UBS FINANCIAL SERVICES INC.
UBS FINANCIAL SERVICES INC. fnrw-backend Sat, 07/25/2026 – 21:57 MC ID PWJC MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.s3.com/rule605/pwjc MC Last Updated Sat, 07/25/2026 – 21:57
5 endpoint blind spots your EDR/XDR was never built to see
In August 2025, 126 malicious packages landed in the npm registry. Even after the community caught the initial wave, 80 of these hidden backdoors remained actively listed. That was enough. Over 86,000 downloads. Malicious code in PhantomRaven, packages running in the production systems of Fortune 500 companies worldwide. And throughout the entire window, not a single EDR/XDR […]

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and […]
US House Votes to Extend Cyber Sharing Law for 10 Years
Chris Liotta reports: Lawmakers voted to extend a key cyberthreat sharing law for another decade, attaching the long-stalled reauthorization to Washington’s annual defense policy bill. The U.S. House of Representatives narrowly approved its $1.15 trillion fiscal year 2027 national defense authorization act in a 216-212 vote Wednesday, including a provision that would reauthorize the Cybersecurity Information… […]
AU: Sydney nurse accused of downloading patients’ data in alleged ‘breach of trust’
Caitlin Powell reports: A male registered nurse from northern Sydney has been charged after allegedly downloading the data of multiple patients. Police received a report on Wednesday, July 22, that a NSW Health employee had allegedly accessed and downloaded patient information without authorisation. Detectives launched an investigation under Strike Force Civic and, after inquiries, searched a home in Frenchs Forest… […]
No Need to Hack When It’s Leaking: Click to Pray edition
Jessica Lyons reports on today’s entry in the “No Need to Hack When It’s Leaking” files: Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users worldwide, has leaked people’s names and email addresses for months – or longer – according to an ethical hacker who said she found… […]

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain […]
Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday
Industry professionals debate whether it represents a lab containment failure or an unprecedented agentic capability milestone. The post Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday appeared first on SecurityWeek.
AegisAI Raises $36 Million for AI-Powered Email Security
The company has raised a total of $49 million in funding, including from Battery Ventures, Accel and Foundation Capital. The post AegisAI Raises $36 Million for AI-Powered Email Security appeared first on SecurityWeek.
In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion attempt. The post In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws appeared first on SecurityWeek.
Rockwell Patches Code Execution Flaws in Arena Simulation Software
A researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations. The post Rockwell Patches Code Execution Flaws in Arena Simulation Software appeared first on SecurityWeek.

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recent investigations into insurance-focused phishing operations reveal a more immediate approach. Instead of harvesting

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. “Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, […]

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis. “The portal combined build generation, finance,

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their diff. The chain needs no administrator rights, continuous integration (CI) runner access, victim interaction
25-02850.pdf
25-02850.pdf Anonymous (not verified) Fri, 07/24/2026 – 17:25 Case ID 25-02850 Forum FINRA Document Type Award Claimants Venu Madhav Kailasa Respondents BOFA Securities, Inc. Neutrals Arthur S. Joseph Marleen H. Levi Alice E. Winkler Hearing Site New York, NY Award Document 25-02850.pdf Documentum DocID 385ef8f4 Award Date Official Fri, 07/24/2026 – 12:00 Related Content Off […]
APEX CLEARING CORPORATION
APEX CLEARING CORPORATION fnrw-backend Fri, 07/24/2026 – 17:11 MC ID APCC MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.s3.com/rule605/apex MC Last Updated Fri, 07/24/2026 – 17:10
24-02709.pdf
24-02709.pdf Anonymous (not verified) Fri, 07/24/2026 – 17:05 Case ID 24-02709 Forum FINRA Document Type Award Claimants Cesar Gonzalez Respondents J.P. Morgan Securities, LLC Neutrals Michael S. Matek Richard Lane Miller John William Kenesey Hearing Site Chicago, IL Award Document 24-02709.pdf Documentum DocID 247ac090 Award Date Official Fri, 07/24/2026 – 12:00 Related Content Off Claimant […]
2025086924101 Taspia Rahman CRD 7757705 AWC lp.pdf
2025086924101 Taspia Rahman CRD 7757705 AWC lp.pdf Anonymous (not verified) Fri, 07/24/2026 – 15:30 Case ID 2025086924101 Document Number 81d91884 Document Type AWCs (Letters of Acceptance, Waiver, and Consent) Individuals Taspia Rahman Action Date Fri, 07/24/2026 – 12:00 Related Content Off Attachment 2025086924101 Taspia Rahman CRD 7757705 AWC lp.pdf Individual CRD 7757705
25-01825.pdf
25-01825.pdf Anonymous (not verified) Fri, 07/24/2026 – 15:10 Case ID 25-01825 Forum FINRA Document Type Award Claimants Rajesh Malik Respondents Charles Schwab & Co., Inc. Neutrals Robert J. Scafuri Barbara E. Dixon Robert M. Shwab Hearing Site Cleveland, OH Award Document 25-01825.pdf Documentum DocID 5411b55e Award Date Official Fri, 07/24/2026 – 12:00 Related Content Off […]
Sponsor mismatch is the silent killer of enterprise transformation
Late in a large enterprise SAP transformation, the strategic governance conversations began to drift. Instead of executive decisions, we found ourselves debating whether the program needed dedicated testing, whether cutover required a full weekend, whether twenty Agile teams really needed coordination support and whether offshore resources were adding value at all. The questions were not […]
3 cybersecurity issues that should keep every CEO awake at night
For years, I have been saying that cybersecurity is no longer a technology problem. It has become a business leadership challenge. Yet, despite record levels of spending, ever-growing security teams, increasingly sophisticated technologies and a constant stream of new regulations, organizations continue to suffer major cyber incidents with alarming regularity. Every week seems to bring […]
What is a business analyst? A key role for business-IT efficiency
What is a business analyst? Business analysts (BAs) are responsible for bridging the gap between IT and the business using data analytics to assess processes, determine requirements, and deliver data-driven recommendations and reports to executives and stakeholders. BAs engage with business leaders and users to understand how data-driven changes to process, products, services, software, and hardware can […]
CIOs beware: DNS KSK rollover could kick off wave of mysterious outages
Predicting an outage is tricky business, but CIOs might want to circle Oct. 11, 2026, through Jan. 11, 2027, for likely trouble of a potentially widespread and puzzling nature. That’s because a relatively trivial update to DNSSEC on Oct. 11, one that will take full effect by Jan. 11, is likely to deliver a series […]
Why I changed how I pitch AI: It’s no longer about saving money, but managing tokens and adoption
I have worked alongside enterprise technology for more than 30 years and watched AI evolve from a lab experiment into the modern boardroom’s core focus. However, the last few years of implementing AI alongside our customers have delivered our most profound reality checks. The initial hype has faded, leaving CIOs to drive real enterprise value. […]
Atos launches sovereign cloud service to power comeback
Atos has launched a new sovereign cloud platform aimed squarely at European public sector bodies, healthcare providers and defense organizations. It’s the latest effort by European companies in their fight back against US dominance. Atos Sovereign Cloud offers a range of controls for data management, providing customers with resilience and full control over their data, […]
Getting a grip on shadow tokens and AI blowouts
Four months of Claude Code — that’s all it took for Uber to burn through its entire annual budget for AI. Token after token, engineers embraced the platform with few control mechanisms tying costs to outcomes. The result was a budget runaway and a clear case study in how limited oversight snowballs into an AI […]
Model Context Protocol is going stateless to make scaling simpler
Model Context Protocol (MCP), the emerging standard for connecting AI models to external tools and enterprise data, is undergoing its biggest architectural overhaul yet. The latest release candidate, scheduled for release on July 28, removes protocol-level sessions in favor of a stateless architecture, a change which industry experts say is intended to make MCP easier […]
IT leaders: Leading-edge AI insights await at TechCrunch Disrupt
For CIOs, learning from the startup ecosystem has never been more critical. As pressure mounts to transform business operations with AI and agentic systems, IT leaders should be looking to those on the AI vanguard for insights into the strategic and technical decisions necessary to launch, grow, and thrive in today’s AI-disrupted business environment. So […]

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. “BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.
Suspect arrested in investigation into sadistic “764” group
From the Dutch Police: In an investigation into so-called online sadistic COM networks, a suspect from North Holland was arrested on Monday, July 20. As a member of the group ‘764’, the suspect allegedly asked girls to cut themselves and write his online username on surfaces such as walls with their blood—known as ‘bloodsigns’. He… […]
Crime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.
Previous reporting about the Navigate360 breach focused on tips submitted by students, teachers, and parents. In this article, we focus on tips submitted to Crime Stoppers and law enforcement-related programs that use Navigate360’s software. Links to previous articles on this breach are at the end of this article. Background In 1976, an Albuquerque detective had… […]
Origin silent on settlement as alleged fired employee breach detail emerges
Roxanne Libatique reports: Origin Energy has declined to comment on a public claim that it privately resolved a cyber extortion threat – a posture that, as of July 24, leaves the company managing simultaneous obligations to regulators, the ASX, and an insurance market now aware that the alleged access point was a fired former employee’s… […]
T-Mobile violated WA data breach notification law, judge rules
Mirandah Davis-Powell reports: T-Mobile failed to properly notify customers of a data breach in which 40 million people had sensitive personal information stolen and sold on the dark web, a King County Superior Court judge ruled Friday. The Washington attorney general’s office filed the civil lawsuit against the Bellevue-based company in January 2025. The lawsuit alleged that T-Mobile… […]
Furious KPMG boss expels senior partner over confidential documents in locker
Colin Kruger provides today’s reminder of the insider threat: The most serious whistleblower claim from the KPMG scandal, that senior partners had illicitly accessed sensitive Lendlease board documents and kept them in a work locker, has been confirmed and led to the immediate expulsion of former chief operating officer, Eileen Hoggett. “I can confirm that… […]
IL: Weeks after cyberattack, ETHS students receive phishing scam emails
Bob Chiarito reports: Six weeks after a cyberattack shut down the campus for two days, several Evanston Township High School students received phishing emails this week. The emails offered students part-time jobs paying $550 for two to three hours of work, three times a week and came from a student’s ETHS email account. The emails were signed by “Human Resource”… […]
Millions of California-bought cars can be hijacked via Bluetooth
Brandon Vigliarolo reports: At least 2.2 million vehicles fitted with dealer-installed KARR and SWDS security systems are vulnerable to nearby Bluetooth attacks that can unlock doors or prevent a stopped vehicle from starting, according to researchers at the University of California San Diego. An advance look at the research published by UCSD this week (the full writeup won’t be… […]
Clop gang targets Windchill, FlexPLM in data theft attacks
Sergiu Gatlan reports: The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecurity company… […]

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim’s organization. The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of […]

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITYSYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet. XBOW’s testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing’s image tier, not on one bad […]

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we’ve collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to identity-layer access controls. Where we’ve collectively landed is […]
Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models
SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek.
Abstract Raises $25 Million to Expand Composable Security Operations Platform
The latest investment round brings the total raised by Abstract to nearly $50 million. The post Abstract Raises $25 Million to Expand Composable Security Operations Platform appeared first on SecurityWeek.
Chick-fil-A Accounts Get Fried in Credential Stuffing Attack
Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts. The post Chick-fil-A Accounts Get Fried in Credential Stuffing Attack appeared first on SecurityWeek.
Is Patching Dead? Vulnerability Management in the Post-Mythos Era
You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching Dead? Vulnerability Management in the Post-Mythos Era appeared first on SecurityWeek.
OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider
AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider appeared first on SecurityWeek.
Data Breach Confirmed After Australian Energy Giant Origin Is Hacked
A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it. The post Data Breach Confirmed After Australian Energy Giant Origin Is Hacked appeared first on SecurityWeek.

Top AIs invent same fake PyPl and npm package names
Enterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent libraries and hackers create malicious packages in response. The top AI coding tools are remarkably consistent in their hallucinations: Researcher Aleksandr Churilov found the same 127 fake package names generated by five different […]

Tycoon2FA takedown reshapes the phishing landscape
Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”. “Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March […]

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand’s Ministry of Finance, which runs the country’s treasury and tax collection. The agent then worked through the ministry’s network on its own, checking hosts for ways to […]

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software’s source code. Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators […]

Ransomware groups are hammering your vulnerable VPNs
Cybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin ransomware strain. A critical authentication bypass flaw (CVE-2026-0257) in Palo Alto GlobalProtect portal and gateway was the common link in a series of intrusions in June, Arctic Wolf Labs warns. Exploitation of the vulnerability came […]
Ransomware groups are hammering your vulnerable VPNs
Cybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin ransomware strain. A critical authentication bypass flaw (CVE-2026-0257) in Palo Alto GlobalProtect portal and gateway was the common link in a series of intrusions in June, Arctic Wolf Labs warns. Exploitation of the vulnerability came […]

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote […]

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously […]
ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)
Post Content

AgentForger proves AI agents can become persistent insider threats
A new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to install. Its researchers have discovered AgentForger, a phishing-based attack that silently creates and launches a fully autonomous AI agent within OpenAI workspaces. Once running, the agent has full access […]
2023078559701 Theodore William Byrer CRD 2980696 AWC ks.pdf
2023078559701 Theodore William Byrer CRD 2980696 AWC ks.pdf Anonymous (not verified) Thu, 07/23/2026 – 16:40 Case ID 2023078559701 Document Number ac9dd7a5 Document Type AWCs (Letters of Acceptance, Waiver, and Consent) Individuals Theodore William Byrer Action Date Thu, 07/23/2026 – 12:00 Related Content Off Attachment 2023078559701 Theodore William Byrer CRD 2980696 AWC ks.pdf Individual CRD 2980696

Check Point hole grants unauthenticated attackers full SmartConsole admin privileges
Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin privileges, is now being exploited in the wild. The vulnerability, CVE-2026-16232, was given a CVSS score of 9.3. In its security alert, Check Point described the bug as one allowing an unauthenticated […]
Check Point hole grants unauthenticated attackers full SmartConsole admin privileges
Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin privileges, is now being exploited in the wild. The vulnerability, CVE-2026-16232, was given a CVSS score of 9.3. In its security alert, Check Point described the bug as one allowing an unauthenticated […]
25-02606.pdf
25-02606.pdf Anonymous (not verified) Thu, 07/23/2026 – 15:55 Case ID 25-02606 Forum FINRA Document Type Award Claimants David Milowe Jacqueline Milowe Respondents RBC Capital Markets LLC Neutrals Madelon M. Rosenfeld Jane C. Carney Paul Allan Massaro Hearing Site Boston, MA Award Document 25-02606.pdf Documentum DocID df39cfe7 Award Date Official Thu, 07/23/2026 – 12:00 Related Content […]
26-00444.pdf
26-00444.pdf Anonymous (not verified) Thu, 07/23/2026 – 15:55 Case ID 26-00444 Forum FINRA Document Type Award Claimants Ethan Turnbull Respondents Robinhood Financial, LLC. Neutrals Arthur Neil Tolciss Hearing Site New York, NY Award Document 26-00444.pdf Documentum DocID e8d7c62b Award Date Official Wed, 07/22/2026 – 12:00 Related Content Off Claimant Representatives Ethan V. Turnbull Respondent Representatives […]
24-00497.pdf
24-00497.pdf Anonymous (not verified) Thu, 07/23/2026 – 15:55 Case ID 24-00497 Forum FINRA Document Type Award Claimants Ameriprise Financial Services, LLC. Respondents Adam Jurewicz LPL Financial LLC Neutrals Kenneth R. Starr Charles L.A. Terreni Linda L. Maslar Hearing Site Columbia, SC Award Document 24-00497.pdf Documentum DocID 66f354a3 Award Date Official Thu, 07/23/2026 – 12:00 Related […]
4 ways AI-driven defense is rewriting the cybersecurity playbook
The cybersecurity landscape has evolved beyond human scale. Today’s adversaries have replaced predictable, manual playbooks with machine-generated attack chains that can breach traditional controls in seconds. To bridge the gap, organizations must move past legacy, reactive controls and embrace a fundamentally different, AI-driven architecture: Agentic Endpoint Security (AES). AES represents a paradigm shift, moving security […]
PAULSON INVESTMENT COMPANY LLC
PAULSON INVESTMENT COMPANY LLC fnrw-backend Thu, 07/23/2026 – 14:58 MC ID PICL MC Reporter Type Broker-Dealer MC Paragraph MC Link https://www.paulsoninvestment.com MC Last Updated Thu, 07/23/2026 – 14:57
Sovereign AI has become the public-sector CIO’s control problem
In public-sector and regulated-cloud work, I learned that sovereignty rarely starts as a national strategy. It starts as an auditor’s question: Who can prove where the data went, which system made the decision and what changes when the vendor or infrastructure does? That question is now moving into AI, and most sovereign-AI debates answer the […]
AI success requires a full-stack CIO
Every CIO I speak with today is wrestling with some version of the same question: How do we move faster with AI and deliver on our commitments? It’s an understandable concern. Boards and CEOs are asking about AI. Business leaders are experimenting with use cases. Employees are discovering tools daily, while technology vendors promise unprecedented […]
Smaller, smarter, safer: How to build agentic AI on the right foundation
When it comes to building an effective AI stack, context is king and power isn’t everything it’s cracked up to be. “Smaller, smarter, safer — this is a bet our company has taken in how we deploy AI internally,” said Ricky Thakrar, head of sales and account management at Zoho, provider of a suite of […]
Principles every enterprise must test before the attack arrives
I haven’t slept much in the past few weeks. Not because of some theoretical cyber risk that keeps many executives awake, but because reality just delivered a real wake-up call to our industry — a call that every executive must answer, now. Imagine this: A major global enterprise, a company most of us interact with […]
7 CRM trends for 2026: AI brings decisive action to customer workflows
Agentic AI has advanced from the promises-and-pilots phase of 2025 to reality and rollouts in 2026. In the process, agentic AI is transforming virtually every aspect of customer relationship management (CRM), the platform that manages sales, marketing, and customer service. “Last year, everybody was dipping their toes into the water,” says Keith Kirkpatrick, research director […]
Stop asking AI nicely: Here’s how to get work-ready results every time
Over the past few years, I have learned that basic prompts produce inconsistent, hallucination-prone results that no executive would trust in production. What turned the tide was my move to advanced prompting techniques. These weren’t theoretical experiments; they became a practical foundation for reliable, measurable outcomes. I want to share the techniques that consistently delivered […]
The new value architecture of the AI-native SaaS era
The traditional methods of measuring success no longer tell the full story. Here’s what should replace them — and why. In brief: AI is transforming software as a service (SaaS), and the old ways of keeping score no longer apply. Smart companies are evolving new metrics that provide deeper insight into how AI-native software is […]
How to navigate the AI talent wars
Cloudflare recently beat Q1 2026 earnings. Revenue up 34% year over year. EPS ahead of consensus. Full-year guidance raised. Then, in the same breath, they announced 1,100 layoffs, 20% of the company. CEO Matthew Prince’s explanation: “The way we work at Cloudflare has fundamentally changed.” Block did the same thing. Beat guidance, raised outlook, cut […]
OpenAI Presence raises new questions about enterprise automation and jobs
OpenAI has launched Presence, an enterprise service for deploying voice and chat agents that can resolve customer and employee requests, potentially automating some work now handled by frontline support teams. The agents can answer questions and operate IT systems, and enterprises can decide what actions the agents may take and when they should seek human […]
Google CEO distracts from Gemini 3.5 Pro delay with talk of Gemini 4 and monthly releases
Google CEO Sundar Pichai has sought to allay concerns over the delayed release of the Gemini 3.5 Pro large language model. He dodged questions about it in Google’s quarterly earnings call on Wednesday by focusing on the company’s next frontier AI model, Gemini 4, and plans to release subsequent LLMs at an almost monthly cadence. […]

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client. The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it. The […]

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Most of this week’s trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threats change every week. Subscribe, and we’ll alert […]
When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)
Two disclosures, five days apart, described the same intrusion from opposite ends —

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which shared details of the vulnerability with The Hacker News ahead […]

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or […]
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
Publication: April 7, 2026 Last Update: July 22, 2026 TLP: Clear From the updated version of the Joint Cybersecurity Advisory: Executive Summary The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors… […]

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it was offline by the […]
Panduit IntraVUE
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling. The following versions of Panduit IntraVUE are affected: IntraVUE <=3.2.1a14 CVSS Vendor Equipment Vulnerabilities v3 10 Pronetiqs Panduit IntraVUE Plaintext Storage of […]
Johnson Controls C-CURE 9000 and Victor application server
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected: C-CURE 9000 and victor <=v2.90_v3.0 victor Web <=v7.1 CVSS Vendor Equipment Vulnerabilities v3 9.6 Johnson Controls Johnson Controls C-CURE 9000 and […]
MZ Automation lib60870
View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. The following versions of MZ Automation lib60870 are affected: lib60870 <=2.4.0 CVSS Vendor Equipment Vulnerabilities v3 8.2 MZ Automation MZ Automation lib60870 Out-of-bounds Read Background Critical Infrastructure Sectors: Chemical, Energy, Water and Wastewater […]
MZ Automation libIEC61850
View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions. The following versions of MZ Automation libIEC61850 are affected: libIEC61850 >=v1.0.0|<=v1.6.1 CVSS Vendor Equipment Vulnerabilities v3 8.1 MZ Automation MZ Automation libIEC61850 Stack-based […]
Johnson Controls XAAP Android
View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected: XAAP Android <1.53 CVSS Vendor Equipment Vulnerabilities v3 3.3 Johnson Controls Johnson Controls XAAP Android Cleartext Storage of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing […]

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is […]
Rockwell Automation ThinManager
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application’s intended directory. The following versions of Rockwell Automation ThinManager are affected: ThinManager >=13.0.0|<13.0.7, >=13.1.0|<13.1.5, >=13.2.0|<13.2.4, >=14.0.0|<14.0.2 CVSS Vendor Equipment Vulnerabilities v3 8.1 Rockwell Automation Rockwell Automation ThinManager Improper Limitation of […]
Weintek cMT3092X
View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cMT3092X are affected: cMT3092X firmware <20210218 EasyWeb <v2.1.20 CVSS Vendor Equipment Vulnerabilities v3 8.8 Weintek Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a […]
Vibe-Coded Apps Riddled With Exploitable Security Flaws
Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek.
StrongestLayer Raises $4.1 Million in Seed Funding Extension
The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek.
When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover
Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. The post When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover appeared first on SecurityWeek.
Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek.
Palo Alto Networks to Acquire Observability Platform Provider Embrace
Acquisition follows January’s Chronosphere deal, deepening Palo Alto Networks’ push beyond core security into observability. The post Palo Alto Networks to Acquire Observability Platform Provider Embrace appeared first on SecurityWeek.
Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
Hackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms. The post Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts appeared first on SecurityWeek.
US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices
An updated advisory from federal agencies provides information on the techniques used to hack programmable logic controllers. The post US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices appeared first on SecurityWeek.
New Check Point Zero-Day Vulnerability Exploited in the Wild
The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek.
Assaf Keren Appointed New CISO of Meta
He replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek.
Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses
Hackers recently obtained non-sensitive customer information and other documents from the company. The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses appeared first on SecurityWeek.

