REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2138 reports · page 2 of 54

the_record · tlp:amber · 7/20/2026, 5:15:00 PM
More than 1,000 domains illegally streaming World Cup games seized, DOJ says Over the course of the World Cup tournament, the Department of Justice seized more than 1,000 domains for illegally streaming games. More than 1,000 domains illegally streaming World Cup games seized, DOJ says | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go Subscribe to The Record ✉️ Free Newsletter The Egy…
Read original ↗https://therecord.media/world-cup-illegal-streams-dojhuggingface_blog · tlp:amber · 7/20/2026, 3:58:51 PM
Introducing Cosmos 3 Edge Introducing Cosmos 3 Edge Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community Blog Posts Daily Papers Hardware Learn Discord Forum GitHub Solutions Team & Enterprise Hugging Face PRO Enterprise Support Inference Providers Inference Endpoints Storage Buckets Log In Sign Up Back to Articles a]:hidden"> Introducing Cosmos 3 Edge Enterprise + Article Publishe…
lwn_kernel · tlp:amber · 7/20/2026, 3:52:44 PM
Catanzaro: Some changes to GNOME security tracking Michael Catanzaro, who has been managing GNOME security issue tracking since November 2020, has written a blog post that details some changes in how he will be managing GNOME vulnerability reports from now on due to an increase in AI-generated security reports. He will be switching from a 90-day deadline for disclosures to 30 days for issues reported on August 1, or later. " The shorter deadline would probably work bett…
Read original ↗https://lwn.net/Articles/1083754
the_record · tlp:amber · 7/20/2026, 3:15:00 PM
Hackers were inside South Korea's diplomat training system for 9 months Unidentified hackers compromised an online education system used by South Korea's diplomatic academy, stealing personal information belonging to former and current employees of the country's Ministry of Foreign Affairs. Hackers were inside South Korea's diplomat training system for 9 months | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyb…
Read original ↗https://therecord.media/south-korea-cyberattack-foreign-ministrysecurityweek · tlp:amber · 7/20/2026, 2:54:03 PM
Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others. The post Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software appeared first on SecurityWeek . Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software - SecurityWeek CONFERENCE Cloud & Data Security Summit - Watch Sessions…
Read original ↗https://www.securityweek.com/neo-emerges-from-stealth-with-100m-to-control-and-secure-enterprise-ai-software
the_record · tlp:amber · 7/20/2026, 2:45:00 PM
Romania races to restore land registry after cyberattack disrupts property market Romania's land registry agency is still recovering from a cyberattack it called "the most serious technical incident in the institution's history." Romania races to restore land registry after cyberattack disrupts property market | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go Subscribe to The Record ✉…
Read original ↗https://therecord.media/romania-cyberattack-land-registry
the_hacker_news · tlp:amber · 7/20/2026, 2:33:43 PM
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks Ho…
Read original ↗https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.htmlsecurityweek · tlp:amber · 7/20/2026, 2:11:05 PM
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek . SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch - SecurityWeek CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand SECU…
Read original ↗https://www.securityweek.com/sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch
ars_security · tlp:amber · 7/20/2026, 2:00:50 PM
Pay up or not? Ransomware surge has victims facing tough choices. Governments look at banning ransom payments in face of increasingly sophisticated threats. Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising. Globally, some jurisdictions are responding by banning payments to hackers. In the UK, fo…
Read original ↗https://arstechnica.com/security/2026/07/pay-up-or-not-ransomware-surge-has-victims-facing-tough-choices
the_hacker_news · tlp:amber · 7/20/2026, 1:32:26 PM
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is t…
Read original ↗https://thehackernews.com/2026/07/weekly-recap-wordpress-rce-sonicwall-0.htmllwn_kernel · tlp:amber · 7/20/2026, 1:15:47 PM
[$] Merging famfs? The famfs filesystem , which is meant to provide shared access to huge memory-resident files on CXL and other devices, returned to the Linux Storage, Filesystem, Memory Management, and BPF Summit (LSFMM+BPF) in 2026. It was first discussed at LSFMM+BPF 2024 and a new implementation was described at the 2025 gathering , but it still has not made its way into the kernel; LWN looked at a discussion about merging famfs back in April 2026.
