Cybersecurity News and Vulnerability Aggregator

Cybersecurity news aggregator

Top Cybersecurity Stories Today

The Hacker News 7h ago

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) -

The Hacker News 3h ago
CVE

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets an attacker "execute code in the context of the current process," per the

The Hacker News 7h ago
CVE

In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. "We identified unauthorized access to a limited set of internal datasets and to several credentials used by

The Hacker News 23h ago

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this

Latest

Monday, July 20
r/cybersecurity Just now

I manage ESET Endpoint for Windows via ESET PROTECT for a set of machines. One of my own domains is being blocked and I can't get it to pass through. Setup: \- Domain: clean, verified on VirusTotal (0/95, no vendor flags it) \- URLs have a query parameter that's unique per link, e.g. [domain.com/?rid=xxxx](http://domain.com/?rid=xxxx) Problem: when opening the link, ESET blocks it and the browser (Opera) shows ERR\_NETWORK\_ACCESS\_DENIED. What I've tried so far: 1. Added the domain to the "Found malware is ignored" address list type - no effect (makes sense, that's content scanner only, not antiphishing). 2. Added the domain to the "Allowed" address list type in Web access protection -> URL Address Management - still blocked after the policy was pushed to the machine. 3. Verified the domain's reputation is clean, so it's not a cloud reputation/LiveGrid issue. Questions: \- Does the "Allowed" URL list type actually override the antiphishing heuristic module, or is antiphishing a separate mechanism that ignores URL address lists entirely? \- Could ERR\_NETWORK\_ACCESS\_DENIED specifically indicate Network Attack Protection (IDS) blocking by IP, rather than Web access protection blocking by URL? If so, where do I properly exclude an IP from Network Attack Protection in ESET PROTECT policies (not just Web access protection's Excluded IP addresses)? \- Has anyone dealt with ESET's antiphishing heuristics flagging URLs with tracking-style query parameters (like ?rid=) as suspicious even when the domain itself is clean? Any pointers to the exact policy path or exclusion type that actually works would help a lot.

r/computerforensics Just now

A new **13Cubed** episode is out! In this episode, we'll look at a tool that can run multiple Volatility 3 plugins simultaneously, automating your memory analysis and saving you valuable time during investigations. Watch now: [https://www.youtube.com/watch?v=0GMTydimOP4](https://www.youtube.com/watch?v=0GMTydimOP4) More at [youtube.com/13cubed](http://youtube.com/13cubed)

