Cyber Security News
- Get link
- X
- Other Apps
"Zero Trust Network (ZTNA) Solutions: Our top picks by use case (2026)."
Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents. Accessed on 25 July 2026, 1742 UTC.
Content and Source compiled by https://feedly.com.
https://feedly.com/i/collection/content/user/f401222a-bca6-4c45-9cc1-183f239e8d86/category/0ce2e207-9c3a-4916-959e-00213c9be23b
Please check link or scroll down to read your selections. Thanks for joining us today.
Russ Roberts (https://www.hawaiicybersecurityjournal.net).
Cyber Security News
168
Today
Cyber Security News / 2h
The VPN is finally dying, and ZTNA is what replaces it — least-privilege access to individual applications instead of a tunnel onto your whole network. But the right ZTNA depends entirely on who you are: a 40-person startup replacing a clunky VPN needs a very different tool than a global enterprise consolidating onto SASE. So this guide matches eight ZTNA solutions to the situations where each ge
Yesterday
Infostealer malware has become the connective tissue of modern cybercrime, quietly harvesting credentials and session data that ransomware crews later use to walk straight into corporate networks. Documented by Darkowl, ransomware operators no longer need to breach firewalls when infostealer malware has already handed them the keys. Infostealer malware runs quietly on infected endpoints, exfiltra
Cyber Security News / 12h
Google Threat Intelligence Group (GTIG) announced a major overhaul to how it tracks and names cyber threat actors, rolling out a unified cryptonym-based naming schema designed to standardize threat attribution across platforms. The change addresses long-standing fragmentation between Mandiant and Google’s Threat Analysis Group (TAG), which historically operated separate, independently evolved tra
A multi-stage phishing campaign that impersonates trusted business communications, including a global logistics provider and a government tax authority, to deploy Phantom Stealer v3.5.0, a credential-harvesting malware that exfiltrates data via SMTP. Documented by Seqrite , the campaign uses two distinct phishing lures sharing an identical infection chain. The first impersonates UPS Forwarding Hu
Six federal agencies have updated a joint cybersecurity advisory warning that Iranian-affiliated threat actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. government facilities, water systems, and energy infrastructure. The advisory, tracked as AA26-097A, was first published in April 2026 and revised on July 22, 2026, expanding its scope significantl
An Illinois man has pleaded guilty to multiple federal charges after orchestrating a large-scale social engineering campaign targeting Snapchat users, exposing persistent risks tied to account takeover (ATO) attacks and SMS-based phishing. According to the U.S. Attorney’s Office for the District of Massachusetts, 27-year-old Kyle Svara of Oswego, Illinois, admitted to aggravated identity theft, w
Cl0p ransomware affiliates are actively exploiting a critical zero-day in PTC Windchill and FlexPLM (CVE-2026-12569) to gain unauthenticated remote code execution, drop JSP webshells, and exfiltrate sensitive engineering data for double‑extortion. Documented by ISAC, the campaign targets internet‑exposed PLM environments across manufacturing, automotive, aerospace, and retail/apparel sectors, lev
Microsoft has confirmed that LG has agreed to disable an unsolicited McAfee promotional pop-up delivered through its Monitor App Installer, following a wave of user complaints about the software silently arriving via Windows Update. The issue began when Reddit user Mags_Smash reported that Windows Update had silently installed the “LG Monitor App Installer” after connecting three LG UltraGear mon
New malware-as-a-service (MaaS) offering “WARDEN” has emerged on cybercrime forums, pitching a Windows infostealer that blends credential theft, cryptocurrency hijacking, and payload delivery behind a single, feature-rich control panel. Marketed by the operator using the handle “WardenStealer,” the platform appears aimed at traffickers and other financially motivated actors who want turnkey data-
