What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,042 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 2d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 3d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 4d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 4d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 5d ago
-
13th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximat…
-
Threat Actors Achieve Persistence After SQL Injection
See how a threat actor used SQL injection and BadIIS to gain persistence, disable Windows Defender, and quietly install a cryptominer.
-
CVE-2008-4128: Cisco IOS — Cisco IOS Cross-Site Request Forgery Vulnerability
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" …
-
From Prompt Engineering to Intent Engineering
Intent Engineering/images/intent-engineering.webp/images/intent-engineering.webp I think the number one thing people could do right now to be more effective with AI is switch from Prompt Engineering/blog/ai-is-mostly-prompting to …
-
Minimizing Machine Work Maximizes Human Work
Minimizing machine work maximizes human work header/images/minimizing-machine-work-maximizes-human-work.webp/images/minimizing-machine-work-maximizes-human-work.webp Behavioral geneticists like Robert Plominhttps://en.wikipedia.or…
-
Glendale Community College: 793,925 accounts breached
Data exposed: Academic records, Dates of birth, Email addresses, Genders, Government issued IDs, Names, Phone numbers, Physical addresses. In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" ext…
-
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42 .
-
Recreating the Bell Labs Cafeteria
Bell Labs cafeteria header/images/recreating-the-bell-labs-cafeteria.webp/images/recreating-the-bell-labs-cafeteria.webp Anthropichttps://www.anthropic.com's Claude is named after Claude Shannonhttps://en.wikipedia.org/wiki/Claude…
-
AI Blogging From Inside Vim
A human hand writing a manuscript while a mechanical hand places a small patch of text with tweezers/images/ai-blogging-from-inside-vim.webp/images/ai-blogging-from-inside-vim.webp Daniel didn't write this one. I'm Kai, his AI ass…
-
The Good, the Bad and the Ugly in Cybersecurity – Week 28
Authorities launch Operation First Light 2026, attackers deploy Forg365 to hijack Microsoft accounts, and rival cyberspies breach Pakistani police networks.
-
Building Our Future Together
In my first weeks as Executive Director of EFF, I’ve been reminded every day how consequential this moment is in determining what kind of future we will have. We are on the edge. What each one of us steps up to do – with our exper…
-
Automated Moderation Is Here to Stay—Accountability Must Keep Pace
This post is part 2 in a series about automated content moderation. Read the first post here . When whistleblower Frances Haugen leaked a set of documents from Meta in 2020, among the revelations was a jarring statistic: The compa…
-
Guide to System Hardening: Checklist & Best Practices [2026] | Huntress
Threat actors want an easy way in. Use this practical system-hardening checklist to close gaps and learn how to secure your environment today.
-
Breach of Confidence: 10 July 2026
I ve started replying to emails with sorry, Claude ate it and people seem to accept this without question. We truly live in remarkable times. Claude Desktop becomes a sleeper agent Red teamers compromised an email inbox, synced a …
-
Weekly Cyber Update: 10 July 2026
A new agentic ransomware discovery; a maximum severity ColdFusion bug to patch; a government push for Cyber Essentials across the supply chain; and a new NCSC plan for cyber defence The Cyber Threat Intelligence Briefing is a week…
-
CVE-2026-56291: Balbooa Forms — Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
-
CVE-2026-48939: iCagenda iCagenda — iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
-
"We Want Texans to Know Their Rights": Q&A with Mayday Health on the Impact of Surveillance on Abortion Care
Last May, EFF reported that a sheriff’s office in Texas searched data from more than 83,000 automated license plate reader (ALPR) cameras to track down a woman suspected of self-managing an abortion. ALPRs are promoted as tools fo…
-
The House Passed The KIDS Act—The Senate Should Reject It
Last week, the House voted on the KIDS Act , a disjointed package of legislation that seeks to control Americans’ web browsing and private messaging. The package combines a revised version of the Kids Online Safety Act ( KOSA), wi…
-
Patch for Windows Defender 0-day could allow attackers to fill hard disk
The feud between NightmareEclipse and Microsoft shows no signs of resolving soon.
-
Reduce Human Risk | Build a Strong Security Awareness Training Program | Huntress
Build a security awareness training program that actually changes user behavior. Huntress Managed SAT delivers engaging content, phishing sims, and results.