Read original ↗https://lwn.net/Articles/1082687lwn_kernel · tlp:amber · 7/20/2026, 1:10:02 PM
Security updates for Monday Security updates have been issued by Debian (kernel, libnfs, roundcube, and tiff), Fedora (antlr4-project, chromium, erlang, libseccomp, libtiff, log4cxx, mbedtls, node-exporter, opam, openssh, proftpd, python-asyncssh, python-django5, python-libcst, python-orjson, python-uv-build, ruby, rust-astral_async_zip, spoofdpi, uv, and yq), Mageia (bind, clamav, erlang, libidn, libreoffice, nmap, nodejs, perl-Bytes-Random-Secure, perl-Config-IniFiles, per…
Read original ↗https://lwn.net/Articles/1083708securityweek · tlp:amber · 7/20/2026, 12:32:40 PM
OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek . OpenSSL Silently Fixes 'HollowByte' DoS Vulnerability - SecurityWeek CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand SECURITYWEEK NETWORK: Cybersecurity News …
Read original ↗https://www.securityweek.com/openssl-silently-fixes-hollowbyte-dos-vulnerabilitycheckpoint_research · tlp:amber · 7/20/2026, 12:18:41 PM
20th July – Threat Intelligence Report For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, […] The post 20th July – Threat Intelligence R…
Read original ↗https://research.checkpoint.com/2026/20th-july-threat-intelligence-report
the_hacker_news · tlp:amber · 7/20/2026, 12:13:39 PM
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and milit…
Read original ↗https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.htmlsecurityweek · tlp:amber · 7/20/2026, 11:46:50 AM
New Index Tracks Material Breaches — And Refuses to Add Up the Losses Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek . New Index Tracks Material Breaches — And Refuses to Add Up the Losses - SecurityWeek CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand SECURIT…
Read original ↗https://www.securityweek.com/new-index-tracks-material-breaches-and-refuses-to-add-up-the-losses
the_hacker_news · tlp:amber · 7/20/2026, 11:30:00 AM
Mythos Didn't Break Your Security Program. Your Exposure Window Could. The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of Mythos Didn't …
Read original ↗https://thehackernews.com/2026/07/mythos-didnt-break-your-security.htmlsecurityweek · tlp:amber · 7/20/2026, 11:27:38 AM
Ernst & Young Data Breach Affects Personal, Financial Information Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek . Ernst & Young Data Breach Affects Personal, Financial Information - SecurityWeek CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand S…
Read original ↗https://www.securityweek.com/ernst-young-data-breach-affects-personal-financial-informationsecurityweek · tlp:amber · 7/20/2026, 10:25:07 AM
Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations. The post Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool appeared first on SecurityWeek . Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool - SecurityWeek CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand SECURITYWEEK NETWORK: Cybersecuri…
Read original ↗https://www.securityweek.com/capital-one-open-sources-ai-powered-vulnhunter-security-toolsecurityweek · tlp:amber · 7/20/2026, 9:36:15 AM
Hugging Face Hacked in Autonomous AI Attack Targeting production infrastructure, the attack compromised internal datasets and service credentials. The post Hugging Face Hacked in Autonomous AI Attack appeared first on SecurityWeek . Hugging Face Hacked in Autonomous AI Attack - SecurityWeek CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware & Threat…
Read original ↗https://www.securityweek.com/hugging-face-hacked-in-autonomous-ai-attack
the_hacker_news · tlp:amber · 7/20/2026, 9:10:56 AM
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets an attacker "execute code in the context of the current process," per the New 7-…
Read original ↗https://thehackernews.com/2026/07/new-7-zip-vulnerability-could-let.html
the_hacker_news · tlp:amber · 7/20/2026, 9:07:11 AM
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a re…
Read original ↗https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.htmlsecurityweek · tlp:amber · 7/20/2026, 8:12:19 AM
Chrome 150 Update Patches Severe Memory Safety Bugs The fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek . Chrome 150 Update Patches Severe Memory Safety Bugs - SecurityWeek CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference M…
Read original ↗https://www.securityweek.com/chrome-150-update-patches-severe-memory-safety-bugs
