Enterprise Security / Security Incident Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News…

Read more

This new Windows malware can take over your PC and wipe it clean | Malware

Microsoft published new research on GigaWiper, a modular Golang backdoor for Windows that combines robust remote access with multiple ways to permanently destroy systems and data. GigaWiper is a Windows…

Read more

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws | Cybersecurity

Ravie LakshmananJul 10, 2026AI Security / Vulnerability Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential…

Read more

Attackers Exploit ‘Ill Bloom’ Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets | Cybersecurity

Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words…

Read more

Microsoft fixes RoguePlanet zero-day in Defender | Malware

Microsoft issued a security update that fixes the zero-day vulnerability known as RoguePlanet in Microsoft Defender. RoguePlanet is tracked as CVE-2026-50656, a Microsoft Defender elevation of privilege (EoP) vulnerability. As we…

Read more

6.9 million driver’s license numbers stolen from AssuranceAmerica | Malware

Insurance provider AssuranceAmerica has confirmed a data breach affecting the personal information and driver’s license numbers of up to 6.9 million people. AssuranceAmerica provides car and rental insurance to customers…

Read more

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs | Cybersecurity

Ravie LakshmananJul 09, 2026Developer Security / Supply Chain Security Datadog Security Labs is warning of “several overlapping campaigns” that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through…

Read more

How World Cup crypto prediction sites take your money | Malware

Crypto prediction and betting sites are appearing around the World Cup, and researchers have already tracked scams aimed at fans, including fake ticketing, fixed-match betting, prediction scams, and fan-branded meme…

Read more
Update cookies preferences