REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
2138 reports · page 9 of 54
cisa_alerts · tlp:amber · 7/14/2026, 12:00:00 PM
Rockwell Automation 1715-AENTR EtherNet/IP Adapter View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device. The following versions of Rockwell Automation 1715-AENTR EtherNet/IP Adapter are affected: 1715-AENTR EtherNet/IP Adapter <=3.003 (CVE-2026-10577) CVSS Vendor Equipment Vulnera…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-04cisa_alerts · tlp:amber · 7/14/2026, 12:00:00 PM
CISA Urges SharePoint Hardening After New Exploitations CISA is aware of active exploitation of vulnerabilities CVE-2026-32201 , CVE-2026-45659 , and CVE-2026-56164 , enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, suc…
cisa_alerts · tlp:amber · 7/14/2026, 12:00:00 PM
ABB T-MAC Plus View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways. The following versions of ABB T-MAC Plus are affected: T-MAC Plus 4.0-24 (CVE-2025-14771, CVE-2025-14772, CVE-2025-14773, CVE-2025-14774) CVSS Vendor Equipme…
Read original ↗https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03
the_hacker_news · tlp:amber · 7/14/2026, 11:55:00 AM
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way these wallets talk to websites and blockchain servers can tie a person's separate addresses together and let outsiders follow them from site to site. And on a site that already holds a name or…
Read original ↗https://thehackernews.com/2026/07/study-of-85-crypto-wallet-extensions.html
the_hacker_news · tlp:amber · 7/14/2026, 11:30:00 AM
How Pentera Turns AI Security Workflows into Validation Engines AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragmented risk signals: scanner output, severity scores, threat intelligence, configuration findings, and exposure data. That fragmentation matters because attackers do not move through environments one How Pentera Turns …
Read original ↗https://thehackernews.com/2026/07/how-pentera-turns-ai-security-workflows.html
the_hacker_news · tlp:amber · 7/14/2026, 11:21:35 AM
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments, without ever generating a successful sign-in event that would otherwise alert defenders. And bad actors have begu…
Read original ↗https://thehackernews.com/2026/07/oauth-client-id-spoofing-lets-attackers.htmlsecurityweek · tlp:amber · 7/14/2026, 11:17:56 AM
SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud The flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization. The post SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud appeared first on SecurityWeek . SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual E…
Read original ↗https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloudsecurityweek · tlp:amber · 7/14/2026, 10:51:01 AM
US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks. The post US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers appeared first on SecurityWeek . US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual…
Read original ↗https://www.securityweek.com/us-allies-warn-of-russian-cyberattacks-targeting-critical-infrastructure-routers
talos · tlp:amber · 7/14/2026, 10:47:18 AM
[Video] Where protection starts: Cisco Talos Intelligence Integrations Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies. Cybersecurity has always involved elements of uncertainty. Every day, security teams are asked to make decisions with incomplete information, while attackers…
Read original ↗https://blog.talosintelligence.com/video-where-protection-starts-cisco-talos-intelligence-integrations
talos · tlp:amber · 7/14/2026, 10:00:06 AM
The serpent’s tongue: Luring the Python out of its den This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments. Python's popularity, readable syntax, and extensive third-party library ecosystem make it an attractive target for threat actors seeking to compromise developer devices and…
Read original ↗https://blog.talosintelligence.com/the-serpents-tongue-luring-the-python-out-of-its-densecurityweek · tlp:amber · 7/14/2026, 9:32:15 AM
Valarian Raises $50 Million for Sovereign Infrastructure Control Layer UK-based cybersecurity firm Valarian has raised a total of $70 million for its ACRA technology. The post Valarian Raises $50 Million for Sovereign Infrastructure Control Layer appeared first on SecurityWeek . Valarian Raises $50 Million for Sovereign Infrastructure Control Layer - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware &…
Read original ↗https://www.securityweek.com/valarian-raises-50-million-for-sovereign-infrastructure-control-layersecurityweek · tlp:amber · 7/14/2026, 9:04:39 AM
Multiple Jscrambler Packages Impacted by Supply Chain Attack A threat actor poisoned several Jscrambler NPM package versions to drop a cross-platform credential stealer. The post Multiple Jscrambler Packages Impacted by Supply Chain Attack appeared first on SecurityWeek . Multiple Jscrambler Packages Impacted by Supply Chain Attack - SecurityWeek SECURITYWEEK NETWORK: Cybersecurity News Webcasts Virtual Events ICS: ICS Cybersecurity Conference Malware & Threats Cyberwar…
Read original ↗https://www.securityweek.com/multiple-jscrambler-packages-impacted-by-supply-chain-attack
the_hacker_news · tlp:amber · 7/14/2026, 9:02:48 AM
Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out of the intercepted request, and pulled back a file the agent had been told in plain terms not G…
Read original ↗https://thehackernews.com/2026/07/grok-build-uploads-entire-git.htmleset · tlp:amber · 7/14/2026, 8:53:00 AM
