From SecurityWeek · 40 stories
Critical Linux Kernel Vulnerabilities: DirtyClone, Bad Epoll, and GhostLock
Three critical Linux kernel vulnerabilities, DirtyClone (CVE-2026-43503), Bad Epoll (CVE-2026-46242), and GhostLock (CVE-2026-43499), have been disclosed, each allowing privilege escalation. DirtyClone targets cloned network packets, Bad Epoll exploits a race condition, while GhostLock leverages a 15-year-old use-after-free flaw. Each vulnerability has a patch available, emphasizing the need for prompt system updates to mitigate exploitation risks.
Critical Gitea Docker Vulnerability CVE-2026-20896 Faces Active Exploitation
Gitea Docker images are subject to a critical authentication bypass vulnerability (CVE-2026-20896) now under active exploitation. The flaw allows attackers to impersonate any user, including administrators, via reverse proxy authentication with default configurations. It affects versions before 1.26.3 and about 6,200 instances globally.
12 Million Affected in KDDI Data Breach, Exploiting Zero-Day Vulnerability
KDDI, a major Japanese telecom provider, confirmed a breach affecting 12.2 million email addresses and 7.6 million passwords via a compromised email system used by five ISPs. The breach exploited a zero-day vulnerability in third-party software. KDDI has implemented security measures and coordinated password resets to prevent future incidents.
Chinese APT UAT-7810 Develops New Malware to Expand ORB Network
Chinese APT group UAT-7810 has advanced its Operational Relay Box (ORB) network with new malware, including LONGLEASH, DOGLEASH, and JARLEASH. These tools exploit known router vulnerabilities to enhance the group's cyber espionage capabilities, posing potential risks to critical infrastructure.
GitHub Agentic Workflows Vulnerable to Prompt Injection, Exposing Private Repos
Noma Labs identified a prompt injection vulnerability, named GitLost, in GitHub's Agentic Workflows, enabling data leaks from private repositories. Attackers can manipulate AI agents to disclose private content through crafted public issues. This highlights security concerns in using AI-driven workflows in GitHub's system.
Medtronic Hack Exposes Data of Nearly 4 Million People in ShinyHunters Breach
Medtronic suffered a data breach in April 2026, compromising the personal and medical information of over 3.8 million individuals, with some sources claiming 9 million records affected. The ShinyHunters group accessed Medtronic's corporate IT systems, despite the company's reassurance about device safety. Medtronic is offering credit monitoring and support services to those impacted, highlighting security vulnerabilities in healthcare technology.
FortiBleed Campaign Compromises Fortinet Devices, Linked to Ransomware Groups
The FortiBleed campaign has been connected to the INC and Lynx ransomware groups, compromising credentials from Fortinet devices. Researchers found the operation entailed scanning 11,250 FortiGate portals and compromised 354 targets, leading to 12 ransomware deployments. The breach highlights significant cybersecurity risks, affecting organizations globally.
Critical Flaws Found in Belgian eID Software Affecting 2 Million Users
Security researcher James Arnott discovered critical vulnerabilities in Connective digital identity software, used by over two million people in Belgium for digital identity authentication and electronic signatures. These flaws allowed malicious websites to read eID details, trick users into revealing PINs, forge electronic signatures, and execute remote code, impacting the trust model of Belgium's digital ecosystem.
EU Establishes New Team to Enforce AI Act, Targeting Deepfakes and Illicit Imagery
The European Union launched a new team in Brussels to enforce its AI Act, which comes into force on Sunday. This team will monitor AI companies for violations related to deepfakes, illicit imagery, and cyber threats, requiring AI-generated content to be labeled.
AI Weaponizes Dangling DNS Takeovers, Expanding Attack Surface and Automation
Security firm Silent Push demonstrated how AI can significantly scale 'dangling DNS takeover' attacks, a method where attackers exploit forgotten DNS records pointing to deleted cloud resources. This research, dubbed 'DangleGeddon', shows AI's capability to automate discovery, script generation, and exploitation, making these attacks a more potent threat for nation-state actors focused on disruption.
Oracle Patches 1,449 Vulnerabilities in July 2026 Security Update
Oracle released its July 2026 Critical Patch Update, addressing 1,449 vulnerabilities across 334 products, many identified using AI. With around 600 patches allowing remote exploitation, organizations are urged to update immediately to mitigate the risk of attacks.
Trump Executive Order Mandates Mapping of Defense Supply Chains for Cybersecurity
President Trump signed an executive order requiring the mapping and securing of critical defense supply chains, emphasizing software and technology used in national security. This initiative aims to enhance visibility and security against cyber and economic threats across all tiers of suppliers, impacting both prime and subcontractors.
VMware Avi Load Balancer Patches 7 Critical Vulnerabilities
Broadcom announced patches for seven vulnerabilities in VMware Avi Load Balancer, including critical authentication bypass and remote code execution issues. Organizations are advised to update promptly to prevent potential exploitation, especially as VMware flaws have been targeted in past attacks.