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, and Amazon Linux can meet the conditions for exploitation. The […]
Stakeholder event on guidelines on the interplay between data protection and competition law: save the date
Stakeholder event on guidelines on the interplay between data protection and competition law: save the date ikerinar Thu, 07/23/2026 – 09:48

Microsoft’s 3-day patching directive comes with added operational risk
Microsoft 365 Director Jeremy Chapman this month took to video to tell Windows admins that the days of delaying security patches are over. Complex enterprise systems and historic incidents involving patch problems have caused many admins to hold fire on immediately applying security patches, in many cases deferring patch rollouts for two to four weeks […]

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an
ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd)
Post Content
ID: Kootenai County notifies residents of data breach
Nick Hawthorne reports: Kootenai County has begun notifying residents whose personal information may have been compromised in a ransomware attack detected on the county’s computer network in late March. According to a Kootenai County press release, the County discovered the ransomware on March 30, 2026, and immediately took action to secure its network and restore… […]
TN: Data breach delays start of Sumner County school year
Camellia Burris reports: One Middle Tennessee school district is delaying the start of the school year due to a data breach in its computer network. School officials in Sumner County discovered the breach in its computer network earlier this week and subsequently revised the district calendar so the problem could be resolved before students return… […]

German law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group Kratos
A global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia. The effort was managed by German law enforcement and involved agencies from the US, Indonesia and other countries. Although a German statement claimed that […]
Instructure Incident Driving 58 Percent of Breach Notices in 2026
GovTech reports: The mega breach is back in 2026, according to a new report from the Identity Theft Resource Center (ITRC). The nonprofit group, which works to prevent and reduce incidences of identify theft, found that 1,029 data compromises generated 471 million breach notices in the first half of the year, with one incident —… […]
OpenAI Models Escaped Containment and Hacked Hugging Face
It’s happened. The nightmare of the future is now in our present. Or was this just old-fashioned negligence? Lily Hay Newman and Dell Cameron report: OpenAI disclosed on Tuesday that it lost control of two AI models during a security test that ended in a breach of the open AI research platform Hugging Face. Describing the incident as… […]

Critical Zimbra security update fixes 9 vulnerabilities
Business email and collaboration suite Zimbra has received a major security update that fixes several critical issues that could allow attackers to execute malicious code on the server or in users’ browsers. Available in commercial and open-source editions, Zimbra Collaboration Suite is a self-hosted Microsoft Exchange alternative that is popular with businesses, government entities, and […]
DRIVEWEALTH, LLC
DRIVEWEALTH, LLC fnrw-backend Wed, 07/22/2026 – 15:46 MC ID DWWT MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.s3.com/rule605/drvw MC Last Updated Wed, 07/22/2026 – 15:46
DRIVEWEALTH, LLC
DRIVEWEALTH, LLC fnrw-backend Wed, 07/22/2026 – 15:45 MC ID DWFT MC Reporter Type OTC Market Maker MC Paragraph MC Link https://public.s3.com/rule605/drvw MC Last Updated Wed, 07/22/2026 – 15:45
FINRA Seeks Comment on Modernizing Communications Rule
FINRA Seeks Comment on Modernizing Communications Rule K34060 Wed, 07/22/2026 – 15:31 July 15, 2026 Features FINRA Seeks Comment on Modernizing Communications RuleFINRA published Regulatory Notice 26-14 on July 9 requesting comment on a proposal to modernize our rules related to communications with the public. The proposal would adopt a more risk-based standard for supervising […]
Member Firms Reelect Curtis, Elect Gettenberg to FINRA Board
Member Firms Reelect Curtis, Elect Gettenberg to FINRA Board K34060 Wed, 07/22/2026 – 15:24 July 22, 2026 Features Member Firms Reelect Curtis, Elect Gettenberg to FINRA Board FINRA announced the results of the Board of Governors elections following last week’s Annual Meeting of member firms. Scott Curtis, Chief Operating Officer of Raymond James Financial, was reelected as a Large […]
4 recs for CIOs to optimize AI budgets and improve sustainability
In the client-server era, the penalty for inefficient programming, such as unoptimized database calls, was largely confined to application responsiveness. Today, in the AI era, code, architectural, and platform inefficiencies are no longer just a performance issue, they’re a financial and environmental liability. Left unchecked, poor code cascades into soaring token costs and spikes data […]
The engineering bottleneck has changed. Is your org prepared?
AI agents can turn a clear description into working software, the engineer’s judgement is what makes the difference: deciding what to build, catching the tradeoff the agent didn’t know to weigh, and owning the call on whether the result is right. That judgement has always been the hard part of engineering. It just used to […]
The compound effect your AI adoption strategy is missing
For many engineering teams, AI adoption means individual engineers write code faster while overall team velocity remains stagnant. Individual speed and team speed are produced by different things, and AI has mostly accelerated the first but not the second. The step from individual AI adoption to team advantage is one many organizations haven’t taken yet, […]
The AI bill is the easy part. The hard part is everything it changed
Your CFO has a simple question. “We’re spending more on AI. What are we getting for it?” Most CIOs cannot answer it — not because AI isn’t creating value, but because the accounting systems we inherited were built before AI existed as a category of labor. This June, the conversation shifted from token maxing to […]
Leadership bottlenecks slow AI adoption
At Cisco, VP of engineering Jason Andrews deals with all the same technical issues as every other company deploying AI, including ensuring it’s governed, secure, and integrating multiple data sources, legacy systems, and AI models. But these issues are relatively straightforward compared to the bigger challenges relating to the fast pace of change, specifically how […]
How a contextual AI fabric turns organizational memory into AI advantage
Across industries, a version of the same conversation is playing out in technology leadership meetings. Enterprises have deployed AI broadly, and foundation models keep getting more capable. Yet the outputs still feel generic, shaped by industry patterns rather than by the organization producing them. McKinsey’s AI Trust Maturity Survey found that while overall AI maturity […]
The $3 trillion assembly line: Why CIOs must industrialize the data center supply chain
You are one of the six billion people (75% of the world population) online today, and every click you make is routed through the data center. Data centers, whether knowingly or unknowingly, play a very critical role in your daily online activities. With an increasing population, increasing usage of online presence, and now omniscient AI, […]
CyCognito Brings Always-On AI Pentesting to External Attack Surface Management
CyCognito, a leading exposure management platform, today introduced Continuous AI Pentesting. The new capability bakes AI-driven offensive pentesting directly into the platform, leveraging the rich context it already maintains for every exposed asset. This enables CyCognito to deliver AI pentesting as a continuous service, circumventing the cost and coverage constraints that confine comparable solutions to […]
Oracle expands Cloud@Customer with new database service for mid-sized workloads
Oracle is expanding its Cloud@Customer on-premises portfolio with a managed database offering that it says will enable enterprises to run databases, applications, and AI agents in their own data centers, helping CIOs modernize mid-sized workloads while meeting data residency, regulatory, and low-latency requirements. The hybrid cloud offering, Base Database Cloud@Customer, combines existing database and infrastructure […]
Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware
Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware. Fusion Middleware was particularly hard hit, with new security patches for 355 security vulnerabilities, 219 of them remotely exploitable without authentication, meaning they […]

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or more. Reports filed before that date, including those already in GitHub’s growing triage queue, will retain […]

Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware
Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware. Fusion Middleware was particularly hard hit, with new security patches for 355 security vulnerabilities, 219 of them remotely exploitable without authentication, meaning they […]

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes […]
Rondo Meets Geoserver, (Wed, Jul 22nd)
This isn’t a new attack, but something I saw “pop-up” in our logs this week:
PRINCIPAL SECURITIES, INC.
PRINCIPAL SECURITIES, INC. fnrw-backend Wed, 07/22/2026 – 13:09 MC ID PRIN MC Reporter Type Broker-Dealer MC Paragraph MC Link https://www.principal.com/sec-rule-606-trade-reporting MC Last Updated Wed, 07/22/2026 – 13:09

Cisco’s new AI model tells code reviewers where to look for vulnerabilities
Cisco has revealed a family of open-weight AI models called Antares that, it said, can help security teams isolate potentially vulnerable parts of a software repository before deeper investigation begins. Rather than detecting a specific CVE or generating a patch, these models search a codebase using only a Common Weakness Enumeration (CWE) description and return […]

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data. The shortcoming has been codenamed HermeticReader by Guardio Labs. It’s officially tracked as CVE-2026-48294 (CVSS score: 7.4), with the vulnerability
Greedy ransomware crews return for seconds after victims cough up first extortion payments
Connor Jones reports: Authorities have long warned organizations not to pay ransoms, and fresh figures underline why: handing over the money doesn’t mean the crooks leave you alone. Proofpoint survey data suggests that 58 percent of affected UK organizations paid a ransom. Worse, 22 percent of those who pay get extorted again anyway. The UK… […]

OpenAI model escape puts enterprise AI defenses on notice
Some of OpenAI’s most powerful AI models teamed up to escape their sandbox and attack systems at Hugging Face in a cybersecurity evaluation gone wrong, the company has admitted. The models under test were modified to allow them to perform potentially harmful actions that production versions would refuse. The incident highlights how, if AI prompt […]

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”). “The filename parameter is concatenated into
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal […]

The Fastest Path to AI Adoption Runs Through Security
Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned. According to McKinsey’s State of AI report, 76 percent of employees now […]

Why Modern SOCs Need Multi-Layered Detections
The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely. The CrowdStrike Global Threat Report estimates around 79% of attacks are malware-free, as threat actors rely on
CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek.
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek.
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville The post SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity appeared first on SecurityWeek.
Empirical Security Raises $25 Million in Series A Funding
The startup will use the investment to accelerate the development of its threat prediction and discovery products. The post Empirical Security Raises $25 Million in Series A Funding appeared first on SecurityWeek.
Cisco Launches Low-Cost AI Models for Source Code Security
The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek.
Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
New executive order calls for end-to-end visibility into defense supply chains, including software dependencies, foreign ownership and cyber-related supplier risks. The post Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains appeared first on SecurityWeek.
OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face
OpenAI says its AI models went rogue, as CISOS call the incident a watershed moment, warning that autonomous AI threat models have officially crossed into production reality. The post OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face appeared first on SecurityWeek.
Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife
The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary. The post Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife appeared first on SecurityWeek.
Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI. The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek.
Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation
Using AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement. The post Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation appeared first on SecurityWeek.

AI, security operations and the new race against time
When Anthropic unveiled Project Glasswing and the Mythos model, much of the discussion focused on the capabilities themselves. Security leaders debated what these systems could mean for vulnerability discovery, exploit development and the pace of offensive innovation. Researchers examined technical benchmarks. Industry observers questioned how quickly these capabilities might fall into attackers’ hands. Those conversations […]

10 survival tips for CSOs who report to the CEO
As the CSO grows in prominence, security leaders are increasingly earning a seat at the executive table, reporting directly to the CEO with the expectation to help drive business strategy and ensure organizational success. Reporting to the CEO unlocks greater access and influence for security leaders, and while CSOs who report to their organization’s CIO […]

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on Monday, the Frankfurt public prosecutor’s cybercrime unit (ZIT) and Germany’s […]

New CISO appointments 2026
The upper ranks of corporate security are seeing a high rate of change as companies try to adapt to the evolving threat landscape. Many companies are hiring a chief security officer (CSO) or chief information security officer (CISO) for the first time to support a deeper commitment to information security. Follow this column to keep […]

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain. The package, named “Newtonsoftt.Json.Net,” masquerades as the Newtonsoft.Json library and is a trojanized fork. Seven versions of the package have been published to the
Risky Business #845 -- OpenAI's Skynet moment
On this week’s show special guest co-host Chris Krebs joins Patrick Gray and James Wilson to discuss the week’s cybersecurity news. They cover: Oopsie daisy! OpenAI agents went rogue and hacked Hugging Face US and China trade AI model ban threats Iran has been using SS7 queries to locate and target US troops Scattered Spider […]

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft’s official Azure DevOps MCP server, and it works because one of its tools […]

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an “even more capable pre-release model,” was behind the security incident that targeted Hugging Face’s production infrastructure last week. The AI company said the models were operating with “reduced cyber refusals for evaluation purposes” that might otherwise limit their […]
ISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd)
Post Content

LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on […]
Milford, New Hampshire Confirms Unauthorized Activity, Withholds Details of Suspected Cyberattack
Milford, New Hampshire is a quintessential New England town. But charm is no defense against cyberattackers, and it appears that the town may have been attacked last week. As DysruptionHub was the first to report, the town began experiencing problems early on July 15. Town email alerts, shared with DataBreaches by a town resident, reveal… […]
Pay up or not? Ransomware surge has victims facing tough choices.
Hannah Murphy reports: Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising. Globally, some jurisdictions are responding by banning payments to hackers. In the UK, for… […]
JUMP EXECUTION, LLC
JUMP EXECUTION, LLC fnrw-backend Tue, 07/21/2026 – 15:56 MC ID JRET MC Reporter Type OTC Market Maker MC Paragraph MC Link https://public.s3.com/rule605/jleq/ MC Last Updated Tue, 07/21/2026 – 15:56
JUMP EXECUTION, LLC
JUMP EXECUTION, LLC fnrw-backend Tue, 07/21/2026 – 15:54 MC ID JSDP MC Reporter Type Single Dealer Trading System MC Paragraph MC Link https://public.s3.com/rule605/jleq/ MC Last Updated Tue, 07/21/2026 – 15:54
&PARTNERS
&PARTNERS fnrw-backend Tue, 07/21/2026 – 15:48 MC ID APRT MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.s3.com/rule605/aprt MC Last Updated Tue, 07/21/2026 – 15:48
2017056224801 tastytrade, Inc. CRD 277027 AWC ks.pdf
2017056224801 tastytrade, Inc. CRD 277027 AWC ks.pdf Anonymous (not verified) Tue, 07/21/2026 – 15:30 Case ID 2017056224801 Document Number aad9c52f Document Type AWCs (Letters of Acceptance, Waiver, and Consent) Action Date Tue, 07/21/2026 – 12:00 Related Content Off Attachment 2017056224801 tastytrade, Inc. CRD 277027 AWC ks.pdf
Cyberattack against Maine telecom disrupted municipal internet service in 23 towns
Colin Wood reports: At least one municipal government was among those to see their internet service disrupted after a cyberattack against a Maine telecommunications firm Sunday caused an outage affecting 23 towns along the state’s midcoastal region. A local NBC affiliate reported that the government office of Damariscotta, a tourist town of roughly 2,300 inhabitants, known for… […]
What is RPA? A revolution in business process automation
What is robotic process automation? Governed by business logic and structured inputs, robotic process automation (RPA) employs software “bots” to automate repetitive tasks within business process workflows. RPA tools enable companies to configure these bots to capture and interpret applications for processing a transaction, manipulating data, triggering responses, and communicating with other digital systems. RPA […]
Small models, sovereign advantage: Why Australia should build its own AI edge
For the past three years, the AI conversation has been dominated by scale. Bigger models, bigger compute clusters, bigger headlines. But the next wave of competitive advantage won’t come from who can rent the biggest model; it will come from who can build the smallest one that knows their business. That model is the small […]
IT leaders confident but cooked when it comes to rogue AI agents
A large majority of IT and security leaders are confident in their teams’ ability to detect when an AI agent has gone rogue, but few are able to take quick action to mitigate the fallout when an agent exceeds its intended scope. Nine in 10 IT and security leaders surveyed by IT observability vendor WanAware […]
Asymmetric warfare in financial services: AI-powered fraud demands unified command
Military strategists know that asymmetric wars are lost not at the point of attack but at the seams between defensive units, where no single commander owns the territory and information moves slower than the threat. In January 2024, a finance employee at Arup’s Hong Kong office learned this lesson for $25 million, joining a video […]
The token debate: What CIOs can learn from the laws of thermodynamics
What if the next breakthrough in Enterprise AI doesn’t come from computer science alone? What if it comes from applying principles that physicists have understood for more than a century? According to Gartner, rising token-driven AI spend is straining budgets and challenging cost justification. As organizations race to deploy generative AI and agentic systems, token […]
The AI allocation trap: Record spend, vanishing returns
In a single month, one enterprise reportedly spent half a billion dollars on AI. A consultant told Axios that the client had handed its workforce AI licenses, set no usage limits and let the meter run until finance noticed. The figure is spectacular, and it is the wrong thing to fear. That half-billion-dollar accident is […]
AWS standardizes more AI billing data to simplify cost analysis
AWS has updated AWS Data Exports, its service for generating and managing cost and usage Reports (CURs), to include standardized Amazon Bedrock product metadata, making it easier for enterprise engineering teams to analyze AI usage and spending as they scale AI deployments spanning multiple foundation models. The update extends billing exports with normalized fields for […]
Certinia acquires AI services company Moonnox
AI-powered professional services automation provider Certinia has acquired Moonnox, an AI-native automation platform created for the sector. It extends Certinia’s system of action, Veda, offering a new suite of AI agents that automate administration, project management and project deliverables, the company said. The acquisition will add real-time native context capture across applications such as Salesforce, […]
SAP developers face education debt, user group warns
Many enterprises are investing tens of millions in modernizing their SAP landscapes, but are often underestimating a crucial factor for success, the training of their own developers, according to the German-Speaking SAP User Group, DSAG. The user association urges CIOs to treat the continuing education of SAP developers not as a voluntary training measure but […]
HireQuotient Extends AI Recruiting Capabilities to Paylocity Customers in Frontline Industries
HireQuotient, an AI-native recruiting platform, today announced its integration with Paylocity (Nasdaq: PCTY), bringing AI-powered candidate sourcing and screening capabilities to Paylocity customers in manufacturing, building services, construction, healthcare and insurance, which are industries where deskless and frontline hiring has historically been underserved by AI recruiting tools. Employers in these sectors who already use HireQuotient […]

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked, effectively undermining the feature’s privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a year, when it was […]
STIFEL, NICOLAUS & COMPANY, INCORPORATED
STIFEL, NICOLAUS & COMPANY, INCORPORATED fnrw-backend Tue, 07/21/2026 – 14:26 MC ID STFX MC Reporter Type Alternative Trading System MC Paragraph MC Link https://public.s3.com/rule605/stfl/ MC Last Updated Tue, 07/21/2026 – 14:26

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code on a developer’s machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a […]

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
Google’s DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that’s designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model will be exclusively available to governments and trusted partners via CodeMender as part of a […]

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a […]

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal […]
Captive Portal Detection, (Tue, Jul 21st)
Not everything our honeypots detect is an attack. Sometimes it is just “odd traffic”, and this is one example: Our “First Seen” list currently includes “http://detectportal.firefox.co

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. […]
Personal data of all South Korean diplomats believed leaked in ‘unprecedented’ cyberattack
Seo Ji-Eun reports: The personal information of nearly all of South Korea’s diplomatic personnel is presumed to have been compromised in what the Foreign Ministry on Tuesday called an “unprecedented” cyberattack, exposing up to 10,000 administrative and intelligence records. The data system of the Korea National Diplomatic Academy (KNDA) — an institution affiliated with the… […]
NYSDFS Secures $50 Million Penalty from Swedbank for Withholding Information from Investigators
One of the biggest breaches of 2016 was the Panama Papers leak. The law firm at the heart of it, Mossack Fonseca, closed its doors in 2018, unable to recover from all the damage. But while the law firm folded, investigations continued. The New York Department of Financial Services announced that it has settled charges… […]
Suno Data Breach had a breach in 2025. Why is it first being known now?
Millions here, tens of millions there. Are we all getting breach fatigue by now? Over on HaveIBeenPwned, Troy Hunt reports that Suno experienced a data breach in November 2025, which 404 Media first made public this month: In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the… […]
Seoul Notifies 4.62 Million of Ttareungyi Data Breach, Offers Free Passes
Kim Eun-bi reports: The Seoul Metropolitan Government will send individual text messages to about 4.62 million citizens affected by a data breach involving membership information for Ttareungyi, the city’s public bike-sharing service, notifying them of the leaked items and offering compensation such as 30-day passes. The Seoul Facilities Corporation said the same day that it… […]
Rockwell Automation FactoryTalk Services Platform
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations. The following versions of Rockwell Automation FactoryTalk Services Platform are affected: FactoryTalk Directory (FTSP) 6.60 CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Services […]
Siemens CADRA
View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens CADRA are […]
Rockwell Automation Studio 5000 Logix Designer
View CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions of Rockwell Automation Studio 5000 Logix Designer are affected: Studio 5000 Logix Designer V36.00 (CVE-2026-9108) Studio 5000 Logix Designer V35.00 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) Studio 5000 Logix Designer V35.01 […]
Rockwell Automation 1718-AENTR/1719-AENTR
View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected: 1718/ 1719 Ex I/O 3.011 CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1718-AENTR/1719-AENTR Allocation of Resources Without Limits or Throttling Background Critical […]
Rockwell Automation 1734 POINT I/O
View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1734 POINT I/O are affected: 1734 POINT I/O 3.023 CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1734 POINT I/O Allocation of Resources Without Limits or […]
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
View CSAF Summary Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks’ upstream security notifications. [1] https://security.paloaltonetworks.com/ The following versions of Siemens RUGGEDCOM APE1808 with Palo Alto […]
Siemens IAM Client
View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products […]
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability CVE-2026-60137 WordPress Core SQL Injection Vulnerability These types of vulnerabilities are frequent […]
Siemens SIDIS Secured SmartPlug
View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the latest version. The following versions of Siemens SIDIS Secured SmartPlug are affected: SIDIS Secured […]
Tycon Systems TPDIN-Monitor-WEB2
View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected: TPDIN-Monitor-WEB2 2.3.9 CVSS Vendor Equipment Vulnerabilities v3 9.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using […]

AI agents can escape sandboxes without ever breaking them
Sandboxes have become a key security control for AI coding agents, but new research suggests they may not provide the isolation many organizations assume. Pillar Security has disclosed a series of vulnerabilities showing how agents in tools such as Cursor, Codex, Gemini CLI, and Antigravity can indirectly cross security boundaries without technically escaping their sandboxes. […]
Ernst & Young Data Breach Affects Personal, Financial Information
Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek.
New Index Tracks Material Breaches — And Refuses to Add Up the Losses
Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek.
OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek.
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek.
Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software
Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others. The post Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software appeared first on SecurityWeek.
Zimbra Update Patches Critical Vulnerabilities
The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek.
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek.
Clover Health Investments Discloses Data Breach
Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek.
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek.

