Security · Top stories
AI-Generated Ransomware Discovered Exploiting Chromium API on Windows and Android
A new ransomware artifact created by the AI model DeepSeek combines theoretical attacks with real browser functionality, enabling browser-based ransomware on Windows and Android. This marks the first identified practical attack chain of its kind, indicating a significant shift in the cybersecurity threat landscape.
Critical Flaw CVE-2026-46817 in Oracle E-Business Suite Exploited
A critical vulnerability in Oracle E-Business Suite, CVE-2026-46817, is now being actively exploited. Impacting versions 12.2.3 to 12.2.15, the flaw allows unauthenticated attackers to take control of Oracle Payments, necessitating immediate patching for affected instances.
Mustang Panda Exploits Zoho WorkDrive in Campaign Against Indian Government
The Mustang Panda group has launched campaigns targeting the Indian government, utilizing Zoho WorkDrive to transmit commands and steal data. This approach leverages legitimate service traffic to mask malicious activities and is part of broader espionage efforts aimed at India's hydropower initiatives and defense relations with Taiwan.
Microsoft Removes 119 Malicious Edge Extensions Involved in Malware Operation
Microsoft has removed 119 Edge extensions from its Add-ons store that concealed malware within images and fonts, compromising user credentials and facilitating ad fraud. The extensions, installed by up to 2.6 million users, utilized steganography to hide malicious code, operating undetected for years.
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
A public proof-of-concept has been released for CVE-2026-55200, a critical flaw in libssh2 that may allow memory corruption and code execution for connected clients. This vulnerability affects all versions up to 1.11.1, posing significant risks as libssh2 is widely used in various applications and systems.
Hijacked npm and Go Packages Deploy Python Infostealer via VS Code Tasks
Cybersecurity researchers have identified hijacked npm and Go packages that deploy a Python-based infostealer on compromised systems. This method utilizes a concealed VS Code task to execute malware upon opening a project folder, facilitating data theft and persistent access.
Tesla Settles FSD Crash Lawsuit Amid Ongoing Federal Investigation
Tesla has settled a lawsuit concerning a fatal crash involving its Full Self-Driving (FSD) system while federal investigations into the system's safety continue. The National Highway Traffic Safety Administration is examining if FSD can adequately handle low visibility conditions, after several incidents, potentially affecting future Tesla recalls or regulations.
Anonymous GitHub user releases unpublished zero-days for major software
An anonymous GitHub account has begun releasing previously undisclosed zero-day vulnerabilities in popular software, including Floci and FFmpeg. The account claims to utilize an AI-driven fuzzing workflow and intends to share serious vulnerabilities, impacting software security practices.
Russian hackers identified as responsible for $2.5B Jaguar Land Rover breach
A cyberattack on Jaguar Land Rover (JLR) last year has been traced to Russian hackers. The breach caused production delays and significant economic losses, prompting a £1.5 billion government bailout.
Linux pedit COW Exploit Allows Root Access via Cached Binary Poisoning
A critical flaw in the Linux kernel's traffic-control subsystem allows unprivileged users to gain root access on vulnerable systems. The exploit targets the memory cache of setuid binaries, enabling attackers to inject and execute malicious code while bypassing file integrity checks.
CISA Warns of Exploited Flaws in Lantronix EDS5000 and PTC Windchill
The CISA has issued alerts concerning the exploitation of critical vulnerabilities in Lantronix EDS5000 and PTC Windchill systems. The Lantronix flaw allows code execution with escalated privileges, while the Windchill vulnerability enables remote code execution. Both alerts urge immediate patching to mitigate risks posed by these active threats.
Miasma Malware Compromises npm Packages and GitHub Actions
Researchers identified a supply chain attack involving Miasma malware targeting multiple npm packages and GitHub Actions. The attack compromises developer credentials to propagate malware across various software ecosystems, posing significant security risks.
Popular Chrome Ad Blocker Can Execute Arbitrary JavaScript Code
The Chrome ad blocker 'Adblock for YouTube,' with over 10 million installs, has been found to contain functionality for executing arbitrary JavaScript code remotely. This could potentially allow for significant privacy risks, including data theft, although no malicious activity has been reported to date.
New Mistic Backdoor Discovered Linked to KongTuke in Cyber Attack Campaigns
A new backdoor named Mistic has emerged in attacks directed at various sectors, linked to the KongTuke group. The stealthy malware is designed for long-term access, employing sophisticated evasion techniques such as memory-based execution and DLL side-loading, marking a significant threat to targeted organizations.
