What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,039 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 3d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 4d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 4d ago
-
CVE-2026-50522: Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
-
We Wrote an Academic Paper on Conficker in 2026
And it s over 16,000 words. While the rest of the cybersecurity world moves on with AI and next generation technologies, the OT cybersecurity community is oft left behind, dealing with increasingly unique legacy challenges and tec…
-
What Are Initial Access Brokers?
Discover what initial access brokers (IABs) are, how they compromise networks to sell their access to other attackers, and how to protect your business.
-
Apps targeted at US troops contain Chinese and Russian code
More than one-eighth of apps analyzed contained foreign code.
-
A new extortion cocktail: office printers, small ransoms, and BitLocker
We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.
-
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Ukraine's computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code. Read more in my ar…
-
New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.
-
Weekly Update 513: Clauding The Home Network
I reckon this week s video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - if ever there was an actual value proposition for AI it s taking lots o…
-
CVE-2026-60137: WordPress Core — WordPress Core SQL Injection Vulnerability
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code e…
-
CVE-2026-63030: WordPress Core — WordPress Core Interpretation Conflict Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
-
CVE-2026-0770: Langflow Langflow — Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
-
CVE-2021-27137: DD-WRT DD-WRT — DD-WRT Stack-Based Buffer Overflow Vulnerability
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
-
Protect Your Privacy with California's DROP Tool
Are you a California resident? Then we've got exciting news for you: there's a tool just for you that lets you take a single, relatively easy step to protect your privacy. It's called a DROP request. (That's Delete Request and Opt…
-
Suno: 55,282,226 accounts breached
Data exposed: Email addresses, Names, Partial credit card data, Phone numbers, Physical addresses, Purchases. In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following ye…
-
An Explosion of Surveillance Towers is Coming to U.S. Borders, Costing Over $1 Billion
A new report from the Government Accounting Office reveals that the Department of Homeland Security (DHS) plans to nearly triple the number of surveillance towers along U.S. borders, from the current 830 to 2,300 by 2034. DHS expe…
-
“Stealth Crawlers” Are Not a Threat to the Open Web. Bills Targeting Them Would Be.
There’s a new boogeyman in the battles over AI: so-called “stealth crawlers.” We’ll admit it—the term “stealth crawlers” sounds quite nefarious. In reality, they’re anything but. “Stealth crawlers” are simply automated tools to ac…
-
Pay up or not? Ransomware surge has victims facing tough choices.
Governments look at banning ransom payments in face of increasingly sophisticated threats.
-
How We Cut Noise Before It Hits the Analyst
Learn how Huntress' AI signal triage and AI-powered SOC triage cut noise before it reaches human analysts. And discover why that matters for response times.
-
The Agentic SOC: Transforming Data into Defensive Velocity
Transform SOC data chaos into autonomous intelligence with modern AI pipelines and agentic AI to empower human analysts.
-
From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab
Executive summary An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructu…
-
A stitch in time saves… 29!
Privyet, droogs! Yes – we ve been stitching time and saving the world a full 29 years already! And last Friday we celebrated those 29 years in typically unrestrained, loud, colorful, and rock rollicking style. Also typical: the ve…
-
20th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst Young, a global accounting and professional services company, has disclosed a…
-
Paidwork: 23,272,765 accounts breached
Data exposed: Bank account numbers, Dates of birth, Device information, Education levels, Email addresses, Financial transactions, Genders, IP addresses, Names, Passwords, Personal interests, Phone numbers, Physical addresses, Pro…
-
AI Is Just Thinking and Doing
Charcoal sketch of business figures feeding a blank scroll into a massive thinking machine/images/ai-is-thinking-and-doing.webp/images/ai-is-thinking-and-doing.webp One useful way to cut through noise and hype in AI conversations …
-
The Broken Link In Cybersecurity Nobody Wants To Fix – Is It What You Think?