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. “By the early hours of Saturday morning (UTC), successful exploitation was already well

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host […]

White hat hacker Park Chan-am zeros in on the AI era’s key security challenges
Dubbed the “Genius Hacker,” Park Chan-am began his white hat hacker journey at the precocious age of 11, winning awards at domestic and international hacking competitions since his teenage years. He has since served as a cybersecurity advisor for various Korean government agencies, including the National Police Agency, and has played a key role in […]

Context bombing heralds a new AI era of deceptive defense
Attackers are increasingly using AI agents to automate all phases of cyberattacks, prompting the security industry and enterprises to find new network defense approaches. One technique that shows promise is to intentionally plant decoy files with prompts that trigger the content safety guardrails built into LLMs with the goal of crashing rogue agentic workflows. Using […]

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it’s observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. Patches for […]
ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)
Post Content
25-02713.pdf
25-02713.pdf Anonymous (not verified) Mon, 07/20/2026 – 19:45 Case ID 25-02713 Forum FINRA Document Type Award Claimants Mark Roberts Respondents Creativeone Securities, LLC Neutrals David G. Skeen Katherine Hendricks Douglas Earl McLaren Hearing Site Kansas City, MO Award Document 25-02713.pdf Documentum DocID 83dcb3c2 Award Date Official Mon, 07/20/2026 – 12:00 Related Content Off Claimant Representatives […]
25-00114.pdf
25-00114.pdf Anonymous (not verified) Mon, 07/20/2026 – 19:45 Case ID 25-00114 Forum FINRA Document Type Award Claimants Dale Raimann Respondents Charles Schwab & Co., Inc. Neutrals Nicholas John Taldone Heather Criss Keller Jared J Perez Hearing Site Tampa, FL Award Document 25-00114.pdf Documentum DocID d36e75fb Award Date Official Mon, 07/20/2026 – 12:00 Related Content Off […]
24-02186.pdf
24-02186.pdf Anonymous (not verified) Mon, 07/20/2026 – 19:45 Case ID 24-02186 Forum FINRA Document Type Award Claimants LPL Financial LLC Respondents Christian Zernich Neutrals Robert J. Scafuri John J. Neely Valerie G. Fitzgerald Hearing Site Pittsburgh, PA Award Document 24-02186.pdf Documentum DocID 051a9580 Award Date Official Mon, 07/20/2026 – 12:00 Related Content Off Claimant Representatives […]
INTERACTIVE BROKERS CORP.
INTERACTIVE BROKERS CORP. fnrw-backend Mon, 07/20/2026 – 17:07 MC ID ISDP MC Reporter Type Single Dealer Trading System MC Paragraph MC Link https://www.interactivebrokers.com/en/general/about/IBKR-ATS-605-IBCO-Reports.p… MC Last Updated Mon, 07/20/2026 – 17:07
INTERACTIVE BROKERS CORP.
INTERACTIVE BROKERS CORP. fnrw-backend Mon, 07/20/2026 – 17:05 MC ID FRAC MC Reporter Type OTC Market Maker MC Paragraph MC Link https://www.interactivebrokers.com/en/general/about/IBKR-605-IBCO-FRAC-Reports… MC Last Updated Mon, 07/20/2026 – 17:04

ServiceNow’s sandbox escape RCE hole now exploited in the wild
A sandbox security hole that could lead to remote code execution (RCE), patched last week by ServiceNow, is being actively exploited in the wild, according to a report from threat intel firm Defused. The report, posted on X, said the firm is “observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE (CVE-2026-6875).” Defused CEO Simo […]
The audit trail CIOs need before the next cyber crisis
In one ransomware response I observed, the master operational dashboard remained green while the underlying environment told a very different story. It was a classic example of what we in the IT audit profession call the “watermelon effect”—green on the outside, red on the inside. Beneath that dashboard sat an unmapped web of legacy technical […]
The 6 kinds of AI agent architectures
Somewhere in the last eighteen months, “AI agent” stopped being a useful term. CIOs may even be afraid to ask what “agent” truly means, as it now seems to describe everything from a chatbot that answers HR questions to an autonomous research system that plans its own week of work. When a single phrase carries […]
Finding the right balance between autonomy and scale
For diversified enterprises, few operating model questions are as persistent or polarizing as centralization versus decentralization. Decentralization promises speed, ownership, and local responsiveness. Centralization promises efficiency, standardization, and leverage. Both can be right. Both can be wrong. The challenge is that many organizations end up with both models operating at once, without enough clarity about […]
Building the network for agentic AI: The foundation for autonomous enterprise operations
Enterprise AI is entering a new phase. While the first wave of generative AI focused on human productivity and content creation, the next wave — agentic AI — will fundamentally change how organizations operate. Agentic AI systems are capable of reasoning, planning, making decisions and executing actions across applications, workflows and business processes with minimal […]
7 issues impacting AI strategies — and how CIOs should respond
CIOs remain at the forefront of setting the course for AI adoption in their organizations. In fact, 82% of CIO respondents to CIO.com’s 2026 State of the CIO survey are responsible for researching and evaluating AI products, with 78% of IT leaders saying their IT departments are driving AI adoption efforts, with business units aligning […]
With AI, activity is not value
The emergence of artificial intelligence is beginning to expose a profound weakness in the way modern enterprises measure performance. For decades, business evaluation systems have been built around the logic of the industrial and transactional economy. Revenue growth, operating margins, earnings per share, labor productivity, return on investment and market share became the dominant indicators […]
AI’s problems aren’t what you think
The biggest and loudest prediction about AI is that it will eliminate millions of jobs. It is dramatic and easy to repeat. But from what I’ve seen, inside most enterprises the more immediate problem has turned out to be something else entirely: a growing mass of tools, agents, models and usage costs spreading faster than […]
The technology behind every live sports moment
When a goal goes in during a tournament quarter-final and a hundred million people watch it at the same time, what they feel is the goal. The roar, the replay, the disbelief. They do not feel the contribution feeds traversing private media networks across continents, or the edge nodes absorbing a traffic spike that appeared […]
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
Last week, Searchlight Cyber released details about a vulnerability they are calling “wp2shell”. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can […]

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. “FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it […]

AI adoption and business acceleration are changing the expectations of technology risk management
As AI becomes embedded in customer experiences, internal workflows, and throughout the supply chain, security leaders are being asked to do more than manage risk. They are being asked to help the business make more informed decisions and move faster. At the same time, AI has evolved faster than the programs built to govern it. […]

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, […]

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already […]

Patch now: WordPress REST API bug allows remote code execution
Organizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platform’s built-in REST Batch API. The flaw, dubbed wp2shell, enables attackers to execute arbitrary code against a default WordPress installation without requiring plugins, authentication, or special configuration. Adam Kues of Searchlight Cyber first […]

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands’ civilian and […]

New ACR Stealer campaigns use WebDAV, MSHTA to evade detection
Microsoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, and sensitive business documents. In a new report, Microsoft researchers detailed two separate campaigns observed between late April and mid-June 2026 that use different execution techniques for the same theft. The campaign […]
Broken Promises of Anonymity: Four Months Later, Still No Transparency. Now We’re Seeking Accountability.
On March 18, 2026, Navigate360 learned that 8.3 million anonymous tips had been exposed. The company’s response—and the silence of the programs that depend on its platform—has persisted for months. We’re now seeking accountability through state and federal regulators. A DataBreaches.net Editorial In March 2026, the world learned that a hacktivist had acquired 8.3 million… […]

Mythos Didn't Break Your Security Program. Your Exposure Window Could.
The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain […]
WP2Shell WordPress Vulnerabilities Exploited in the Wild
Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
Chrome 150 Update Patches Severe Memory Safety Bugs
The fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek.
Hugging Face Hacked in Autonomous AI Attack
Targeting production infrastructure, the attack compromised internal datasets and service credentials. The post Hugging Face Hacked in Autonomous AI Attack appeared first on SecurityWeek.
Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations. The post Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool appeared first on SecurityWeek.

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro’s Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow […]

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other […]

SOCs face a human challenge as AI speeds alerts and threats
Security operations centers (SOCs) have spent years struggling under the weight of growing alert volumes, expanding attack surfaces, and chronic staffing shortages. Now artificial intelligence is adding a new complication: not just more information, but more machine-generated information that must itself be evaluated. “There is an asymmetry here because you now have to parse through […]

Claude Mythos FAQ: Capabilities, access, competitors, implications
1. What is Claude Mythos? Claude Mythos is an advanced AI model developed by Anthropic and is optimized for cybersecurity and healthcare applications. Mythos 5 was originally released in April to a small group of vetted technology partners ahead of a planned wider rollout. Anthropic established Project Glasswing, a consortium that gives limited, controlled access […]

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. “We identified unauthorized access to a limited set of internal datasets […]

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below – git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) – Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) […]
ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)
Post Content

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade. Triggering it […]
Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)
We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans that our honeypot network detects.

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia’s
Medical giant Abbott investigates two cyber incidents as ShinyHunters and ShadowByt3$ both claim breaches
Anna Zhadan reports: American healthcare giant Abbott Laboratories is investigating two cyber incidents that appear to be unrelated: one involving its Cancer Diagnostics business and another affecting its LabCentral portal. Although unrelated, the two disclosures came within days of each other. On July 16th, Abbott said it was investigating an incident involving unauthorized access to a limited… […]

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this
NY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic Data
There’s another update in the litigation involving 23andMe, below, but this won’t be the last update, as California’s Attorney General has also recently sued them under California’s privacy laws. New York Attorney General Letitia James and a bipartisan coalition of 42 other attorneys general today secured $18 million from genetic testing company 23andMe for failing to… […]
Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday
Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI. The post Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday appeared first on SecurityWeek.
Beacon Security Raises $13 Million for Security Data Platform
The startup helps organizations detect, hunt, and protect their assets across environments at machine speed. The post Beacon Security Raises $13 Million for Security Data Platform appeared first on SecurityWeek.
Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive
(Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up? The post Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive appeared first on SecurityWeek.
In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach. The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared first on SecurityWeek.

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install […]

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. […]
25-00951.pdf
25-00951.pdf Anonymous (not verified) Fri, 07/17/2026 – 15:50 Case ID 25-00951 Forum FINRA Document Type Award Claimants Nicholas Nuzzi Respondents Jesse Krapf Joao Pinto Spartan Capital Securities, LLC Neutrals Tina E. Patterson James Andrew Calder Krista Shreet Hearing Site Norfolk, VA Award Document 25-00951.pdf Documentum DocID ff5471af Award Date Official Fri, 07/17/2026 – 12:00 Related […]
ONE GROWTH SECURITIES LLC
ONE GROWTH SECURITIES LLC fnrw-backend Fri, 07/17/2026 – 15:45 MC ID DWLY MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.newrange.com/605/onepay MC Last Updated Fri, 07/17/2026 – 15:44
Salesforce’s Agentforce product maturity questioned as KeyBanc cites weak customer traction
Salesforce’s AI agent platform, Agentforce, is seeing weaker-than-expected customer traction, according to a recent KeyBanc Capital Markets investment research note, which attributed the slowdown in part to the product itself, stating that “Agentforce, as a product, just isn’t there” yet, following customer checks and a CIO survey. “Our checks and customer conversations have not been […]
5 steps to secure your infrastructure in the frontier model era
The industry conversation around AI infrastructure has narrowed to a single dimension: scale. The focus is on GPUs, power, cooling and the massive physical footprint required to train and run AI agents and models. At the same time, organizations are adjusting to the speed and scale with which AI is identifying vulnerabilities — which is […]
New Linux Foundation project aims to make payments native to AI workflows
The Linux Foundation has launched the x402 Foundation, a new industry body that will oversee the x402 payment protocol, an open standard designed to let AI agents, applications, and APIs pay for digital services over HTTP. The x402 protocol, originally developed by Coinbase, embeds payment capabilities directly into web interactions, allowing AI agents, APIs, and applications to […]
SAP: Latest news and insights
SAP (NYSE:SAP) is an enterprise software vendor based in Walldorf, Germany. Its cloud and on-premises enterprise resource planning (ERP) software, including S/4HANA, helps organizations manage their business operations and customer relations. The German multinational also offers a vast array of software solutions tailored to specific facets of the enterprise, including data management, analytics, and supply […]
The build vs. buy dilemma at the heart of enterprise AI
For three decades, enterprise software has been a buy-it decision. Packaged software from SAP, Oracle and Salesforce covered roughly 80% of requirements at a fraction of the cost of building. The economics were obvious, and for traditional applications, they still are. AI is introducing a wrinkle that is forcing even the most committed enterprise software […]
How to add XLAs to your outsourcing contract
Organizations usually face the same questions concerning XLAs: What should we measure, who owns the data, how should incentives work, and how will this change provider behavior after signature. There are no easy answers either, but after advising clients in MSP relationships with major providers, I’ve seen what works and what doesn’t. Successful XLA programs […]
AI makes its case against the ‘business-savvy CIO’
Once upon a time, there were actual arguments as to whether CIOs should be business people, not technology people. With any luck, these arguments were stomped out back here: “The case against the ‘business-savvy CIO’” — which drove the arguments for this false dichotomy into the ground back in 2018. Some complications have arisen in […]
Why technology leaders are losing the AI conversation to the people who report to them
I keep seeing a version of the same scene. A CEO has a question about AI. It is a real question, the kind that will shape where the company spends the next two years. The CEO does not bring it to the CIO. They bring it to a data leader two levels down, or to […]
The last human relationship in cybersecurity
We are inundated with promises that artificial intelligence will save us and that the next governance framework will protect us. Buy this platform, adopt that model and the hard part finally gets easier. After 15 years in this field, I have wanted that shortcut as much as anyone. But both promises are downstream of something […]
China creates World AI body with Russia and 27 others, but without US
China has created an international organization to set standards and introduce regulation for AI, inviting 28 other countries to join — but the US, a leading AI powerhouse is not part it. The World Artificial Intelligence Cooperation Organization (WAICO) was established by 29 countries, including China, Russia and Brazil, at a ceremony in Shanghai, China, […]

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an “unprecedented” four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron,
26-00431.pdf
26-00431.pdf Anonymous (not verified) Fri, 07/17/2026 – 14:35 Case ID 26-00431 Forum FINRA Document Type Award Claimants Derek Ambrosi Respondents Wells Fargo Advisors Financial Network Neutrals Keely D. Parr Hearing Site Hartford, CT Award Document 26-00431.pdf Documentum DocID b34d9ad9 Award Date Official Fri, 07/17/2026 – 12:00 Related Content Off Claimant Representatives Derek Ambrosi Respondent Representatives […]
CANTOR FITZGERALD & CO.
CANTOR FITZGERALD & CO. fnrw-backend Fri, 07/17/2026 – 14:22 MC ID WSMM MC Reporter Type OTC Market Maker MC Paragraph MC Link https://nam11.safelinks.protection.outlook.com/?url=http%3A//disclosure.bestxst… MC Last Updated Fri, 07/17/2026 – 14:22
2025084815701 Tory A Duggins CRD 4556340 OHO Decision df.pdf
2025084815701 Tory A Duggins CRD 4556340 OHO Decision df.pdf Anonymous (not verified) Fri, 07/17/2026 – 14:05 Case ID 2025084815701 Document Number f27306e0 Document Type OHO Decisions Individuals Tory A Duggins Action Date Wed, 06/10/2026 – 12:00 Related Content On Attachment 2025084815701 Tory A Duggins CRD 4556340 OHO Decision df.pdf Individual CRD 4556340
FBI arrests man accused of using Steam games to drain victims’ crypto wallets
Lorenzo Franceschi-Bicchierai reports: U.S. prosecutors have accused a Florida man of uploading fake video games that contained malware to Steam, the popular PC games platform. Once victims downloaded and installed the games, the malware was designed to infect their computers, steal their passwords and other data, and drain their crypto wallets, according to a criminal… […]

OnlyFans performers become unlikely allies of CISOs in securing websites
CISOs at government organizations and universities have an unexpected ally coming to their aid: OnlyFans models. For some time, hackers have exploited weaknesses in the websites of universities or government departments to host scams or malware, using content stolen from the OnlyFans website as bait to attract victims. Now, according to security researchers at Upguard, […]

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast […]

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors […]

Google must open Android to rival AI agents, EU orders
The European Union is stepping up its actions against US tech giants under the Digital Markets Act, which is intended to ensure fair competition between digital platforms. On Thursday, the European Commission issued two rulings to limit Google’s dominance. The Commission ordered Google to open up the Android operating system to AI assistants other than […]

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. “Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto […]
EDPB calls for legal basis for cross-regulatory information sharing
EDPB calls for legal basis for cross-regulatory information sharing ipetstef Fri, 07/17/2026 – 14:50

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing. Google has […]

The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move from concept to operational deployment at commercial speed. Now the focus shifts to the trusted
Oak Emerges From Stealth Mode With $60 Million in Funding
The startup has built an AI-powered Identity Operating System that governs all identities across an organization’s environment. The post Oak Emerges From Stealth Mode With $60 Million in Funding appeared first on SecurityWeek.
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency. The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek.
AI Data Centers Are Being Built Faster Than They Can Be Secured
AI infrastructure introduces new security risks that traditional data center designs were never built to handle. The post AI Data Centers Are Being Built Faster Than They Can Be Secured appeared first on SecurityWeek.
Two Scattered Spider Hackers Sentenced to Jail in UK
Thalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL). The post Two Scattered Spider Hackers Sentenced to Jail in UK appeared first on SecurityWeek.
Legacy Systems, Real-World Impacts: The Reality of OT Security
Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity’s most challenging balancing acts. The post Legacy Systems, Real-World Impacts: The Reality of OT Security appeared first on SecurityWeek.
Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack
The company has yet to determine the full scope, nature, and impact of the incident. The post Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack appeared first on SecurityWeek.
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server. The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek.
Risk Ledger Raises $32 Million in Series B Funding
The British firm has built a collaborative platform to help organizations address supply chain security risks. The post Risk Ledger Raises $32 Million in Series B Funding appeared first on SecurityWeek.
Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei
The company disconnected its systems on July 13 and is starting to gradually restore operations. The post Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei appeared first on SecurityWeek.

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan’s Zvartnots airport, held up a phone with […]
Regulate me, please...
An article about regulation of Big Tech AI and what we can do about it writen by Marek Tuszunski

The SaaS blind spot: Why security teams can’t get inside their own apps
Most organizations I work with have invested heavily in cloud security. They have endpoint detection tools, SIEM platforms, cloud security posture management, and skilled security teams running on a 24/7 shift. And yet, when I ask them a simple question — who has admin access in your Salesforce tenant right now? — The room goes […]

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery […]

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering. Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic […]

Fake TTF files deliver stealthy malware in global phishing campaign
Threat actors are now abusing an ordinary font file to deliver low-detection malware capable of stealing credentials and establishing persistence on compromised Windows systems. According to a new research from Fortinet’s FortiGuard Labs, a global phishing campaign is actively using heavily obfuscated JavaScript and a Lua-based loader posing as a TrueType Font (TTF) file to […]

Senior executives are killing your shadow AI strategy
Shadow IT has long been a major problem for CISOs, but the biggest problem may be coming from the executive suite’s hunger for unsanctioned AI. Nearly two-thirds of senior decision-makers admit to using unapproved AI tools, compared to just 31% of lower-level employees, according to a survey by Microsoft solutions partner TrustedTech. The use of […]

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization
ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)
Post Content
24-02522.pdf
24-02522.pdf Anonymous (not verified) Thu, 07/16/2026 – 17:20 Case ID 24-02522 Forum FINRA Document Type Award Claimants Lea Wiviott Boracchia Marc Boracchia Respondents Michael Byrne Northwestern Mutual Investment Services Neutrals Peter H. Daly Carol Ann Jensen Kiosha L Ford Hearing Site San Francisco, CA Award Document 24-02522.pdf Documentum DocID cf13c49f Award Date Official Thu, 07/16/2026 […]
25-02154.pdf
25-02154.pdf Anonymous (not verified) Thu, 07/16/2026 – 17:15 Case ID 25-02154 Forum FINRA Document Type Award Claimants William Hernandez Respondents Charles Schwab & Co., Inc. Neutrals Dineo Coleman Gary Fern M. Laethem Stephanie E. Simmons Hearing Site Los Angeles, CA Award Document 25-02154.pdf Documentum DocID 84be3ecb Award Date Official Thu, 07/16/2026 – 12:00 Related Content […]
The Breach That Won’t End: An Update on Canvas, and how they created an EdTech’s Vendor Trust Problem
Jeff Piontek comments on the Instructure breach: The forensic review has taken far longer than anyone expected. Through June, Instructure was still finalizing customer-specific findings and asking institutions to designate a security contact to receive them. In early July, the company began delivering the first wave of institution-specific data packets, through a permissioned file-sharing link… […]
DeepMind CEO pushes for AI industry self-regulation
Google DeepMind CEO Demis Hassabis is pushing for the US AI industry to self-regulate, with the support of government, as a starting point for an international creating shared international standards. In a blog post, he called for a focus on artificial general intelligence (AGI) and national security. But it is precisely that focus on national […]
Did AI decide who lost their jobs? Meta is heading to court over that question
Enterprises that use AI in hiring and firing decisions continue to be under scrutiny, and this time it’s Meta under the microscope. A legal complaint filed on July 13 in a US District Court in California alleges that Meta used AI systems that unfairly and illegally selected workers for termination while they were out on […]
What the World Cup reveals about the operating models CIOs need next
Every major sporting and pop culture event creates a familiar conversation among employers: How much productivity will be lost? This year’s FIFA World Cup was no exception. Before the tournament began, UKG research found that 37% of employees globally planned to adjust their work schedules during the tournament. Some intended to take time off. Others […]
IT leaders prioritize addressing AI skill concerns
Recent data from the CompTIA Tech Jobs Report shows that tech jobs have seen a drop in unemployment, down to 3.1% in May from 3.5% in April, accounting for an increase of around 6,700 in May. Roles that saw the highest demand include software developers and engineers, systems engineers and architects, tech support specialists, cybersecurity […]
What next-generation IT leadership looks like
Today’s CIOs must master a complex balancing act of maintaining operational excellence while enabling AI experimentation, modernizing legacy environments while accelerating innovation, leading workforce transformation while maintaining culture, and communicating fluently across boards, business units, customers, and technical teams alike. Few leaders understand this balancing act better than former Verizon CIO Jane Connell. Over her […]
Why your ERP training program is failing your employees
I have sat in a lot of ERP training sessions over the years. Some were excellent. Most were not. And the ones that failed share a pattern I have come to recognize almost immediately: a vendor trainer at the front of the room, working through the same slide deck they use for every client, at […]
19 AgentOps tools for monitoring AI activity, issues, and costs
With AI increasingly tucked into every cranny of the enterprise, someone has had to step up and provide the tools necessary to discover, track, and monitor all the agents and LLMs and keep them humming along in their various workflows. Thankfully, the DevOps world answered the call, building the tools to support our new overlords […]
FIFTH THIRD SECURITIES, INC.
FIFTH THIRD SECURITIES, INC. fnrw-backend Thu, 07/16/2026 – 13:58 MC ID OHIO MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.s3.com/rule605/ftsr/ MC Last Updated Thu, 07/16/2026 – 13:58
FIFTH THIRD SECURITIES, INC.
FIFTH THIRD SECURITIES, INC. fnrw-backend Thu, 07/16/2026 – 13:56 MC ID FTSR MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.s3.com/rule605/ftsr/ MC Last Updated Thu, 07/16/2026 – 13:56

Zoom patches account takeover hole
Zoom has identified, and patched, a critical security hole that “may allow an unauthenticated user to conduct an account takeover via network access.” The issue is especially significant given Zoom’s extensive reach; it reportedly has more than 300 million daily active users, including 470,000 paying business customers. Given that reach, Zoom has been impacted by many […]

Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority’s employees into an office to get their […]
Italy fines WINDTRE €1.7 million over data breaches
Gianluca Semeraro reports: Italy’s data protection authority has fined telecoms operator WINDTRE €1.7 million ($1.94 million) for “serious shortcomings” in its data security systems, leading to two unauthorised breaches and the exposure of personal information belonging to more than 365,000 customers. • The investigation was prompted by the CK Hutchison owned company’s notification of the… […]
Matt Collins Comment On Regulatory Notice 26-14
Matt Collins Comment On Regulatory Notice 26-14 fnrw-backend Thu, 07/16/2026 – 12:00 Matt Collins null null matthew_collins@augustarfinancial.com FINRA Regulatory Notice 26-14 – Comment Regarding Risk-Based Supervision of Retail Communications We generally support FINRA’s effort to modernize Rule 2210 and recognize the challenges that social media platforms, digital communications, and generative artificial intelligence have created for […]

ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation. Old bugs are back, weak defaults are earning their keep, and some […]

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss. A valid token from issuer A carrying a sub that belongs to someone under issuer B logged you in […]

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that’s been spreading via websites infected with ClickFix lures since late April 2026. “The malware is full-featured, lightweight, and modular,” Elastic Security Labs researcher Cyril François said in a technical report. “While the number of C2 [command-and-control] domains is currently small, the daily

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
ClickLock Stealer, a new macOS infostealer, answers a victim’s refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim cancels, installs two LaunchAgents and quietly exits. At the next […]

CISA urges immediate SharePoint hardening as exploits mount
The US Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to immediately secure Microsoft SharePoint deployments after warning that three vulnerabilities affecting the on-premises collaboration platform are being actively exploited. A recent advisory from the federal cybersecurity watchdog asked administrators to patch vulnerable servers, review Microsoft’s mitigation guidance, and assume that internet-facing SharePoint instances […]
NASA Core Flight System (cFS) Health & Safety (HS) Application
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected: Core Flight System (cFS) Health & Safety (HS) Application CVSS Vendor Equipment Vulnerabilities v3 7.5 NASA NASA Core Flight System (cFS) Health […]
Rockwell Automation Flex 5000 Adapter
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation Flex 5000 Adapter are affected: Flex 5000 Adapter 6.011 (CVE-2026-12659) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation Flex 5000 Adapter Double Free Background Critical Infrastructure […]
AutomationDirect Productivity Suite
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a denial-of-service condition in the affected product. The following versions of AutomationDirect Productivity Suite are affected: Productivity Suite <=v4.6.2.2 (CVE-2026-60063, CVE-2026-61389, CVE-2026-60140, CVE-2026-57896, CVE-2026-60073, CVE-2026-61378) CVSS Vendor Equipment […]
Rockwell Automation Arena
View CSAF Summary Successful exploitation these vulnerabilities could allow an attacker to execute arbitrary code in the context of the current process. The following versions of Rockwell Automation Arena are affected: Arena <=V17.00.00 (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation Arena Out-of-bounds Write Background Critical Infrastructure Sectors: Critical […]
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors […]
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are affected: 1756-EN3 <=V12.001 (CVE-2026-9653) 1756-EN2 <=V12.001 (CVE-2026-9653) 1756-ENBT V6.006 (CVE-2026-9653) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT Improper Validation of […]
Rockwell Automation FactoryTalk DataMosaix
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server. The following versions of Rockwell Automation FactoryTalk DataMosaix are affected: DataMosaix Private Cloud <=8.02 (CVE-2026-9292) CVSS Vendor Equipment Vulnerabilities v3 6.1 Rockwell Automation Rockwell Automation FactoryTalk DataMosaix Improper Neutralization of Input During Web Page Generation […]
SALTO ProAccess Space
View CSAF Summary Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credentials and the partition feature to be enabled; installations without partitioning are not affected. The following versions of SALTO […]
Siemens SICAM 8
View CSAF Summary Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: – SICAM A8000 Device firmware – CPCI85 for CP-8031/CP-8050 – SICORE for CP-8010/CP-8012 – SICAM EGS Device firmware – CPCI85 – SICAM S8000 – SICORE Siemens has released new versions for the affected products and […]
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix are affected: CompactLogix 5370 <=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) Compact GuardLogix 5370 <=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) ControlLogix 5570 <=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) GuardLogix 5570 <=V35.015 (CVE-2025-12011, CVE-2025-12012, […]

20+ Hijacked Government Websites Became an Attack Channel
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation revealed previously undocumented backdoor behavior, hidden infrastructure relationships, and multiple attack arms behind a campaign
AU: Regulator’s preliminary findings did not indicate Qantas breached privacy obligations
Vlad Constantinescu reports that the Office of the Australian Information Commissioner has determined that although the Qantas data breach of 2025 resulted in 5.67 million customer records being compromised and leaked, the regulator’s preliminary inquiry did not indicate that Qantas was likely to have breached the country’s privacy rules. The attack began when an attacker… […]
Thalha Jubair and Owen Flowers sentenced to prison
Stanley Murphy-Johns, Rosie Shead, and Alex Levy report that Thalha Jubair, 20, and Owen Flowers, 18, were both sentenced at Woolwich Crown Court to 5 years and six months in prison for hacking Transport for London. In a televised sentencing, Mr Justice Turner addressed the defendants and said: “I’m satisfied that your actions were primarily… […]

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click “Buy Now” instead. Ask a coding assistant to apply a maintainer’s fix from a GitHub thread, and a fake comment can make it run a stranger’s command on your computer. Neither trick hijacks the […]
Virtual Event Today: Cloud & Data Security Summit
Attendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. The post Virtual Event Today: Cloud & Data Security Summit appeared first on SecurityWeek.
Windows Bind Link Attacks Can Hide Malware From EDR Tools
Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products. The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek.
CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days. The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek.
Unpatched Cursor Vulnerability Exposes Users to Code Execution
An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically. The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek.
Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities
The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products. The post Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities appeared first on SecurityWeek.
Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day
The researcher stripped the proof-of-concept (PoC) exploit to prevent immediate exploitation of the vulnerability. The post Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day appeared first on SecurityWeek.
Old UEFI Shims Expose Systems to Secure Boot Bypass
Signed by Microsoft, the vulnerable UEFI shim bootloaders could be abused on any system, regardless of the OS. The post Old UEFI Shims Expose Systems to Secure Boot Bypass appeared first on SecurityWeek.
China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans
Chinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures. The post China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans appeared first on SecurityWeek.
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
Attackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code. The post F5 Patches Multiple NGINX, BIG-IP Vulnerabilities appeared first on SecurityWeek.
Splunk, Zoom Patch Critical Vulnerabilities
The flaws could allow attackers to access credentials and data, take over accounts, and escalate their privileges. The post Splunk, Zoom Patch Critical Vulnerabilities appeared first on SecurityWeek.