r/cybersecurity 2h ago
CVE

I’m the researcher credited for [CVE-2026-14440.](https://vulnerability.circl.lu/vuln/CVE-2026-14440) I’m posting here to ask for help pressure-testing the threat model. [Cloudflare Universal SSL](https://developers.cloudflare.com/ssl/edge-certificates/universal-ssl/) is the default free automated certificate system for active Cloudflare zones. In the affected configuration, Cloudflare’s authoritative DNS can serve an automatically managed `CAA RRset` instead of the stricter CAA policy configured by the domain owner, if he/she wants to use them. [RFC 8657](https://datatracker.ietf.org/doc/rfc8657/) lets a domain owner narrow certificate issuance with `accounturi` and `validationmethods` \- e.g. “this CA may issue, but only from my ACME account / only using this validation method.” If the CA never sees those parameters in the actually served CAA response, that extra control is not enforced at all. **What is publicly established at this moment:** \- NVD describes exploitation as non-trivial. \- An attacker would need an ACME account at one of the CAs in the served CAA RRset. For LE - easy done. \- The attacker would also need to satisfy domain-control validation across multiple geographically distinct network perspectives. This is where [MPIC (Multi-Perspective Issuance Corroboration)](https://www.digicert.com/blog/mpic-for-digital-certificates) comes in. The CA/Browser Forum now requires MPIC for applicable validations, but I’m not sure how consistently it has been deployed across CAs in practice or how independent their validation perspectives really are. \- If the chain succeeds, the result can be a browser-trusted TLS certificate and a MITM window. \- CT logging can reveal the certificate after issuance, but CT does not prevent issuance. I'm not sure whether a security analyst would be able to distinguish a CF issued certs from a malicious ones in CT logs. They show that a certificate exists, but they do not identify the requester. Cloudflare’s own documentation says that CT alerts are off by default; most certificate alerts are routine; automatic Cloudflare issuance can generate alerts; backup certificates can generate alerts; shared SAN certificates can complicate interpretation. In other words, a lot of noise. **Where I want community input:** For ordinary attackers, the exploitation chain is too expensive for most targets. The more relevant threat model may be an actor with provider-, routing-, or infrastructure-level leverage (you name it). Removing RFC 8657 account and validation-method binding obviously makes certificate issuance easier for such an actor. The harder question is whether the remaining barriers — especially multi-perspective domain validation, Cloudflare’s anycast architecture, and post-issuance CT visibility — are enough to keep the attack impractical? Previously we already had the [jabber. ru incident](https://www.devever.net/~hl/xmpp-incident): valid publicly trusted certificates, traffic redirection apparently occurring in provider networks, and a long-lived TLS MITM without an obvious compromise of the service’s own servers. For me, it raises a concrete defensive question: *Could an actor with lawful, covert, or otherwise privileged access to network providers satisfy modern multi-perspective validation and use this CAA weakness as part of a targeted interception operation?* This also makes the PRISM / Section 702 history relevant. State-scale collection can involve compelled provider assistance and upstream/downstream collection paths. I am not claiming PRISM used this CVE, or that any agency is exploiting Cloudflare customers. Just a hypothesis worth thinking about. **And more questions for defenders / PKI people:** 1. What level of network control would actually be required to satisfy modern MPIC in this scenario: one hosting provider, one transit provider, several regional paths, or something stronger? 2. Does Cloudflare anycast materially block this attack, or could an actor operating inside provider infrastructure influence validation perspectives? I mean CF controls pretty much 20% of the Internet. 3. What mechanism (if any) could distinguish an attacker-requested certificate from normal Universal SSL issuance, renewal, backup certificates, or shared SAN certificates? 4. Are there documented incidents besides jabber. ru where trusted certificate issuance and provider-level traffic interception were combined? There was a story about [Venezuela BGP anomaly](https://blog.cloudflare.com/bgp-route-leak-venezuela/) , but I base my knowledge about it on several public reports - haven't dig through it properly. 5. Is the realistic risk limited to targeted interception of high-value domains, or is there a plausible route to operating this at larger scale? If you need more info about the CVE, you can read about it here in [my research](https://david-osipov.vision/en/blog/cybersecurity/cloudflare-ssl-mitm-flaw-2026/). But it's optional.

r/cybersecurity 3h ago
CVE

I came across this handbook while browsing the Cryptocurrency Village website: [https://www.cryptocurrencyvillage.cc/chackhandbook-2026.pdf](https://www.cryptocurrencyvillage.cc/chackhandbook-2026.pdf) The handbook introduces the *Cryptohack Badge*, an ESP32 C3 based device designed to teach hardware hacking, embedded systems, and cryptocurrency security through hands on projects. Rather than only explaining how a hardware wallet works, it walks you through building one while learning how the hardware and firmware work together. Some of the topics include: • Embedded systems programming • Hardware hacking and firmware development • NFC, Bluetooth, and WiFi • Hardware wallet design • Bitcoin, Ethereum, Solana, and Monero transaction signing • Security concepts behind cryptocurrency devices Even if cryptocurrency is not your primary interest, I think it looks like a solid resource for anyone interested in embedded security, reverse engineering, or learning how secure hardware devices are built. Has anyone here experimented with projects like this or built their own hardware security devices? I'd be interested to hear your thoughts.

The Hacker News 3h ago
CVE

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets an attacker "execute code in the context of the current process," per the

The Hacker News 3h ago

A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential

r/ReverseEngineering 5h ago

To reduce the amount of noise from questions, we have disabled self-posts in favor of a unified questions thread every week. Feel free to ask any question about reverse engineering here. If your question is about how to use a specific tool, or is specific to some particular target, you will have better luck on the [Reverse Engineering StackExchange](http://reverseengineering.stackexchange.com/). See also /r/AskReverseEngineering.