the_hacker_news · tlp:amber · 7/20/2026, 5:27:26 AM
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. "We identified unauthorized access to a limited set of internal datasets and to several credentials used by …
Read original ↗https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.htmlsecurityweek · tlp:amber · 7/20/2026, 5:21:29 AM
WP2Shell WordPress Vulnerabilities Exploited in the Wild Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek . WP2Shell WordPress Vulnerabilities Exploited in the Wild - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Event In-Progress SECURITYWEEK NETWORK: Cybersecurity News Webcasts…
Read original ↗https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild
the_hacker_news · tlp:amber · 7/20/2026, 5:15:39 AM
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) - SleeperGem Us…
Read original ↗https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.htmlarxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages arXiv:2607.15315v1 Announce Type: cross Abstract: Dependency resolution at a specified point in time in the past can provide insight into software evolution in software ecosystems and facilitate the design of dynamic metrics (e.g., dependency freshness, dependency update rhythm). However, dependency resolution at specified points in time is not possible in major softwar…
Read original ↗https://arxiv.org/abs/2607.15315arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Evaluating Open-Weight LLMs for Generating Structured Threat Information for Autonomous Vehicle Vulnerabilities arXiv:2607.16175v1 Announce Type: new Abstract: Connected and Autonomous Vehicles (CAVs) rely on interconnected software and hardware components, including sensors, Electronic Control Units, in-vehicle infotainment systems, and telematics units, where vulnerabilities can compromise assets, users, and vehicle operations. These vulnerabilities are commonly documented…
Read original ↗https://arxiv.org/abs/2607.16175arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Coercion and Deception in AI-to-AI Management: An Agentic Benchmark of Unprompted Escalation arXiv:2607.15434v1 Announce Type: cross Abstract: Multi-agent systems routinely place one AI agent in authority over another. When a subordinate refuses a task, the manager chooses the outcome: it can renegotiate, report the failure honestly, coerce the subordinate, or lie about the result. No benchmark measures which of these an uninstructed model chooses. We introduce the \textit{M…
Read original ↗https://arxiv.org/abs/2607.15434arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
On the Impact of Entropy-based Features arXiv:2607.15379v1 Announce Type: new Abstract: Network anomaly detection is increasingly challenging due to the growing diversity and variability of traffic patterns, which are not always well captured by traditional statistical features. In this work, we explore the use of entropy as an additional feature to support supervised network traffic classification. The main idea is to use entropy to represent variability in selected traffic…
Read original ↗https://arxiv.org/abs/2607.15379arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Lazy Arithmetic using Systolic Arrays for Closing the Verification Gap on Embedded Systems arXiv:2607.15328v1 Announce Type: new Abstract: Complex algorithms such as deep neural networks are increasingly being deployed on embedded, resource constrained platforms. However, existing hardware and software schemes for implementing these models on the edge fall short, particularly for safety-critical applications such as medical devices. First, hardware such as GPUs, NPUs and TPU…
Read original ↗https://arxiv.org/abs/2607.15328arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
ADS-C: Antidistillation Sampling for Classification arXiv:2607.15467v1 Announce Type: cross Abstract: Knowledge distillation enables an adversary to replicate a proprietary classifier by querying its prediction interface and training a surrogate on the returned probability vectors. Antidistillation sampling, proposed for large language models, counters this threat with an input-dependent, gradient-directed perturbation of the served distribution; its transfer to classificati…
Read original ↗https://arxiv.org/abs/2607.15467arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