CISA urges software vendors to formalize vulnerability disclosure programs
The Cybersecurity and Infrastructure Security Agency (CISA) and four international cybersecurity agencies have published guidance urging software manufacturers and online service providers to establish coordinated vulnerability disclosure (CVD) programs, saying structured engagement with security researchers can help improve vulnerability management and product security. Published jointly with the US National Security Agency (NSA), Japan Computer Emergency […]

AI Can Find Bugs, But Human Knowledge Still Proves Them
Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive testing workflows at impressive speed. That is a real advantage for […]

When AI gets a body, it inherits an attack surface
Most security leaders I know working on AI robotics are being shown the same kind of video. A humanoid folds a shirt, sorts a bin, walks a warehouse aisle and a vendor uses the clip to move an embodied AI system from pitch to purchase order. Someone then has to sign off. Robot demos create […]

Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide
Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people’s Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext. A researcher publishing under the handle tokay0 put the […]

The executive profile your security team isn’t defending
A few years ago, I was retained to conduct a digital risk review for the chief executive of a mid-sized financial services firm. The brief was standard. Assess what was publicly available about the executive, identify exposure and advise on remediation. The AI tools I used completed the substantive reconnaissance in under ten minutes. What […]

OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol
OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely. “GPT‑Red is a strong red-teamer, and our previous models are highly vulnerable to its prompt injection attacks,” the artificial intelligence (AI) company said. “We use GPT‑Red […]

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover
Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. “Improper Input Validation in Zoom Desktop Client for Windows, Zoom […]

Flaw surge fuels need for CISOs to rethink vulnerability management
Security experts are calling on enterprises to revise their vulnerability management strategies and move towards “just in time” patching in response the increased pace of vulnerability exploitation. Attackers are turning to AI to increase the rate of vulnerability exploitation and supply chain compromise so that traditional forms of vulnerability management are no longer keeping pace. […]
ISC Stormcast For Thursday, July 16th, 2026 https://isc.sans.edu/podcastdetail/10010, (Thu, Jul 16th)
Post Content
25-00416.pdf
25-00416.pdf Anonymous (not verified) Wed, 07/15/2026 – 17:20 Case ID 25-00416 Forum FINRA Document Type Award Claimants Coralia Boudreaux Respondents Candida Harris Edward Jones Neutrals Steven Gerard Goerke Will Murphy Barry David Thorpe Hearing Site Boca Raton, FL Award Document 25-00416.pdf Documentum DocID 92aba0de Award Date Official Wed, 07/15/2026 – 12:00 Related Content Off Claimant […]
ROTH CAPITAL PARTNERS, LLC
ROTH CAPITAL PARTNERS, LLC fnrw-backend Wed, 07/15/2026 – 16:42 MC ID ROTH MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.s3.com/rule605/roth/ MC Last Updated Wed, 07/15/2026 – 16:42

NPM ecosystem hit with two new supply chain compromises
Attacks targeting developer ecosystems are increasing in frequency and sophistication, with Node.js developers firmly in this week’s crosshairs, as multiple npm packages belonging to the open-source AsyncAPI and Jscrambler Code Integrity were poisoned with malware following compromised development credentials. The incidents highlight the cascading effect of software supply chain attacks in which stolen credentials are […]
Sean Mannello Comment On Regulatory Notice 26-14
Sean Mannello Comment On Regulatory Notice 26-14 fnrw-backend Wed, 07/15/2026 – 16:28 Sean Mannello AZ US smannello@osaic.com Osaic – www.osaic.com Hello, I support FINRA’s effort to modernize Rule 2210 and adopt a more risk-based supervisory framework for retail communications. In my experience reviewing communications, the current rule often requires the same level of review for […]
2019064499301 Centaurus Financial Inc. CRD 30833_Patrick Michael Carroll CRD 2676119 AWC ks.pdf
2019064499301 Centaurus Financial Inc. CRD 30833_Patrick Michael Carroll CRD 2676119 AWC ks.pdf Anonymous (not verified) Wed, 07/15/2026 – 16:00 Case ID 2019064499301 Document Number 119b0157 Document Type AWCs (Letters of Acceptance, Waiver, and Consent) Individuals Patrick Michael Carroll Action Date Wed, 07/15/2026 – 12:00 Related Content Off Attachment 2019064499301 Centaurus Financial Inc. CRD 30833_Patrick Michael […]
HRT FINANCIAL LP
HRT FINANCIAL LP fnrw-backend Wed, 07/15/2026 – 15:40 MC ID HRTS MC Reporter Type Single Dealer Trading System MC Paragraph MC Link https://external.s3.com/rule605/hrtf/ MC Last Updated Wed, 07/15/2026 – 15:40
The hidden AI cost driver: Harness design can make or break enterprise agent economics
A largely overlooked layer of the AI stack is emerging as a major driver of enterprise costs. New testing by AI consultancy Systima found that agent harnesses, the software that coordinates models, tools and workflows, can generate significant token overhead through their configuration alone, potentially inflating the cost of AI deployments as organizations scale agents […]
Context is becoming AI’s most misunderstood word
If you spend enough time in Silicon Valley AI circles, you’ll hear the same message over and over again: AI needs context. The statement is broadly true. The problem is that “context” has become one of the least precise terms in the industry. Depending on who is using it, context can mean documents, dashboards, reports, […]
Senior executives abuse shadow AI twice as much as regular employees do
Shadow IT has long been a major problem for IT leaders, but the biggest problem may be coming from the executive suite’s hunger for unsanctioned AI. Nearly two-thirds of senior decision-makers admit to using unapproved AI tools, compared to just 31% of lower-level employees, according to a survey by Microsoft solutions partner TrustedTech. The use […]
BMW elevates its AI humanoid robot strategy to include logistics
When people hear the term artificial intelligence, they usually think of chatbots or data analysis. But at BMW’s Spartanburg plant in the US, AI is now getting hands, legs, and eyes. Under the term physical AI, the automaker is integrating the new humanoid AI robt Figure 03 into its production logistics. The move comes as […]
The trillion-dollar question: When should legacy applications make way for AI?
If you just read the headlines, it would seem as if AI is now writing all of the world’s code and powering every application businesses run on. That’s far from true. Just 4 of 33 AI pilots reach production, according to IDC Research — leaving legacy applications still fueling the wheels of commerce. This “silent […]
5 ways for CIOs to avoid AI bill shock
Gen AI spending is moving beyond the familiar software model of seats, licenses, and pilots. As AI shifts from copilots to embedded workflows and autonomous agents, one user request can trigger multiple model calls, retrieval steps, retries, orchestration layers, and infrastructure events. A tool that looks affordable in pilot may behave very differently once connected […]
AI is paying off, but governance is lagging behind
Enterprises are facing two simultaneous challenges with AI: The risks associated with it are evolving faster than governance frameworks, while the business benefits are often difficult to measure. This is one of the key findings of The Value of AI, a study commissioned by SAP from Oxford Economics. Now in its second year, the study […]
Calgary 911 employee charged with breach of trust
Manjot Singh reports: Calgary police say a City of Calgary 911 employee has been charged following an investigation into the unauthorized disclosure of confidential information. Police say the investigation began in January after allegations that sensitive information was being accessed and shared outside authorized channels. Investigators allege the accused used her position to access and… […]

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. “While the AI complied with their request to generate botnet code, it included a safety disclaimer that the […]
WilmerHale Sued Over Client Personal Information Data Breach
Alex Ebert reports: Wilmer Cutler Pickering Hale & Dorr should pay millions of dollars in damages for loss of clients’ personal information in a May data breach, a putative class action claims. The lawsuit, filed Tuesday in the US District Court for the District of Columbia, seeks negligence and contract damages on behalf of “thousands” of… […]
Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach
Munsif Vengattil and Aditya Kalra Ransomware group World Leaks has posted on the dark web a huge cache of files related to India’s largest nuclear plant, including purported blueprints of parts of its facilities and supplier details — information it labelled as coming from Reliance Group. The Kudankulam Nuclear Power Plant, located in the southern… […]

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet’s own desktop software. Sometimes it waits until you plug the device in first. […]

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below – CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation in the DOM: Navigation component “We are aware that exploit code for this is public, […]

New Windows Bind Link techniques let attackers evade EDR, security controls
Attackers who already have administrator privileges on a Windows machine have newer ways to slip past endpoint security without exploiting a vulnerable driver or modifying trusted binaries. Bitdefender researchers have warned against three techniques that abuse Windows Bind Links, a legitimate filesystem virtualization capability, to occupy security tools with clean files while malicious ones execute […]

White House launches AI-driven vulnerability clearinghouse to speed cyber remediation
The White House is expanding the use of AI beyond cyber threat detection into vulnerability management, launching a new program that aims to help government agencies and critical infrastructure operators identify, prioritize, and remediate software vulnerabilities faster. Called Gold Eagle, the initiative will act as a centralized clearinghouse for cybersecurity vulnerabilities, coordinating vulnerability reporting, verification, […]
Nayax updates its incident status; states it won’t pay any extortion demand
It’s common for victims and threat actors to disagree sharply over the scope of an attack or its significance. Today’s example involves Israeli fintech Nayax and a group called The Syndicate. In previous coverage, DataBreaches cited Nayax’s submission to the Securities and Exchange Commission. At the time, Nayax reported an incident involving an unnamed subsidiary,… […]

New bugs in Claude for Chrome allow extensions to abuse AI privileges
Two vulnerabilities found in Anthropic’s Claude for Chrome extension remain exploitable months after they were reported to the company, a research by Manifold Security noted. According to the researchers, the flaws can allow a malicious browser extension to trigger Claude into performing privileged actions, including reading Gmail messages, Google Docs content, and Calendar entries on […]
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors […]
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a coordinated vulnerability disclosure (CVD) program for working with external security researchers that includes a clear vulnerability disclosure policy (VDP) and process for triaging, remediating and assigning […]

SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctioned browser extensions, and autonomous agents. Employees routinely paste intellectual property into
AU: Partnered Health Data Breach Exposes Patient Records at Family Clinics
Trevor Long reports: A large health care chain that owns family medical clinics across Australia has been the victim of a cyber breach which has exposed the data of their patients, including potentially treatment information. Partnered Health runs a large number of clinics across Australia, with sixteen of them listed as directly affected, and a… […]

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments. “The PoC […]

New Webinar: Closing the Approval Gap in AI-Era Ad Tech
A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reveals how this Approval Gap forms, and gives your team the blueprint to close it before an auditor, regulator, or attacker finds it first. The […]
Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar
A ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions. The post Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar appeared first on SecurityWeek.
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal. The post 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer appeared first on SecurityWeek.
Adobe Patches Critical ColdFusion Vulnerabilities
The ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges. The post Adobe Patches Critical ColdFusion Vulnerabilities appeared first on SecurityWeek.
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims
The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. The post Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims appeared first on SecurityWeek.
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
Two flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed. The post Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek.
SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
SonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution. The post SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits appeared first on SecurityWeek.
Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed. The post Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates appeared first on SecurityWeek.
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell
The industrial giants fixed dozens of vulnerabilities across their ICS products, with advisories also released by CISA and VDE CERT. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell appeared first on SecurityWeek.
Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption
The company has rolled out a fix and is restoring access for Storage Zones Controller customers who apply it. The post Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption appeared first on SecurityWeek.
White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative
The new program stems from an AI-focused Executive Order signed by President Trump on June 2. The post White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative appeared first on SecurityWeek.

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tokens. Cursor keeps […]

When 80,000 fans log on at once: The 2026 World Cup’s unique cybersecurity issues
With the World Cup in full swing, stadiums across North America are currently accommodating thousands of fans every match day. That said, the stadiums’ biggest security challenge isn’t of a physical nature. It is not hyperbolic to say that football stadiums are some of the most chaotic endpoint environments in enterprise IT. On game days, […]

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below – @asyncapi/generator-helpers@1.1.1 @asyncapi/generator-components@0.7.1 @asyncapi/generator@3.3.1 @asyncapi/specs(v6.11.2, v6.11.2-alpha.1) “The

Cybersecurity needs more prevention and less reliance on cure
Ask any medical doctor, and they’ll tell you that prevention is better than cure. It’s more cost-effective and it has better outcomes. The same is true in cybersecurity. But we believe that our industry has veered too far away from this simple concept. We observe that most new tools are detection-focused, and we are calling […]

7 skills and traits of elite security engineers
Security engineers play a pivotal role in enterprise cybersecurity, because they are the professionals who design, build, and deploy security systems to protect an organization’s data, applications, systems, networks, and other IT components against a variety of cyber threats. Finding not just qualified security engineers, but the best and brightest available, needs to be a […]

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below – CVE-2026-15409 (CVSS score: 10.0) – A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to
Microsoft is forcing an enterprise transition to passkeys
Passkeys have been around for some time, but enterprise-wide adoption to this point has been slow for a number of reasons. But soon, many Microsoft customers won’t have a choice. Starting September 1, Microsoft will roll out passkeys as the default authentication method in its cloud-based identity and access management (IAM) service Entra ID. And […]
ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th)
Post Content
Recent DShield SIEM Update, (Tue, Jul 14th)
The last update to the DShield SIEM [4] was in Sep 2025 which contained some minor tweaks. This update currently is using ELK stack version 8.19.15, contains some additional dashboards and new logs.
WEALTHFRONT BROKERAGE LLC
WEALTHFRONT BROKERAGE LLC fnrw-backend Tue, 07/14/2026 – 19:10 MC ID WLTF MC Reporter Type OTC Market Maker MC Paragraph MC Link https://public.s3.com/rule605/wlth MC Last Updated Tue, 07/14/2026 – 19:10
WEALTHFRONT BROKERAGE LLC
WEALTHFRONT BROKERAGE LLC fnrw-backend Tue, 07/14/2026 – 19:03 MC ID WLTH MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.s3.com/rule605/wlth MC Last Updated Tue, 07/14/2026 – 19:03
Elon Musk promises to delete all data following a leak of users’ confidential information
Abror Shuhratov reports: xAI, the company founded by Elon Musk, has announced emergency measures following a serious controversy involving the unauthorized uploading of users’ private code and confidential information to a server via the Grok Build CLI tool. The company’s head stated that, for security reasons, all previously uploaded user data will be permanently deleted. This decision… […]
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims
Eduard Kovacs reports: A new ransomware group named D1R in recent days listed Synopsys and Bosch on its Tor-based leak website. The cybercriminals claimed to have exploited a vulnerability in Synopsys’ website to access a corporate client database containing 40,000 entries, and they are threatening to leak the stolen data unless a ransom is paid…. […]
Finland issues wanted notice for hacker behind massive psychotherapy data breach
I was really unpleasantly surprised when they let him out while on appeal, and now they may not be able to return him to prison? Did no one foresee that he might not stick around to be sent back to prison? Daryna Antoniuk reports: Finnish police have reportedly issued a wanted notice for convicted hacker Aleksanteri… […]
25-01736.pdf
25-01736.pdf Anonymous (not verified) Tue, 07/14/2026 – 17:10 Case ID 25-01736 Forum FINRA Document Type Award Claimants Wells Fargo Clearing Services, LLC Respondents Mathew Tong Neutrals Jonathan H. Krotinger Hearing Site San Francisco, CA Award Document 25-01736.pdf Documentum DocID abf49c7c Award Date Official Tue, 07/14/2026 – 12:00 Related Content Off Claimant Representatives William McC Montgomery […]
Rewards For Justice offers reward for info on Media Land, ML.Cloud, and three individuals associated with it
Rewards for Justice announced a $10M reward for information on the Russian-based bulletproof hosting (BPH) services company Media Land, its associated company ML.Cloud, and associated staff Aleksandr Alexandrovich Volosovik, Kirill Andreevich Zatolokin, and Yuliya Vladimirovna Pankova: Media Land offers BPH services such as hosting illicit and illegal content, registering private domains on behalf of customers,… […]

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft’s own CVEs by its Security Update Guide count, more than triple June’s previous high of around 200. Those two live bugs are the ones to grab first. Microsoft credits incident responders […]

Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. Nearly 60 of […]
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
This patch Tuesday includes a staggering 622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft’s Edge browser. 62 of the vulnerabilities are rated critical. One was disclosed before today, and two have already been exploited.
2025085271501 Michael S. Schoolcraft CRD 6375300 AWC vrp.pdf
2025085271501 Michael S. Schoolcraft CRD 6375300 AWC vrp.pdf Anonymous (not verified) Tue, 07/14/2026 – 15:05 Document Number 257d757b Related Content Off Attachment 2025085271501 Michael S. Schoolcraft CRD 6375300 AWC vrp.pdf
The essence of data management CIOs must embrace
Since the advent of generative AI, the use of AI in business has shifted from something we should do to something we must do to survive. Many companies are now working to utilize AI with the aim of improving productivity and creating value. Here, I would like to pose a question to you all once […]
Deluxe Corporation beats the odds with mainframe migration using AI
Deluxe may have prevailed against the odds when it successfully migrated from a 50-plus-year-old mainframe recently. The company was able to move from it to a cloud environment in about 12 months without a major hitch, and while AI did some of the heavy lifting. The save will amount to about $4.9 million a year […]
Where Meta’s WhatsApp agent can actually win
Message a business on WhatsApp this week and you may be greeted by software. On June 3, Meta made its Business AI agent available to companies everywhere, a bot that answers questions, recommends products, books appointments, qualifies sales leads and hands you to a human when it gets stuck. It comes bundled in WhatsApp’s premium […]
How AI agents are shaping the future of work
I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing functionality. At the end of 2025, Anthropic and OpenAI […]
How do you go from junior to staff engineer when AI writes the code?
A few weeks ago, a new hire at Aviator, fresh out of college, asked me a question I didn’t have a clean answer to. How do I become a senior engineer, or even a staff engineer? What should I learn, and how? It’s a fair question and a harder one to answer than it was […]
Your service vendors are being rebuilt around AI
Venture-backed firms are buying up the support, finance-ops and managed-services providers enterprises rely on and re-platforming them around AI agents — and the renewal that follows arrives priced per outcome, sold as your advantage. The acquisition-built structure and unproven stability create governance and continuity risks your vendor process isn’t sized for. Here’s how to keep […]
Defending SaaS-based applications against ShinyHunters OAuth abuse
From Microsoft Security Research and Microsoft Defender Security Research Team: In a series of campaigns observed between mid-2025 and mid-2026, Microsoft identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply chain compromise, and misconfigured guest access to target customer SaaS-based applications such as Salesforce instances. The threat actors… […]

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows an authenticated attacker to leverage logical errors in memory management to cause a […]
25-02324.pdf
25-02324.pdf Anonymous (not verified) Tue, 07/14/2026 – 13:30 Case ID 25-02324 Forum FINRA Document Type Award Claimants Raymond Sardina Respondents Raymond James & Associates, Inc. Neutrals Vincent C. Pangia Paul Bennett Marrow Eric Ross Cromartie Hearing Site Boca Raton, FL Award Document 25-02324.pdf Documentum DocID 9a12c8eb Award Date Official Tue, 07/14/2026 – 12:00 Related Content […]

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar. Both this and ClaudeBleed need a rogue extension that can already run a script on claude.ai; the difference is scope. Anthropic restricted the […]
Doxbin admin jailed for egging on swatters from behind a screen
Connor Jones reports: A Welshman was sentenced to prison on Tuesday for his role in numerous swattings in the UK, US, and Canada. Callum Dare, 26, was an administrator of Doxbin, a dark web platform frequented by individuals that expose the personally identifiable information (PII) of people, usually to encourage harassment or to target them through… […]

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. “LabubaRAT creates a reusable foothold for hands-on activity,” Blackpoint Cyber researchers Sam Decker and Nevan Beal said in an analysis published today. “Once deployed, it can profile the host,

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. Miggo’s security team, which discovered and reported the flaws, said one “leaks the broker’s confidential OAuth
EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint
EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint ipetstef Tue, 07/14/2026 – 15:39

11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard. “An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware,”
Rockwell Automation 1715-AENTR EtherNet/IP Adapter
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device. The following versions of Rockwell Automation 1715-AENTR EtherNet/IP Adapter are affected: 1715-AENTR EtherNet/IP Adapter <=3.003 (CVE-2026-10577) CVSS Vendor Equipment Vulnerabilities […]
CISA Urges SharePoint Hardening After New Exploitations
CISA is aware of active exploitation of vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services […]
ABB T-MAC Plus
View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways. The following versions of ABB T-MAC Plus are affected: T-MAC Plus […]
ABB Advant Master Online Builder
View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions. The following versions of ABB Advant Master Online Builder are […]
ABB Ability Edgenius
View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to […]
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability CVE-2026-56164 Microsoft SharePoint Server Missing Authentication for Critical Function […]

Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way these wallets talk to websites and blockchain servers can tie a person’s separate addresses together and let outsiders follow them […]
RabbitMQ Vulnerability Threatens Enterprise Systems
Unauthenticated attackers could obtain the broker’s confidential OAuth client secret, allowing them to take control of the broker. The post RabbitMQ Vulnerability Threatens Enterprise Systems appeared first on SecurityWeek.
Cybersecurity M&A Roundup: 37 Deals Announced in June 2026
Significant cybersecurity M&A deals announced by 1Password, Accenture, Cisco, F5, Rubrik, and SailPoint. The post Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 appeared first on SecurityWeek.
Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption
Once a notorious blackhat hacker, McGraw shares his journey from high school hacking and prison to redemption as a cybersecurity advocate. The post Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption appeared first on SecurityWeek.
Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules
A new CMMC review and reform task force will conduct a comprehensive review of the program. The post Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules appeared first on SecurityWeek.
Multiple Jscrambler Packages Impacted by Supply Chain Attack
A threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer. The post Multiple Jscrambler Packages Impacted by Supply Chain Attack appeared first on SecurityWeek.
Valarian Raises $50 Million for Sovereign Infrastructure Control Layer
UK-based cybersecurity firm Valarian has raised a total of $70 million for its ACRA technology. The post Valarian Raises $50 Million for Sovereign Infrastructure Control Layer appeared first on SecurityWeek.
US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers
Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks. The post US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers appeared first on SecurityWeek.