The Hacker News 7h ago
CVE

In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. "We identified unauthorized access to a limited set of internal datasets and to several credentials used by

The Hacker News 7h ago

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) -

Sunday, July 19
The Hacker News 23h ago

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's

The Hacker News 23h ago

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this

r/blueteamsec Jul 19

After Unit 42's report on the Chrome wallpaper extension campaign **"Ovkas" & "Gameograf"** I decided to dig into it myself and see how far the campaign actually extended. Starting from the published IOCs, I pivoted through shared infrastructure, publishers, and code similarities. So far, I've identified **703 Chrome extensions** that appear to belong to the same campaign, **many of which are still live on the Chrome Web Store**. Initial Campaign: [Unit 42](https://raw.githubusercontent.com/PaloAltoNetworks/Unit42-timely-threat-intel/refs/heads/main/2026-06-01-Adware-Wallpaper-Chrome-Extension-Campaign.txt) I've now published the full dataset [MalExt.io](https://malext.io/?q=https%3A%2F%2Fraw.githubusercontent.com%2FPaloAltoNetworks%2FUnit42-timely-threat-intel%2Frefs%2Fheads%2Fmain%2F2026-06-01-Adware-Wallpaper-Chrome-Extension-Campaign.txt) The dataset raises a bigger question: how large is this campaign really, and how many related extensions are still active?

Saturday, July 18
r/blueteamsec Jul 18

Hey everyone, **Full Write-up & Screenshots:** [https://medium.com/@osamamamoussa/from-alert-to-core-dump-hunting-zeus-malware-using-suricata-splunk-yara-and-volatility-4ce18f517f87?sharedUserId=osamamamoussa](https://medium.com/@osamamamoussa/from-alert-to-core-dump-hunting-zeus-malware-using-suricata-splunk-yara-and-volatility-4ce18f517f87?sharedUserId=osamamamoussa) I'm currently studying defensive security and working on my SOC portfolio. I am sharing a lab I built to practice hands-on malware analysis and detection engineering. I recently set up a malware analysis lab to detonate and investigate the **Zeus Banking Trojan**. Here is a quick breakdown of the detection and forensics pipeline: * **Victim:** Windows VM + Sysmon. * **SIEM/IDS:** Ubuntu VM + Splunk Enterprise + Suricata IDS. I wrote a full step-by-step write-up with screenshots and the exact Splunk queries.

r/Malware Jul 18
CVE

Hello everyone, A few months ago I shared my open database of malicious browser extensions. I'm happy to say it has now grown to **over 500 malicious CRX samples**. It started as a small research project, but it's continued to grow as I discover and collect more malicious extensions. My goal is to make it a useful resource for researchers, students, and anyone interested in browser extension security. One thing I'm working on next is making the data easier to consume in other tools. At the moment I'm considering exposing it in formats such as: * JSON * CSV I'm also thinking about adding things like an API or threat-intelligence style feeds if people think they'd be useful. I'd love to hear your thoughts: * What format would you actually use? * Are there any security tools or platforms you'd like to integrate it with? * Is there any metadata you'd find useful that I'm currently missing? Repository: [https://github.com/GherardoFiori/MaliciousBrowserExtensions](https://github.com/GherardoFiori/MaliciousBrowserExtensions?utm_source=chatgpt.com) **Please remember these are live malicious browser extensions. Handle them with care.** Project: [https://exterminai.com/](https://exterminai.com/) Any feedback is appreciated. Thanks!

r/netsec Jul 18

The White House recently announced the **Gold Eagle Initiative**, a new federal program designed to use AI to centralize, prioritize, and accelerate vulnerability patching across critical infrastructure, government agencies, and tech partners. Operating out of CMU's Software Engineering Institute, it essentially acts as an AI-driven **clearinghouse to fix security flaws** before threat actors can exploit them. Because let's face it, our current bug reporting and patching systems are absolute speed demons. It only takes a **lifetime** 🤦🏻‍♂️ or two to get a critical vulnerability acknowledged and fixed, so why change anything? Btw, my candid opinion about the status of current vulnerability reporting is painfully slow, so we desperately need a framework that actually moves at the speed of the threat landscape. I think this initiative is genuinely a good idea and a step in the right direction, though the announcement is still light on the exact technical implementation. I’m personally eager to see what will happen in practice, but it is definitely an impressive concept. What are your thoughts on this? Will an AI-coordinated pipeline actually help scale response times, or is it just going to generate massive noise and triage fatigue for overworked infosec teams?