Forgotten UEFI shims undermining Secure Boot ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities Forgotten UEFI shims undermining Secure Boot Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White paper…
Read original ↗https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot
the_hacker_news · tlp:amber · 7/14/2026, 8:02:33 AM
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious activities, including ransomware attacks against Americans. The VPN, named First VPN Service (1VPNS), has been accused of offering its tools to ransomware groups, along with its 45-year-old Ukrainia…
Read original ↗https://thehackernews.com/2026/07/us-sanctions-first-vpn-service-and.html
the_hacker_news · tlp:amber · 7/14/2026, 7:08:36 AM
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog. The packages did not go after the developers who might install them. The operators used the registry as free hosting for a booby-trapped proxy site and let the students who came to dodge 148…
Read original ↗https://thehackernews.com/2026/07/148-npm-packages-disguised-as-student.html
the_hacker_news · tlp:amber · 7/14/2026, 6:19:24 AM
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it. In Mic…
Read original ↗https://thehackernews.com/2026/07/microsoft-maps-year-long-shinyhunters.htmlcheckpoint_research · tlp:amber · 7/14/2026, 12:51:31 AM
AI Security Report 2026 For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from Check Point Research documents a transition that goes further. AI has crossed from assistant to operator. Where it once helped attackers prepare, it now runs the […] The post AI Security Report 2026 appeared first on Che…
Read original ↗https://research.checkpoint.com/2026/ai-security-report-2026
the_record · tlp:amber · 7/13/2026, 11:00:00 PM
Hackers steal Lidl customer data from external service provider The retailer said the incident did not affect its online shopping platform itself but involved a separately stored customer database maintained by a third-party provider. According to notifications sent to Lidl's German, Belgian and Dutch customers on Friday, the attackers briefly accessed the file and exfiltrated part of its contents. Hackers steal Lidl customer data from external service provider | The Record…
Read original ↗https://therecord.media/hackers-steal-lidl-customer-datamicrosoft_mstic · tlp:amber · 7/13/2026, 10:02:41 PM
Defending SaaS-based applications against ShinyHunters OAuth abuse Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications. The post Defending SaaS-based applications against ShinyHunters OAuth abuse appeared first on Microsoft Security Blog . In this article Attack chain overv…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse
ars_security · tlp:amber · 7/13/2026, 9:03:07 PM
The US government warns that Russia state hackers are coming after your router With residential proxies all the rage, CISA urges router users to be vigilant. The federal government is warning users of home and small office routers to secure their devices as Russia state hackers continue to mass-compromise them for use in obscuring nefarious actions against sensitive organizations in the public and private sectors. Both the Russian and Chinese governments have been compromis…
Read original ↗https://arstechnica.com/security/2026/07/the-us-government-warns-that-russia-state-hackers-are-coming-after-your-router
the_record · tlp:amber · 7/13/2026, 8:50:00 PM
EU leaders eye social media ban for children under age 13 “While ultimately it is up to parents to decide when children get their first smartphones, what we already have is a consensus that there needs to be a start date for the age children can join social media,” says European Commission President Ursula van der Leyen. EU leaders eye social media ban for children under age 13 | The Record from Recorded Future News Leadership Cybercrime Nation-state Influence Operations Te…
Read original ↗https://therecord.media/eu-proposed-social-media-ban-kids-under-13
the_hacker_news · tlp:amber · 7/13/2026, 5:36:12 PM
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is implemented in native C++, according to Jamf Threat Labs. "It validates the victim's login password locally before CrashS…
Read original ↗https://thehackernews.com/2026/07/crashstealer-macos-malware-uses.html
the_hacker_news · tlp:amber · 7/13/2026, 5:17:24 PM
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version. The collector was dormant. An empty allow-list kept it switched off, and no proof has emerged that it ever gathered or sent a single browsing domain. T…
Read original ↗https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.htmlmicrosoft_mstic · tlp:amber · 7/13/2026, 5:00:00 PM
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare. The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID appeared first on Microsoft Security Blog . As identity attacks grow more sophisticated in the AI era, organizations need st…
Read original ↗https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id
ars_security · tlp:amber · 7/13/2026, 3:06:34 PM
Now, defenders are embracing the prompt injection, too "Context bombing" tricks hacking agents into shutting down before they can do harm. Prompt injections, the malicious commands attackers embed into content to entice large language models to follow them, have been attackers’ go-to tool for turning AI platforms against their users. A well-phrased command sneaked into an email or calendar invitation is often all it takes to cause the LLM to exfiltrate sensitive data or fol…
Read original ↗https://arstechnica.com/security/2026/07/now-defenders-are-embracing-the-prompt-injection-too