Affected endpoints showed unusual Defender exclusions, new persistence mechanisms, and outbound connections aligned with remote access and credential theft activity, leading analysts to treat incidents as full RA T-level compromises rather than benign adware. Huntress tracks this malvertising-driven operation as “FakeAgent,” highlighting the abuse of Claude’s own artifact hosting and the use of a
A newly disclosed eight high-severity vulnerabilities in NodeBB, a popular Node.js-based forum platform, all discovered during a six-hour AI-driven whitebox penetration test. The flaws affected default NodeBB instances prior to version 4.14.0 and included cross-site scripting (XSS) , authentication bypasses, and unauthorized data exposure. NodeBB’s maintainers responded quickly, rolling out fixes
Jul 23, 2026
TAG-195, also known as Golden Chickens or Venom Spider, is a financially motivated MaaS developer long linked to credential theft and remote access tooling for multiple criminal operators. Insikt Group recently identified four new malware families in this ecosystem, naming two of them TinyEgg and ChonkyChicken, alongside a modularized ChonkyChicken variant and a Chrome-focused helper dubbed Chrom
JetBrains has patched a critical path traversal vulnerability in IntelliJ IDEA that allows attackers to achieve arbitrary code execution simply by tricking a developer into opening a maliciously crafted project. Tracked as CVE-2026-59792, the flaw carries a CVSS score of 9.6 and was disclosed on July 10, 2026, alongside a broader batch of security fixes covering IntelliJ IDEA and TeamCity. The vu
Origin Energy has confirmed that a recent cyberattack led to unauthorized access and disclosure of customers’ personal and partial financial data, raising fresh concerns over the resilience of Australia’s critical infrastructure providers. The incident, disclosed in a series of updates between 22 and 24 July 2026, affects an as-yet-unknown number of accounts across the country’s largest electrici
Hackers are abusing modern browser features like ServiceWorkers and SharedWorkers to assemble malware entirely inside the victim’s browser memory. The SourTrade malvertising operation is a live example of how this technique is being weaponized against retail traders and crypto investors . SourTrade has been active since late 2024, buying programmatic ads and impersonating TradingView, Solana, and
Apache Syncope, the widely deployed open-source identity management platform , has patched a batch of critical vulnerabilities that could let low-privilege users escalate to administrator status and execute arbitrary code on the server. The Apache Software Foundation disclosed six new CVEs affecting versions 3.0.x, 4.0.x, and 4.1.x, with fixes rolled out in versions 4.1.2 and 4.0.7. Apache Syncop
Google has released a new Chrome Stable channel update addressing multiple high-severity memory safety vulnerabilities, including out-of-bounds write and use-after-free flaws that could potentially lead to arbitrary code execution. The latest update upgrades Chrome to version 150.0.7871.186/.187 for Windows and macOS, and 150.0.7871.186 for Linux. The rollout is gradual and expected to reach user
Threat actors are compromising hotel and conference-center Wi‑Fi gateways to steal Microsoft 365 accounts from traveling employees without sending phishing emails or infecting endpoints. The campaign uses DNS poisoning and, in some cases, Microsoft device-code flow abuse to redirect users to attacker-controlled infrastructure. The activity has reportedly been active since at least June 2026. It a
A newly observed Lampion malware campaign is targeting Portuguese users with phishing emails disguised as routine financial and administrative messages. Researchers at Acronis Threat Research Unit (TRU) found that the operation relies on oversized, obfuscated HTML and Visual Basic Script (VBS) files before using Windows’ rundll32.exe utility to launch a roughly 750MB remote-access Trojan (RAT) .