Phishing for dummies: Forg365 lowers barrier to M365 account takeovers
A newly documented phishing-as-a-service platform distributed through Telegram is lowering the technical barrier to Microsoft 365 account takeovers by giving less-skilled attackers automated tools to evade some authentication controls and retain access after compromise. The platform, called Forg365, uses AI-assisted lure creation alongside device-code abuse and adversary-in-the-middle techniques, according to research published by security company […]

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read
xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out of the intercepted request, and […]

AI incidents need a new playbook. Here’s how to build one
Seventy-one percent of organizations say AI has access to core business systems. Only 16% govern that access effectively, according to the 2026 CISO AI Risk Report. Ask your IR team three questions: Where is your AI system inventory? What happens if a production model starts generating harmful outputs? Who has the authority to take it […]

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors’ and other cybercriminals’ malicious activities, including ransomware attacks against Americans. The VPN, named First VPN Service (1VPNS), has been accused of offering its tools to ransomware groups, along with its 45-year-old Ukrainian

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
A campaign of 148 npm packages disguised as student web proxies turned visitors’ browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog. The packages did not go after the developers who might install them. The operators used the registry as free hosting for a booby-trapped proxy site […]

AI-powered breaches provide wake-up call for incident response
Enterprises have worked for years to improve detection and response times in the face of increasingly sophisticated attacks that relied on manual hacking and living-of-the-land techniques. AI is now threatening to undo those efforts. An increasing number of threat actors are automating all phases of attacks, including lateral movement by using LLM-powered agents, severely reducing […]

Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it. In
ISC Stormcast For Tuesday, July 14th, 2026 https://isc.sans.edu/podcastdetail/10006, (Tue, Jul 14th)
Post Content

US authorities warn of Russian attacks on critical infrastructure
The US authorities NSA, FBI, and CISA warn that Russian hackers have recently carried out a number of attacks on critical infrastructure in North America and Europe. Hackers are reportedly breaking into networks using vulnerable and misconfigured routers, making it extra important to install the latest security patches. The most vulnerable are infrastructure related to energy, communications, […]
VPN service favored by ransomware groups is sanctioned by US
Suzanne Smalley reports: The U.S. government on Monday sanctioned a VPN provider and its Ukrainian administrator for abetting ransomware gangs behind attacks on American municipalities, hospitals, schools and businesses. First VPN Service (1VPNS) provided ransomware groups with tools to “hide their identities, disguise malicious software, and evade detection — enabling attacks that have caused billions… […]
WEBULL FINANCIAL LLC
WEBULL FINANCIAL LLC fnrw-backend Mon, 07/13/2026 – 16:20 MC ID WBUS MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.s3.com/rule605/webl/ MC Last Updated Mon, 07/13/2026 – 16:20
GREEN PIER FINTECH LLC
GREEN PIER FINTECH LLC fnrw-backend Mon, 07/13/2026 – 16:00 MC ID GNPR MC Reporter Type OTC Market Maker MC Paragraph MC Link https://s3.com/ MC Last Updated Mon, 07/13/2026 – 15:59
AI voice agents and the human touch: A new playbook for SME customer engagement
Customer expectations don’t end when business hours do, which is why delivering a fast, always-on customer experience (CX) has traditionally required large call centres and significant resources. This often placed small businesses at a disadvantage, as many lacked the manpower and budget to provide 24/7 support at scale. Today, AI has completely levelled the playing […]
Infrastructure for the agentic era: A new conversation layer for the Twilio Platform
A new era of customer engagement is taking shape. AI agents are quickly becoming integral to the way businesses serve, support, and sell to customers — able to respond, reason, and take action in ways that go far beyond scripted automation. Many customer journeys, however, are still built on systems that don’t talk to each […]
Voice AI vs conversational AI: What’s the difference?
Voice AI. Conversational AI. You’ve seen both terms everywhere—sometimes in the same sentence, sometimes used as if they mean the same thing. They don’t. But they’re not opposites either. One is a category of technology. The other is a specific way to deliver it. Mix them up and you end up making the wrong platform […]
Why the future of customer service is resolution, not fast replies
Most AI agents today are optimised for responsiveness—faster first responses, shorter wait times, higher service rates. And on those metrics, they’re delivering. It’s no surprise then that 90% of business leaders believe their customers are satisfied with conversational AI experiences. Yet only 59% of consumers agree, according to Twilio’s latest report on conversational AI. What […]
Your AI agent shouldn’t know everything – it should know who to ask
Intro Consumers across APJ are getting more impatient. They expect brands to resolve their issues in just 24 minutes on average. If the brand is unsuccessful, 34% say they’ll switch channels to find a faster path to resolution, and 30% say they’ll abandon the effort altogether. Most leaders reading this insight would respond by improving […]
IT hiring sees a boost as software development jobs slowly bounce back
Tech job postings rose for the sixth straight month in June, as employers are increasingly on the hunt for qualified talent to support major technological initiatives, according to the most recent CompTIA Tech Jobs Report. “June’s employment data suggests that employers are ramping up their technology investments and hiring the talent needed to support them,” […]
Why AI needs contextual intelligence — not just bigger models
A product manager on my team recently asked me where we were seeing the most issues across the engineering team. Instead of guessing, I had an engineering lead point Claude at our Jira via an MCP connector and look at the bug patterns himself. One team had a wildly disproportionate share of tickets — about […]
What’s next for CIOs? Omnicom’s Leif Maiorini has insights
Like many CIOs, Omnicom’s Leif Maiorini has become all too familiar over the past few years with the challenges of ever-shrinking IT roadmaps.“CIOs used to follow a five-year planning cycle, but five years is an eternity,” says the advertising and public relations titan’s CIO for corporate services. Agentic AI, arguably one of the most transformative […]
AI is freeing up capital. Most companies have no plan for what comes next
AI tools today enable faster processes, leaner operations and lower costs, making efficiency wins the new baseline. However, for many businesses, the strategy stops at those first wins. This has created a growing leadership blind spot: Once you achieve AI ROI, how do you make the most of it? If there is no clear reinvestment […]
CIOs must rethink operating models to unlock AI at scale
Almost every company has a board or executive AI mandate. Vendors are rolling out agentic AI platforms. The pressure to move is intense. But the reality on the ground looks different. Eighty-three percent of organizations say data quality is their top AI challenge, and 74% struggle to demonstrate ROI, according to Lopez Research. And only […]
NG: Zenith Bank, Others To Be Arraigned Over Alleged Data Breach
Fatima Abdullahi reports: The Federal High Court in Abuja has fixed July 21, 2026, for the arraignment of Zenith Bank Plc and three other defendants over allegations of illegally accessing and disclosing the confidential financial records of Makers Island Company Limited. The other defendants are Oluwaseyi Famousa, Paul Oku and Yesu-Felix Abosede Alice. Justice Hauwa… […]

CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that’s capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is implemented in native C++, according to Jamf Threat Labs. “It validates the victim’s login password locally before

Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version. The collector was dormant. An empty allow-list kept it switched off, and no proof has emerged that it ever gathered or sent a […]
26-00179.pdf
26-00179.pdf Anonymous (not verified) Mon, 07/13/2026 – 11:30 Case ID 26-00179 Forum FINRA Document Type Award Claimants Thomas Moran Respondents Wells Fargo Advisors Financial Network Neutrals Madelon M. Rosenfeld William J. Bender Susan L. Walker Hearing Site Boca Raton, FL Award Document 26-00179.pdf Documentum DocID be6f6187 Award Date Official Mon, 07/13/2026 – 12:00 Related Content […]
25-01036.pdf
25-01036.pdf Anonymous (not verified) Mon, 07/13/2026 – 11:30 Case ID 25-01036 Forum FINRA Document Type Award Claimants Michael Blanchard Estate of Mary Blanchard Mary F. Blanchard Trust Michael J. Blanchard Trust Respondents Stifel, Nicolaus & Co., Inc. Heidi Chamberlain William Hadden Neutrals Louis H Miron Julius Z. Frager Jacqueline Marie Pierre Hearing Site Montpelier, VT […]

⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That’s supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don’t file tickets. That’s the shape of this week. Trusted code turns on the people […]

Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial […]
MORGAN STANLEY
MORGAN STANLEY fnrw-backend Mon, 07/13/2026 – 10:41 MC ID MSSB MC Reporter Type Broker-Dealer MC Paragraph MC Link http://public.s3.com/rule605/mswm MC Last Updated Mon, 07/13/2026 – 10:41

New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false “fact” about the user, hide the change, and quietly steer its answers in later sessions. When it […]

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts. Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing

RabbitMQ flaws expose OAuth secrets, risk complete takeover of the broker
RabbitMQ has patched two access control vulnerabilities affecting the widely used open-source message broker that could expose enterprise application data and, in some deployments, allow attackers to gain complete control over the messaging infrastructure. The flaws, discovered by Miggo Security, exposed OAuth secrets to unauthenticated attackers, letting low-privileged users potentially spy on other tenants. “RabbitMQ […]

Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, […]
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates […]

Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling
Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read. Each read gets pinned to the moment it happened: the time, your location, what you were doing, […]
EU and UK hit Russia with joint sanctions over cyberattacks
BGNES News reports: The European Union and the United Kingdom have imposed coordinated sanctions against Russia in connection with cyberattacks in Europe. Brussels and London have accused the Federal Security Service of the Russian Federation (FSB) of recent malicious activities. This move comes amid warnings from Western officials that Russia has intensified its “hybrid” campaign… […]
A cyberattack in March resulted in ZEGO filing for insolvency
A statement on ZEGO Textilveredelungszentrum GmbH’s website explains why they are filing for insolvency: Insolvency proceedings have been initiated – and why we are still looking ahead Ladies and gentlemen, dear business partners, Today we are contacting you with a message that is very difficult for us personally. ZEGO Textilveredelungszentrum GmbH has filed for insolvency…. […]
Progress urges ShareFile admins to shut down servers over “credible” threat
Lawrence Abrams reports: Progress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a “credible external security threat” targeting the on-premises secure file-sharing software. ShareFile is Progress Software’s enterprise secure file sharing and collaboration platform that allows customers to host their files… […]
Centers Laboratory Data Breach Affects 540,000 Individuals
The WorldLeaks extortion group claimed to have stolen 720 GB of data from the healthcare testing and laboratory services provider. The post Centers Laboratory Data Breach Affects 540,000 Individuals appeared first on SecurityWeek.
Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns
The company notified customers to manually shut down their servers while it is investigating a credible threat. The post Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns appeared first on SecurityWeek.
Organizations Warned of Exploited Joomla Extension Vulnerabilities
Threat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution. The post Organizations Warned of Exploited Joomla Extension Vulnerabilities appeared first on SecurityWeek.
EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign
The move targeted people and entities accused of links to an online spying network that the EU claims targeted governments and carried out sabotage operations against critical infrastructure. The post EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign appeared first on SecurityWeek.
Zimbra Patches Critical Code Execution Vulnerability
The flaw results in malicious code embedded in crafted emails being executed when the emails are opened. The post Zimbra Patches Critical Code Execution Vulnerability appeared first on SecurityWeek.
Jurassic Park, cybersecurity and the dangerous myth of control
Jurassic Park wasn’t really about dinosaurs. It was about arrogant people building systems they believed were controllable. “Life finds a way” is probably the most famous line from the entire franchise. Ian Malcolm’s warning that no matter how sophisticated the technology becomes, no matter how expensive the fences are, and no matter how confident the […]

Your AI risk register is not an incident response plan
Picture the moment after an AI issue is reported. A security analyst is reviewing a ticket reporting that an internal AI tool produced the wrong recommendation in a live business workflow. The risk is not theoretical anymore. Someone wants to know whether this is a security incident, a model issue, a privacy issue, a vendor […]

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history. From that one lapse, French security firm Lexfo lifted the operator’s entire toolkit and pivoted through it to two […]

Can AI narrow cybersecurity’s class divide?
At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes. In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would then begin building detections or fixes, Steve Schmidt, chief security officer at Amazon, tells […]

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below – CVE-2026-48939 – A vulnerability in the
Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th)
The setup
ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th)
Post Content
KR: Military targeted in nearly 19,000 cyberattack attempts in 2025: lawmaker
Chae Yun-hwan reports: Cyberattack attempts against the South Korean military reached nearly 19,000 last year, marking the highest figure in five years, a lawmaker said Sunday. The military was targeted in 18,951 cyberattack attempts in 2025, compared with 11,700 in 2021, 9,115 in 2022, 13,599 in 2023 and 14,419 in 2024, according to Rep. Yu… […]
Ghost Accounts Abuse GitHub API in Mass Recon Campaign
Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members. The post Ghost Accounts Abuse GitHub API in Mass Recon Campaign appeared first on SecurityWeek.
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook that drops and executes a native binary, one build each for Windows, macOS, and Linux. Socket flagged the release six minutes after it was published. If you or one of […]
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026. “At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and
Armenian National Extradited to the United States Pleads Guilty to Ransomware Extortion Conspiracy
PORTLAND, Ore.— An Armenian national extradited from Ukraine to the United States pleaded guilty yesterday for his role in Ryuk ransomware attacks and an extortion conspiracy targeting companies throughout the United States, including a technology company operating in Oregon. Karen Serobovich Vardanyan, 34, pleaded guilty to conspiracy and computer fraud. According to court documents, between… […]
Ransomware negotiator who conspired with BlackCat threat actors sentenced to 70 months in prison
Jon Brodkin reports that a third co-conspirator who helped BlackCat attackers by giving them inside information on victims’ defense strategies has now been sentenced. A former ransomware negotiator was sentenced to 70 months in prison yesterday after colluding with BlackCat scammers to extort the victims he was hired to protect. As a ransomware negotiator for the company DigitalMint,… […]
TikTok class action alleges data breach affected 2.4B users
Brandon Richards reports: California resident Sean Mortazi filed a class action lawsuit against TikTok Inc. on June 11, 2026, alleging a data breach exposed the personal data of more than 2.4 billion users worldwide. The complaint, filed in the U.S. District Court for the Central District of California, claims TikTok stored unencrypted data and skipped basic… […]
Dutch police trace Odido telco cyberattack to suspected local accomplice; May leak voice recording
Daryna Antoniuk reports: Dutch police said Thursday they had uncovered evidence suggesting that Dutch criminals were involved in the cyberattack on telecom provider Odido that exposed the personal data of more than 6 million customers earlier this year. Authorities said a Dutch-speaking man posing as an Odido IT employee called the company’s customer service department before the… […]
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
The attackers call victims to direct them to phishing websites mirroring Microsoft Entra ID login pages. The post Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers appeared first on SecurityWeek.
China, India-Linked Hackers Both Targeted Same Pakistani Police Force
Both foes and allies have targeted the Balochistan Police force in Pakistan for at least two years, according to SentinelOne. The post China, India-Linked Hackers Both Targeted Same Pakistani Police Force appeared first on SecurityWeek.
Third US Security Expert Sentenced to Prison for Helping Ransomware Gang
Angelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group. The post Third US Security Expert Sentenced to Prison for Helping Ransomware Gang appeared first on SecurityWeek.
In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops
Other noteworthy stories that might have slipped under the radar: Abnormal AI sued by Anthropic, AssuranceAmerica data breach affects 7 million people, NSA brings back TAO. The post In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops appeared first on SecurityWeek.
Wireshark 4.6.7 Released, (Sat, Jul 11th)
Wireshark release 4.6.7 fixes 12 vulnerabilities and 16 bugs.
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to execute malicious scripts in a user’s session. It has yet […]
TRF Technical Specification Updates for Extended Operating Hours
Technical Notice TRF Technical Specification Updates for Extended Operating Hours July 10, 2026 K33357 Fri, 07/10/2026 – 17:17 FINRA is publishing updated Technical Specifications for FINRA’s Trade Reporting Facilities1 (TRFs) in support of the upcoming extension of the TRF operating hours to 23 hours per day, five days per week. As previously announced in a Technical […]
Gobierno de TI: el factor decisivo para que la IA no desborde a las organizaciones
La carrera por incorporar inteligencia artificial (IA) a los procesos empresariales está avanzando a una velocidad que muchas organizaciones tienen dificultades para controlar. La presión por innovar, automatizar y obtener ventajas competitivas está obligando a las compañías a replantearse una disciplina que durante años ha permanecido en un segundo plano: el gobierno de TI. La […]
Operate like a Formula 1 team: The new AI operating model
It is lap 47 of 57. Before the race began, the team had already processed gigabytes of race data, simulations, tire models, weather forecasts, competitor tendencies and scenario plans. But on the pit wall, there is tension. The race leader’s tires are degrading faster than predicted. A rival has just pitted for fresh tires and […]
AI’s potential to infect the hiring process with bias
You’ll be hard pressed to find an area of corporate America where AI hasn’t found a place, and that includes the tech hiring process. A survey from MyPerfectResume found that 73% of employers say they use AI in hiring decisions, while 52% use it for decisions around restructuring and role planning. On the other side, […]
Your next insider threat doesn’t have a badge. It has an API token
The threat that I now spend most of my time designing against doesn’t look like a breach at all. At least not at first. Imagine a team deploys an agent that does exactly what it’s permitted to do: it reads a customer record, summarizes it, then sends the summary to an outside address. Every step […]
How a Formula 1 IT director balances innovation and stability at 200 mph
Michael Taylor has spent 25 seasons with the Mercedes-AMG Petronas F1 team, working every IT role from trackside support to engineering systems to business transformation. Today, as IT director, he leads an 18-person team responsible for one of the most data-intensive operations in the world. When a car rolls out of the garage, it carries […]
Accelerating financial closes with help from AI agents: A pragmatic guide
Historically, financial closes required were tedious, manual-intensive processes, which makes them excellent candidates for agentification. AI agents can handle much of the “dirty work” associated with integrating financial data from various sources, reconciling transactions and so on. That said, there are limits on how far AI agents can go in streamlining and accelerating the closing […]
SAP concedes to EU, freeing CIOs from expensive support shackles
The European Commission is ending an antitrust investigation into SAP after the company made numerous concessions worldwide regarding maintenance and support services for on-premises versions of its ERP solution. The Commission began its investigation in September 2025, concerned that SAP forces customers to buy its services for longer, and for more licenses, than they need. […]
IBM grows mainframe family with rack, frame models targeting AI, hybrid clouds
IBM is looking to expand the reach of its foundational mainframe portfolio by adding new single frame and rack mounted versions of its Z and LinuxONE systems. The IBM z17 portfolio adds a single frame and rack mount versions that bring mainframe capabilities into smaller, customizable footprints. The LinuxONE Rockhopper family gets a single frame and […]
Deadline for Comments on Regulatory Notice 26-14
Deadline for Comments on Regulatory Notice 26-14 DixonR Fri, 07/10/2026 – 14:26 FINRA Requests Comment on Proposed Changes to Modernize Rule 2210 (Communications with the Public) Event Category Request For Comments Add to Calendar Yes All Day 1 Event Date Fri, 09/11/2026 – 02:00 – Fri, 09/11/2026 – 12:00 America/New York
SOFI SECURITIES LLC
SOFI SECURITIES LLC fnrw-backend Fri, 07/10/2026 – 12:42 MC ID SOFI MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.s3.com/rule605/sofi MC Last Updated Fri, 07/10/2026 – 12:42
URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a “credible external security threat.” The company has temporarily disabled access to the affected accounts, a step it says it took “out of an abundance of caution” while […]
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown threat actors compromised the Injective Labs SDK project’s GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs can crash a device. The other two could let an attacker who slips a malicious image in front of […]
Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched
Researchers at Ledger’s Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card’s password to anything the attacker picks. No old password. No backup card. Once it is reset, whoever did it controls the wallet and can move the coins out. This is […]