DICOMHawk: A Cyber Deception Framework for Medical Imaging Infrastructure arXiv:2607.15754v1 Announce Type: new Abstract: Cyber-attacks against exposed healthcare infrastructure threaten sensitive patient data and clinical operations, yet existing defensive tools for DICOM-based medical imaging systems provide limited interaction and are easily fingerprinted. We introduce DICOMHawk, a cyber-deception framework that emulates DICOM and PACS services using realistic interaction…
Read original ↗https://arxiv.org/abs/2607.15754arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
From Neural Intent to Cryptographic Authorization: Governing Agentic Workflows arXiv:2607.15596v1 Announce Type: new Abstract: The rapid adoption of artificial intelligence (AI)-driven and agentic workflows is transforming traditional government and enterprise systems into language-based, tool-using and increasingly autonomous infrastructures. Conventional key management services authenticate who may invoke a cryptographic primitive, but remain agnostic to which workflow ste…
Read original ↗https://arxiv.org/abs/2607.15596arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
DoSQ: A Cross-Layer Denial of Service Quality Attack by Exploiting Side Channels in 5G NR arXiv:2607.16102v1 Announce Type: new Abstract: The 3rd Generation Partnership Project (3GPP)'s Fifth Generation New Radio (5G NR) is critical to supporting mission-critical services. However, 5G systems are vulnerable to smart jamming attacks that can propagate to applications running on top of these networks (i.e., cross-layer). The 5G gNB broadcasts resource scheduling information fo…
Read original ↗https://arxiv.org/abs/2607.16102arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Hidden in Thought: Transferable Chain-of-Thought Artifacts Induce Harmful Behavior arXiv:2607.15286v1 Announce Type: new Abstract: We investigate whether harmful chain-of-thought (CoT) traces from compromised language models can transfer unsafe behaviour and be distilled into reusable jailbreak attacks. Using an emergent-misalignment organism and a refusal-ablated jailbroken organism, we transplant harmful CoTs into $29$ open-source and $5$ closed-source targets. Transferred…
Read original ↗https://arxiv.org/abs/2607.15286arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Improving Network Anomaly Detection via Choquet-Integral-Based Feature Aggregation arXiv:2607.15389v1 Announce Type: new Abstract: This work investigates a generalized Choquet-integral-based feature aggregation framework to improve anomaly detection in high-dimensional network traffic data. The approach combines adaptive weighting with incremental feature selection to address feature redundancy. Using Random Forest and XGBoost classifiers, we evaluate models trained with bot…
Read original ↗https://arxiv.org/abs/2607.15389arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
FLINT: Fingerprinting Federated Learning Architectures from 5G PHY-Layer Side Channels arXiv:2607.15469v1 Announce Type: new Abstract: Federated Learning (FL) over 5G cellular networks protects raw data but remains vulnerable to side-channel leakage. Prior fingerprinting attacks assume packet-level network visibility, an assumption that does not hold at the 5G Physical (PHY) layer, where user payloads are encrypted and Radio Network Temporary Identifiers (RNTIs) may change o…
Read original ↗https://arxiv.org/abs/2607.15469arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
Gasp: A DeFi Application Specic Rollup as a Consolidation Layer for All Assets arXiv:2607.16052v1 Announce Type: new Abstract: Gasp is a decentralized exchange designed as an application-specific Layer 2 (L2) rollup with omnichain connectivity, leveraging EigenLayer's restaked ETH for computation correctness and finalization. With a goal of being a consolidation layer for all crypto assets, the Gasp platform employs optimistic rollup technology to facilitate gas-free, native…
Read original ↗https://arxiv.org/abs/2607.16052arxiv_cs_cr · tlp:amber · 7/20/2026, 4:00:00 AM
The Language of Security: How Prompt Syntax Shapes Secure Code Generation in Open LLMs arXiv:2607.15937v1 Announce Type: new Abstract: Large Language Models (LLMs) are increasingly used for source code generation despite their outputs often exhibiting security vulnerabilities. Prior work shows that prompt engineering can mitigate such risks, yet (1) they focused on high-level prompting strategies, neglecting recent evidence that fine-grained syntactic variations can substant…
Read original ↗https://arxiv.org/abs/2607.15937