SecurityTicks

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access 2026-07-21 at 17:04 By Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with […]

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access Read More »

JadePuffer returns with ransomware built to target AI models and infrastructure

JadePuffer returns with ransomware built to target AI models and infrastructure 2026-07-21 at 16:38 By Zeljka Zorz JadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure. The extortion contact embedded in

JadePuffer returns with ransomware built to target AI models and infrastructure Read More »

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit 2026-07-21 at 16:30 By A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Read More »

Druva brings backup, recovery and governance to AI workloads

Druva brings backup, recovery and governance to AI workloads 2026-07-21 at 16:25 By Industry News Druva has announced Druva AI Resilience, a new approach that helps organizations recover, govern, and defend the systems, activity, and context behind AI-powered work. The launch introduces new and expanded capabilities for Microsoft Copilot, Claude Code, Druva Model Context Protocol

Druva brings backup, recovery and governance to AI workloads Read More »

Exploitarium: Inside the Archive Behind the Mass 0-Day Drop

Exploitarium: Inside the Archive Behind the Mass 0-Day Drop 2026-07-21 at 16:23 By Serhii Melnyk Coordinated vulnerability disclosures operate on a straightforward premise: the affected vendor is notified first, given a defined window to remediate, and public disclosure follows. This article is an excerpt from LevelBlue SpiderLabs Blog View Original Source

Exploitarium: Inside the Archive Behind the Mass 0-Day Drop Read More »

Robinhood-backed DEX Arcus expands with tokenized assets, perps

Robinhood-backed DEX Arcus expands with tokenized assets, perps 2026-07-21 at 16:16 By Cointelegraph by Helen Partz Arcus, built by the dYdX team, adds tokenized stocks and perpetual futures on Robinhood Chain as platforms compete to bring traditional assets onchain. This article is an excerpt from Cointelegraph.com News View Original Source

Robinhood-backed DEX Arcus expands with tokenized assets, perps Read More »

Cisco’s open-weight Antares models make vulnerability localization cheaper

Cisco’s open-weight Antares models make vulnerability localization cheaper 2026-07-21 at 16:01 By Mirko Zorz A security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to thousands

Cisco’s open-weight Antares models make vulnerability localization cheaper Read More »

Empirical Security Raises $25 Million in Series A Funding

Empirical Security Raises $25 Million in Series A Funding 2026-07-21 at 15:47 By Ionut Arghire The startup will use the investment to accelerate the development of its threat prediction and discovery products. The post Empirical Security Raises $25 Million in Series A Funding appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Empirical Security Raises $25 Million in Series A Funding Read More »

SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity

SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity 2026-07-21 at 15:30 By SecurityWeek News Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville The post SecurityWeek Launches Critical

SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Read More »

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs 2026-07-21 at 14:58 By An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Read More »

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication 2026-07-21 at 14:55 By Ionut Arghire Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Read More »

CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG

CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG 2026-07-21 at 14:30 By Kevin Townsend Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek.

CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG Read More »

Shufti simplifies cross-border compliance with the Glocal Platform

Shufti simplifies cross-border compliance with the Glocal Platform 2026-07-21 at 14:06 By Industry News Shufti has launched the Shufti Glocal Platform, a compliance lifecycle management solution designed to help organizations manage identity verification, fraud prevention, risk assessment, and regulatory compliance through a single platform across every industry, every region, and every use case. For decades,

Shufti simplifies cross-border compliance with the Glocal Platform Read More »

SonicWall SMA zero-days were exploited weeks before disclosure

SonicWall SMA zero-days were exploited weeks before disclosure 2026-07-21 at 13:35 By Zeljka Zorz Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June 22,

SonicWall SMA zero-days were exploited weeks before disclosure Read More »

Bitcoin price gains to $66.3K as range breakout attempt sparks one-month high

Bitcoin price gains to $66.3K as range breakout attempt sparks one-month high 2026-07-21 at 13:26 By Cointelegraph by William Suberg Bitcoin beat out local resistance to pass $66,000 amid predictions of as much as 6% BTC price upside if momentum continued. This article is an excerpt from Cointelegraph.com News View Original Source

Bitcoin price gains to $66.3K as range breakout attempt sparks one-month high Read More »

Fake FBI agents target people who already got scammed

Fake FBI agents target people who already got scammed 2026-07-21 at 13:21 By Sinisa Markovic Scammers are impersonating FBI personnel who supposedly handle Internet Crime Complaint Center (IC3) complaints, using that disguise to deceive and revictimize people who already lost money once. The IC3 published the update on July 20, 2026, building on an earlier

Fake FBI agents target people who already got scammed Read More »

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data 2026-07-21 at 13:19 By Eduard Kovacs A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Read More »

Scroll to Top