REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2138 reports · page 7 of 54

the_hacker_news · tlp:amber · 7/15/2026, 3:30:30 PM
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet's own desktop software. Sometimes it waits until you plug the device in first. The page is malicious. The app around it is the real one you installed, and …
Read original ↗https://thehackernews.com/2026/07/okobot-malware-framework-injects-seed.htmlsecurityweek · tlp:amber · 7/15/2026, 2:37:13 PM
Unpatched Cursor Vulnerability Exposes Users to Code Execution An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically. The post Unpatched Cursor Vulnerability Exposes Users to Code Execution appeared first on SecurityWeek . Unpatched Cursor Vulnerability Exposes Users to Code Execution - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Event In-Progress SECURITYWEEK NETWORK: Cybersecu…

the_record · tlp:amber · 7/15/2026, 2:14:00 PM
Dutch police dismantle global crypto investment scam, arrest alleged mastermind Authorities said Wednesday that the group operated like a legitimate international business since at least 2021, running about two dozen call centers across several countries and employing more than 700 people who posed as professional financial advisers. Dutch police dismantle global crypto investment scam, arrest alleged mastermind | The Record from Recorded Future News Leadership Cybercrime N…
Read original ↗https://therecord.media/dutch-police-dismantle-global-crypto-investment-scamsecurityweek · tlp:amber · 7/15/2026, 2:07:44 PM
CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days. The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek . CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Event In-Progress SECURITYWEEK NETWORK: Cyber…
Read original ↗https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-sharepoint-vulnerabilitiesmandiant · tlp:amber · 7/15/2026, 2:00:00 PM
The Risk of Exposed Cloud Functions and How to Harden Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RF…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/exposed-cloud-functions-hardenlwn_kernel · tlp:amber · 7/15/2026, 1:35:43 PM
[$] Lockless MPSC FIFO queues for io_uring Processes that use io_uring tend to keep a lot of balls in the air; being able to have many operations underway at any given time is part of the point of that API in the first place. The io_uring subsystem must, as a result, keep track of a lot of tasks that have to be performed at the right time. In current kernels, io_uring uses a standard kernel linked-list primitive to track those work items. As of the 7.2 kernel release, though…
Read original ↗https://lwn.net/Articles/1081871lwn_kernel · tlp:amber · 7/15/2026, 1:19:02 PM
Security updates for Wednesday Security updates have been issued by AlmaLinux (cifs-utils, corosync, cups, freerdp, git-lfs, go-fdo-client and go-fdo-server, go-toolset:rhel8, kernel, kernel-rt, libinput, libxml2, nginx:1.24, openssl, pacemaker, perl-DBI:1.641, php8.4, python-pillow, python3, and python3.12), Debian (grub2, libxfont, opam, and wolfssl), Fedora (freerdp, kernel, and prometheus), Mageia (imagemagick), Oracle (buildah, freerdp, gimp, kernel, nginx, openexr, ope…
Read original ↗https://lwn.net/Articles/1083044
the_hacker_news · tlp:amber · 7/15/2026, 1:18:53 PM
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation in the DOM: Navigation component "We are aware that exploit code for this is public, however we are not aware of Firefox, …
Read original ↗https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware-updates.htmlsecurityweek · tlp:amber · 7/15/2026, 1:00:00 PM
Windows Bind Link Attacks Can Hide Malware From EDR Tools Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products. The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek . Windows Bind Link Attacks Can Hide Malware From EDR Tools - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Event In-Progress SECURITYWEEK NETWORK: Cybersecu…
Read original ↗https://www.securityweek.com/windows-bind-link-attacks-can-hide-malware-from-edr-tools
the_record · tlp:amber · 7/15/2026, 1:00:00 PM
LAPD sidelines relationship with license-plate reader company Flock Safety The Los Angeles Police Department is the latest U.S. municipal agency to rethink its relationship to ALPR company Flock Safety. LAPD sidelines relationship with license-plate reader company Flock Safety | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go Subscribe to The Record ✉️ Free Newsletter Image: Nick Page…
Read original ↗https://therecord.media/lapd-halts-flock-safety-alpr-contractsecurityweek · tlp:amber · 7/15/2026, 12:52:10 PM
Virtual Event Today: Cloud & Data Security Summit Attendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. The post Virtual Event Today: Cloud & Data Security Summit appeared first on SecurityWeek . Virtual Event Today: Cloud & Data Security Summit - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Event In-Progress SECURITYWEEK NETWORK: Cybersecu…
