Uncategorized

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests 2026-07-18 at 16:16 By Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte […]

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests Read More »

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code 2026-07-18 at 16:16 By Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code Read More »

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens 2026-07-18 at 16:16 By A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI,

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens Read More »

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT 2026-07-18 at 16:16 By Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT Read More »

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft 2026-07-18 at 16:16 By Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group),

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft Read More »

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code 2026-07-18 at 02:12 By An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code Read More »

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests 2026-07-17 at 23:20 By Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests Read More »

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT 2026-07-17 at 21:54 By Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT Read More »

Judge won’t block Meta from axing workers who filed AI discrimination lawsuit

Judge won’t block Meta from axing workers who filed AI discrimination lawsuit 2026-07-17 at 21:53 By Reuters Dozens of employees claimed that they were targeted for job cuts by the company’s AI-powered tools because they have disabilities or took medical leave. This article is an excerpt from Latest Technology News | New York Post View

Judge won’t block Meta from axing workers who filed AI discrimination lawsuit Read More »

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images 2026-07-17 at 20:32 By North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. “Any user who ran the

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images Read More »

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens 2026-07-17 at 20:12 By A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI,

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens Read More »

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft 2026-07-17 at 19:39 By Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group),

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft Read More »

Chinese AI firm Moonshot unveils powerful model with capabilities close to Anthropic, OpenAI

Chinese AI firm Moonshot unveils powerful model with capabilities close to Anthropic, OpenAI 2026-07-17 at 17:59 By Thomas Barrabi Dubbed Kimi K3, the large language model was trained on a massive 2.8 trillion parameters – the kernels of data that determine its responses to user questions, according to Moonshot. That would make it one of

Chinese AI firm Moonshot unveils powerful model with capabilities close to Anthropic, OpenAI Read More »

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files 2026-07-17 at 15:52 By ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files Read More »

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage 2026-07-17 at 15:52 By Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering. Russian cybersecurity company Kaspersky,

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage Read More »

Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive

Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive 2026-07-17 at 15:11 By SecurityWeek News (Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up? The post Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive appeared first on SecurityWeek. This article is an

Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive Read More »

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants 2026-07-17 at 14:44 By The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants Read More »

The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?

The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace? 2026-07-17 at 14:30 By Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs

The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace? Read More »

Scroll to Top