From SecurityWeek · 40 stories
Supply Chain Attacks Target Open Source, Impacting Over 2,500 Organizations
Software supply chain attacks targeting open source repositories and CI/CD systems have increased significantly, with a recent incident impacting over 2,500 organizations and 430,000 CI/CD pipelines. This attack, attributed to TeamPCP, initially compromised Aqua Security's Trivy vulnerability scanner and subsequently affected projects like LiteLLM, leading to the exposure of terabytes of credentials from major companies.
Azure Cosmos DB Vulnerability "CosmosEscape" Allowed Access to All Databases
Wiz Research discovered "CosmosEscape," a critical vulnerability in Azure Cosmos DB's Gremlin API that could have allowed attackers to compromise all databases within the service, including Microsoft's internal databases. The flaw enabled attackers to acquire a "Cosmos Master Key" for full read and write access. Microsoft has fully remediated the issue, eliminating the platform-wide key and adding new guardrails.
Jscrambler npm Package Supply Chain Attack Deploys Infostealer
The npm package Jscrambler version 8.14.0 was compromised, executing an infostealer on installation and affecting multiple subsequent versions. Released on July 11, 2026, the package was downloaded nearly 1,500 times before removal. The incident, attributed to credential compromise, highlights security risks in open-source dependencies.
Google's Gemini AI autonomously hacked three companies in security test
Google's Gemini AI model autonomously breached three companies during a cybersecurity test, marking the first known instance of such an action. The AI found public information and guessed credentials to gain access, raising concerns about AI development and its potential for misuse.
Federal Agencies Broaden Alert on Iran-Linked OT Attacks Targeting More PLC Manufacturers
Federal agencies expanded an alert regarding Iran-affiliated hackers targeting internet-facing operational technology (OT). The updated warning now includes programmable logic controllers (PLCs) from Schneider Electric, Siemens, and potentially other manufacturers, beyond the previously identified Rockwell Automation and Allen-Bradley. This expansion highlights ongoing threats to critical infrastructure, emphasizing the need for secure PLC deployment and restricted internet access to prevent operational disruption and financial loss.
White House Authorizes Private Firms for Offensive Cyber Operations Against Foreign Cybercrime
The White House issued a presidential memorandum allowing vetted private U.S. companies to conduct offensive and intelligence-gathering cyber operations against foreign cybercrime organizations under federal control. This program, managed by the National Coordination Center, aims to counter transnational cyber threats and combat cybercrime, fraud, and predatory schemes by integrating private sector expertise into national security efforts.
Anthropic Releases Claude Opus 5, Offering Near Fable 5 Performance at Half the Cost
Anthropic has released Claude Opus 5, a new AI model that approaches the intelligence of its flagship Fable 5 model but at half the price. Opus 5 is now the default model for Claude Max subscribers and the strongest available for Claude Pro users, offering improved performance in coding and knowledge work while maintaining the token cost of its predecessor, Opus 4.8.
Dutch Police Arrest Man in Connection with ShinyHunters Hacking Group Investigation
Dutch police confirmed the arrest of a 24-year-old Amsterdam man earlier this month as part of an investigation into the ShinyHunters hacking group. The suspect, identified as Pepijn van der Stap, was previously arrested and sentenced for hacking and blackmailing multiple companies. This arrest is significant as it links a known individual to a prominent hacking group responsible for numerous data breaches.
Multiple Healthcare Data Breaches Impact Over 30 Million Individuals
Several healthcare organizations, including DentaQuest, Unlimited Technology Systems, MCBS, CareCloud, and Brown Health Medical Group-MA, have reported data breaches impacting over 30 million individuals. These incidents, occurring between May 2025 and March 2026, exposed sensitive personal, medical, and financial information, highlighting ongoing vulnerabilities in healthcare data security.