Read original ↗https://www.securityweek.com/virtual-event-today-cloud-data-security-summitlwn_kernel · tlp:amber · 7/15/2026, 12:49:36 PM
Many old shim versions are still accepted by secure boot The CMU CERT Coordination Center has put out an advisory that many exploitable versions of the shim binary, used to boot Linux on systems with UEFI secure boot enabled, were never added to the revocation list. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operat…
Read original ↗https://lwn.net/Articles/1082940
the_record · tlp:amber · 7/15/2026, 12:15:00 PM
Microsoft smashes Patch Tuesday record for second successive month Vulnerability counts have been surging this year, and Microsoft's mammoth disclosure this week of 622 bugs is larger than the three previous months combined. Microsoft smashes Patch Tuesday record for second successive month | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go Subscribe to The Record ✉️ Free Newsletter Im…
Read original ↗https://therecord.media/microsoft-vulnerabilities-patch-tuesday-releasecisa_alerts · tlp:amber · 7/15/2026, 12:00:00 PM
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a coordinated vulnerability disclosure (CVD) program for working with external security researchers that includes a clear vulnerability disclosure policy (VDP) and process for tri…
Read original ↗https://www.cisa.gov/resources-tools/resources/establishing-coordinated-vulnerability-disclosure-program-work-security-researcherssecurityweek · tlp:amber · 7/15/2026, 11:58:05 AM
US Charges Russian Individuals and Firms for Running Cybercrime Services The suspects and their companies were previously sanctioned by the United States and its allies. The post US Charges Russian Individuals and Firms for Running Cybercrime Services appeared first on SecurityWeek . US Charges Russian Individuals and Firms for Running Cybercrime Services - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Event In-Progress SECURITYWEEK NETWORK: Cybersec…
Read original ↗https://www.securityweek.com/us-charges-russian-individuals-and-firms-for-running-cybercrime-services
the_hacker_news · tlp:amber · 7/15/2026, 11:50:01 AM
SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough. For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctioned browser extensions, and autonomous agents. Employees routinely paste intellectual property into SASE Has An AI Bl…
Read original ↗https://thehackernews.com/2026/07/sase-has-ai-blind-spot-inspecting.html
the_hacker_news · tlp:amber · 7/15/2026, 11:07:07 AM
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments. "The PoC requires Res…
Read original ↗https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html
the_hacker_news · tlp:amber · 7/15/2026, 11:06:57 AM
New Webinar: Closing the Approval Gap in AI-Era Ad Tech A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reveals how this Approval Gap forms, and gives your team the blueprint to close it before an auditor, regulator, or attacker finds it first. The Reality of the Approval Gap It's a pattern every New Webinar: Closing the Approva…
Read original ↗https://thehackernews.com/2026/07/new-webinar-closing-approval-gap-in-ai.htmlsecurityweek · tlp:amber · 7/15/2026, 11:02:57 AM
Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow A critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code. The post Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow appeared first on SecurityWeek . Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Event In-Progress SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events …
Read original ↗https://www.securityweek.com/vulnerabilities-patched-by-fortinet-ivanti-servicenow
the_hacker_news · tlp:amber · 7/15/2026, 10:55:22 AM
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tokens. Cursor keeps re-running it for as long as the project stays open. No prompt Curso…
Read original ↗https://thehackernews.com/2026/07/cursor-flaw-lets-malicious-cloned.htmlsecurityweek · tlp:amber · 7/15/2026, 10:18:25 AM
White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative The new program stems from an AI-focused Executive Order signed by President Trump on June 2. The post White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative appeared first on SecurityWeek . White House Launches AI-Driven 'Gold Eagle' Vulnerability Coordination Initiative - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Ev…
Read original ↗https://www.securityweek.com/white-house-launches-ai-driven-gold-eagle-vulnerability-coordination-initiative
unit42 · tlp:amber · 7/15/2026, 10:00:54 AM
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42 . TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development Menu Tools ATOMs Security Consulting About Us Under Attack? Threat Research Center Thre…
