Uncategorized

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs 2026-07-21 at 14:58 By An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the […]

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Read More »

Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner

Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner 2026-07-21 at 12:00 By This year Security Magazine partnered with The National Center for Spectator Sports Safety and Security (NCS4) to present the Golden Eagle Award to SkySafe as the 2026 Golden Eagle Award winner for its case study submission, “University of Illinois Sets

Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner Read More »

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning 2026-07-21 at 11:59 By Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. “By the

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning Read More »

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack 2026-07-21 at 10:34 By Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack Read More »

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution 2026-07-21 at 09:29 By Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it’s observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution Read More »

Judge approves Anthropic’s $1.5B settlement of authors’ AI copyright lawsuit — first major case to settle

Judge approves Anthropic’s $1.5B settlement of authors’ AI copyright lawsuit — first major case to settle 2026-07-21 at 01:54 By Reuters The case is one of dozens brought by copyright owners including authors and news outlets against tech companies over the training of their large language models. This article is an excerpt from Latest Technology News |

Judge approves Anthropic’s $1.5B settlement of authors’ AI copyright lawsuit — first major case to settle Read More »

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware 2026-07-20 at 23:20 By Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware Read More »

China’s Moonshot AI pauses subscriptions for powerful Kimi K3 model due to surging demand

China’s Moonshot AI pauses subscriptions for powerful Kimi K3 model due to surging demand 2026-07-20 at 21:02 By Thomas Barrabi The Beijing-based firm said Sunday it had experienced “unprecedented compute challenges” and would temporarily focus on ensuring it could serve its existing paid users. The large-language model was trained on 2.8 trillion parameters, making it

China’s Moonshot AI pauses subscriptions for powerful Kimi K3 model due to surging demand Read More »

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign 2026-07-20 at 20:29 By A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico,

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign Read More »

Most American voters have favorable view of AI — despite media focus on controversies: poll

Most American voters have favorable view of AI — despite media focus on controversies: poll 2026-07-20 at 20:04 By Thomas Barrabi In a national poll conducted by HarrisX, 56% of voters said they had a favorable view about AI, while 36% had an unfavorable view. 72% of respondents agreed that AI could help people spend

Most American voters have favorable view of AI — despite media focus on controversies: poll Read More »

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 2026-07-20 at 17:33 By A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 Read More »

Mythos Didn’t Break Your Security Program. Your Exposure Window Could.

Mythos Didn’t Break Your Security Program. Your Exposure Window Could. 2026-07-20 at 17:06 By The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would

Mythos Didn’t Break Your Security Program. Your Exposure Window Could. Read More »

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More 2026-07-20 at 16:32 By A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks,

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More Read More »

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine 2026-07-20 at 15:13 By At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine Read More »

Scroll to Top