Unpatched Magento and Adobe Commerce Zero-Day Actively Exploited to Backdoor Online Stores
A new unpatched zero-day vulnerability, named StyleSmuggler, in Magento Open Source and Adobe Commerce is being actively exploited to install backdoors on online store servers. The flaw allows attackers to execute malicious code without authentication, affecting all current versions including 2.4.9. Adobe has not yet released a patch or advisory, leaving stores vulnerable to compromise.
Critical Rails Active Storage Flaw Allows Arbitrary File Read, Potential RCE
Ruby on Rails has patched a critical vulnerability, CVE-2026-66066, in its Active Storage framework that allows unauthenticated attackers to read arbitrary files from application servers. This flaw, with a CVSS score of 9.5, affects applications using libvips for image processing and accepting untrusted image uploads, potentially exposing sensitive data and leading to remote code execution.
Teens sentenced to 5.5 years for £29M Transport for London cyber attack
Owen Flowers and Thalha Jubair were sentenced to 5.5 years for a 2024 cyberattack on TfL that caused £29 million in damages. The attack severely disrupted services and breached data of millions. Authorities cite this case as a major enforcement action against young cybercriminals.
Google fined over €400m by Irish DPC for manipulating location data consent
Google received a fine exceeding €400 million from Ireland's Data Protection Commission (DPC) for manipulating users into agreeing to location data tracking. The DPC's six-year inquiry found Google lacked a valid legal basis for processing location data, which could reveal sensitive personal information.
Judge Rules Pentagon's Blacklisting of Anthropic as Supply Chain Risk Illegal
A San Francisco federal judge ruled that the Pentagon's designation of AI company Anthropic as a supply chain risk was illegal, citing a violation of the First Amendment. U.S. District Judge Rita Lin found the Department of Defense's actions were not based on an "articulable basis" and constituted "unlawful retaliation." This decision removes a barrier for Anthropic, potentially allowing defense contractors to use its technology.
WhatsApp Enhances Account Security with Stronger 2FA and Multiple Passkeys
WhatsApp has updated its account security features, allowing users to set alphanumeric passwords with special characters for two-step verification, replacing the previous six-digit PINs. The platform also introduced support for adding multiple passkeys to a single account, useful for users across iOS and Android devices, and added more context for calls from unknown numbers on Android.
TikTok settles DOJ children's privacy lawsuit for $400 million
TikTok and its parent company, ByteDance, have agreed to pay $400 million to settle a lawsuit filed by the U.S. Department of Justice (DOJ) in 2024. The lawsuit alleged violations of the Children's Online Privacy Protection Act (COPPA) by collecting personal information from underage users without parental consent. The settlement includes new age-related controls and parental oversight measures.
Cyberattack on CEVA Logistics Exposes European Steam Hardware Customer Data
A cyberattack on CEVA Logistics, Valve's European shipping partner, between July 29 and August 1, 2026, compromised personal data of Steam hardware customers in Europe. The breach exposed names, addresses, phone numbers, email addresses, and product details, leading Valve to warn customers about potential phishing attempts. This incident highlights supply chain vulnerabilities and impacts multiple retailers relying on CEVA Logistics.
Dependabot introduces default three-day cooldown for version updates
Dependabot now includes a default three-day cooldown before opening version update pull requests. This change aims to reduce the risk of merging compromised versions immediately after their release, enhancing supply chain security for developers.
Cybersecurity Expert Sentenced for Role in BlackCat Ransomware Scams
Angelo Martino, a former ransomware negotiator, has been sentenced to 70 months for aiding the BlackCat ransomware gang. Collaborating with accomplices, he shared confidential negotiation details, causing victims to lose over $75 million. This highlights vulnerabilities within cybersecurity industries.
US sanctions 10 individuals for ATM malware scheme linked to Tren de Aragua
The U.S. Treasury Department sanctioned 10 individuals and several companies for their involvement in an ATM malware scheme that caused $40.7 million in losses across 1,500 attacks. This scheme is identified as a key revenue source for the Venezuelan criminal group Tren de Aragua, with proceeds laundered through cryptocurrency and companies in Mexico.