Centers Laboratory Data Breach Impacts Over 540,000 Individuals
Centers Laboratory reported a data breach affecting 542,377 individuals, revealing personal and health information. The breach occurred due to limited access by cybercriminals from the WorldLeaks group, which highlights ongoing threats to healthcare data security.
Keyfactor Secures Over $1 Billion for AI and Post-Quantum Security Solutions
Keyfactor has raised over $1 billion to enhance its Trust Control Plane, addressing identity sprawl and preparing for post-quantum security. This investment will help expand its global operations and advance product innovation amid rising demand for unified cryptographic solutions.
Prompt Injection Attacks Target AI Agents for Fraudulent Crypto Payments
Threat actors are using prompt injection attacks to deceive AI agents into making cryptocurrency payments. Zscaler identified two tactics, including a payment scam disguised as API documentation and a typosquatting operation impersonating a crypto service, which could significantly undermine trust in AI-integrated financial transactions.
ShinyHunters Launches New Oracle PeopleSoft Exploitation Campaign Bypassing WAFs
Mandiant and Google Threat Intelligence Group reported that the ShinyHunters group initiated a new mass-exploitation campaign targeting Oracle PeopleSoft customers. This campaign uses a modified exploit for CVE-2026-35273 to bypass web application firewalls (WAFs), expanding its targets beyond the education sector to various industries.
Modulate Secures $25M in Funding for Voice AI Analysis and Deepfake Detection
Modulate, a Boston-based startup, has raised $25 million in new funding to advance its voice intelligence platform, which provides transcription, emotional analysis, deepfake detection, and policy enforcement for voice agents. This funding enables Modulate to further develop its array of small voice models for nuanced conversation understanding and protection against AI audio generation and scams. The investment highlights continued interest in voice AI technologies that aim to make AI voices more human-like and detect malicious uses of voice cloning.
Astrana Health Reports Data Breach After Social Engineering Attack
Astrana Health, a healthcare management company, disclosed a data breach where private and confidential information was exfiltrated from its servers following a social engineering attack on employees. The company is assessing the extent to which patient, employee, and business data may have been accessed.
BigCommerce Merchants Alerted to Data Breach via Compromised Ribon App Credentials
BigCommerce has notified merchants of data breaches stemming from compromised credentials for third-party Ribon applications, which attackers used to inject malicious scripts into online stores. The breach exposed shopper information such as names, email addresses, phone numbers, and shipping addresses, affecting multiple BigCommerce customers.
US Coast Guard and FBI Board Two Oil Tankers After Cyberattacks During Voyage
US Coast Guard and FBI personnel boarded two oil tankers bound for Texas last month following cyberattacks that disrupted the vessels during their journey. Investigators found evidence of a malicious cyber actor on one ship, the VL Prosperity, which reportedly experienced interference with engine, navigation, and communication systems. This incident highlights ongoing cyber threats to the maritime sector, prompting the Coast Guard to establish a dedicated Office of Maritime Cybersecurity Policy.
BIND 9 Updates Address 14 Vulnerabilities, Including Critical DoH Crash Flaw
The Internet Systems Consortium (ISC) released BIND 9.20.29 and 9.21.26 to fix fourteen security vulnerabilities in its open-source DNS server software. One critical flaw, CVE-2026-77692, allows an unauthenticated attacker to crash a BIND server configured for DNS-over-HTTPS (DoH) with a single crafted request. These updates are important for maintaining the stability and security of DNS infrastructure.
ConnectWise warns of new ScreenConnect vulnerability, provides temporary mitigations
ConnectWise issued a security advisory regarding a new vulnerability in its ScreenConnect Remote Access platform that affects file transfer behavior. While a permanent patch is expected later this week, the company has provided temporary mitigation steps for administrators to implement. This vulnerability is significant because ScreenConnect is widely used by IT professionals, and previous flaws in the platform have been actively exploited by threat actors, including ransomware gangs and state-backed groups.
Amazon appoints cybersecurity expert Kevin Mandia to its board of directors
Amazon has added Kevin Mandia, founder of Mandiant and a cybersecurity veteran, to its board of directors. This appointment comes as companies face increasing cybersecurity threats, particularly those related to artificial intelligence.
Deceptive Android Apps Exploit Google Play Early Access Program to Evade Reviews
Threat actors are misusing Google Play's Early Access program to distribute deceptive Android applications. These apps, which promise rewards or premium content, bypass public reviews and ratings, primarily serving ads to users to generate revenue. Bitdefender identified this activity, noting that some apps, like a Grand Theft Auto imitator, accumulated over a million downloads before removal.
Mathspace discloses data breach affecting over 1 million students, staff, and parents
Online learning platform Mathspace reported a data breach impacting over 1 million individuals in Australia and New Zealand. Attackers exploited a vulnerability in the company's self-hosted Metabase internal reporting system to steal personal information.
OpenAI Expands Daybreak Initiative with $1 Billion for Critical Infrastructure Cyber Defense
OpenAI announced Daybreak for Frontline Defenders, an expansion of its existing Daybreak initiative, committing $1 billion to help critical infrastructure sectors like power, water, and banking use frontier cyber AI for defense. This initiative provides subsidized access to AI models, training, and support to cyber defenders protecting essential services globally and within the United States.