Read original ↗https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnetsecurityweek · tlp:amber · 7/15/2026, 9:48:29 AM
Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption The company has rolled out a fix and is restoring access for Storage Zones Controller customers who apply it. The post Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption appeared first on SecurityWeek . Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Event In-Progress SECURITYWEEK NETWORK: Cyberse…
Read original ↗https://www.securityweek.com/progress-confirms-zero-day-vulnerability-behind-sharefile-disruptionsecurityweek · tlp:amber · 7/15/2026, 9:19:58 AM
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell The industrial giants fixed dozens of vulnerabilities across their ICS products, with advisories also released by CISA and VDE CERT. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell appeared first on SecurityWeek . ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Event In-Pro…
Read original ↗https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-rockwell
the_hacker_news · tlp:amber · 7/15/2026, 9:16:13 AM
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below - @asyncapi/generator-helpers@1.1.1 @asyncapi/generator-components@0.7.1 @asyncapi/generator@3.3.1 @asyncapi/specs(v6.11.2, v6.11.2-alpha.1) "The Compromised AsyncAPI npm Packag…
Read original ↗https://thehackernews.com/2026/07/compromised-asyncapi-npm-packages.htmlsecurityweek · tlp:amber · 7/15/2026, 7:24:52 AM
Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed. The post Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates appeared first on SecurityWeek . Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates - SecurityWeek Virtual Event Today: Cloud & Data Security Summit - Join Event In-Progress SECURITYWEE…
Read original ↗https://www.securityweek.com/critical-vulnerabilities-patched-with-fresh-chrome-150-firefox-152-updates
the_hacker_news · tlp:amber · 7/15/2026, 5:30:21 AM
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below - CVE-2026-15409 (CVSS score: 10.0) - A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to Two SonicWa…
Read original ↗https://thehackernews.com/2026/07/two-sonicwall-sma-1000-zero-days.htmlsecurityweek · tlp:amber · 7/15/2026, 5:19:42 AM
SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits SonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution. The post SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits appeared first on SecurityWeek . SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conferen…
Read original ↗https://www.securityweek.com/sonicwall-issues-urgent-sma-patch-warning-for-two-zero-day-exploitsarxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Auditable and Transparent Fully Authenticated Disk Encryption via USB Storage Interposition arXiv:2607.12716v1 Announce Type: new Abstract: Full Disk Encryption (FDE) has become increasingly important in the last decades due to the evident confidentiality concerns. In most systems, encryption is provided by an operating system driver, through which the user can transparently access the encrypted disk after supplying the required keys (or the credentials from which those keys…
Read original ↗https://arxiv.org/abs/2607.12716arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
On the Security Implications of PQC in TLS: Handshake Exhaustion and IDS Degradation arXiv:2607.12504v1 Announce Type: new Abstract: Post-Quantum Cryptography (PQC) is increasingly being integrated into TLS 1.3 to enhance resilience against quantum-enabled attacks. However, the additional computational and communication overhead introduced by PQC primitives during the handshake phase may also amplify the impact of TLS handshake exhaustion attacks, leading to more severe Dist…
Read original ↗https://arxiv.org/abs/2607.12504arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
AutoTrace: From Patches to Triggers via Agentic Interprocedural Exploration arXiv:2607.12058v1 Announce Type: cross Abstract: Given a vulnerability-fixing commit, trigger localization asks which specific statement turns the vulnerable program state into a concrete unsafe operation. This question is harder than binary vulnerability detection because the answer demands interprocedural, causal reasoning: in a substantial fraction of real-world CVEs the triggering statement lies…
Read original ↗https://arxiv.org/abs/2607.12058arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Trust but Verify? Uncovering the Security Debt of Autonomous Coding Agents arXiv:2607.12428v1 Announce Type: new Abstract: The increasing adoption of autonomous coding agents accelerates software development but also introduces scoped security risks within high-impact file paths that can outpace traditional human review capacity. While prior research has primarily evaluated these systems in terms of functional correctness and productivity, this paper presents a large-scale e…