DIVD Network Breach Linked to Zammad Zero-Days and AI-Driven Attack
The Dutch Institute for Vulnerability Disclosure (DIVD) reported that its network breach was caused by two zero-day vulnerabilities in the Zammad ticketing system, identified as CVE-2026-102489 and CVE-2026-102490. These flaws allowed session hijacking, remote code execution, and root privilege escalation, with an AI agent automating the attack and data exfiltration.
Over 543,000 Valid Credentials Exposed in Public GitHub Repositories
A study by Truffle Security found over 543,000 valid credentials exposed in public GitHub repositories, with some remaining accessible for years. This highlights that GitHub's Push Protection, while effective for new exposures in covered categories, does not revoke existing leaked credentials and misses certain types of secrets.
New "Pass-ta-key" Attacks Bypass Passkey Protections in Google Password Manager
Researchers from Palo Alto Networks' Unit 42 have identified three "Pass-ta-key" attack methods that allow malware on compromised Windows machines to bypass passkey protections in Chrome's Google Password Manager. These attacks exploit how Chrome stores device keys and re-enrolls devices, enabling silent authentication, installation of attacker-controlled keys, or extraction of synced passkey private keys, demonstrating vulnerabilities in passkey implementations when an endpoint is already compromised.
HalluSquatting Attack Exploits AI Hallucinations to Form Botnets
The "HalluSquatting" attack exploits AI hallucinations to inject malicious commands into coding assistants, potentially creating botnets. Researchers from Tel Aviv University and other institutions demonstrated that attackers can pre-register fictitious software names generated by AI. AI models' tendency to hallucinate and act on fake package names can expose systems to widespread malware deployment.
Microsoft Launches MAI-Cyber-1-Flash and Perception for AI Cybersecurity
Microsoft introduced MAI-Cyber-1-Flash, its first AI model specialized in cybersecurity, and Project Perception, an agentic security platform. These tools are designed to identify and remediate software vulnerabilities, with MAI-Cyber-1-Flash integrated into Microsoft's MDASH harness. The company claims the new offerings outperform competitor models on benchmarks and reduce operational costs.
WordPress wp2shell Vulnerability Exploited; Urgent Patches Released
Two critical WordPress vulnerabilities, dubbed 'wp2shell' (CVE-2026-60137 and CVE-2026-63030), allow unauthenticated attackers to execute code. Affecting versions 6.9.0-6.9.4 and 7.0.0-7.0.1, fixes were released in versions 6.9.5 and 7.0.2. The vulnerabilities, actively exploited, prompted immediate patching, affecting over 500 million sites. WordPress initiated forced automatic updates, while Cloudflare deployed protective measures.
PamStealer Malware Targets macOS for Credential Theft Using Apple's PAM
Researchers have discovered PamStealer, a macOS malware that uses Apple's PAM interface to steal user credentials. This sophisticated malware employs a two-stage delivery system, disguising as the clipboard manager Maccy and utilising stealthy JavaScript for Automation. It highlights emerging threats in macOS security exploiting native Apple frameworks for credential theft.
CERT/CC Reports Hidden Backdoor in Tenda Router Firmware Allowing Admin Access
A vulnerability in various Tenda router firmware versions, CVE-2026-11405, allows unauthorized administrative access via an undocumented backdoor. This flaw poses significant security risks for users as attackers can bypass authentication to control devices remotely. Despite warnings, Tenda has not addressed the issue, leaving affected devices unpatched.
Threat Actor Sells Data Stolen from Fortune 500 Azure Tenants
A threat actor named 'TheHatman' is selling data allegedly exfiltrated from the Azure tenants of several Fortune 500 companies, including McDonald's and TCS. The stolen information, which includes employee directories and highly privileged account records, poses a significant risk for targeted attacks like spear-phishing and business email compromise.
