Uncategorized

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware 2026-07-08 at 12:54 By A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices. According to findings from Cisco Talos, UAT-7810 is an advanced persistent threat (APT) actor that’s […]

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware Read More »

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros 2026-07-08 at 09:16 By Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable code has shipped by default in essentially every mainstream distribution since

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros Read More »

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV 2026-07-08 at 08:33 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below – CVE-2026-48282 (CVSS score: 10.0) – A path

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV Read More »

Meta says it’s facing $1.4T in penalties in teen mental health case — a sum equal to tech giant’s valuation

Meta says it’s facing $1.4T in penalties in teen mental health case — a sum equal to tech giant’s valuation 2026-07-07 at 23:21 By Thomas Barrabi Meta said it based the $1.4 trillion figure, which is nearly as large as the company’s entire market cap, on how the attorneys general of California, Colorado, Kentucky and

Meta says it’s facing $1.4T in penalties in teen mental health case — a sum equal to tech giant’s valuation Read More »

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots 2026-07-07 at 20:59 By A critical flaw in Google’s Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project. From there, they could read live conversations, steal

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots Read More »

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service 2026-07-07 at 20:59 By A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim’s phone, steal their banking logins, and capture the one-time codes that protect their

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service Read More »

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts 2026-07-07 at 19:16 By A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. “The campaign did not depend on a

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts Read More »

What Changes When Your Software Supply Chain Includes AI Writing Your Code?

What Changes When Your Software Supply Chain Includes AI Writing Your Code? 2026-07-07 at 18:53 By Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, “software supply chain security” meant one question: what’s in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that

What Changes When Your Software Supply Chain Includes AI Writing Your Code? Read More »

Your 401(k) could be at risk if the AI bubble bursts: Treasury report

Your 401(k) could be at risk if the AI bubble bursts: Treasury report 2026-07-07 at 18:37 By Ariel Zilber AI companies have become so deeply embedded in financial markets that a sharp downturn would ripple far beyond Silicon Valley, according to a report. This article is an excerpt from Latest Technology News | New York

Your 401(k) could be at risk if the AI bubble bursts: Treasury report Read More »

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data 2026-07-07 at 17:04 By A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization’s private repositories, researchers at Noma Security have shown. The attacker needs only to open a normal-looking issue on a public repository, with no

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data Read More »

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker 2026-07-07 at 16:27 By U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal complaint. Microsoft records tied that ID first to the account

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker Read More »

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants 2026-07-07 at 16:27 By Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise. The one-click vulnerability has been codenamed WriteOut by the Sand Security Research

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants Read More »

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities 2026-07-07 at 12:51 By A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign. The activity involves the exploitation of now-patched, critical security flaws in the open-source

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities Read More »

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware 2026-07-07 at 09:40 By Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices’ web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday. “An attacker can exploit

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware Read More »

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA 2026-07-07 at 08:16 By BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices. The vulnerabilities are listed below –

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA Read More »

Bitcoin bounces back after Trump calls himself ‘a big crypto guy’

Bitcoin bounces back after Trump calls himself ‘a big crypto guy’ 2026-07-07 at 05:56 By Taylor Herzlich Bitcoin bounced back Monday after President Trump called himself “a big crypto guy” and gave a positive, if noncommittal, answer when asked about the prospect of digital assets becoming part of his newly-launched Trump Accounts. This article is

Bitcoin bounces back after Trump calls himself ‘a big crypto guy’ Read More »

Scroll to Top