Security · Top stories
Flock cameras expand beyond license plate tracking in the U.S.
Flock Security's surveillance cameras, primarily known for tracking license plates, are increasingly used for broader monitoring, raising privacy concerns. With over 100,000 units installed, these cameras pose significant implications for public surveillance and law enforcement practices.
Ukraine and FBI Uncover Russian Intelligence Messaging Credential Theft Campaign
The Security Service of Ukraine, in collaboration with the FBI, revealed a Russian intelligence operation targeting messaging accounts of officials and civilians. The attackers used fake support messages to coax victims into revealing sensitive credentials.
New SharkLoader Malware Used to Deploy Cobalt Strike in Global Cyberattacks
Kaspersky reports a new malware called SharkLoader is being used to deploy Cobalt Strike in cyber attack campaigns. Targeting various sectors in multiple countries, the campaign reveals a significant and global threat landscape potentially linked to a Chinese-speaking threat actor.
Chinese APT CL-STA-1062 Uses TinyRCT Backdoor in Southeast Asia Cyber Campaign
A Chinese-speaking APT known as CL-STA-1062 has been linked to a new backdoor, TinyRCT, targeting government and critical infrastructure in Southeast Asia. This development highlights a sustained threat environment for state entities in the region.
Amazon Q Developer Flaw Allows Code Execution via Malicious Repos
A high-severity flaw in Amazon Q Developer permitted malicious repositories to execute code and steal developer credentials. The issue stemmed from the way Amazon's AI coding assistant handled Model Context Protocol servers, which has now been patched by Amazon.
Microsoft Alerts on Phishing Campaign Targeting Hotels with Node.js Implant
Microsoft identified a phishing campaign targeting hotels across Europe and Asia that leverages ZIP files containing a Node.js implant. The campaign uses specialized email tactics to bypass security measures and exploit hotel operational themes, highlighting a significant security concern in the hospitality sector.
Russia Used Cellebrite Tools on Activist's iPhone Post-Sales Cutoff
Russian authorities accessed the iPhone of detained activist Andrey Pivovarov using Cellebrite's forensic tools in June 2021, despite the company's pledge to cease sales to Russia. This incident raises serious ethical concerns regarding the use of forensic technology in political prosecutions and reflects ongoing state repression efforts against opposition figures.
Google Reveals Details on Turla's STOCKSTAY Backdoor Targeting Ukraine
Google's Threat Intelligence Group announced the discovery of the STOCKSTAY backdoor, attributed to the Russian cyber espionage group Turla. This malware has been used to target Ukrainian government and military organizations, showcasing an evolution in Turla's cyber capabilities and tactics since its development traceable to late 2022.
Cloudflare Develops Privacy Protocol, curl Bug Discovered, Critical Hoppscotch Vulnerability
Cloudflare, alongside major web browsers, introduced a protocol using Private Access Control Tokens to enhance web privacy. AISLE reported six vulnerabilities in curl, the oldest dating back to 2001, while a critical security flaw in Hoppscotch allows unauthenticated attackers to compromise API instances.
New Rust-based Gaslight Malware Targets macOS with AI Disruption Techniques
A new macOS malware, codenamed Gaslight, uses prompt injection techniques to evade AI analysis. Linked to North Korean threat actors, the malware embeds fabricated system-failure messages to disrupt AI-assisted triage efforts.
DoJ Seizes Huione Cloud Account Linked to Cryptocurrency Fraud
The U.S. Department of Justice has seized a Huione Group cloud account used for money laundering linked to various cyber scams. This action, which follows new sanctions against related entities, aimed to disrupt significant financial networks facilitating fraudulent activities connected to cryptocurrency.
AWS Security Agent enhances features with threat modeling and code review updates
AWS Security Agent, part of AWS Continuum, now includes threat modeling, advanced code reviews, and support for multiple code repositories. These updates aim to enhance application security throughout the development lifecycle by offering context-aware analysis and vulnerability remediation.