Russian state-supported threat actors tracked as LAUNDRY BEAR have exploited a former zero-day flaw in Zimbra Collaboration Suite ZCS webmail to steal up to 90 days of email communications, credentials, and corporate directory data from targeted organizations. The activity, detailed in a joint cybersecurity advisory released on July 23, 2026, has targeted Western government and commercial entitie
Microsoft has warned that phishing operators are increasingly targeting workplace communication platforms such as Microsoft Teams , using chat messages and voice calls to exploit the trust employees place in internal collaboration tools. While email remains the primary initial-access channel, Teams-based social engineering and voice phishing surged during the second quarter of 2026 Microsoft Thre
Security researchers Moe Ghasemisharif, Ruian Duan, Zhanhao Chen, and Daiping Liu have uncovered a RubyGems cryptojacking campaign that distributed trojanized copies of popular Ruby libraries. The malicious packages delay execution for five hours, check for sandboxed environments, and then deploy the XMRig miner to secretly mine Monero on compromised systems. The campaign involves at least two pu
A newly disclosed critical sandbox escape vulnerability chain, dubbed SharedRoot, in Anthropic’s Claude Cowork for macOS allows untrusted content processed by the AI agent to break out of its isolated Linux VM and read/write files anywhere on the host Mac, including SSH keys and cloud credentials. Cowork sandboxes agent sessions inside a Linux VM using Apple’s Virtualization framework, running ea
CERT-UA has disclosed a significant shift in the tactics of threat cluster UAC-0099 , revealing a novel infection chain that abuses a legitimate Notepad++ 8.8.3 executable to sideload malware, alongside an upgraded MATCHBOIL.V2 loader and two new tools named LUNCHPOKE and BURNYBEAR. The campaign, documented since mid-summer 2026, marks a notable evolution from the group’s earlier MATCHBOIL and MA
Cyber Security News / 1d
Vercel has disclosed nine security vulnerabilities in Next.js, the widely used React framework, including two critical-severity flaws that allow attackers to bypass authentication middleware and hijack server-side requests . The advisories, published by researcher KarimPwnz, affect versions ranging from 12.0.0 through 16.2.10, with patches available in 15.5.21 and 16.2.11. The most severe issue,
Moonshot AI’s newly released Kimi K3, a 2.8-trillion-parameter mixture-of-experts model, has demonstrated the growing offensive capability of autonomous AI agents by independently uncovering remote code execution (RCE) vulnerabilities in Redis versions. The findings, shared as non-destructive proofs-of-concept on GitHub , mark one of the fastest documented cases of AI-driven vulnerability discove
A newly disclosed heap buffer overflow in the FreeRDP Windows client’s clipboard channel allows a malicious RDP server to corrupt heap memory and potentially achieve remote code execution (RCE) on connecting endpoints when clipboard redirection is enabled. Akallabeth has identified a critical flaw in FreeRDP’s Windows client , specifically the wfreerdp component handling the static clipboard virt
Sangoma has patched two critical vulnerabilities in FreePBX that allow unauthenticated remote attackers to execute arbitrary commands and take over administrator accounts, prompting a “Red” urgency rating from the project’s security team. Organizations running internet-facing FreePBX 16 or 17 deployments are urged to patch immediately. The first flaw, tracked as GHSA-37j8-fhxx-9vhp , affects the
A newly disclosed vulnerability in Exim, one of the most widely deployed mail transfer agents (MTAs) on Unix-like systems, allows local attackers to escalate privileges by accessing files outside the intended mail spool directory. Tracked as EXIM-Security-2026-06-22.1 (GCVE-25-2026-07-45-1), the flaw carries a High severity rating and affects a massive swath of Exim deployments spanning nearly a
An exposed directory on an operator-controlled Alibaba Cloud server revealed the inner workings of the JadeProx intrusion set, including bash history, webshell paths, phishing kits, and a full post-exploitation toolkit. From this single staging host, investigators traced concurrent operations targeting a Vietnamese public hospital’s medical imaging system, the Malaysian Ministry of Foreign Affair
GitHub Actions abuse is powering a large-scale attack campaign that exploits the cPanel CVE-2026-41940 authentication bypass to steal server credentials and other sensitive secrets from internet-facing hosting environments. The operation turns compromised GitHub repositories and their Actions runners into distributed scanning and exploitation infrastructure. At the same time, Packagist PHP packag
Chick-fil-A has notified customers of a data security incident in which unauthorized parties gained access to Chick-fil-A One loyalty accounts through a credential stuffing attack , exposing personal information and stored account credit for affected users. Chick-fil-A identified suspicious login activity on certain Chick-fil-A One accounts and launched an investigation, ultimately determining th
- Get link
- X
- Other Apps
Comments
Post a Comment
Please leave a comment about our recent post.