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited for Root Access
A zero-day vulnerability in Cisco Catalyst SD-WAN, tracked as CVE-2026-20245, has been exploited to gain root access by an unknown threat actor. This flaw, identified by Mandiant, allows an authenticated attacker to execute commands by manipulating user input, raising serious security concerns for affected systems.
Law Enforcement Disrupts Amadey and StealC Malware Networks, Reclaims 27M Credentials
A law enforcement operation disrupted the Amadey and StealC malware networks, recovering 27 million stolen credentials and restricting over $47 million in criminal cryptocurrency assets. This takedown involved 326 servers and 142 domains and highlights the effectiveness of public and private sector collaboration in combating cybercrime.
Emergence of AI Threat Models Marks a New Era in Cybersecurity
The rise of frontier agentic AI models has drastically reduced the time from threat discovery to execution in cybersecurity. This shift poses a significant risk as AI can exploit vulnerabilities faster than human defenders can respond.
Cisco Introduces Antares AI Models for Code Vulnerability Detection
Cisco Foundation AI has launched Antares, a family of small language models aimed at identifying vulnerabilities within codebases. Antares offers an open-weight approach, balancing cost and accuracy while addressing data sovereignty issues in security research.
AWS Enhances Bot Traffic Security with Web Bot Authentication in WAF Bot Control
AWS WAF Bot Control now includes Web Bot Authentication (WBA), using cryptographic signatures to distinguish legitimate AI bot traffic from malicious activity. This update addresses security challenges in multi-tenant environments such as Amazon Bedrock AgentCore, where traditional IP-based methods fall short. The method leverages two IETF drafts to verify bot identities securely.
Node.js to release security updates for multiple versions on July 27, 2026
The Node.js project plans to release security updates for versions 26.x, 24.x, and 22.x on July 27, 2026. The updates will address high severity security vulnerabilities, emphasizing the need for users to maintain up-to-date software for system security.
SecurityWeek Introduces Critical Impact Awards for Industrial Cybersecurity
SecurityWeek has launched the Critical Impact Awards to recognize achievements in industrial cybersecurity. This awards program aims to honor organizations and individuals based on merit rather than sponsorship, enhancing credibility in the cybersecurity field.
Kenya investigates hack of president's website demanding bitcoin ransom
Kenya is investigating a cyberattack that defaced President William Ruto's official website with a ransom demand of five bitcoins. The attackers claimed this was their third warning to the president, though no sensitive data has been compromised according to government officials.
Researchers Reveal Security Flaws in AI Coding Agents and Open-Source Mobile Frameworks
Researchers from Hong Kong University have highlighted vulnerabilities in AI coding agents, notably OpenAI Codex and Claude Code, which can be bypassed using techniques like SKILLCLOAK. These techniques allow malicious AI add-ons and agents to evade current security scanners. These findings underscore the need for improved security measures in AI agent marketplaces and software, as current defenses are inadequate.
CISO Andreas Gaetje Discusses Career Path at Körber AG
Andreas Gaetje, CISO at Körber AG, reflects on his unconventional career journey from economics to cybersecurity. He emphasizes the significance of adapting to the evolving role of IT security, which has grown from compliance to a critical business threat.
Meta Awards $78,000 Bug Bounty for Critical Customer Support Data Vulnerability
Meta has awarded a $78,000 bounty to researcher Rony K Roy for discovering a vulnerability in its support data system that could have led to the exposure of sensitive customer information. The issue, initially thought minor, was found to allow unauthorized access to support cases and user communications, demonstrating significant flaws in Meta's security framework.
Clover Health Investments Reports Data Breach Affecting Customer Information
Clover Health Investments disclosed a data breach affecting customers' personal and health information due to a social engineering attack that compromised three employee accounts. The company initiated its response plan and engaged cybersecurity experts to handle the situation, though the full impact of the breach is still being investigated.
Apple Appeals to Supreme Court in Epic Games App Store Fee Dispute
Apple has asked the Supreme Court to review a contempt ruling regarding its App Store fees for external payment links. Judge Yvonne Gonzalez Rogers had ruled that Apple's implementation of commissions violated a 2021 injunction. Both Apple and Epic Games have requested a pause in ongoing proceedings pending the Supreme Court's decision.
Unpatched Flaw in Shark Vacuums Allows Unauthorized Control Across AWS Region
A vulnerability in Shark robot vacuums allows attackers to control devices across an AWS region using leaked certificates. This unpatched flaw exposes live camera feeds, home maps, and Wi-Fi credentials while presenting significant privacy risks to users. The issue has been known to SharkNinja since March without a patch.