-
I Think AGI Just Happened
Claude Tag AGI moment header/images/claude-tag-is-agi.webp/images/claude-tag-is-agi.webp I think we just saw the birth of AGI, and it's from the most unexpected place. At least for me. I think it arrived in the form of a product f…
-
European Commission Chooses to Keep EU Users Locked Up Behind Big Tech’s Gates
Users are always seeking more control over their social networking experience to make it better, whether to improve privacy or enhance flexibility. Interoperability between social networking platforms like Facebook and TikTok has …
-
I Wrote a New Book for Corelight
TLDR: I wrote a new book for Corelight called NDR Essentials . It's free at that link. This is the 10th book that I've authored or co-authored. The rest are all posted at taosecurity.com . Why? It was time . That’s what I thought …
-
Conditional Access Misconfigurations Exposed 55 Orgs with MFA On
Two Microsoft 365 attacks got through Conditional Access policies that seemed fully configured. Learn what went wrong and how Huntress Managed ISPM catches these gaps first.
-
CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware | Huntress
Huntress has observed a series of strikingly similar intrusions beginning with CitrixBleed 2 exploitation, employing novel local privilege escalation techniques, and ending in Dragonforce ransomware.
-
Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk
Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing up your interview technique, take a closer look at who is really behind it. Read…
-
Google's New Remote Attestation Scheme is As Bad As Its Old One
Google owes its existence to the open web, but today, its technological “innovations” have much to do with locking users into a “walled garden.” The latest of these is “ reCAPTCHA Mobile Verification ,” an experimental initiative …
-
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself
A 15-year-old boy asked a chatbot for help - and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, "J…
-
AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration | Huntress
Threat actors are now using AI to generate custom PowerShell scripts for Active Directory attacks. Our team analyzed real vibe-coded malware and what it means for defenders.
-
Weekly Update 511: Live from my Riad in Marrakech
How s this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow Anyway, about those data breaches... This week I m talking about the futility of attempting to remove piss from a pool , ye…
-
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake…
-
LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress
LoTL abuse hides in plain sign, using legit tools like PowerShell and RMM software. Learn how to spot the warning signs that separate from routine IT work.
-
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
A cybercrime campaign combined a loader-as-a-service framework and DLL sideloading via a Go-compiled fake MpClient.dll, a novel evasion layer combination. The post Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File In…
-
Automated Moderation Is Here to Stay
This blog post is part 1 of a 2-part series. The second part sets out recommendations for companies and policymakers. Six years ago—one month into a global pandemic—we argued that the automated moderation processes many platforms …
-
Help EFF Cut the AI Hype
In the global race to build and dominate the AI industry, it can sure seem like the interests of ordinary people sit last on the agenda. It's just the opposite for EFF. While companies furiously jam AI tools into their veins and y…
-
Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud
Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims. Read more in my article on the Hot for Security blog.
-
Meta Phishers Abuse Business Account Manager Service | Huntress
Huntress is tracking a threat actor group as they evolve a phishing attack that uses a Facebook feature to send the initial spam lure.
-
Getting to know: Gemma Ungoed-Thomas
Gemma Ungoed-Thomas has spent over two decades performing what she considers the best and most exciting roles in Government and for the very first time, she s ready to talk about it in this exclusive interview with Assured s Elean…
-
5 Cybersecurity Lessons From Taylor & Travis’s Wedding
“Long Live” strong security! Taylor Swift & Travis Kelce’s wedding offers real cybersecurity lessons on layered defense, MFA, deception tools, and more.
-
CVE-2026-48908: JoomShaper SP Page Builder — JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
-
CVE-2026-55255: Langflow Langflow — Langflow Authorization Bypass Through User-Controlled Key Vulnerability
Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
-
CVE-2026-56290: Joomlack Page Builder — Joomlack Page Builder Improper Access Control Vulnerability
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
-
CVE-2026-48282: Adobe ColdFusion — Adobe ColdFusion Path Traversal Vulnerability
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
-
AI Arms Race in Recruiting
Recruiters and candidates are both using AI to game the process. Here's what that means for hiring quality, and what to do about it.
-
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus…
-
6th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 6th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES River Bank Trust, a US financial institution, has experienced a ransomware incident …
-
Plain Text Passwords: The Risks of Storing Them
Plain text passwords are a critical security risk. See a real attack where exposed credentials led to a breach and how Huntress helps prevent it.
-
"Having Birth": What Florida's New Security Law Is Actually For
Building a family in Florida now depends on where you were born. The Governor says that's the point. There's also prison time.
-
Why Don't We Put Handguns in the Convenience Aisle?
We don't put handguns in the convenience aisle/images/handguns-in-the-convenience-aisle.webp/images/handguns-in-the-convenience-aisle.webp A quick thought on this whole "control of AI models" debate. Handguns and Fentanyl are avai…
Last fetch · 0 new