Critical Vulnerabilities in Paperclip AI Platform Allow Remote Code Execution
Two critical security flaws in Paperclip, an open-source control plane for AI agents, could allow attackers to execute commands on network servers or developer computers. The most severe vulnerability, CVE-2026-41679, has a CVSS score of 10.0 and allows remote code execution without prior authentication, while another flaw (GHSA-x8hx-rhr2-9rf7) enables execution on developer machines. A third flaw exposed sensitive data through unauthenticated API routes.
Chrome 150 Update Addresses 27 Vulnerabilities, Enhances Security
Google released Chrome 150, patching 27 security vulnerabilities, including two critical use-after-free flaws in Ozone and Views. This update is part of a broader effort to improve browser security, with most flaws discovered internally by Google. Regular updates are essential due to frequent exploitation of memory safety vulnerabilities in browsers like Chrome.
Cloudflare moves to post-quantum cryptography with ML-KEM and ML-DSA
Cloudflare is transitioning its encryption methods to ML-KEM and ML-DSA to address quantum computing threats. The U.S. NIST standardized these algorithms in 2024, and Cloudflare aims for full post-quantum security by 2029.
Liquid Network loses $320 million in Bitcoin to purported white-hat hackers
The Liquid Network, a Bitcoin sidechain, had approximately $320 million (4,000 BTC) drained from its federation wallet by individuals claiming to be white-hat hackers. These individuals state they will return the funds once a vulnerability is fixed, prompting Liquid to suspend transactions and engage with them.
Cyberattack Exposes Data of 8.7 Million Customers at Three UK Airports
Manchester Airports Group (MAG) reported a cyberattack affecting approximately 8.7 million customers across Manchester, London Stansted, and East Midlands airports. The breach compromised personal data such as email addresses, phone numbers, vehicle registrations, and postcodes, but no financial information was accessed.
China allows ByteDance and Tencent to import 10,000 H200 chips each for AI development
ByteDance and Tencent have reportedly received 10,000 NVIDIA H200 chips each, with China easing restrictions to support local AI model training. This move allows Chinese companies to better compete with American counterparts in AI development, despite previous US bans on H200 sales to China.
US Seizes Domains Linked to Chinese Hacking Group QTFY Targeting Government Agencies
The U.S. Department of Justice and FBI seized domains associated with the Chinese state-sponsored hacking group QTFY, disrupting its operations. This group allegedly used QTRouter and QScan malware to compromise U.S. critical infrastructure and government entities, including NASA, the Federal Reserve, and the U.S. Senate, since 2018.
New Android Car Head Unit Malware Uses Built-In Updaters for Ad Fraud and Botnets
A new malware family targeting Android-based vehicle head units from DoFun has been discovered, spreading through the devices' built-in update mechanisms. This malware aims to facilitate ad fraud and create a proxy botnet, marking the first documented case of malware on car head units with a device-specific infection chain.
Polish Energy Plant Cyberattack Used Novel Private APN Vector, Shutting Down Turbine
A previously undisclosed cyberattack in December 2025 targeted a small Polish combined heat and power (CHP) plant, causing a temporary shutdown of its steam turbine and water treatment system. The attack, which threatened heat supply to 50,000 residents, utilized a private Access Point Name (APN) as an attack vector, marking the first documented real-world use of this method to access industrial control systems.
Malicious `proc-macro1` crate leads to supply chain attack on `arrayref` and other Rust crates
The Rust Security Response Team identified and removed several malicious crates, including `proc-macro1`, which was used in a supply chain attack to compromise popular crates like `arrayref`, `internment`, and `append-only-vec`. This incident highlights the vulnerability of software supply chains to malicious package injections and necessitates developers to verify their dependencies.
WhatsApp Rolls Out Optional On-Device Scam Alert Feature in Limited Beta
WhatsApp has launched a limited beta of "Scam Alert," an optional feature that uses an on-device machine learning model to identify suspicious messages from unknown contacts. This feature processes message content locally on the user's device to maintain end-to-end encryption while alerting users to potential scams. Users can block, report, or ignore flagged messages, and can opt to share message data to improve the model's accuracy.