Mozilla Finds Sensitive Data Sharing by Stardust Period Tracker
Mozilla research reveals Stardust period tracker shares sensitive health data with RudderStack, raising privacy concerns. The data includes birthdates, birth control types, and reproductive goals, potentially affecting privacy, especially in legal contexts in the U.S. after abortion protections were overturned.
OkoBot Malware Targets Cryptocurrency Wallets via Seed Phrase Phishing
OkoBot, a malware framework active since April 2025, targets cryptocurrency wallet users by injecting phishing pages into legitimate wallet apps like Ledger and Trezor. Kaspersky reports hundreds of victims globally, particularly in Brazil, Vietnam, Canada, Mexico, and Türkiye. The malware delivers over 20 payloads to steal credentials and sensitive data, posing a significant threat.
Israeli Startup Oak Launches AI-Driven Identity Management Solution with $60M Funding
Startup Oak has raised $60 million in funding, launching an AI-powered identity management system. This aims to unify identity governance across enterprises, addressing challenges exacerbated by AI. Oak's system combines various identity management tools into a single control plane, already deployed by some enterprise clients.
Dutch Police Uncover Global Crypto Scam, Arrest Alleged Leader
Dutch police dismantled a large-scale international crypto scam, arresting the alleged mastermind and several associates. The scheme, operating through 20 call centers, swindled tens of thousands, making over €100 million monthly. The main suspect is a 46-year-old Israeli-Polish known in the cyberworld, caught in Poland and extradited to the Netherlands.
White House Launches AI-Driven Gold Eagle Initiative for Cybersecurity Coordination
The White House has launched the Gold Eagle initiative, an AI-supported federal clearinghouse for cybersecurity vulnerabilities. This program aims to enhance vulnerability detection and remediation across government and private sectors by facilitating collaboration between software maintainers and infrastructure operators. Gold Eagle is backed by multiple federal agencies and uses AI to manage cybersecurity risks efficiently.
Microsoft's Global Device Identifier (GDID) Raises Privacy Concerns Amidst Hacking Case
A federal complaint unveiled details about Microsoft's Global Device Identifier (GDID) used for tracking Windows devices. The ID, tied to user privacy concerns, played a role in the capture of a teenage hacker, Peter Stokes. It highlights Windows' telemetry features and their implications on surveillance and privacy.
Critical RabbitMQ Vulnerabilities Risk Exposing OAuth Secrets and Tenant Data
A critical vulnerability in RabbitMQ, CVE-2026-5721, exposes OAuth secrets, enabling unauthorized access to sensitive information. An additional flaw can allow logged-in users to access cross-tenant data. These flaws, present since early 2024, have been patched in recent updates. These vulnerabilities underscore the importance of applying security updates to prevent unauthorized access risks.
Australia's eSafety Watchdog Criticizes Tech Giants for Inadequate Sextortion Measures
Australia's eSafety Commission reports over 2,000 sextortion complaints, with 800 from men aged 18-24. Tech companies, including Apple and Meta, face criticism for not effectively combating these threats, especially given recurring coercive scripts. Major platforms identified include Instagram, WhatsApp, iMessage, and Snapchat.
Lidl Data Breach Affects Customers in Germany, Belgium, and Netherlands
Lidl, a European supermarket chain, suffered a data breach affecting online customers in Germany, Belgium, and the Netherlands. Attackers accessed customer data stored by a third-party service provider. Although no payment information was compromised, affected customers have been advised to be cautious of potential phishing scams.
Forg365 Phishing-as-a-Service Targets Microsoft 365 with Sophisticated Methods
Forg365, a new phishing-as-a-service platform, targets Microsoft 365 accounts with advanced techniques such as adversary-in-the-middle attacks, AI-generated lures, and device code phishing. This operation is notable for its complexity and capability to execute persistent access while leveraging legitimate email services for delivery.
Phia Faces Suspension for Alleged Cookie Stuffing in Affiliate Marketing
Phia, co-founded by Phoebe Gates and Sophia Kianni, is accused of cookie stuffing, improperly claiming affiliate sales it did not generate. Investigations revealed the misuse, leading to Phia's suspension from Impact.com. The issue highlights challenges in maintaining transparency in affiliate marketing practices.
Attackers Use Dormant GitHub Accounts for Reconnaissance via API
Datadog Security Labs has identified multiple attack campaigns exploiting dormant GitHub accounts for organizational reconnaissance. Attackers use these accounts with automated tools to gather data, occasionally accessing private repositories. This is significant due to potential risks of further targeted attacks.