Friday, July 17
Cloudflare Jul 17
CVE

Cloudflare has deployed new Web Application Firewall (WAF) protections for two critical vulnerabilities affecting WordPress. The protections address an Unauthenticated Remote Code Execution (RCE) vulnerability in WordPress's REST API and a related SQL Injection vulnerability. The WordPress security team disclosed the vulnerabilities to Cloudflare before public release so that we could prepare protections for customers. Cloudflare has deployed the new rules to protect all customers, including those on free and paid plans, as long as their application traffic is proxied through the Cloudflare WAF. The rules were deployed at 17:03 UTC on July 17 2026. WAF protections reduce exposure while customers update, but they are not a substitute for patching. WordPress has released fixes in version 7.0.2, with backports to affected earlier branches: 6.9.5, 6.8.6, and 7.1 Beta 2 ( see release details ). Versions earlier than 6.8 are not affected. WordPress is treating this as its highest-severity, highest-priority class of issue and is forcing automatic updates to affected sites, so most sites will be updated automatically. We still recommend confirming that you are on a patched release or the backports for your branch and follow the guidance in the official WordPress security release announcement . What you need to know The vulnerabilities affect different parts of the request path: CVE-2026-60137: SQL injection. A vulnerability in WordPress version 6.8 and later allows crafted input to alter a database query. Rating High. CVE-2026-63030: Unauthenticated remote code execution. A vulnerability in WordPress version 6.9 and later allows an unau

The Hacker News Jul 17

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until

The Hacker News Jul 17

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denial-of-service bug and named it, published the

The Hacker News Jul 17

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron,

r/Malware Jul 17

A man from Florida got arrested, allegedly behind the PirateFI and Blockblasters Crypto stealer attacks. The second Game stole 150k from a cancer Patient. https://www.tomshardware.com/tech-industry/cyber-security/fbi-arrests-florida-man-in-steam-malware-investigaton-after-tracing-stolen-bitcoin-to-uber-eats-gift-cards

The Hacker News Jul 17

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter

The Hacker News Jul 17

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing. Google has to ship it in the next major release, Android 18, and by 1 August 2027 at

The Hacker News Jul 17
CVE

Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move from concept to operational deployment at commercial speed. Now the focus shifts to the trusted

The Hacker News Jul 17

Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side

The Hacker News Jul 17

Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering. Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities in

Heimdal Security Jul 17

If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing its persistence 21 seconds into execution. Quarantine didn’t complete until 29 seconds. By the time the alert fired, […] The post MediaArena malvertising: why a quarantine isn’t the end of the incident appeared first on Heimdal Security Blog .

Thursday, July 16
CERT/CC Jul 16
CVE

Overview A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion and service interruption by using standard flow-control parameters such as SETTINGS_INITIAL_WINDOW_SIZE = 0 to stall outbound data for multiple simultaneous request streams. Description HTTP/2 is a widely used application-layer protocol that supports multiplexing, header compression, and flow-control mechanisms to regulate the transmission of data between web browsers and servers. Flow control is designed to prevent senders from overwhelming receivers and relies on client-advertised window sizes to determine the maximum volume of unacknowledged data that can be in transit at any given time. A client can intentionally stall outbound flow control by withholding WINDOW_UPDATE frames or by advertising SETTINGS_INITIAL_WINDOW_SIZE = 0 . In some HTTP/2 implementations, the server continues processing requests and generating complete response bodies even though it is unable to transmit them. The resulting response data remains buffered in memory, and each stalled stream retains its allocated buffer until the connection closes or a timeout occurs. An attacker can exploit this behavior by opening many simultaneous streams and requesting large resources, causing the server to accumulate large amounts of buffered response data. In environments with permissive resource limits, this can lead to excessive memory consumption, swap exhaustion, service instability, and, in severe cases, system crashes. Even under more conservative limits, the attack can exhaust worker or connection resources and de

The Hacker News Jul 16
CVE

Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority's employees into an office to get their passwords reset in person. Both the NCA and the CPS put TfL's losses and recovery

Synack Jul 16

Most security teams underestimate what it costs to build an AI pentesting solution in house. People, AI token costs, infrastructure, and compliance gaps add up faster than the initial business case accounts for, and the hidden bill usually arrives in year two. I’ve been hearing the same question from security leaders lately. They’re all asking […] The post The Hidden Costs of Building an AI Pentesting Solution appeared first on Synack .

