Your next car could be watching your face | Malware
To reduce traffic incidents, all new cars sold in the EU must now include driver-monitoring technology, including Driver Drowsiness and Attention Warning (DDAW) systems and, on newer vehicles, Advanced Driver…
Read moreGitHub ‘Verified’ Commits Can Be Rewritten Into New Hashes Without Breaking Signatures | Cybersecurity
New research shows that a signed Git commit’s hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without…
Read more15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros | Cybersecurity
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable code has…
Read moreClaude Code’s hidden tracker was an “experiment,” says Anthropic | Malware
As a developer, you want to use tools you can trust and rely on. One researcher took that idea seriously enough to scrutinize their local Claude Code (2.1.196) installation. For…
Read moreHow the Reddit and Discord false report scam steals accounts | Malware
A stranger messages you on Reddit. They say someone reported them, and the reporting account looks a lot like yours. Was it you? It wasn’t. That’s not really the point…
Read moreRedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service | Cybersecurity
Swati KhandelwalJul 07, 2026Malware / Mobile Security A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals…
Read moreDEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts | Cybersecurity
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July,…
Read moreFake Netflix, Coca-Cola, and FIFA job scams target marketers | Malware
Attackers are impersonating major companies and recruiters to target marketing professionals, using trusted services and browser tricks to make the scam look legitimate. A BleepingComputer article detailing the campaign found…
Read moreSuspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities | Cybersecurity
A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign….
Read moreScammers are using AI to sell impossible flowers | Malware
We’ve had problems with deepfake celebrity scams, non-consensual deepfake sexual material, and deepfake politicians. Now we have to deal with… deepfake plants? Yup, AI seed slop is now a thing….
Read moreBeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA | Cybersecurity
Ravie LakshmananJul 07, 2026Vulnerability / Enterprise Security BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully…
Read moreChoose your WhatsApp username carefully | Malware
Dutch consumer organization Consumentenbond has warned users to be careful when choosing their optional WhatsApp username. Meta announced the introduction of usernames on June 29, 2026, and encouraged users to…
Read moreIran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations | Cybersecurity
An Iranian hacking group affiliated with Iran’s Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations….
Read moreHow to tell if an image is AI-generated | Malware
A photo of an injured dog by the roadside. A dating profile with pictures that look almost too perfect. A donation appeal showing a family stranded on a rooftop after…
Read moreBreach Transparency Remains Cybersecurity’s Toughest Governance Problem | Cybersecurity
Cybersecurity is entering a new phase. It’s one where the gap between awareness and operational execution is becoming the industry’s biggest challenge. That’s what stood out to me most after…
Read moreNetNut botnet takes a hit. Don’t be part of the next one. | Malware
In a joint operation, Google, the FBI, and other partners have dealt a significant blow to the residential proxy ecosystem by disrupting the NetNut (also tracked as Popa) botnet. NetNut…
Read moreNew TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions | Cybersecurity
Swati KhandelwalJul 06, 2026Cyber Espionage / Endpoint Security Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique,…
Read moreU.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case | Cybersecurity
A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation…
Read moreNorth Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign | Cybersecurity
The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as…
Read moreUnpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices | Cybersecurity
Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The…
Read moreNorth Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets | Cybersecurity
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data…
Read moreVerified X ad spreads Mac malware, while ConsentFix steals Microsoft accounts | Malware
Cybercriminals are finding new ways to trick people into compromising their own devices and accounts. One campaign used a sponsored ad on X to target Mac users, while another technique,…
Read moreEuropean Parliament Member Investigating Spyware Was Hacked With Pegasus | Cybersecurity
A new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device repeatedly hacked with the notorious Pegasus spyware while…
Read moreWinRAR flaw could allow attackers to take control of your computer | Malware
Rarlab has released a new version of the popular WinRAR tool to patch a vulnerability that can be abused in remote code execution attacks. The issue is fixed in WinRAR…
Read more