EU extends mass scanning of messages without a warrant
Members of the European Parliament (MEPs) have failed to block a proposal extending the mass scanning of private communications, a measure they have previously rejected twice. This time too, more votes were cast against the proposal than in favor, but due to the absence of numerous MEPs on the eve of the summer recess, the […]
CrowdStrike identifies five new prompt injection threats to AI
Security company CrowdStrike has identified five new prompt injection techniques that could leave enterprises at risk. Prompt injections attacks exploit the growing use of AI within organizations . They work by tricking LLMs into accepting instructions that a human operator would recognize as dubious. The five new types of attack that CrowdStrike has added to […]
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vulnerabilities is as follows – GHSA-hjr6-g723-hmfm (CVSS score: 8.8) – An operating system
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that propagates malware via counterfeit installers using SEO poisoning techniques, it belies their true organizational
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-48939 iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose […]
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
A single wrong variable on one line in XQUIC, Alibaba’s QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: […]
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report, only 45% of organizations consolidate their asset and exposure data into a single view, and every downstream security program inherits whatever the inventory gets wrong. […]
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation’s inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the exposed files showed researchers how a mass site-hacking […]
15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google
Affecting every major distribution since 2011, the Linux kernel vulnerability allows attackers to gain root access. The post 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google appeared first on SecurityWeek.
12 Million Impacted by Data Breach at Japanese Telco KDDI
Hackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs. The post 12 Million Impacted by Data Breach at Japanese Telco KDDI appeared first on SecurityWeek.
Palo Alto Networks Patches 13 Vulnerabilities
Buffer overflow, DoS, command injection, SSRF, authentication bypass, and other types of vulnerabilities have been found in PAN-OS software. The post Palo Alto Networks Patches 13 Vulnerabilities appeared first on SecurityWeek.
UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge
Two announcements on July 7, 2026, demonstrate the government’s determination to improve the level of cybersecurity within the UK. The post UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge appeared first on SecurityWeek.
QIZ Security Raises $17 Million for Cryptographic Governance Platform
The Israeli company has developed a cryptographic posture and post-quantum cryptography management platform. The post QIZ Security Raises $17 Million for Cryptographic Governance Platform appeared first on SecurityWeek.
Network of 200 GitHub Repositories Used for Malware Infection
A Go module is used to load PowerShell code that fetches a resolver from public dead drops to execute Windows malware. The post Network of 200 GitHub Repositories Used for Malware Infection appeared first on SecurityWeek.
‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism
Researchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution. The post ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism appeared first on SecurityWeek.
GigaWiper Combines Multiple Malware for System-Level Sabotage
The backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command. The post GigaWiper Combines Multiple Malware for System-Level Sabotage appeared first on SecurityWeek.
"Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th)
Anyone who deals with phishing messages caught by basic security filters knows that most phishing samples tend to blend into one another, since only a small set of techniques and approaches keeps reappearing in them. That is precisely why it is worth pausing on the occasional message that does something a little out of the […]
Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets
Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness, an attacker can work it out and take everything it controls. Coinspect has […]
The business case for burning down security debt: A practical approach for CISOs
Security leaders have made strong progress in visibility. Most organizations can now identify vulnerabilities across their applications, dependencies and development pipelines with far more consistency than in the past. Yet a fundamental imbalance remains: Vulnerabilities are being discovered faster than they can be remediated. That imbalance is growing. Today, 82% of organizations carry security debt, […]
Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand
Microsoft is warning defenders about a new backdoor that blurs the line between espionage malware and wipers. In a technical analysis published on Thursday, Microsoft Threat Intelligence detailed GigaWiper, a Golang-based implant first observed in October 2025 intrusions that combines remote administration capabilities with multiple disk-wiping and ransomware routines. Rather than building a new destructive […]
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple victims and working with two other cybersecurity professionals to target additional victims in 2023. In a sentencing memorandum, federal prosecutors described […]
Check Point CTO Jonathan Zanger sees AI elevating the value of cyber
Check Point Software CTO Jonathan Zanger met with CSO Spain during the software company’s Engage 2026 user conference last week in Paris. At the event, Check Point executives and representatives discussed how the company is dealing with various types of threats, how it is adopting AI securely, and how Check Point and others can leverage AI […]
ISC Stormcast For Friday, July 10th, 2026 https://isc.sans.edu/podcastdetail/10002, (Fri, Jul 10th)
Post Content
AI coding tool hole illustrates a big problem with human in the loop
A security hole within AI dev tools has allowed attackers to escape sandboxes by misleading the humans in the loop who were supposed to knowingly approve the tool’s actions, according to cybersecurity research firm Wiz. “We discovered GhostApproval, a systematic vulnerability pattern affecting six of the top AI coding assistants: Amazon Q Developer, Anthropic Claude […]
SR-FINRA-2026-016
SR-FINRA-2026-016 MwinamoC Thu, 07/09/2026 – 18:13 Financial Industry Regulatory Authority, Inc. (“FINRA”) is filing with the Securities and Exchange Commission (“SEC” or “Commission”) a proposed rule change to amend FINRA Rule 4515.01 (Allocations of Orders Made by Investment Advisers) to expand the current exception from the rule’s principal approval requirements to apply to all allocations […]
25-01021.pdf
25-01021.pdf Anonymous (not verified) Thu, 07/09/2026 – 17:00 Case ID 25-01021 Forum FINRA Document Type Award Claimants Lawrence McSorley Respondents Dillon Manley Fidelity Brokerage Services LLC Raymond Wong Neutrals Renee Bryna Gerstman Audrey C. Marks Elizabeth Wylie Hearing Site Denver, CO Award Document 25-01021.pdf Documentum DocID b4d340ae Award Date Official Wed, 07/08/2026 – 12:00 Related […]
25-01369.pdf
25-01369.pdf Anonymous (not verified) Thu, 07/09/2026 – 16:55 Case ID 25-01369 Forum FINRA Document Type Award Claimants Donna Kawasaki Respondents RBC Capital Markets LLC Neutrals Maryanne M. Esser Demetria Charissee Howard Staci Lynette Glenn Hearing Site Dallas, TX Award Document 25-01369.pdf Documentum DocID 6a52c6cb Award Date Official Wed, 07/08/2026 – 12:00 Related Content Off Claimant […]
25-00888.pdf
25-00888.pdf Anonymous (not verified) Thu, 07/09/2026 – 16:55 Case ID 25-00888 Forum FINRA Document Type Award Claimants Brooke Pilant Respondents George Varones Ameriprise Financial Services, LLC Jennifer Schuster William Maclin Neutrals Robert H. Putnam Hayden D. Lait Karl A. Vogeler Hearing Site Memphis, TN Award Document 25-00888.pdf Documentum DocID b4ad04a8 Award Date Official Wed, 07/08/2026 […]
24-01755(2).pdf
24-01755(2).pdf Anonymous (not verified) Thu, 07/09/2026 – 16:50 Case ID 24-01755 Forum FINRA Document Type Motion to Confirm Claimants Betty Parsonage Respondents Randy Fox Neutrals Thomas R. Watkins David F. Sargent David Kennedy Duncan Hearing Site Phoenix, AZ Award Document 24-01755(2).pdf Documentum DocID afdc6f10 Award Date Official Fri, 02/20/2026 – 12:00 Related Content On Claimant […]
¿Formar o contratar? Los CIO más avispados saben la respuesta sobre el talento en la era de la IA
El factor clave para el éxito de la implantación de la IA está pasando a ser, en gran medida, el talento disponible, y no las herramientas de IA instaladas, lo que ejerce presión sobre los responsables de TI para que mejoren las competencias de su plantilla. Dado que las competencias en IA son las más […]
Why the US is at risk of losing the AI talent and productivity war
The hardest thing to manage is change. I wrote that line more than a decade ago in an article about the “XPocalypse,” Microsoft’s end-of-life deadline for Windows XP. My argument then was that the real crisis was not obsolete software. It was the shortage of technically literate professionals capable of guiding organizations through inevitable transitions. […]
AI won’t transform your business if you’re still running it the same way
Many organizations have seen real gains in productivity and automation from experimenting with AI. But only 34% are using AI to deeply transform their businesses, according to Deloitte’s 2026 State of Generative AI in the Enterprise report. Meanwhile, 37% are using the technology at a surface level with little or no change to underlying business […]
10 courses for IT leaders navigating AI change management
Innovations in AI are increasingly impacting daily business operations everywhere. As a result, IT leaders are scrambling to head organizational change around AI adoption. It’s a daunting task to get an entire organization on board with widescale change, but being equipped with the right AI change management knowledge can help smooth the transition. Demand […]
IT isn’t holding AI back, your business processes are
Most CIOs and other IT leaders are confident in their teams’ ability to meet the coming AI challenges, but many believe business operating models and processes need an overhaul. More than 80% of senior IT executives surveyed for the 2026 Global Leadership Technology Study from Deloitte are confident in their organizations’ ability to deploy and govern AI […]
AI’s real bottleneck isn’t compute. It’s distance.
A researcher has an idea worth testing before lunch. The model is ready. The data is sitting right there. But the data is sensitive — regulated, proprietary; the kind that legal has been very clear cannot leave the building. So it can’t go to the cloud cluster. And even if it could, the GPU queue is hours deep, the meter is running, and […]
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
Datadog Security Labs is warning of “several overlapping campaigns” that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. “Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub ‘ghost’ accounts that are often years old, or compromised OAuth tokens and personal
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from. Each is a different way to break a machine: wipe the whole disk, overwrite the Windows drive, […]
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The Microsoft-owned subsidiary noted that the following npm install behaviors that used to run automatically before have been made opt-in – allowScripts defaults to off, meaning
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it […]
Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk
A cloud intrusion that ended with the deployment of cryptomining malware has exposed a bigger risk for enterprises: AI gateways that concentrate access to cloud identities, permissions, and foundation models in a single, highly privileged system. Researchers from cybersecurity firm Darktrace found attackers compromising an AWS EC2 instance acting as a LiteLLM proxy for Amazon […]
UK cyber agency unveils AI-powered Cyber Shield to counter attacks at machine speed
The UK’s National Cyber Security Centre (NCSC) wants to deploy autonomous AI agents capable of finding and neutralizing cyberattacks on national networks in real time, marking Britain’s push toward a sovereign, machine-speed cyber defense system. The blueprint, called Cyber Shield, was developed jointly with the Department for Science, Innovation and Technology (DSIT). “The objective of […]
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
AI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the next host before your team clears the first alert. That is the gap, and it is not your fault. The tools […]
Schneider Electric Easergy MiCOM Px40 Series
View CSAF Summary Schneider Electric is aware of a vulnerability in its Easergy MiCOM Px40 Series products. The [Easergy MiCOM Px40](https://www.se.com/ww/en/product-subcategory/4725-easergy-micom-px40-series/?filter=business-6-medium-voltage-distribution-and-grid-automation) is a protection relay series for Medium Voltage, High Voltage and Extra High Voltage protection. Failure to apply the mitigations provided below may risk unauthorized exposure of basic device identification through the SNMP protocol. […]
OpenPLC v3
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem and escalate this into arbitrary native code execution through the normal OpenPLC program compilation process, potentially resulting in code execution as the OpenPLC runtime user. The following versions of OpenPLC v3 are affected: OpenPLC v3 […]
Schneider Electric PowerChute Serial Shutdown
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to overwrite critical files, forge or inject malicious log data, gain unauthorized account access, trigger denial‑of‑service conditions, truncate or alter logging information, reset user credentials, or expose sensitive information. The following versions of Schneider Electric PowerChute Serial Shutdown are affected: PowerChute Serial Shutdown <=1.4 […]
Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations
The “Rogue Agent” vulnerability could have enabled attackers to silently manipulate AI conversations, exfiltrate data, and compromise every Dialogflow CX agent within the same Google Cloud project. The post Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations appeared first on SecurityWeek.
Webinar Today: Why Email Security Keeps Failing
Join the webinar as we break down why email-layer defenses alone can’t keep pace with the modern phishing ecosystem. The post Webinar Today: Why Email Security Keeps Failing appeared first on SecurityWeek.
China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
Cisco says the threat actor behind the LapDogs campaign has expanded its SOHO router malware toolkit with LongLeash, DogLeash, and JarLeash backdoors. The post China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors appeared first on SecurityWeek.
Accenture Confirms Data Breach After Hacker Claims Source Code Theft
The professional services giant says it contained the incident, remediated its source, and experienced no operational or service delivery impact. The post Accenture Confirms Data Breach After Hacker Claims Source Code Theft appeared first on SecurityWeek.
Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices
Tracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device’s web management interface. The post Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices appeared first on SecurityWeek.
8Layers Raises $2.9 Million for Identity Security Platform
The Spanish startup has closed an extended pre-seed funding round two months after launching its digital identity protection platform. The post 8Layers Raises $2.9 Million for Identity Security Platform appeared first on SecurityWeek.
Chrome 150 Update Patches 27 Vulnerabilities
The security refresh resolves 13 use-after-free bugs, including two critical-severity flaws found by Google. The post Chrome 150 Update Patches 27 Vulnerabilities appeared first on SecurityWeek.
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique
Wiz has disclosed the details of a new AI coding assistant attack method it has dubbed GhostApproval. The post AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique appeared first on SecurityWeek.
Mount Royal University Confirms Data Stolen in Ransomware Attack
Hackers accessed the institution’s internal network and deleted two drives containing employee, student, and university data. The post Mount Royal University Confirms Data Stolen in Ransomware Attack appeared first on SecurityWeek.
Microsoft Patches Defender ‘RoguePlanet’ Vulnerability
The privilege escalation vulnerability tracked as CVE-2026-50656 has been patched with a Microsoft Malware Protection Engine update. The post Microsoft Patches Defender ‘RoguePlanet’ Vulnerability appeared first on SecurityWeek.
Summer of Clearinghouses
Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quietly months earlier, heads down, taking findings and shipping fixes, because customers kept asking […]
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According to a new report published by the Threat Hunter Team from Symantec, the ransomware was first publicly spotted in the wild on May 21, 2026. It’s assessed […]
Two arrests this week in unrelated crimes involved Japanese teenagers using ChatGPT to assist in their crimes
The Japan Times reports: An 18-year-old man has been arrested for his suspected involvement in a cyberattack on the operator of the Kaikatsu Club internet cafe chain, according to investigative sources. On Wednesday, the Metropolitan Police Department’s cybercrime countermeasure division arrested the company employee from Tokyo’s Katsushika Ward, who was in the second year of… […]
Agentic AI identity: A 6-stage maturity model for non-human identities
In a client engagement last year, an LLM-based deployment agent with standing access to a production Kubernetes cluster triggered a four-hour outage through a malformed configuration push. In the IAM, the agent appeared as a service account with a long-lived API key, no MFA, no scoped revocation path. When the incident review team asked which […]
Why fixing your data architecture matters more than upgrading your detection models
Security leaders have been on a spending sprint. The global AI in cybersecurity market is valued at $44 billion in 2026 and is projected to reach $213 billion by 2034, a trajectory that reflects genuine belief that machine learning will close the gap between the volume of threats and the capacity of human analysts. That […]
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine (“mpengine.dll”), which provides scanning, detection, and cleaning capabilities for its antivirus and
Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images
Meta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI content, and it’s enabled by default. “You can also @-mention Instagram accounts in the Meta AI app to bring specific Instagram profiles right into your images,” the social media giant said in […]
Lateral movement risk rises as enterprises emphasize convenience over containment
Poorly segmented networks and weak security controls continue to undercut security organizations’ ability to identify and contain attacks, giving attackers free rein after initial compromise, according to a recent study based on real-world enterprise security telemetry. Zero Networks’ 2026 Lateral Movement Exposure Report — based on analysis of 54 trillion activities across 312 live enterprise […]
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker’s code on your own machine instead. That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls “Friendly Fire.” It works against Anthropic’s Claude Code and OpenAI’s Codex when either is running […]
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer’s computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead. The affected tools are Amazon Q Developer, Anthropic’s Claude Code, Augment, Cursor, Google Antigravity, […]
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains. The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, […]
ISC Stormcast For Thursday, July 9th, 2026 https://isc.sans.edu/podcastdetail/10000, (Thu, Jul 9th)
Post Content
_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th)
[This is a Guest Diary by Jason Callahan, an ISC intern as part of the SANS.edu BACS program]
Nayax investigating breach; The Syndicate claims it acquired 1 billion card records and other important data
Nayax is a global fintech company headquartered in Israel that provides cashless payment and management solutions for unattended retail and self-service machines. The firm is publicly traded on both the Tel Aviv and Nasdaq stock exchanges. This month, Nayax submitted a Form 6-K to the Securities and Exchange Commission. The form contained an “Explanatory Statement:”… […]
GitHub’s public APIs are becoming an enterprise reconnaissance tool
GitHub continues to be a scintillating target for attackers because it sits in the middle of the software supply chain and gives threat actors three things they crave: source code, secrets, and automated pipelines to run amok in. Datadog Security Research has been tracking what it calls a “sustained pattern” of GitHub API abuse over […]
PUMA CAPITAL, LLC
PUMA CAPITAL, LLC fnrw-backend Wed, 07/08/2026 – 16:02 MC ID PUMA MC Reporter Type OTC Market Maker MC Paragraph MC Link https://www.pumacap.com/605606?PUMA_605= MC Last Updated Wed, 07/08/2026 – 16:02
Deadline Fast Approaching to Vote in FINRA Board Election
Deadline Fast Approaching to Vote in FINRA Board Election K34060 Wed, 07/08/2026 – 15:30 July 8, 2026 Features Deadline Fast Approaching to Vote in FINRA Board ElectionFINRA encourages member firms to vote before July 13 in the election for one Small Firm Governor and one Large Firm Governor to the FINRA Board of Governors. These […]
Uniondale Union Free School District – Audit Follow-Up by New York State Comptroller (2023M-61-F)
In October 2023, NYS Comptroller Thomas DiNapoli released an IT audit of the Uniondale Union Free School District on Long Island. The purpose of the audit was to examine management of non-student user network controls. The audit report found, in part: District officials did not adequately manage nonstudent network user accounts and permissions. As a… […]
Anthropic shines a light into the Claude AI black hole
Anthropic has found a way to shed new light on how its models solve problems, thanks to its discovery of what it has dubbed the J-space. “We find that Claude has developed a small collection of internal neural patterns that, compared to all its other internal processing, play a special role. We call the collection […]
The AI ROI gap isn’t a model problem. It’s a workflow problem
Anthropic says Claude now writes more than 80% of the code merged at one of the most sophisticated AI companies on the planet. Foundry’s 2026 State of the CIO study says fewer than one in five enterprises can show that their AI initiatives have met or exceeded their ROI goals. Both numbers came out this […]
Your AI rollout is succeeding. Your organization is failing
In the past 90 days, I have fielded five separate compliance inquiries from enterprise CIOs and federal agencies asking the same question: our AI models are performing well, but we cannot explain our decisions to regulators. One financial services CDO deployed machine learning models across her entire credit risk function. Adoption was tracking at 97 […]
The tech behind patient-first transformation at USME
As a medical equipment rental company that rents, sells, and manages movable medical devices, including infusion pumps, monitors, ventilators, and incubators, USME’s mission is simple in definition, but highly sophisticated in practice. “Our job is to deliver the right equipment to the right place at the right time,” says CIO Antonio Marin. “When you look […]
Why is it so hard to measure the ROI of AI?
Danish multinational pharmaceutical Novo Nordisk is very interested in speeding up the time it takes to get drugs to market as patents expire. “If you have a blockbuster drug, a one-week delay can be $10 to $100 million,” says Stephanie Bova, the company’s digital transformation officer. “It’s massive money because you have less time on […]
New US CIO appointments, July 2026
Movers & Shakers is where you can keep up with new CIO appointments and gain valuable insight into the job market and CIO hiring trends. As every company becomes a technology company, CEOs and corporate boards are seeking multi-dimensional CIOs and IT leaders with superior skills in technology, communications, business strategy, and digital innovation. The […]
¿Por qué resulta tan difícil medir el ROI de la IA?
La multinacional farmacéutica danesa Novo Nordisk está muy interesada en acelerar el tiempo que se tarda en lanzar medicamentos al mercado a medida que expiran las patentes. “Si tienes un medicamento superventas, un retraso de una semana puede suponer entre 10 y 100 millones de dólares”, afirma Stephanie Bova, responsable de transformación digital de la […]
AI changed our cloud strategy. Quantum changes the questions behind it
The strangest thing about cloud strategy is how confident it looks in PowerPoint and how nervous it feels in real life. I’ve sat in rooms where the cloud slide looked clean enough to frame. Public cloud here. Private cloud there. Hybrid for the awkward middle child. Multi-cloud for resilience, bargaining power and the faint hope […]
Reallocating cybersecurity capital in the Mythos era
Throughout my career, I’ve seen countless technological shifts categorized as “unprecedented” that turned out to be merely incremental. The recent deployment of advanced, agentic AI models — what we are categorizing here as the “Mythos” capability — is fundamentally different. It represents a permanent, structural shift in the risk and financial dynamics of the enterprise. […]
MCAP LLC
MCAP LLC fnrw-backend Wed, 07/08/2026 – 14:39 MC ID MCAP MC Reporter Type Broker-Dealer MC Paragraph MC Link https://public.s3.com/rule605/mcap/ MC Last Updated Wed, 07/08/2026 – 14:39
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders. The agents are not malicious. They just do a lot of things that, to a behavioral engine, look exactly like an […]
Patients Sue Healthcare Corporations Over Data Breaches, Sharing of Personal Information
Mikeie Honda Reiland reports: A suite of recent class action lawsuits in state and federal courts seeks to hold large healthcare corporations accountable for exposing or leaking patients’ personally identifiable information (PII) and protected health information (PHI). On June 11 in Davidson County Circuit Court, three Jane Does filed suit against CareNow, which operates more… […]
Why Bangladesh’s new data protection law may fail to protect your data
Meem Arafat Manab reports: On August 19, 2025, hackers broke into Shwapno’s customer database. They took 410 gigabytes of data: the names, phone numbers, and purchase histories of forty lakh registered customers. They demanded $1.5 million. Shwapno refused, secured its systems, and said nothing to its customers for seven months. When the hackers published the… […]
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist. New research, which its authors call HalluSquatting, turns that habit into an attack: work out the fake names an AI reliably invents, register […]
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution. The list of vulnerabilities is as follows – CVE-2026-50746 (CVSS score: 10.0) – An improper access control vulnerability in UniFi Connect Application that […]
New Ghost Phishing Wave Is Breaking Traditional Email Security
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft […]
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names. The X/Twitter account IRIS C2 (@C2IRIS) has gained more […]
GitHub AI agent leaks private repositories via prompt injection attack
A prompt injection attack can trick GitHub’s preview Agentic Workflows into retrieving content from private repositories and publishing it publicly, exposing a broader risk as enterprises deploy AI agents with privileged access to software development environments, according to new research from Noma Security. The AI security company detailed the attack, dubbed GitLost, in a blog […]
Cybercriminals exploit India’s tax filing season with a dual-malware campaign
Cybercriminals are exploiting India’s tax filing season with a new malware campaign that refuses to put all its eggs in one basket. Researchers at Cyderes have uncovered a sophisticated phishing operation that poses as the Indian Tax Department to deliver two remote access trojans (RATs) through a multi-stage infection chain, giving attackers persistent access to […]
EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain
EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain ipetstef Wed, 07/08/2026 – 13:34
CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker
Tarah Wheeler is CISO at TPO Group, a firm that provides cybersecurity consultancy for high-stakes organizations. But despite this elevated position, her journey was far from typical. The post CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker appeared first on SecurityWeek.
Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks
Researchers say the Iran-linked threat actor used an adaptable modular malware framework and compromised IT service providers to reach high-value targets in Israel. The post Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks appeared first on SecurityWeek.
Critical Adobe ColdFusion Vulnerability Exploited in Attacks
Hackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10. The post Critical Adobe ColdFusion Vulnerability Exploited in Attacks appeared first on SecurityWeek.
CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws
The audits are reportedly being spearheaded by CISA’s Attack Surface Evaluation team, a specialized unit tasked with conducting digital defense assessments and simulated hacking exercises. The post CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws appeared first on SecurityWeek.
Critical Gitea Flaw Under Active Exploitation, Researchers Warn
Attackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets. The post Critical Gitea Flaw Under Active Exploitation, Researchers Warn appeared first on SecurityWeek.
County Government Reportedly Paid $1 Million to Cyber Extortion Group
The alleged victim, believed to be a small Ohio county, reportedly paid the extortion group to prevent the public release of sensitive stolen data. The post County Government Reportedly Paid $1 Million to Cyber Extortion Group appeared first on SecurityWeek.
Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection
Researchers show how attackers can use a crafted public GitHub Issue to trick AI-powered workflows into exposing data from private repositories without authentication. The post Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection appeared first on SecurityWeek.
CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws
Two newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA’s Known Exploited Vulnerabilities catalog, with federal agencies given until July 10 to patch. The post CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws appeared first on SecurityWeek.
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices. According to findings from Cisco Talos, UAT-7810 is an advanced persistent threat (APT) actor that’s responsible for maintaining and proliferating LapDogs, an ORB network that first came to […]
My threat feed told me it was ‘Chalubo.’ The binary disagreed
I’ve spent two years doing incident response and threat intel, and the one habit I’d keep if I had to give up every other is also the most boring. I don’t act on a piece of intelligence until I’ve checked it against the thing it claims to describe. It’s slow. It’s tedious. Almost nobody does […]