New Kimsuky campaign compromised South Korean software vendors
Research Reveals Evolving Use of Residential Proxies in Carding Operations
Flare researchers analyzed 2,889 underground posts to understand how carders are utilizing residential proxies. The findings indicate that while residential IP addresses are critical, they are increasingly seen as unreliable and require careful selection and combination with other digital identity tools.
Operational Technology Security Faces Unique Challenges in Vulnerability Management
Operational Technology (OT) security presents distinct challenges compared to IT security, especially in vulnerability management processes. This difference arises from the traditional design of OT systems, which often lack modern security features and focus primarily on denial of service (DoS) impacts rather than remote code execution.
Mandiant Highlights Risks of Exposed Serverless Applications
Mandiant warns that publicly exposed serverless applications often lack authentication and can lead to serious compromises in cloud environments. The report provides guidance on how to secure these vulnerable deployments, which are increasingly used in AI workflows.
Recent Clearinghouse Announcements Lack Significance, Says Industry Expert
Numerous tech companies have launched clearinghouses for vulnerability data, including Athena. The article argues that while the influx of clearinghouses may seem significant, most won't provide actionable solutions to security issues in the software supply chain.
Remote Attestation Enhances Host Trust in Security Operations
Remote attestation enables verification of a host's security state before it starts processing. By using Trusted Platform Module (TPM) technology, organizations can ensure that systems meet specified configurations, significantly reducing risks from compromised machines.
Post-quantum cryptography guidance released for CISOs
Over a dozen economies issued guidance on post-quantum cryptography (PQC) adoption. The focus is on strategic organization-wide changes required for compliance and modernization beyond just algorithm updates.
AI Tools Facilitate Service Desk Attacks, Highlights Need for Enhanced Security
IBM's report indicates that 16% of data breaches involved AI tools, often for social engineering attacks at service desks. This trend makes it essential for organizations to improve identity verification processes to protect sensitive operations from AI-enabled impersonation.
Challenges of Identity Lifecycle Management for AI Agents
Identity lifecycle management systems, designed for human employees, struggle to accommodate AI agents. This gap presents governance issues as enterprises increasingly integrate autonomous agents, necessitating updates to existing frameworks.
Richard Bejtlich Advocates for NDR in Modern Security Operations
Richard Bejtlich highlights the growing need for Network Detection and Response (NDR) in cybersecurity. His guide emphasizes moving beyond traditional alerts to prioritize actionable evidence in detecting and mitigating threats.
Webinar Highlights Behavioral AI for Modern Email Security Threats
BleepingComputer is hosting a webinar on July 8, 2026, focused on the limitations of traditional email security against evolving threats like phishing and business email compromise. Experts will discuss how behavioral AI can automate the detection and response process, addressing attacks that leverage trusted identities and legitimate workflows.
Integrating Autonomous AI and Analyst Copilots in Security Operations Centers
A Fortune 50 CISO discussed AI agents in security operations centers (SOC), revealing limitations in current designs that may overlook many alerts requiring human judgment. The insights of psychologist Daniel Kahneman emphasize the need for a balanced approach between automatic and deliberate human cognition in AI architecture for effective security.
Guide to Removing Your Personal Data from the Internet
Personal data is widely available for sale due to data brokers. This poses security risks and privacy concerns for individuals, as their information can be exploited in scams and harassment. Automated solutions like Incogni can aid in data removal efforts.
Guide to Threat Models for Cybersecurity Challenges
Soatok provides an informal guide to threat modeling, emphasizing its importance in cybersecurity. The guide outlines key questions necessary for creating effective threat models and offers insights into identifying and prioritizing potential threats.
Guide on Detecting and Preventing Subdomain Takeovers
This article outlines how to identify and prevent subdomain takeovers, a tactic where threat actors exploit dangling DNS records. It stresses the importance of managing DNS configurations to mitigate risks associated with this security vulnerability.
Webinar on Defending Against Rapid AI-Powered Attacks Announced
A free webinar hosted by Zscaler will focus on defending against AI-driven attacks, which have become significantly faster. The session will provide strategies to adapt security measures in response to these advanced threats, emphasizing Zero Trust principles.