CERT/CC Jul 16

Overview A Pickle deserialization vulnerability has been discovered within the SGLang project , enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsystem must be enabled, and an attacker must have network access to the SGLang service. No patch is available at this time, and no response was obtained from the project maintainers during coordination. Description SGLang is an open-source framework for serving large language models (LLMs) and multimodal AI models, supporting models such as Qwen, DeepSeek, Mistral, and Skywork, and is compatible with OpenAI APIs. A vulnerability has been discovered within the tool and is tracked as follows: CVE-2026-14890 SGLang uses an expert-parallel backup subsystem designed to handle the large amount of compute and memory constraints associated with different model types. This system, when running, exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network. The vulnerability is caused by the ZeroMQ PULL socket in expert_backup_manager.py binding to an external IP address with no authentication, meaning that any process that can reach the endpoint can send a payload that eventually gets deserialized with Pickle. This vulner

r/netsec Jul 16

RFC 8628's device authorization grant lets a TV or CLI "poll" for login on a second screen. On Google's implementation, the entire session was transferable across browsers, the authorization server never checked that the client\_id and scope in the consent URL matched the ones the device\_code was issued for, and prompt=none turned the whole thing into a one-click, invisible account takeover.

The Guardian Jul 16
CVE

Thalha Jubair, 20, and Owen Flowers, 19, sentenced to five and a half years each for cyber-attack that cost Transport for London £39m The data of millions of commuters was stolen, Londoners were left out of pocket and 27,000 Transport for London staff were forced to reset their passwords. Over four days in 2024 a pair of teenage hackers had London’s transport network at their mercy. Thalha Jubair and Owen Flowers had burrowed into the heart of Transport for London’s IT systems and held the “keys to the kingdom”. Continue reading...

The Guardian Jul 16

‘Malicious actor’ obtains sensitive data including Medicare numbers, treatment details and pathology results in cyber-attack on Partnered Health Follow our Australia news live blog for latest updates Get our breaking news email , free app or daily news podcast Australians’ medical records and patient information could be sold on the hidden market, an expert has warned, after a cyber-attack at one of the nation’s biggest healthcare providers. Partnered Health revealed 21 clinics across several cities including Sydney, Melbourne and Canberra were affected when a “malicious actor” accessed its data on 23 June. Continue reading...

Wednesday, July 15
r/Malware Jul 15

Hi r/Malware, If you ever need to quickly scan a suspicious file, URL, or installed application on an Android device using VirusTotal, I have built an open-source client called Veto. It lets you run queries using your own API key directly from your mobile device. GitHub: [https://github.com/ProfessorQuantumUniverse/Veto](https://github.com/ProfessorQuantumUniverse/Veto) I am currently trying to release the app on Google Play and need to fulfill Google's closed testing period. If you would like to test this tool, please consider opting in. Steps to join: 1. Join a Google Group: [veto\_android@googlegroups.com](https://groups.google.com/g/veto_android) 2. Opt-in link: [https://play.google.com/apps/testing/com.quantum\_prof.vtscansuite](https://play.google.com/apps/testing/com.quantum_prof.vtscansuite) 3. Play Store link: [https://play.google.com/store/apps/details?id=com.quantum\_prof.vtscansuite](https://play.google.com/store/apps/details?id=com.quantum_prof.vtscansuite) Feedback from malware analysts is highly valued!

CERT/CC Jul 15
CVE

Overview A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL dispatch routines [RM1.1][MB1.2]to perform arbitrary kernel memory read and write operations, ultimately obtaining NT AUTHORITY\SYSTEM privileges and compromising the security of the affected system. Description The tdeio64.sys driver distributed by Pegatron Corporation, a Taiwanese electronics manufacturer that produces motherboards and OEM components, is a Windows Driver Model (WDM) driver that provides low-level access to system I/O ports and hardware components. The driver exposes the \\.\TdeIo device interface and processes privileged IOTL requests without enforcing adequate access control or validating user-supplied memory addresses. CVE-2026-14961 By sending a crafted DeviceIoControl request, an unprivileged attacker can abuse the driver's IOCTL dispatcher to perform arbitrary kernel memory reads and writes. This capability can be used to overwrite the current process token with the SYSTEM process token, resulting in privilege escalation to NT AUTHORITY\SYSTEM . CVE-2026-14960 In addition to arbitrary kernel memory access, the driver exposes IOCTLs capable of interacting directly with hardware I/O ports. An attacker who successfully exploits these interfaces may be able to manipulate hardware resources in ways that extend beyond normal operating system protections. Impact &l

