all—News
Top News
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
July 14, 2026OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
July 17, 2026Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
July 17, 2026Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
July 23, 2026Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
July 24, 2026Microsoft releases Windows 10 KB5099539 extended security update
July 14, 2026Latest News
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User InteractionAdobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareA fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard, also known as
Amgen says cloud data breach exposed patient health, proprietary infoPharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.
Arch Linux disables AUR package adoption to stop malware floodThe Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.
Online ad firm Adform’s script compromised to steal cryptocurrencyOnline advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker.
OpenAI says its new GPT 5.6 models are becoming more cost-efficientOpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient.
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurkA Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,
Hacker uses DeepSeek AI to autonomously attack vulnerable serversA Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement.
- CISA warns of cyberattacks disrupting U.S. water utilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector.
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that
- 1
- 2
- 3
- 4
- 5
- 6
- 1982