July 2026

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands 2026-07-16 at 18:27 By Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that’s been spreading via websites infected with ClickFix lures since late April 2026. “The malware is full-featured, lightweight, and modular,” Elastic Security Labs researcher Cyril François said […]

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands Read More »

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password 2026-07-16 at 18:27 By ClickLock Stealer, a new macOS infostealer, answers a victim’s refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password Read More »

20+ Hijacked Government Websites Became
an Attack Channel

20+ Hijacked Government Websites Became
an Attack Channel 2026-07-16 at 18:27 By More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation revealed previously undocumented backdoor behavior, hidden infrastructure relationships, and

20+ Hijacked Government Websites Became
an Attack Channel Read More »

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands 2026-07-16 at 18:27 By Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click “Buy Now” instead. Ask a coding assistant to apply a maintainer’s fix from a GitHub thread,

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands Read More »

Legacy Systems, Real-World Impacts: The Reality of OT Security

Legacy Systems, Real-World Impacts: The Reality of OT Security 2026-07-16 at 18:15 By Tod Beardsley Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity’s most challenging balancing acts. The post Legacy Systems, Real-World Impacts: The Reality of OT Security appeared first on SecurityWeek. This article is an excerpt from

Legacy Systems, Real-World Impacts: The Reality of OT Security Read More »

Scattered Spider members jailed over Transport for London hack that cost £29 million

Scattered Spider members jailed over Transport for London hack that cost £29 million 2026-07-16 at 16:48 By Sinisa Markovic Two members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters

Scattered Spider members jailed over Transport for London hack that cost £29 million Read More »

Adaptiva simplifies secure patch management for air-gapped networks

Adaptiva simplifies secure patch management for air-gapped networks 2026-07-16 at 16:46 By Industry News Adaptiva has announced AirGap for OneSite Patch, a new capability that extends autonomous patch management to air-gapped environments. Developed in response to growing demand from government agencies, critical infrastructure operators, and large enterprises managing highly secure environments, AirGap for OneSite Patch

Adaptiva simplifies secure patch management for air-gapped networks Read More »

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites 2026-07-16 at 16:43 By Rodel Mendrez You’re browsing a legitimate small business website. Before the page loads, a familiar Cloudflare box appears: “Verify you are human.” It asks you to open Terminal, paste a code, and press Enter. You’ve seen this before. You follow the steps.

ClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites Read More »

20+ Hijacked Government Websites Became
an Attack Channel

20+ Hijacked Government Websites Became
an Attack Channel 2026-07-16 at 16:41 By More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation revealed previously undocumented backdoor behavior, hidden infrastructure relationships, and

20+ Hijacked Government Websites Became
an Attack Channel Read More »

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands 2026-07-16 at 16:41 By Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click “Buy Now” instead. Ask a coding assistant to apply a maintainer’s fix from a GitHub thread,

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands Read More »

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor 2026-07-16 at 16:41 By An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin (“srt64.sys”), as the kernel-mode rootkit is referred to, was first documented

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor Read More »

Alpaca raises $135M to fund tokenized agent-first infrastructure

Alpaca raises $135M to fund tokenized agent-first infrastructure 2026-07-16 at 16:34 By Cointelegraph by Robert Lakin The BNP-backed brokerage infrastructure provider is expanding into tokenized markets and AI-native financial services as both DeFi and TradFi companies pursue onchain business. This article is an excerpt from Cointelegraph.com News View Original Source

Alpaca raises $135M to fund tokenized agent-first infrastructure Read More »

Gambling on random Pokémon cards: Onchain gagcha hits record high as crypto sinks

Gambling on random Pokémon cards: Onchain gagcha hits record high as crypto sinks 2026-07-16 at 16:30 By Cointelegraph by Artem G Users spent a record $324 million on onchain gacha in June, even as Bitcoin hit a 21-month low. The thrill of scoring a top Pokemon card from a random pack is becoming big business

Gambling on random Pokémon cards: Onchain gagcha hits record high as crypto sinks Read More »

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance 2026-07-16 at 16:23 By Zeljka Zorz On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a coordinated vulnerability disclosure (CVD) program. Six days earlier, CISA published a blog post

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance Read More »

Two Scattered Spider Hackers Sentenced to Jail in UK

Two Scattered Spider Hackers Sentenced to Jail in UK 2026-07-16 at 16:21 By Eduard Kovacs Thalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL). The post Two Scattered Spider Hackers Sentenced to Jail in UK appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Two Scattered Spider Hackers Sentenced to Jail in UK Read More »

Prediction markets defy crypto downturn with record Q2 volume: CoinGecko

Prediction markets defy crypto downturn with record Q2 volume: CoinGecko 2026-07-16 at 16:05 By Cointelegraph by Helen Partz Prediction markets reached a record $113.8 billion in notional volume in Q2 as spot CEX trading, derivatives volume and stablecoin market cap declined. This article is an excerpt from Cointelegraph.com News View Original Source

Prediction markets defy crypto downturn with record Q2 volume: CoinGecko Read More »

AI Data Centers Are Being Built Faster Than They Can Be Secured

AI Data Centers Are Being Built Faster Than They Can Be Secured 2026-07-16 at 16:00 By Kevin Townsend AI infrastructure introduces new security risks that traditional data center designs were never built to handle. The post AI Data Centers Are Being Built Faster Than They Can Be Secured appeared first on SecurityWeek. This article is

AI Data Centers Are Being Built Faster Than They Can Be Secured Read More »

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands 2026-07-16 at 15:50 By Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that’s been spreading via websites infected with ClickFix lures since late April 2026. “The malware is full-featured, lightweight, and modular,” Elastic Security Labs researcher Cyril François said

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands Read More »

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing 2026-07-16 at 15:43 By Eduard Kovacs The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.  The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing Read More »

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password 2026-07-16 at 15:33 By ClickLock Stealer, a new macOS infostealer, answers a victim’s refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password Read More »

Scroll to Top