There s a problem in cybersecurity I haven t been able to let go of these past few weeks. I ve been returning to it and looking at it from different angles. To begin, I asked whether we re solving the wrong problem in cybersecurit…
-
Joseph Steinberg To Speak At 2026 International Summit Against Human Trafficking
Joseph Steinberg will speak at the US Capitol on Thursday, July 23rd, as part of the 5th International Summit Against Human Trafficking. The International Summit Against Human Trafficking brings together survivors, leaders, advoca…
-
Kimi K3 Might Have Just Started a Crash of the US Economy
Kimi K3 and the US economy/images/kimi-k3-us-economy-header.webp/images/kimi-k3-us-economy-header.webp Not enough people realize that China's push for open source AIhttps://www.google.com/search?q=popular+Chinese+AI+models is an e…
-
Google’s Gemini lets strangers send messages from your locked Android phone
Gemini, Google's AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone. Read more in my article on the Hot …
-
It’s Not Safe To Pay SafePa
Huntress has observed Akira ransomware affiliates in action, as well as ReadText34 and INC ransomware being deployed.
-
Victory! Flock Ends Rollout of Audio “Distress Detection” of Human Voices
Reversing course, Flock Safety—the surveillance technology vendor most known for its extensive network of automated license plate readers — has announced that it will end a pilot for its acoustic gunshot detection devices to ident…
-
Your Vision. Your Legacy. Your Future.
This month, we celebrate 36 years of EFF and a mission that is bigger than any one of us. Thanks to EFF, communities around the world are demanding that technology protects their freedom, advances justice, and opens doors to oppor…
-
The Good, the Bad and the Ugly in Cybersecurity – Week 29
Authorities sanction Russian-based cybercriminals, attackers deploy Starland malware, and 300 imposter GitHub repos push BoryptGrab infostealer.
-
Breach of Confidence — 17 July 2026
I ve spent the week watching people argue about whether AI will replace security analysts whilst ignoring the fact that most organisations still can t tell you where their crown jewels are stored. Priorities remain wonderfully int…
-
How the Watch Dogs Video Game Series Mirrored and Predicted Real-World Digital Rights Issues
When Ubisoft's Watch Dogs 2 was released in 2016, it was a headtrip for those of us working on digital-rights issues in the Bay Area. During the day, I'd fight tech-authoritarianism from EFF's San Francisco offices and then, at ni…
-
Microsoft VSS: Still Essential, But Not the Whole Story
Microsoft VSS remains a cornerstone of Windows data protection, but its architectural limits matter. Learn when to rely on it and when to go beyond it.
-
Weekly Cyber Update: 10 July 2026
A new campaign threatens vulnerable content management systems; Progress Software patches a zero-day; Microsoft issues a record patch haul; and Russia’s FSB is targeting routers again. The Cyber Threat Intelligence Briefing is a w…
-
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appea…
-
FreeBSD Released the Most Security Advisories in Project History in June 2026
On average, the FreeBSD security team releases about 2 security advisories per month. AI has changed this. In April, the project released 8 advisories, with 6 powered by AI . In May, the count decreased slightly to 7. Today I took…
-
AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report
Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report appeare…
-
Anubis ransomware: what you need to know
The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.
-
Now, even Russia's most elite hackers are using Clickfix to infect devices
The social-engineering technique has primarily been a tool of financially motivated criminals.
-
Begun, the Patch Wars have
Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.
-
Custom HTML for Custom Phishing: Make the Fake Feel Real
Build personalized, realistic phishing scenarios with Huntress Custom HTML for Custom Phishing, tailored to your organization's unique risks and vendors.
-
Meet Athena: Huntress' Agentic SOC Analyst
Learn how Huntress' Athena brings agentic AI to the SOC, investigating signals end-to-end while human analysts own the final call.
-
HelloNet campaign: new malicious modules launched through the ViPNet update system
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
-
44 years of Blade Runner.
In the summer of 1982 – 44 years ago – arguably one of the greatest works in the history of Hollywood-kind premiered: Blade Runner. But in Chinese numerology, 44 is a bad number ( four sounds a lot like death in Mandarin), so, sho…
-
GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.
-
The Hunter's Paradox: Is it time to embrace automated threat hunting?
Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like.
-
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.
-
EFF and ARTICLE 19 Submission to the European Commission on the DSA Trusted Flagger Guidelines
EFF and ARTICLE 19 have submitted joint comments to the European Commission on draft guidelines for the Digital Services Act’s trusted flagger mechanism. Having long advocated for a DSA that protects freedom of expression while pr…
Last fetch 5m ago · 0 new · 2 source error(s)