My Stack Simulator, (Wed, Jul 8th)
The stack is a memory region where a program stores temporary data – like local variables and return addresses. Think of the stack as a pile of plates in your kitchen: you can only add a new plate to the top, and you can only take one away from the top too. Programs use this same […]
13 in-demand IT security certifications for higher pay
With change a constant, cybersecurity professionals looking to improve their careers can benefit from the latest insights into employers’ needs. Data from Foote Partners on the skills and certification most in demand today may provide helpful signposts. Analyzing more than 660 certifications as part of its 2Q 2026 “IT Skills Demand and Pay Trends Report,” Foote Partners […]
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below – CVE-2026-48282 (CVSS score: 10.0) – A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of […]
Soap Box: Using threat hunting to drive detection
In this wholly sponsored Soap Box edition of the podcast Patrick Gray chats with Damien Lewke, the CEO and founder of Nebulock, about the future of threat hunting and detection. Damien spent a decade in the EDR and MDR space before founding Nebulock in 2024. It started off as an AI-powered threat hunt platform but […]
ISC Stormcast For Wednesday, July 8th, 2026 https://isc.sans.edu/podcastdetail/9998, (Wed, Jul 8th)
Post Content
Washington Dept. of Social and Health Services announces massive data breach
KIRO7 reports: The Washington Department of Social and Health Services (DSHS) is issuing a notice of a massive data breach that happened in March, potentially compromising the personal data of around 8,600 people. An internal investigation revealed that a former DSHS employee accessed the data without authorization. Some of the data the employee improperly potentially… […]
16-year-old KVM flaw allows attackers to escape VMs and take over Linux servers
A critical vulnerability in the Kernel-based Virtual Machine (KVM) module of the Linux kernel allows attackers with root access in a guest VM to execute arbitrary code on the host system. This violates the most important security boundary that cloud providers and enterprises rely on to isolate sensitive processes on servers. The vulnerability, tracked as […]
25-00712(3).pdf
25-00712(3).pdf Anonymous (not verified) Tue, 07/07/2026 – 17:35 Case ID 25-00712 Forum FINRA Document Type Motion to Vacate Claimants Kestra Financial, Inc. Kestra Investment Services, LLC Respondents James Eddins II Neutrals Lynne M. Gomez Hearing Site New Orleans, LA Award Document 25-00712(3).pdf Documentum DocID 33cd6397 Award Date Official Wed, 12/24/2025 – 12:00 Related Content On […]
25-00712(2).pdf
25-00712(2).pdf Anonymous (not verified) Tue, 07/07/2026 – 17:35 Case ID 25-00712 Forum FINRA Document Type Motion to Vacate Claimants Kestra Financial, Inc. Kestra Investment Services, LLC Respondents James Eddins II Neutrals Lynne M. Gomez Hearing Site New Orleans, LA Award Document 25-00712(2).pdf Documentum DocID cebbc2c4 Award Date Official Wed, 12/24/2025 – 12:00 Related Content On […]
Watch out for fake support calls in Microsoft Teams
Palo Alto Networks’ security division, Unit 42, is warning of yet another campaign targeting Microsoft Teams users. The new campaign begins with Teams users receiving an email asking if they would like to participate in a survey. If they open the attached PDF file, they will shortly thereafter receive a voice call purporting to be […]
WELLS FARGO CLEARING SERVICES, LLC
WELLS FARGO CLEARING SERVICES, LLC fnrw-backend Tue, 07/07/2026 – 16:44 MC ID WELS MC Reporter Type OTC Market Maker MC Paragraph MC Link https://www.wellsfargoadvisors.com/disclosures/legal-disclosures/order-routing-… MC Last Updated Tue, 07/07/2026 – 16:43
WELLS FARGO CLEARING SERVICES, LLC
WELLS FARGO CLEARING SERVICES, LLC fnrw-backend Tue, 07/07/2026 – 16:43 MC ID WRET MC Reporter Type Broker-Dealer MC Paragraph MC Link https://www.wellsfargoadvisors.com/disclosures/legal-disclosures/order-routing-… MC Last Updated Tue, 07/07/2026 – 16:43
WELLS FARGO ADVISORS FINANCIAL NETWORK, LLC
WELLS FARGO ADVISORS FINANCIAL NETWORK, LLC fnrw-backend Tue, 07/07/2026 – 16:41 MC ID FNET MC Reporter Type Broker-Dealer MC Paragraph MC Link https://www.wellsfargoadvisors.com/disclosures/legal-disclosures/order-routing-… MC Last Updated Tue, 07/07/2026 – 16:41
With AI, a wrong answer is a bug. A wrong action is an incident
A copilot that gives a wrong answer is a quality problem. An AI agent that takes a wrong action is an incident, sometimes a reportable one. That single difference is most of the story of where banking AI security is heading, and most banks’ current controls were built for the first kind of problem, not […]
Modernizing legacy IT with AI without triggering regulatory risk
AI is accelerating modernization projects that previously required months of analysis. But in highly regulated organizations, an uncomfortable reality quickly emerges: The risk is no longer in converting the code, but in demonstrating that the new version still does exactly what the old one did. Almost every management committee has made the same decision this […]
Build or buy? Smart CIOs know the answer for AI talent
The key ingredient for successful AI deployment is largely becoming the talent available, not the AI tools installed, putting pressure on IT leaders to upskill their workforces. With AI skills both the highest in demand and the hardest to hire for, many IT leaders and their C-suite colleagues are rolling out comprehensive AI training programs […]
The data reckoning: How exponential growth is rewriting the rules of cost, risk and AI
Something structural is happening to enterprise data and most organizations are only beginning to fully understand. Data volumes are growing faster than any original assumptions about how to store, govern and extract value from information. At the same time, the cost of getting it wrong is rising sharply: inflated infrastructure spend, expanding cyber exposure and […]
Envirotech Vehicles Closes Merger with Azio AI Ahead of Schedule, Positioning Combined Company to Capture $487 Billion 2026 AI Infrastructure Opportunity
Revised transaction structure enables immediate closing, accelerating the Company’s strategic pivot toward AI data centers, enterprise GPU compute, and digital power infrastructure. Envirotech Vehicles, Inc. (NASDAQ: EVTV) (“EVTV” or the “Company”) today announced the successful completion of its merger with Azio AI Corporation (“Azio AI”) on July 2, 2026, paving the way for the Company […]
Preparing for infrastructure constraints, from memory shortages to power limits
Historically, infrastructure planning followed a predictable script. CIOs balanced budgets, refresh cycles and procurement approvals and when demand spiked, the solution was straightforward — find the funding and scale up. The only real constraint was budget. Today, the biggest constraints aren’t sitting in spreadsheets; they’re rooted in physical reality. High-bandwidth memory is in short supply. […]
Rubén Andrés Priego (Singular Bank): “En la banca del futuro no competiremos por la experiencia de usuario sino por la del agente [de IA]”
> allowfullscreen> Conocido sobre todo por sus servicios como “boutique de inversión”, el banco Singular Bank, nacido en el año 2020 gracias al impulso del exconsejero delegado del Banco Santander Javier Marín Romano, después de adquirir y transformar la estructura del antiguo banco digital Self Bank, es en la actualidad una entidad con más de […]
Tether believes intelligence should not be a service people rent
The world is advancing toward a future in which over 10 billion humans coexist with trillions of autonomous agents in a superintelligent universe. However, the cloud-hosted systems that currently dominate AI’s operational models lack the architectural elasticity to support this growing demand for compute resources. Championed by managed GPU Clusters and centralized data centers, cloud […]
More Odd DNS Records: NIMLOC, (Tue, Jul 7th)
Yesterday, I talked about NAPTR records and how they are related to RCS. But there is another “odd” record that shows up in my DNS logs. This one isn’t new, but I don’t think I ever covered it: NIMLOC. At least that is what Zeek calls it. But let’s see what it is all about.
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim’s phone, steal their banking logins, and capture the one-time codes that protect their accounts. Zimperium’s zLabs, which found the operation, says it looks like a new variant of […]
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
A critical flaw in Google’s Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project. From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a […]
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. “The campaign did not depend on a fake Microsoft password page. It used a malicious collaboration-style lure to push users into […]
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization’s private repositories, researchers at Noma Security have shown. The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access to the organization. If that organization has given the agent read access […]
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker
U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal complaint. Microsoft records tied that ID first to the account the attackers used to keep access during the May 2025 intrusion, then to online accounts prosecutors say […]
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise. The one-click vulnerability has been codenamed WriteOut by the Sand Security Research team. “An outsider could go from having no access to taking over any Writer AI
Bojangles sued again by workers over Russian hacker data breach. NC judge weighs in
Chase Jordan reports an update in the litigation stemming from a 2024 breach by Hunters International. This case has raised a number of issues about standing and negligence and has been up and down in the courts, with plaintiffs seeming to fare better in state court: A class-action lawsuit over a 2024 data breach of Bojangles employee… […]
Jacksonville, Texas, keeps some city systems offline after cyber incident
DysruptionHub reports: Jacksonville, Texas, took some city systems offline after detecting suspicious network activity Friday, leaving some online services unavailable Monday as officials investigated a cybersecurity incident. The city said it detected the activity July 3 and later determined it was related to a cybersecurity incident. Officials took affected systems offline, disabled some systems as… […]
Hydro-Québec Le Circuit Electrique charging station backend
View CSAF Summary Successful exploitation of these vulnerabilities could lead to privilege escalation, or result in a denial-of-service attack. The following versions of Hydro-Québec Le Circuit Electrique charging station backend are affected: Le Circuit Electrique charging station backend CVSS Vendor Equipment Vulnerabilities v3 9.8 Hydro-Québec Hydro-Québec Le Circuit Electrique charging station backend Improper Access Control, […]
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based […]
Siemens Mendix Studio Pro
View CSAF Summary Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that user. Siemens has released new versions for several affected […]
Siemens SINEC OS
View CSAF Summary SINEC OS before V4.0 contains multiple vulnerabilities. Siemens has released a new version for RUGGEDCOM RST2428P and recommends to update to the latest version. The following versions of Siemens SINEC OS are affected: RUGGEDCOM RST2428P (6GK6242-6PA00) vers:intdot/<4.0 CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens SINEC OS Improper Restriction of Operations within […]
Digi International PortServer TS, Digi One SP IA
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and gain access to restricted resources, obtain credentials, and inject malicious scripts. The following versions of Digi International PortServer TS, Digi One SP IA are affected: PortServer TS Digi One SP Digi One SP IA Digi One IA CVSS Vendor […]
Hitachi Energy PROMOD V
View CSAF Summary Hitachi Energy is aware of insecure HTTP transmission vulnerability in PROMOD V product versions listed in this document. This vulnerability could allow attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access. The following versions of Hitachi Energy PROMOD V are affected: PROMOD […]
Labcenter Proteus 9
View CSAF Summary Successful exploitation of these vulnerabilities could disclose information and allow a malicious user to execute arbitrary code on affected installations. The following versions of Labcenter Proteus 9 are affected: Proteus 9.1_SP4_Build_42914 CVSS Vendor Equipment Vulnerabilities v3 7.8 Labcenter Electronics Labcenter Proteus 9 Out-of-bounds Write, Stack-based Buffer Overflow, Use After Free Background Critical […]
Hitachi Energy e-mesh EMS
View CSAF Summary Hitachi Energy is aware of a buffer overflow vulnerability that affects e-mesh EMS product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer overflow condition, potentially resulting in application outages (denial of service) and possible arbitrary code execution. Please refer to the Recommended Immediate Actions for […]
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability CVE-2026-56290 Joomlack Page Builder Improper Access Control Vulnerability These types of vulnerabilities are a […]
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, “software supply chain security” meant one question: what’s in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? SolarWinds, Log4Shell, and XZ Utils all taught the same lesson: the risk […]
Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments
Researchers uncovered two campaigns embedding indirect prompt injections in malicious websites to exploit autonomous AI agents browsing the web. The post Prompt Injection Attacks Trick AI Agents Into Making Crypto Payments appeared first on SecurityWeek.
Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability
Organizations are urged to patch after proof-of-concept code makes the Linux root escalation flaw easier to exploit. The post Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability appeared first on SecurityWeek.
North Korean Hackers Target Open Source Developers in Supply Chain Attacks
The PolinRider campaign has compromised more than 100 legitimate open source packages and repositories to deliver a backdoor and information stealer to developers. The post North Korean Hackers Target Open Source Developers in Supply Chain Attacks appeared first on SecurityWeek.
Armored Likho APT Targeting Government, Electric Power Entities
The threat actor uses modular RATs and information stealers in financially motivated and cyber espionage campaigns. The post Armored Likho APT Targeting Government, Electric Power Entities appeared first on SecurityWeek.
The Shift Toward Business-Aligned Risk Management
Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. The post The Shift Toward Business-Aligned Risk Management appeared first on SecurityWeek.
Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks
Securonix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog information stealer. The post Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks appeared first on SecurityWeek.
Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security
The investment will accelerate Keyfactor’s machine identity, PKI, and cryptographic security platform as enterprises prepare for AI-driven and post-quantum threats. The post Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security appeared first on SecurityWeek.
Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems
The 16-year-old Januscape flaw affects Linux’s KVM hypervisor, allowing attackers to escape virtual machines and potentially execute code on the underlying host. The post Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems appeared first on SecurityWeek.
Why The Gentlemen ransomware is a test of identity and recovery controls
The Gentlemen ransomware underscores a challenge many CISOs face: stopping attackers after they gain an initial foothold. Researchers say the malware can spread across enterprise networks using legitimate Windows management tools while simultaneously attempting to weaken security and recovery systems. A report from Picus Security shows the malware combines self-propagation with the abuse of trusted […]
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign. The activity involves the exploitation of now-patched, critical security flaws in the open-source email solution, such as CVE-2024-42009 (CVSS score: 9.3), to siphon credentials,
The modern CISO is becoming the next CFO
At some point, every security leader gets asked a version of the same question: Are we good? It tends to arrive when something is at stake and the person asking needs to know they can rely on the answer. I learned what that question really means at a firm I was with earlier in my […]
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices’ web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday. “An attacker can exploit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices. The vulnerabilities are listed below – CVE-2026-40138 (CVSS score: 9.2) – A pre-authentication vulnerability exists in the
Insignary Closes SBOM Accuracy Gap With Binary-Level Clarity for Regulatory Risk
Most software composition analysis tools read what developers declare. Insignary Clarity’s patented binary-first platform analyzes what is actually built, shipped, and deployed — including the open-source components that never appear in any manifest. Insignary, Inc., whose patented binary fingerprint technology has been cited in four Gartner research reports, today announced its recognition as a Sample […]
ISC Stormcast For Tuesday, July 7th, 2026 https://isc.sans.edu/podcastdetail/9996, (Tue, Jul 7th)
Post Content
AI agents fall for indirect prompt injection traps
Some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans, Zscaler found in a test of major LLMs. The security vendor looked at various forms of indirect prompt injection (IPI) traps and found that, whereas many models fell […]
Zscaler finds autonomous agents succumb to IPI traps
In a test of major LLMs, Zscaler found that some autonomous AI agents fell victim to frauds, reinforcing how easily some high-end enterprise agents can be conned by schemes that would fool few, if any, humans. The security vendor looked at various forms of indirect prompt injection (IPI) traps and found that, whereas many models […]
The “Anonymous” Tip System That Wasn’t: Three Months Later, Why Hasn’t Navigate360 Notified Anyone?
Trigger Warning: This post includes content from tips submitted to anonymous tiplines by or about students. While identity information is redacted, tips may include obscenities and explicit references to sexual abuse, rape, assault, self-harm, violence, suicidal ideation, pornography, and pedophilia. Overview On March 18, 2026, DDoSecrets and Straight Arrow News reported on a dataset provided… […]
26-00131.pdf
26-00131.pdf Anonymous (not verified) Mon, 07/06/2026 – 18:50 Case ID 26-00131 Forum FINRA Document Type Award Claimants Jerry Shi Respondents Robinhood Securities, LLC Neutrals Thomas P. Valenti Hearing Site Chicago, IL Award Document 26-00131.pdf Documentum DocID 073ae551 Award Date Official Mon, 07/06/2026 – 12:00 Related Content Off Claimant Representatives Jerry Shi Respondent Representatives Dominick F. […]
2024084471901 Kim Thien Tran CRD 5575725 AWC lp.pdf
2024084471901 Kim Thien Tran CRD 5575725 AWC lp.pdf Anonymous (not verified) Mon, 07/06/2026 – 16:25 Case ID 2024084471901 Document Number 08837a8e Document Type AWCs (Letters of Acceptance, Waiver, and Consent) Individuals Kim Thien Tran Action Date Thu, 07/02/2026 – 12:00 Related Content Off Attachment 2024084471901 Kim Thien Tran CRD 5575725 AWC lp.pdf Individual CRD 5575725
25-00364(2).pdf
25-00364(2).pdf Anonymous (not verified) Mon, 07/06/2026 – 16:10 Case ID 25-00364 Forum FINRA Document Type Motion to Vacate Claimants Steven Seid Respondents Touchstone Securities, Inc. Neutrals Ronald Chun Gary Kostow Anthony Knight Hearing Site San Francisco, CA Award Document 25-00364(2).pdf Documentum DocID 412515fa Award Date Official Wed, 06/03/2026 – 12:00 Related Content On Claimant Representatives […]
25-01900.pdf
25-01900.pdf Anonymous (not verified) Mon, 07/06/2026 – 16:05 Case ID 25-01900 Forum FINRA Document Type Award Claimants Ralph Courtland Respondents Wells Fargo Clearing Services, LLC Neutrals John P. Cullem Michael S. Jordan David A. Schuler Hearing Site Jersey City, NJ Award Document 25-01900.pdf Documentum DocID 09cfa9f7 Award Date Official Mon, 07/06/2026 – 12:00 Related Content […]
25-02186.pdf
25-02186.pdf Anonymous (not verified) Mon, 07/06/2026 – 16:05 Case ID 25-02186 Forum FINRA Document Type Award Claimants Elizabeth McMullen Respondents Yvonne Kelly Neutrals Karimu F. Hill-Harvey Elizabeth A. Townes Shawn Joseph Barko Hearing Site Tampa, FL Award Document 25-02186.pdf Documentum DocID e7b4ba64 Award Date Official Mon, 07/06/2026 – 12:00 Related Content Off Claimant Representatives Elizabeth […]
Why AI agents will make your governance playbook obsolete
Large Australian banks have started implementing agentic AI at scale this year. The same is happening across the country’s larger enterprises. These are not pilots, but production systems that are the tip of a global trend. Research company Gartner expects 40% of enterprises to embed AI agents in applications by the end of 2026, up […]
AI doesn’t eliminate inefficiency. It amplifies it
Over the past two years, I have spent a significant amount of time discussing artificial intelligence with technology leaders, business executives and teams across my own organization. Most conversations begin with questions about the use cases, tools, governance and return on investment. Leaders want to know which technologies are creating the most value, where to […]
Playing to win at the AI casino
Most executives approach AI cautiously, like people trying to stretch one bankroll across an entire night on the casino floor. They spread their chips, hedge every move, celebrate the occasional small win, and tell themselves they played wisely because they didn’t lose much. It feels disciplined and responsible. But in a market shifting this quickly, […]
6 new rules of IT leadership — and what they replace
AI is changing how work gets done and who does it — at all levels of the organization. That means it’s also changing how executives do their jobs and how they need to lead, as execs are now being asked to use AI to reimagine their organizations and navigate the uncertainties that go with that […]
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
An Iranian hacking group affiliated with Iran’s Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations. The activity, which has primarily singled out IT providers and government sectors, has been attributed to a threat cluster tracked by Check Point Research
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
A use-after-free bug in Linux’s KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. Dubbed ‘Januscape’ and tracked as CVE-2026-53359, the flaw sits in the shadow MMU code that KVM shares across both Intel and AMD. The public proof-of-concept panics the host; the […]
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the “X-WEBAUTH-USER” header from any source IP address, effectively allowing an unauthenticated internet client to get […]
The agentic blind spots in your zero trust program
Stephen Wilson, field chief technology officer for HashiCorp, an IBM company, likens AI agents to “really smart kindergartners.” “They know how to do something, but they have no clue as to why they should do it,” Wilson says. This combination of superior execution power and lack of judgment can create a significant challenge for organizations […]
Identity: The operational control plane for agentic AI
Existing security controls weren’t designed for AI agents. Static credentials and standing privileges aren’t sufficient for an emerging model where organizations need to rapidly authorize, limit, and revoke permissions from autonomous agents, sometimes more than once within a single workflow. Agentic AI requires organizations to carefully consider how to govern agentic identity, agent-to-agent communication, secrets […]
Operationalizing Agentic AI: from assisted to autonomous
Ever since ChatGPT made its public debut nearly four years ago, governance and security have largely lagged behind AI adoption. Eager to experiment with AI tools and find ways to improve their work and personal lives, users have uploaded corporate data, financial records, and even their own health information to large language models (LLMs). While […]
RCS and DNS: The NAPTR Record, (Mon, Jul 6th)
Over the last year, with recent updates to iOS and Android, RCS (Rich Communication Services) has become an increasingly used protocol [1]. RCS is supposed to eventually replace SMS, and in addition to richer formatting, provides added (but optional) security. RCS messages may be end-to-end encrypted and digitally signed. Unlike SMS, which was “bolted on” […]
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
A streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary. Home devices became a routing cover. Clean code pulled dirt from a dependency. Identity shortcuts aged badly. AI […]
Alberta, Centurion Project sued over alleged data breach that affected millions of voters
Carrie Tait reports: A retired lawyer is suing Alberta, its Chief Electoral Officer and two organizations that support secession for their respective roles in an alleged data breach affecting 2.9 million residents in the province. Clint Docken, a former class-action lawyer, last week filed a sweeping lawsuit stemming from allegations the Centurion Project unlawfully obtained… […]
ISC Stormcast For Monday, July 6th, 2026 https://isc.sans.edu/podcastdetail/9994, (Mon, Jul 6th)
Post Content
This AI agent autonomously hacked a network, adapted on the fly, and demanded a ransom
A fully autonomous AI agent conducted an end-to-end cyber intrusion and extortion campaign after exploiting a vulnerable Langflow server, demonstrating how large language models could accelerate ransomware operations, according to research published by Sysdig. Sysdig detailed the operation in a research paper, saying the AI agent, dubbed JadePuffer, completed the entire intrusion chain, from initial […]
How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions
Building a shortlist for an AI SOC evaluation can be tough. SIEM, SOAR, and pureplay AI SOC vendors are all saying the same thing. But behind the identical label sit very different products, from chat assistants bolted onto a legacy SIEM to agent platforms that run detection, triage, investigation, and response on their own data […]
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensitive data from compromised hosts. The multi-stage campaign, codenamed Operation DragonReturn by Seqrite Labs, involves sending spear-phishing emails impersonating the Income Tax Department of India.
Single points of failure fail. The SaaS layer is not an exception
Higher education has consolidated its entire academic operation into a handful of massive SaaS platforms. The LMS manages instruction, grading and communication. The SIS owns enrollment, records and financial aid. Identity and productivity live in a small number of cloud providers. These are not peripheral tools — they are the operational infrastructure of the institution. […]
AI isn’t closing the skills gap — it’s exposing the validation gap
If you wanted to become a basketball star, how would you get started? You wouldn’t read a book on basketball and take an online course. You’d set up a hoop in your driveway, join a local team to train, and play in real matches. So why do we expect cybersecurity professionals to learn their skills […]
New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them radiates a faint radio signal a nearby receiver can decode. But TrojPix works only once malware […]
New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS
Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that’s capable of targeting Windows, Linux, and macOS environments. According to LevelBlue, the cross-platform malware is advertised under a malware-as-a-service (MaaS) model, costing anywhere between $150 for one month to $1,200 for lifetime access. Other subscription tiers include $300 for
Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits. In a proof of concept, they reconstructed a signed-in user’s full Gmail address from a single visit, with no […]
7 cyber risk assessment gotchas to avoid
A cyber risk assessment helps security teams identify, estimate, and prioritize potential threats and vulnerabilities to key enterprise digital and physical assets. Yet, despite its importance, many CISOs fall victim to several types of “gotchas” that prevent them from fully achieving their risk assessment goals. An assessment should be an essential part of every organization’s […]
SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing
Scanners meant to catch malicious add-on “skills” for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology. Their strongest trick slipped past every scanner tested more than 90% of the time, and the same […]
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd part: the group that took the money calls itself Kairos, but it may not be […]
AdaptHealth says attackers sweet-talked their way into cloud systems and stole patient data
Connor Jones reports: AdaptHealth says attackers used social engineering to breach its systems and steal sensitive patient data, including passwords associated with insurance billing. The medical equipment company disclosed the attack to the Securities and Exchange Commission (SEC) on Thursday, noting that attackers accessed internal patient management systems, document storage platforms, and external electronic health record system… […]
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider. “The campaign remains active, and new malicious packages are likely to continue appearing as threat actors […]
In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting
Noteworthy stories that might have slipped under the radar: Anonymous-linked Canadian hacker jailed, researcher drops zero-days in open source projects, Venezuelans sentenced in the US over ATM jackpotting. The post In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting appeared first on SecurityWeek.
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter because FatFs is nearly everywhere. It ships inside the firmware that runs security cameras, drones, industrial controllers, hardware crypto wallets, and other devices […]
An AI just carried out a cyber attack without any human oversight for the first time
Anthony Cuthbertson reports: Security researchers have uncovered what they believe to be the first ever instance of an artificial intelligence agent executing a cyber attack from start to finish without human assistance. The AI-powered attack marks a major milestone for both artificial intelligence and cyber security, raising concerns that AI is lowering the barrier for cyber criminals. The fully automated campaign involved… […]
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out. Bad Epoll sits in the same small stretch of kernel code where Anthropic’s most powerful AI model, […]
Los agentes de IA ponen en riesgo 234.000 millones de dólares del gasto empresarial en SaaS, según Gartner
“Ya no se compra software principalmente para personas; cada vez se compra más para agentes”, explica George Brocklehurst, vicepresidente ejecutivo de Gartner. “Durante un par de décadas, el software se ha evaluado por su interfaz y por la experiencia de usuario: facilidad de uso, flujos de trabajo, formación. Cuando los agentes de IA se convierten […]
SAP cuts hiring and travel to fund AI