the_hacker_news · tlp:amber · 7/13/2026, 3:05:57 PM
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets. That's the shape of this week. Trusted code turns on the people who installed it. Old bugs from last year are still landing because the fix sat in a qu…
Read original ↗https://thehackernews.com/2026/07/weekly-recap-sharefile-threat-citrix.htmlkrebs_on_security · tlp:amber · 7/13/2026, 3:03:28 PM
Lessons Learned from CISA’s Recent GitHub Leak The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb. The Cy…
Read original ↗https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leaklwn_kernel · tlp:amber · 7/13/2026, 2:14:08 PM
[$] Shielding running kernels against exploits with BPF Cisco has some unusual challenges when it comes to deploying security patches across the company's many devices running custom kernels. John Fastabend spoke about his work preventing exploits with BPF at the 2026 Linux Storage, Filesystem, Memory-Management, and BPF Summit . The technique could substantially reduce the time necessary to respond to kernel vulnerabilities, but it will not be fully effective unless more ho…
Read original ↗https://lwn.net/Articles/1081546chainalysis · tlp:amber · 7/13/2026, 1:56:28 PM
Courtroom-Ready Analytics: How Chainalysis Met the Daubert Standard Blockchain tracing tools like Chainalysis Reactor help investigators untangle the financial networks behind illicit activity: fraud, theft, sanctions evasion, cybercrime,… The post Courtroom-Ready Analytics: How Chainalysis Met the Daubert Standard appeared first on Chainalysis . Daubert Standard: How Chainalysis Reactor Met the Bar Chainalysis Products Crypto Investigations Investigations Solutions R…
Read original ↗https://www.chainalysis.com/blog/chainalysis-daubert-standard-sterlingov
the_hacker_news · tlp:amber · 7/13/2026, 1:49:48 PM
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false "fact" about the user, hide the change, and quietly steer its answers in later sessions. When it works, the person reads an ordinary-looking reply and never learns their assistant was tampered with. The Ne…
Read original ↗https://thehackernews.com/2026/07/new-memghost-attack-plants-persistent.htmllwn_kernel · tlp:amber · 7/13/2026, 1:26:16 PM
Final normal Debian bookworm release Debian has announced the final normal update for Debian 12 ("bookworm"). Long-term-support updates will continue until 2028 . As may be expected from a stable version, the update is mostly limited to security fixes. Still, it may be time for Debian users to look into upgrading to a more recent version. Conveniently, Debian 13 ("trixie") also received an update this weekend, with many of the same security fixes. Final normal Debian bookwo…
Read original ↗https://lwn.net/Articles/1082647checkpoint_research · tlp:amber · 7/13/2026, 1:06:08 PM
13th July – Threat Intelligence Report For the latest discoveries in cyber research for the week of 13th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES U.S. auto insurer AssuranceAmerica has disclosed a data breach affecting approximately 7 million people. Attackers targeted an employee and used compromised credentials to access company systems, stealing names, contact information, driver’s license […] The post 13th July – Threat Intel…
Read original ↗https://research.checkpoint.com/2026/13th-july-threat-intelligence-report
the_hacker_news · tlp:amber · 7/13/2026, 1:03:33 PM
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts. Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing Forg36…
Read original ↗https://thehackernews.com/2026/07/forg365-phaas-targets-microsoft-365.htmllwn_kernel · tlp:amber · 7/13/2026, 12:40:26 PM
Security updates for Monday Security updates have been issued by Debian (chromium, libxfont, mesa, opam, and wireless-regdb), Fedora (acl, attr, chromium, cjson, composer, docker-compose, jfrog-cli, librabbitmq, libssh2, libXfont2, log4cxx, OpenImageIO, openssh, p11-kit, perl-Crypt-DSA, perl-HTML-Gumbo, prometheus, python-dulwich, python-idna, python-pillow, python-tornado, sssd, tmux, upower, webkitgtk, xorg-x11-server, and xorg-x11-server-Xwayland), Mageia (libarchive and …
Read original ↗https://lwn.net/Articles/1082642cisa_alerts · tlp:amber · 7/13/2026, 12:00:00 PM
CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk e…
Read original ↗https://www.cisa.gov/news-events/alerts/2026/07/13/cisa-adds-one-known-exploited-vulnerability-catalog
cisa_alerts · tlp:amber · 7/13/2026, 12:00:00 PM
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds o…
Read original ↗https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a
the_hacker_news · tlp:amber · 7/13/2026, 11:54:46 AM
Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read. Each read gets pinned to the moment it happened: the time, your location, what you were doing, even how you were using your phone. Some versions in the filing would listen all day; others would Meta F…
Read original ↗https://thehackernews.com/2026/07/meta-files-patent-for-ai-that-can.html
the_hacker_news · tlp:amber · 7/13/2026, 11:37:05 AM
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as we mapped out the broader architecture, something kept nagging at me. The design they w…
Read original ↗https://thehackernews.com/2026/07/thinking-fast-and-slow-in-soc-case-for.html
the_hacker_news · tlp:amber · 7/13/2026, 11:02:33 AM
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. "The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD_Report.html to measure the success of the Attacker Us…
Read original ↗https://thehackernews.com/2026/07/attacker-uses-suspected-ai-generated.html