CERT/CC Jul 15

Overview Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attackers to forge RSA (PKCS#1 v1.5) and Ed25519 signatures under specific, exploitable conditions. Description Both vulnerabilities stem from insufficient enforcement of canonical cryptographic structures during verification: in the RSA case, non-standard ASN.1 encodings and undersized padding are accepted; in the Ed25519 case, non-canonical signature scalars are not rejected. As a result, node-forge accepts signatures that appear valid internally but are rejected by industry-standard libraries such as OpenSSL and Node.js’s native crypto module. The vulnerabilities affect node-forge versions 0.1.2 through 1.3.3 for RSA-PKCS#1 v1.5, and 0.7.4 through 1.3.3 for Ed25519. Both issues were resolved in v1.4.0, released on 2026-04-05. CVE-2026-33894 arises in lib/rsa.js , where RSASSA-PKCS1-v1_5 verification accepts forged signatures due to two related flaws. First, the ASN.1 parser for DigestInfo permits non-canonical encodings—specifically, structures with more than the two required fields (algorithm OID and octet string), including attacker-controlled additional data. Second, the PKCS#1 v1.5 decoding logic fails to enforce the RFC 2313 requirement that the padding string ( PS ) must be at least 8 bytes . These combined weaknesses enable attackers to construct specially crafted signatures, particularly with low public exponents (e.g., e = 3 ), that node-forge validates successfully while standard implementations correctly reject them.

r/Malware Jul 15

# Romanian Government Cadastre (ANCPI) cyber attack A very serious ransomware attack is underway on the networks of ANCPI, Romania’s national cadastre agency. Our close monitoring of the threat actor Bytetobreach — who carried out a similar attack last month on Latvia State Forests — detected simultaneous uploads on dark web forums regarding this incident. These claims were later confirmed on ANCPI’s official website. What was described as a “small technical incident” in yesterday’s press release has suddenly been recharacterized by ANCPI itself as “the most serious technical incident in the institution’s history.” Sources : [https://www.ancpi.ro/](https://www.ancpi.ro/) (official press releases ) [https://pwnforums.st/Thread-DATABASE-RO-Thy-arss-shall-be-spanked-Romania-ANCPI](https://pwnforums.st/Thread-DATABASE-RO-Thy-arss-shall-be-spanked-Romania-ANCPI)[https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked-Romania-ANCPI](https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked-Romania-ANCPI)

Troy Hunt Jul 15

Presently sponsored by: CoreView: Misconfigurations in Microsoft 365 leave doors open. Scan your tenant for free?. "Build a smart home", they said. "It'll make life so much better", they said. Well, life wasn't very bloody good at 23:00 the other night after travelling 33 hours from Paris only to find the IoT doorlock batteries dead and the 9V "jump start" procedure completely failing! Eventually, the locksmith arrived and opened an old-school physical lock on another door in an alarmingly short time. So, lessons: Battery-powered locks suck and will eventually lock you out of your house Don't trust a fallback mechanism as rudimentary as "hold a 9V battery on some terminals" Always have an old school manual backup approach, AKA "a key" As I say in the video, we do have other doors that have keys, and if it weren't for the complacency we developed, we would have had one of these accessible. But alas, we didn't. The path forward is to take a deep dive into Ubiquiti's Access ecosystem , which I've flagged in the past, and by pure coincidence, I already had a meeting lined up with them to discuss just this. So, the hardware is on the way, and I'll have something entirely new to play with in the coming weeks. Stay tuned!

Tuesday, July 14
Synack Jul 14

The EU AI Act's security requirements go beyond governance documentation and AI literacy training. High-risk AI systems need adversarial testing to prove they can withstand real attacks. Policies describe intent. Testing produces evidence. The post The EU AI Act Is Not Just a Compliance Deadline; It’s a Security Validation Challenge appeared first on Synack .