SAP is limiting hiring and travel spending to help pay for its AI transformation. The tech giant will “exclusively focus new hiring on selected profiles only, mainly core Al roles, that are critical for our long-term success,” staff were reportedly told in an internal email. The email also said that internal travel, unless it is […]
Cisco’s in-house AI assistant is a jack of all trades
Since the advent of ChatGPT, enterprises have been intent on transforming generative AI’s potential as a digital assistant into productivity enhancements in every pocket of the organization. Networking giant Cisco is one company that has been at the leading edge of that pursuit. The original idea for an internal assistant started at Cisco as ChatGPT […]
Cisco tiene un asistente de IA interno… y sirve para todo
Desde la irrupción de ChatGPT, las empresas han intentado transformar el potencial de la IA generativa como asistente digital en mejoras de productividad para todas las áreas de la organización. Cisco es una de las compañías que se ha situado a la vanguardia de este esfuerzo. La idea original de crear un asistente interno surgió […]
Cloud sovereignty: First four providers sign up to CISPE certification program
The European Union’s drive towards some form of digital sovereignty has just received a boost with the first four companies ready to support the EU cloud sovereignty project. Four cloud service providers — Etix, Phocea, Thésée Datacenter, and Gigas — have signed up for the CISPE Sovereign and Resilient Cloud Service Certification program. Currently, they […]
AI token prices are cooling — but why?
A measure of daily spending on AI usage has fallen since its peak in May — although interpreting what the decline means is challenging. The Silicon Data LLM Token Expenditure Index (SDLLMTK) is a daily snapshot of the state of the market. It draws data from a multitude of providers and produces a blended rate, […]
Unpacking Workday’s agentic AI pricing model
Only 35% of CIOs have full visibility into their AI operating costs, according to a new KPMG survey. That makes it difficult for them to control spend on software-as-a-service offerings from vendors who, like Workday, have incorporated pay-as-you-go agentic AI into their offerings. Workday is one of several vendors that have shifted to a hybrid […]
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that’s distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, remote access, recovery disruption, and ransomware execution, bringing together diverse functions under one
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft. According to JFrog, the packages “rollup-packages-polyfill-core” and “rollup-runtime-polyfill-core” mimic the legitimate “rollup-plugin-polyfill-node” project, down to the description, repository metadata, and
Microsoft 365 users fall victim to one-in-a-million password spray attack
Microsoft users have been hit by a massive, automated password spray attack. Among those targeted by the attack were clients of security company Huntress. It reported that the attackers made 81 million attempts to log into its customers’ accounts between June 12 and 26 — and succeeded in at least 78 cases. And that’s just […]
Adobe premieres a second Patch Tuesday each month to deliver fixes faster
Adobe will now issue security patches for its products twice as often to deal with the increasing pace of software vulnerability discovery and exploitation. This follows Oracle’s decision to increase its quarterly patch program to a monthly one. Adobe issues patches on the second Tuesday of each month, as do Microsoft and SAP. Starting in […]
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan. “Armored Likho blends financially motivated campaigns targeting private individuals with targeted cyber espionage aimed at organizations,” Kaspersky said in a technical analysis published today. “
HK: Shun Hing Group data breach affects 920,000 customers, 1.05m files encrypted in cyber attack
Erwin Wong reports: Shun Hing Group has confirmed that its computer systems were compromised by hackers in March, resulting in a significant data breach affecting customers and staff. Founded in 1953 by the late Dr William Mong, Shun Hing Group has grown into a leading and diversified Hong Kong conglomerate, best known as the sole… […]
New CitrixBleed-like NetScaler flaw sees exploit attempts in the wild
Citrix NetScaler appliances have been a constant target for attackers in recent years, most recently through an information leak vulnerability dubbed CitrixBleed 3, the latest in a series of NetScaler memory overreads going back to 2023. This week, Citrix patched yet another CitrixBleed-like vulnerability and there are signs of in-the-wild exploitation already. The new memory […]
European Parliament Member Investigating Spyware Was Hacked With Pegasus
A new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device repeatedly hacked with the notorious Pegasus spyware while serving on a committee that was tasked with investigating the abuse of such commercial surveillance tools in the bloc. “Through forensic analysis of his device, […]
Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm
Anthropic said Tuesday night that its AI model called Claude Fable 5 is now widely available. The post Trump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm appeared first on SecurityWeek.
FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks
Researchers say credentials harvested from hundreds of thousands of FortiGate firewalls are being used to facilitate ransomware attacks by the INC and Lynx operations. The post FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks appeared first on SecurityWeek.
How to Conduct a Successful Audit of AI-Driven Software Development
As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. The post How to Conduct a Successful Audit of AI-Driven Software Development appeared first on SecurityWeek.
New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure
Hackers are targeting NetScaler appliances using public PoC code to retrieve arbitrary memory content in the HTTP response. The post New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure appeared first on SecurityWeek.
Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution
The DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor’s sandbox and execute arbitrary code on the underlying operating system. The post Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution appeared first on SecurityWeek.
Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices
NetNut rented access to millions of compromised devices, allowing cybercriminals and nation-state actors to mask their identities during attacks. The post Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices appeared first on SecurityWeek.
Alleged Scattered Spider Hacker Extradited to US
Prosecutors say 19-year-old Peter Stokes was a member of Scattered Spider, the hacking group linked to more than 100 network intrusions and over $100 million in ransom payments. The post Alleged Scattered Spider Hacker Extradited to US appeared first on SecurityWeek.
Medtronic Data Breach Impacts 3.8 Million People
In April, ShinyHunters accessed the company’s corporate IT systems and stole patients’ personal and medical information. The post Medtronic Data Breach Impacts 3.8 Million People appeared first on SecurityWeek.
Agentic AI Used to Conduct Ransomware Attack via Langflow
Attack demonstrates how LLM agents can combine known exploitation techniques with real-time reasoning to automate complex, multi-stage intrusions. The post Agentic AI Used to Conduct Ransomware Attack via Langflow appeared first on SecurityWeek.
PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
Cybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data. The stealer, discovered by Jamf Threat Labs, is distributed as a compiled AppleScript (.scpt) file impersonating Maccy, a legitimate open-source clipboard manager. It has been codenamed PamStealer owing to its […]
FBI Seizes NetNut Proxy Platform, Popa Botnet
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa […]
La resiliencia de identidad empieza donde termina el ‘backup’
La identidad se ha convertido en el nuevo perímetro corporativo. En un entorno dominado por modelos híbridos, servicios en la nube y arquitecturas zero trust, prácticamente todas las operaciones dependen de mecanismos de autenticación y autorización. Cuando estos sistemas dejan de funcionar, el impacto va mucho más allá de una interrupción tecnológica: se paralizan procesos […]
Why AI savings are an illusion without process re-engineering
The PC was heralded as revolutionary; it was going to save time, revolutionize our work… But it became an opportunity lost. Paper became digital files. Filing cabinets became shared drives. Memos became email. We sometimes worked faster. We did not necessarily work differently. And we certainly did not work more efficiently. The underlying logic: approval […]
4 reasons AI projects fail that have nothing to do with technology
Having worked with dozens of companies in various stages of AI adoption, I’ve had a front-row seat to the myriad reasons (and sometimes excuses) why AI projects fail to launch, fail to make it past pilots or fail to deliver business value and ROI. While every organization’s circumstances are unique, the root causes are often […]
How AI automation is reshaping the IT leadership pipeline
In the wake of AI, the early-talent job market is in decline across all jobs and industries, with a 10% drop since 2021, according to a recent report from SAP. When isolated for the top 10 most common entry level job titles, including software engineer, customer support, and data analyst, job openings declined 35% from […]
IT governance: Best practices for aligning IT and business strategy
The unprecedented pace of AI’s evolution and its use have put a strain on organizations. According to a 2026 study from the IBM Institute for Business Value study, 77% of organizations reported that AI adoption is outpacing their governance capabilities. Although governance practices — including the discipline of IT governance — predate AI, the challenges […]
Addressing consequence blindness
Enterprises do not suffer from a lack of oversight. They have dashboards, risk forums, architecture boards, vendor reviews, cyber controls, transformation offices, capital committees, regulatory programs, audit findings, service reports and enough status updates to make even the most patient executive reach for stronger coffee. The issue is not that senior leaders fail to recognize […]
Agentic AI puts $234B in enterprise SaaS spending at risk, Gartner says
AI agents are poised to challenge traditional enterprise software business models, placing up to $234 billion in application software spending at risk by 2030 as they increasingly bypass human users and interact directly with business systems, according to Gartner. “You are no longer buying software primarily for people; you are increasingly buying it for agents,” […]
Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices
Google has significantly degraded NetNut, one of the biggest networks that turns home devices into rented relays for other people’s traffic. Working with the FBI, Lumen, and others, Google’s Threat Intelligence Group (GTIG) said this week it had reduced the network’s pool of usable devices by millions. Google identifies NetNut, also tracked as Popa, as a network […]
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. “Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral
Global Schools Holdings Cites Two Injunctions in a Bid to Chill Our Reporting. It Won’t Work.
My About page is pretty clear about legal threats: If you want to send me legal threats about my reporting or comments, knock yourself out, but don’t be surprised to see me report on your threat, any confidentiality sig blocks you may attach notwithstanding. I have been threatened with lawsuits many times, and to be… […]
26-00309.pdf
26-00309.pdf Anonymous (not verified) Thu, 07/02/2026 – 12:50 Case ID 26-00309 Forum FINRA Document Type Award Claimants TradeStation Securities, Inc. Respondents James Lightning Neutrals Cary Valden Sorensen Hearing Site Houston, TX Award Document 26-00309.pdf Documentum DocID cb64dc17 Award Date Official Wed, 07/01/2026 – 12:00 Related Content Off Claimant Representatives Myra C. Mormile-Wolper Respondent Representatives James […]
26-00329.pdf
26-00329.pdf Anonymous (not verified) Thu, 07/02/2026 – 12:45 Case ID 26-00329 Forum FINRA Document Type Award Claimants Tuyet Burke Respondents Alpaca Securities LLC Neutrals Harlita R. Tomlinson Hearing Site Indianapolis, IN Award Document 26-00329.pdf Documentum DocID aedcf8f8 Award Date Official Thu, 07/02/2026 – 12:00 Related Content Off Claimant Representatives Tuyet Burke Respondent Representatives John H. […]
Cyber Alert: NGINX Critical Vulnerability
Cyber Alert: NGINX Critical Vulnerability K30658 Thu, 07/02/2026 – 11:29 FINRA firms should be aware of a security vulnerability that poses potentially severe risks to organizations using NGINX products. FINRA recommends sharing this Cyber Alert with appropriate information technology and information security personnel—as well as any third-party vendors that may use NGINX—to identify whether your […]
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
This week’s security news is mostly about weak spots. Browsers, bots, sandboxes, AI systems, and email flows all show the same problem in different ways. Everything looks normal until someone tests a small gap and finds a way through. This is not one big break. It is small permissions, weak checks, open systems, and normal […]
OLD MISSION CAPITAL, LLC
OLD MISSION CAPITAL, LLC fnrw-backend Thu, 07/02/2026 – 11:01 MC ID OLDM MC Reporter Type Single Dealer Trading System MC Paragraph MC Link https://www.oldmissioncapital.com MC Last Updated Thu, 07/02/2026 – 11:01
OLD MISSION MARKETS LLC
OLD MISSION MARKETS LLC fnrw-backend Thu, 07/02/2026 – 10:46 MC ID OLMN MC Reporter Type Broker-Dealer MC Paragraph MC Link https://www.oldmissioncapital.com MC Last Updated Thu, 07/02/2026 – 10:46
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that’s designed to gain surreptitious access to a victim’s email correspondence via the Google API. “In this campaign, the attackers focused their attention on corporate email communications hosted on Gmail, targeting access compromise via APIs,” Kaspersky said in a detailed […]
ST Engineering iDirect iQ-Series Terminals
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals are affected: Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057) 3315‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057) 9‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057) CVSS Vendor Equipment Vulnerabilities […]
Gardyn IoT Hub
View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control IoT Hub managed devices. The following versions of Gardyn IoT Hub are affected: Home Firmware Studio Firmware Cloud API <2.12.2026 (CVE-2026-13768, CVE-2026-55726, CVE-2026-54477) CVSS Vendor Equipment Vulnerabilities v3 10 Gardyn Gardyn IoT Hub Use of Hard-coded Credentials, Exposure of […]
CubeSpace CW0057 Reaction Wheel
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to upload arbitrary malicious firmware to the device. The following versions of CubeSpace CW0057 Reaction Wheel are affected: CW0057 Reaction Wheel CVSS Vendor Equipment Vulnerabilities v3 6.1 CubeSpace CubeSpace CW0057 Reaction Wheel Improper Verification of Cryptographic Signature Background Critical Infrastructure Sectors: Communications Countries/Areas […]
Identity Lifecycle Management Wasn't Built for AI Agents
Identity lifecycle management was architected around a person with an employment record, a manager, and a departure date. AI agents have none of those. As autonomous principals proliferate across enterprise environments, the governance model built for humans develops structural blind spots that traditional IGA tools weren’t designed to detect. This guide covers where that model […]
Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack
Citrix urges customers to patch NetScaler after fixing six vulnerabilities, including the HTTP/2 Bomb flaw and a high-severity CitrixBleed-style information disclosure bug. The post Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack appeared first on SecurityWeek.
Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities
Seven of the security defects have a maximum severity rating of 10/10 and could lead to arbitrary code execution. The post Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities appeared first on SecurityWeek.
Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings
Microsoft’s new Teams admin policy requires organizer approval for external AI bots, giving organizations greater visibility and control over automated participants in sensitive meetings. The post Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings appeared first on SecurityWeek.
CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability
CISA says threat actors are exploiting a recently patched SharePoint remote code execution vulnerability (CVE-2026-45659). The post CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability appeared first on SecurityWeek.
‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials
Researchers show how context manipulation can cause agentic browsers to abandon safety guardrails and exfiltrate sensitive credentials. The post ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials appeared first on SecurityWeek.
Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability
A PoC exploit has been available since public disclosure, and the first exploitation attempts were observed last week. The post Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability appeared first on SecurityWeek.
Argo CD flaw shows why GitOps infrastructure should be treated as tier zero
A newly disclosed vulnerability in Argo CD is drawing attention to the security risks of GitOps platforms, with researchers warning that the flaw could allow attackers who gain a foothold inside a Kubernetes cluster to execute code and manipulate application deployments. Security firm Synacktiv said in a report that the flaw affects Argo CD’s repo-server […]
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job: breaking in, stealing credentials, moving deeper into the network, then encrypting and wiping a company’s […]
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. “An operator tied to FortiBleed’s infrastructure was found actively working negotiation panels for both groups, tying mass FortiGate credential theft directly to ransomware deployment
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs. Run one, and it quietly lifts your saved passwords, browser cookies, and files, then hands the […]
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deserialization of untrusted data. The issue
ISC Stormcast For Thursday, July 2nd, 2026 https://isc.sans.edu/podcastdetail/9992, (Thu, Jul 2nd)
Post Content
Sandbox bypass flaws in Cursor IDE highlight prompt injection as an RCE vector
Researchers have discovered two vulnerabilities in the widely used Cursor AI-enabled integrated development environment (IDE) that can be exploited through prompt injection to achieve remote code execution (RCE). The two flaws, tracked as CVE-2026-50548 and CVE-2026-50549, allow attackers to break out of Cursor’s command execution sandbox, the protective layer that’s supposed to prevent the internal […]
25-00946.pdf
25-00946.pdf Anonymous (not verified) Wed, 07/01/2026 – 17:25 Case ID 25-00946 Forum FINRA Document Type Award Claimants Bryan Rigg Ian Rigg Justin Rigg Sophia Rigg Respondents Pershing LLC Pershing Advisor Solutions LLC Cantella & Co., Inc. Neutrals Dineo Coleman Gary Gayle D. Anthony Cecelia Dianne Jefferson Hearing Site Dallas, TX Award Document 25-00946.pdf Documentum DocID […]
26-00299.pdf
26-00299.pdf Anonymous (not verified) Wed, 07/01/2026 – 17:25 Case ID 26-00299 Forum FINRA Document Type Award Claimants Equitable Advisors, LLC Equitable Network LLC Respondents Olivier Marcelin Neutrals Cynthia A. DiMarco Hearing Site New York, NY Award Document 26-00299.pdf Documentum DocID 456958f4 Award Date Official Wed, 07/01/2026 – 12:00 Related Content Off Claimant Representatives Andrea Villalpando […]
25-01988.pdf
25-01988.pdf Anonymous (not verified) Wed, 07/01/2026 – 17:25 Case ID 25-01988 Forum FINRA Document Type Award Claimants Angelo Piccone Respondents Richard Carlesco Neutrals Tracy L. Allen Hearing Site Buffalo, NY Award Document 25-01988.pdf Documentum DocID a297a5a9 Award Date Official Wed, 07/01/2026 – 12:00 Related Content Off Claimant Representatives Angelo Piccone Respondent Representatives James L. Kopecky
24-02150.pdf
24-02150.pdf Anonymous (not verified) Wed, 07/01/2026 – 17:25 Case ID 24-02150 Forum FINRA Document Type Award Claimants Michelle Feland Respondents Raymond James Financial Services, Inc. Neutrals Michael D. Briggs Hearing Site Bismarck, ND Award Document 24-02150.pdf Documentum DocID 7f6d00a5 Award Date Official Tue, 06/30/2026 – 12:00 Related Content Off Claimant Representatives Daniel J. Frisk Respondent […]
25-02797.pdf
25-02797.pdf Anonymous (not verified) Wed, 07/01/2026 – 17:25 Case ID 25-02797 Forum FINRA Document Type Award Claimants Paul Valdivia Respondents Fidelity Brokerage Services LLC Neutrals John P. Cullem Andrea U. Calve Linda J. Baer Hearing Site Columbia, SC Award Document 25-02797.pdf Documentum DocID 91f846c6 Award Date Official Wed, 07/01/2026 – 12:00 Related Content Off Claimant […]
Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters
Argo CD, a widely used tool for deploying software to Kubernetes, has an unpatched flaw in its repo-server component that lets an unauthenticated attacker run code, provided they can reach the component’s internal network port. Synacktiv, which found the bug, says it can lead to a full cluster takeover. There is no fix and no […]
19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges
A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of Justice announced on July 1. Peter Stokes, 19, a dual U.S. and Estonian citizen, appeared in a Chicago federal court on June 30, where a judge ordered […]
A framework for operational autonomy: Integrating CloudOps, FinOps and AIOps
Operational autonomy is quickly becoming one of the defining capabilities of a modern enterprise. As digital estates become more distributed, cloud environments more dynamic and AI consumption more expensive and less predictable, traditional operating models begin to show their limits. Teams can no longer rely only on manual oversight, disconnected monitoring tools or periodic financial […]
SAP reshuffles exec oversight of AI
For the second time this year, SAP is shaking up its executive ranks as it continues its quest to adapt to an AI-centric world. The first shake-up came in March, with the creation of the Customer Value Group, merging SAP’s Customer Success and Customer Services and Delivery organizations to put sales, delivery, services, and support […]
Shadow agents: How IT leaders must govern ‘headless’ AI before it breaks the enterprise
Earlier this year, I was running my own local AI agent, a system I built called LaptopAI-Agent, which uses a LangGraph reasoning loop, a local Ollama model and a set of tools that can read files, query my git repositories and monitor system processes, all running entirely on my laptop with no cloud calls. I […]
Using AI to reinvent care delivery at Novant Health
In healthcare, the pressure to improve outcomes while reducing costs has never been greater. Yet many organizations are still applying AI to existing systems rather than using it to fundamentally change them. At Novant Health, that shift is being driven in part by establishing the chief AI officer role last year, which Vijay Sankararaman has […]
7 ways to ensure effective digital leadership in the age of agentic AI
Research suggests pioneering CIOs must blend AI agents with human skills. So how can digital leaders establish an effective balance between agentic and professional capabilities, and successfully lead their people into the agentic-enabled future? Here are seven best-practice tips from the experts. 1. Get past the fear. Huy Dao, director of data and ML platform […]
US reverses export restrictions on Anthropic’s Fable 5, Mythos 5 AI models
The US government has reversed export restrictions on Anthropic’s frontier AI models Fable 5 and Mythos 5, allowing the company to resume global access after nearly three weeks of disruption triggered by concerns over the models’ cybersecurity capabilities. “As of today, June 30, the export controls on Fable 5 and Mythos 5 have been lifted,” […]
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT. Kaspersky said the activity is part of a “massive, multi-domain, multi-language” campaign that distributes malicious installer archives hosted on spoofed websites. These installers masquerade as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam, among others.
VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer
Cybersecurity researchers have flagged a new multi-stage malware delivery attack chain that uses social engineering and Blogger pages to deliver an information stealer called PureLogs. The activity has been codenamed VEIL#DROP by Securonix. It’s suspected that the initial payloads are distributed either via spear-phishing or a drive-by compromise, which occurs when an unsuspecting user lands […]
Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures
A Brazilian banking trojan called Ousaban is going after Windows users who bank in Spain and Portugal. Fortinet’s FortiGuard Labs identified the campaign in May 2026. It opens with a phishing PDF disguised as a corrupted file, checks that the visitor is really in Spain or Portugal, and hides its real payload inside an image. The goal […]
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe has released patches for multiple maximum-severity security flaws impacting Adobe ColdFusion and Adobe Campaign Classic. The ColdFusion updates “resolves critical and important vulnerabilities that could lead to arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass,” Adobe said in an alert released Tuesday. The vulnerabilities are listed
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-45659 Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing […]
Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History
The ruling was made in the case of a bank robber whose identity was discovered through a geofence warrant. The post Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History appeared first on SecurityWeek.
Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat
Chris Thompson’s journey took him from hacking game controls as a teenager to founding IBM’s X-Force Red team. The post Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat appeared first on SecurityWeek.
Aflac Japan Data Breach Impacts 4.38 Million
Hackers accessed the insurance giant’s policyholder portal multiple times between June 15 and June 25. The post Aflac Japan Data Breach Impacts 4.38 Million appeared first on SecurityWeek.
Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks
Decades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors. The post Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks appeared first on SecurityWeek.
BlueHammer Vulnerability Exploited in Ransomware Attacks
The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released. The post BlueHammer Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek.
Google Patches 382 Chrome Vulnerabilities
Fifteen of the newly patched flaws have been rated ‘critical’ and 67 have been rated ‘high severity’. The post Google Patches 382 Chrome Vulnerabilities appeared first on SecurityWeek.
Massive Password Spray Campaign Targeting Azure CLI
Hackers were seen making over 81 million login attempts originating from systems associated with hosting provider LSHIY. The post Massive Password Spray Campaign Targeting Azure CLI appeared first on SecurityWeek.
Dawnguard Raises $6.3 Million for Security Architecture Automation Platform
The company has publicly launched its solution to help organizations design, build, and operate secure cloud systems. The post Dawnguard Raises $6.3 Million for Security Architecture Automation Platform appeared first on SecurityWeek.
Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari
The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users. The post Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari appeared first on SecurityWeek.
Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors
From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. The post Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors appeared first on SecurityWeek.
Acknowledgement of receipt
Acknowledgement of receipt Dear Contact Thank you for your message. You will find the answer to the vast majority of requests sent to us on the following page https://www.edpb.europa.eu/contact_en. We will respond further only if your request is not already addressed on that page. Please note that the EDPB/EDPB Secretariat will not respond to abusive […]
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware
Large language models keep inventing web addresses that do not exist. Attackers have started buying those made-up domains before anyone else can, then hosting phishing pages on them to catch traffic that AI tools point their way. Palo Alto Networks’ Unit 42 calls the trick phantom squatting, and its new research shows it is already happening in […]
Detection engineering: A programmatic approach to identifying cyber threats
Detection engineering, which was once a niche practice among mostly large companies, appears to have evolved into a capability that organizations across industries now consider essential to their security operations. What is detection engineering? Detection engineering is about creating and implementing systems to identify potential security threats within an organization’s specific technology environment without drowning in […]
Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls
Anthropic is putting Claude Fable 5 back online worldwide. On June 30, the U.S. Commerce Department lifted the export controls it had imposed on Fable and its more tightly controlled sibling Mythos 5 about two and a half weeks earlier. Fable 5 returns to users on Wednesday, July 1, across Claude.ai, the Claude Platform, Claude Code, […]
Risky Business #844 -- China closes AI vulndev gap as USA lifts Fable ban
On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover: Anthropic’s Fable 5 returning while OpenAI’s GPT-5.6 gets thrown in model jail Distillation, cheap tokens, and AI chat harvesting is an industry in China Edge becomes a lolbin via a new malicious extension An Iranian APT boss’s […]
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
Cybersecurity researchers have warned of a “massive, ongoing, automated password spray attack” aimed at Microsoft’s Azure command-line interface (CLI), compromising dozens of accounts in the process. The activity, per Huntress, originates from an IPv6 address range (2a0a:d683::/32) controlled by internet infrastructure provider LSHIY LLC (AS32167). “Between June 12 and June 26, the threat
Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery
ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake “prove you’re human” pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise. The same research also turned up a […]
Why Ask Credentials If There Are Secret Codes?, (Wed, Jul 1st)
This morning, an interesting phishing email hit my mailbox. It targets Metamask[1], a cryptocurrency wallet, available as a browser extension and a mobile app, that lets users store, send, and receive crypto money. It’s pretty popular, so a juicy target for criminals. In February, I already mentioned a campaign against them[2].
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition. The vulnerabilities are listed below – CVE-2026-8451 (CVSS score: 8.8) – An insufficient input validation
ISC Stormcast For Wednesday, July 1st, 2026 https://isc.sans.edu/podcastdetail/9990, (Wed, Jul 1st)
Post Content