12-Year-Old PostgreSQL Vulnerability Allows Database and Server Takeover
A cybersecurity firm discovered a critical vulnerability, CVE-2026-6471 (PostGREShell), in PostgreSQL versions released since 2014, enabling attackers with low privileges to achieve remote code execution and privilege escalation. This flaw, stemming from missing authorization in logical decoding, allows unauthorized file loading and execution, posing a significant risk to the tens of thousands of companies using PostgreSQL.
AIR Raises $50M to Secure AI Agent Software Supply Chain
AI security startup AIR emerged from stealth with $50 million in seed funding to develop a platform for vetting AI agent skills and add-ons. The platform discovers AI agents, continuously vets their components, and blocks interactions that fail security criteria, addressing risks associated with AI agents operating autonomously across enterprise systems.
Palo Alto Networks Acquires AI Agent Platform Console to Enhance Cortex Capabilities
Palo Alto Networks has acquired Console, an AI-native platform that enables organizations to build agentic workflows and automate operational tasks using natural language. This acquisition will integrate Console's technology into Palo Alto's Cortex platform, allowing security teams to automate investigation, prioritization, and action across enterprise environments.
Hasbro discloses data breach affecting employee personal and financial information
Toy manufacturer Hasbro has disclosed a data breach impacting an undisclosed number of employees, with personal and financial information exposed. This incident follows a separate cyberattack in March that caused $25 million in revenue loss, though Hasbro has not linked the two events.
Trump Order Declares National Emergency to Block Foreign Backdoors in US Power Grid
President Trump issued Executive Order 14420, declaring a national emergency to address vulnerabilities in the US bulk power system from foreign-supplied electrical equipment. The order prohibits the acquisition, import, transfer, or installation of certain foreign-produced bulk-power equipment after August 26, 2026, if deemed to pose security risks. This aims to mitigate supply chain risks and potential embedded hardware backdoors in critical infrastructure.
Okta Exceeds Q2 Estimates, Reports Increased Demand for AI Identity Security
Okta surpassed Wall Street's fiscal second-quarter earnings and revenue estimates, driven by increased demand for identity security solutions related to AI agents. The company's shares rose 20% in extended trading, reflecting strong financial performance and strategic moves in the evolving AI security landscape.
ReliaQuest employee targeted in social engineering attack by ShinyHunters
Cybersecurity firm ReliaQuest confirmed that an employee was targeted in a social engineering attack by the ShinyHunters group, which attempted to gain access to internal systems. Although one employee entered credentials on a fake SSO page, device-trust controls prevented the attackers from accessing applications or customer data. This incident highlights the ongoing threat of social engineering and the importance of multi-layered security controls.
Apollo Global Management Confirms Data Breach Affecting Personal Information
Private equity firm Apollo Global Management confirmed a data breach where hackers stole personal information from its cloud systems between July 6 and July 10. The incident involved a social engineering attack and is part of a wider hacking campaign targeting financial institutions.
Apple Releases Security Updates for macOS, iOS, and iPadOS Addressing WebKit Vulnerabilities
Apple released security updates for macOS, iOS, and iPadOS to fix dozens of vulnerabilities, primarily in the WebKit browser engine. These patches are important for user security, as the flaws could lead to crashes, data disclosure, and arbitrary code execution.
Heights Finance Data Breach Exposes Financial and Personal Information of Nearly 750,000 Customers
Heights Finance, a debt consolidation loan company, experienced a data breach in May that exposed sensitive financial and personal information, including Social Security numbers, for approximately 734,828 customers. The breach occurred on a third-party cloud platform and did not affect the company's internal loan management systems. This incident highlights the ongoing risks associated with third-party cloud service providers and the potential for widespread data compromise in the financial sector.
RingCentral Data Breach Impacts 1.6 Million Accounts After Social Engineering Attack
RingCentral experienced a data breach in July, affecting 1.6 million individuals, following a "sophisticated social engineering campaign." The ShinyHunters extortion group claimed responsibility and leaked data after RingCentral did not meet their demands, leading to the information being added to HaveIBeenPwned.
Trezor Customers Affected by Data Breach at Shipping Partner ShipMonk
Hardware wallet manufacturer Trezor disclosed a data breach impacting nearly 14,000 customers after its shipping provider, ShipMonk, experienced unauthorized access to its systems. The incident exposed customer order data, including names, addresses, emails, and phone numbers, for orders placed between May 10 and August 8, 2026. Trezor's own systems were not compromised, but the breach raises concerns about potential phishing attempts targeting affected users.
New York Funds Water System Cybersecurity; Senate Bill Proposes $300M Annual Federal Aid
New York State has allocated over $9 million to 153 drinking water and wastewater systems to enhance cybersecurity defenses and comply with new state standards. Concurrently, Senate Democrats introduced the Water Cyber Shield Act, proposing $300 million annually for national water infrastructure cybersecurity improvements and expanded EPA authority, following recent cyberattacks on water systems.