Read original ↗https://arxiv.org/abs/2607.12428arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
VanillaBench: The Hidden Accuracy Cost of Adversarial Robustness arXiv:2607.12545v1 Announce Type: new Abstract: Adversarial robustness research has produced hundreds of defended models over the past decade, yet the literature almost universally reports robustness results in isolation: standard (clean) accuracy and adversarial accuracy of the robust model are shown, but the gap to the corresponding vanilla model is rarely quantified. We introduce VanillaBench, a systematic b…
Read original ↗https://arxiv.org/abs/2607.12545arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Open-Source Intelligence and Music Information Retrieval for Geographic Attribution of Musical Affect and the Ecological Limits of Population Inference arXiv:2607.12517v1 Announce Type: new Abstract: A common intuition holds that a region's music mirrors the temperament of its people, so that melancholic melodies mark melancholic populations. We test the measurable half of that intuition and reject the inferential half. Using the Essen Folksong Collection, a corpus of thousa…
Read original ↗https://arxiv.org/abs/2607.12517arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
When Binaries Talk Back: Representation-Confusion Attacks on LLM-Assisted Reverse Engineering arXiv:2607.12507v1 Announce Type: new Abstract: LLM-assisted reverse-engineering (RE) systems analyze strings, decompiler output, and tool reports derived from ttacker-controlled binaries. A binary can make data look like instructions or records from one origin look like independent evidence. We call such failures Representation-Confusion Attacks in Reverse Engineering (RARE): the p…
Read original ↗https://arxiv.org/abs/2607.12507arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Silent Alarm: A J-Space Protocol for Comparing Danger Recognition Across Models and Quantization Levels arXiv:2607.12792v1 Announce Type: new Abstract: Jailbreak-robustness research typically evaluates safety through generated responses using an LLM-as-judge approach. Such evaluations, however, are sensitive to the benchmark's grading procedure and capture only observed behavior on a given set of attacks, without directly revealing the hidden fragility of the underlying safe…
Read original ↗https://arxiv.org/abs/2607.12792arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
$\mathrm{P}^{3}$CDA: Privacy-Preserving and Provably Secure Cross Domain Authentication Scheme for Internet of Drones arXiv:2607.12288v1 Announce Type: new Abstract: With the rapid expansion of the Internet of Drones (IoD) and the increasing mobility of drones, cross-domain interactions among geographically distributed domains have become inevitable. Cross-domain authentication is therefore a fundamental security requirement for IoD. However, existing authentication schemes …
Read original ↗https://arxiv.org/abs/2607.12288arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Explaining Intrusion Alert Decisions of Deep Learning-based Network Intrusion Detection Systems for Security Analysts arXiv:2607.12203v1 Announce Type: new Abstract: In this paper, we present EXP-SEC, a novel framework which can explain the intrusion detection decisions of DL-based NIDS (which lead to security alerts) in a way that is aligned with the domain knowledge of analysts working in Security Operations Center (SOC). We highlight the following features of our framewor…
Read original ↗https://arxiv.org/abs/2607.12203arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
Antiproof: Synthesizing Vulnerability Detectors and Proofs of Exploitability arXiv:2607.12316v1 Announce Type: new Abstract: Discovering vulnerabilities before attackers exploit them requires high recall and reliable automatic validation, but existing approaches struggle to achieve both without prohibitive cost. We present Antiproof, an end-to-end vulnerability discovery system that combines neuro-symbolic detector synthesis for high-recall discovery with proof-of-exploitabi…
Read original ↗https://arxiv.org/abs/2607.12316arxiv_cs_cr · tlp:amber · 7/15/2026, 4:00:00 AM
A Scalable Cloud-Orchestrated and Service-Oriented Multi-Domain QKD Network with PQC Integration arXiv:2607.12765v1 Announce Type: new Abstract: Quantum key distribution (QKD) offers unconditional security but existing QKD networks remain difficult to scale across heterogeneous infrastructures and administrative domains due to vendor-specific interfaces, trusted-node constraints, and limited interoperability. This work presents a flexible multi-domain and multi-site quantum-…
Read original ↗https://arxiv.org/abs/2607.12765