Uncategorized

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots 2026-07-07 at 20:59 By A critical flaw in Google’s Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project. From there, they could read live conversations, steal

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots Read More »

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service 2026-07-07 at 20:59 By A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim’s phone, steal their banking logins, and capture the one-time codes that protect their

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service Read More »

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts 2026-07-07 at 19:16 By A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. “The campaign did not depend on a

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts Read More »

What Changes When Your Software Supply Chain Includes AI Writing Your Code?

What Changes When Your Software Supply Chain Includes AI Writing Your Code? 2026-07-07 at 18:53 By Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, “software supply chain security” meant one question: what’s in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that

What Changes When Your Software Supply Chain Includes AI Writing Your Code? Read More »

Your 401(k) could be at risk if the AI bubble bursts: Treasury report

Your 401(k) could be at risk if the AI bubble bursts: Treasury report 2026-07-07 at 18:37 By Ariel Zilber AI companies have become so deeply embedded in financial markets that a sharp downturn would ripple far beyond Silicon Valley, according to a report. This article is an excerpt from Latest Technology News | New York

Your 401(k) could be at risk if the AI bubble bursts: Treasury report Read More »

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data 2026-07-07 at 17:04 By A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization’s private repositories, researchers at Noma Security have shown. The attacker needs only to open a normal-looking issue on a public repository, with no

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data Read More »

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker 2026-07-07 at 16:27 By U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal complaint. Microsoft records tied that ID first to the account

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker Read More »

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants 2026-07-07 at 16:27 By Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise. The one-click vulnerability has been codenamed WriteOut by the Sand Security Research

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants Read More »

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities 2026-07-07 at 12:51 By A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign. The activity involves the exploitation of now-patched, critical security flaws in the open-source

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities Read More »

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware 2026-07-07 at 09:40 By Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices’ web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday. “An attacker can exploit

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware Read More »

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA 2026-07-07 at 08:16 By BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices. The vulnerabilities are listed below –

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA Read More »

Bitcoin bounces back after Trump calls himself ‘a big crypto guy’

Bitcoin bounces back after Trump calls himself ‘a big crypto guy’ 2026-07-07 at 05:56 By Taylor Herzlich Bitcoin bounced back Monday after President Trump called himself “a big crypto guy” and gave a positive, if noncommittal, answer when asked about the prospect of digital assets becoming part of his newly-launched Trump Accounts. This article is

Bitcoin bounces back after Trump calls himself ‘a big crypto guy’ Read More »

Microsoft lays off nearly 5K workers, most of them at Xbox:  ‘Our business today is not healthy’

Microsoft lays off nearly 5K workers, most of them at Xbox:  ‘Our business today is not healthy’ 2026-07-07 at 05:56 By Marc Vartabedian Microsoft is axing about 3,200 jobs across its Xbox video game business as the company moves to restructure the struggling division and pours resources into artificial intelligence.  The layoffs include 1,600 employees

Microsoft lays off nearly 5K workers, most of them at Xbox:  ‘Our business today is not healthy’ Read More »

Major crypto holder Strategy sells $216M of Bitcoin as it abandons Michael Saylor’s ‘never sell’ mantra

Major crypto holder Strategy sells $216M of Bitcoin as it abandons Michael Saylor’s ‘never sell’ mantra 2026-07-07 at 05:56 By Taylor Herzlich Crypto-treasury giant Strategy sold $216 million of Bitcoin last week – a sign that it is abandoning co-founder Michael Saylor’s “Never sell your Bitcoin” mantra as a slumping digital asset market hits its

Major crypto holder Strategy sells $216M of Bitcoin as it abandons Michael Saylor’s ‘never sell’ mantra Read More »

Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations

Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations 2026-07-07 at 00:06 By An Iranian hacking group affiliated with Iran’s Ministry of Intelligence and Security (MOIS) has been wielding a previously undocumented modular command-and-control (C2) framework dubbed Cavern (aka Cav3rn) targeting Israeli organizations. The activity, which has primarily singled out IT providers and

Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations Read More »

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems 2026-07-06 at 21:51 By A use-after-free bug in Linux’s KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it. Dubbed ‘Januscape’ and tracked as CVE-2026-53359, the flaw sits

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems Read More »

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure 2026-07-06 at 20:22 By Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure Read More »

Scroll to Top