Krebs on Security Jul 14

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild. Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, as do approximately 250 other elevation of privilege flaws fixed this month; they include CVE-2026-56155 — an Active Directory Federation Services bug — and CVE-2026-56164 , a Microsoft Sharepoint vulnerability.

Cloudflare Jul 14

On July 3, 2026, the Albanian communications authority (AKEP), the operator of the .al country-code top-level domain (TLD) of Albania, attempted a DNSSEC key rollover. Something went wrong, resulting in DNSSEC validation failures. Any validating DNS resolver receiving these signatures was required by the DNSSEC specification to reject them and return errors to clients. That includes 1.1.1.1 , the public DNS resolver operated by Cloudflare. The .al TLD is the online home of Albanian government services, banks, and media; it ranks #191 on Cloudflare Radar's TLD ranking . Anyone trying to visit those sites, using a validating resolver, found them unreachable during the incident. The failure had the potential to affect every .al domain, regardless of where it was hosted or which authoritative nameservers served it. Just two months earlier, a similar incident struck .de , the TLD of Germany. As we described in our blog post on the incident , our response was to install a Negative Trust Anchor (NTA) for .de , temporarily suspending DNSSEC validation in 1.1.1.1 to keep domains reachable while the registry resolved the issue. We did the same for . al . NTAs restore resolution, but silently. A client receiving a response served under an NTA has no way to tell, from the response alone, that DNSSEC validation was bypassed, leaving it unable to distinguish a legitimate answer from a spoofed one. For the .al incident, 1.1.1.1 addressed that gap for the first time, returning a new Extended DNS Error (EDE) code alongside every affected res

Monday, July 13
Synack Jul 13

Most enterprises test less than a third of their attack surface, and attackers have already moved to AI-speed offense. Agentic AI closes the coverage gap, but only when paired with human expertise: an AI-first, human-validated model that secures critical infrastructure without sacrificing operational safety. The post Why the Future of Pentesting Needs Humans and Agentic AI Working Together appeared first on Synack .

r/netsec Jul 13

I wrote this after spending an unreasonable amount of time making CET-compliant callstack spoofing work end-to-end on hardware with Intel CET enabled. The technique combines three primitives: thread pool execution for a clean stack base, enum callback trampolining for a real signed mid-stack frame, and indirect syscalls. The actual contribution is the CET compliance mechanism: a `jmp`\-based context switch combined with direct shadow stack pointer reconciliation via `RDSSPQ`/`INCSSPQ`, without touching unwind metadata. Different approach from BYOUD. Implemented in Rust with inline assembly.

Krebs on Security Jul 13

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb. On May 15, 2026, the security firm GitGuardian asked for help in notifying CISA about the existence of a public GitHub repository called “Private CISA” that included 844 MB of sensitive CISA-related data. One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers. Another file — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems. CISA quickly acknowledged our initial alert, but took more than 48 hours to invalidate the AWS keys and many other important secrets leaked in the GitHub repo. In its report on the data leak , CISA said the complexities of the agency’s systems and interconnections with federal and industry partners caused its key rotation to take long

Cloudflare Jul 13
APT

Bot mitigation is an adversarial game: attackers adapt, defenders respond, and the cycle continues. At Cloudflare, we stay ahead by combining visibility across our global network with signals from the client-side environment. At the network level, we analyze over 1 trillion requests per day to understand reputation, patterns, and anomalies across more than 20% of the web. On the client side, we’ve pushed detection deeper with Cloudflare Turnstile , which has evolved from a CAPTCHA replacement to a risk-based managed challenge that adapts the amount of friction needed to verify the user is authentic. Today, Turnstile runs nearly 3 billion times per day on some of the most sensitive endpoints on the Internet, helping verify users at key moments like login, signup, and checkout. This improves protection on the most important areas of customer applications, but still leaves limited visibility into the rest of the application — how humans and bots actually interact across the full user journey. This is the visibility gap we’re closing today with our launch of Precursor . Introducing Precursor Precursor is a client-side, session-based verification system, built with privacy in mind, that uses dynamically injected JavaScript to continuously collect behavioral signals as visitors interact with your application. These signals are processed and incorporated into Cloudflare’s bot protection in real time, allowing us to continuously distinguish human traffic from automated or agentic traffic. This extends the client-side detections offered by a

Story Overview