REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
136 reports · page 1 of 4

the_hacker_news · tlp:amber · 7/21/2026, 8:59:30 AM
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. "By the early hours of Saturday morning (UTC), successful exploitation was already well WordPress w…
Read original ↗https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html
the_hacker_news · tlp:amber · 7/21/2026, 7:34:32 AM
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem. The entry New ENCFORGE Ran…

the_hacker_news · tlp:amber · 7/21/2026, 6:29:26 AM
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. Patches for the flaw were
Read original ↗https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html
the_hacker_news · tlp:amber · 7/20/2026, 6:23:03 PM
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. "FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP FakeG…
Read original ↗https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
the_hacker_news · tlp:amber · 7/20/2026, 5:29:50 PM
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it more than a Exp…
Read original ↗https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html
the_hacker_news · tlp:amber · 7/20/2026, 2:33:43 PM
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks Ho…
Read original ↗https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html
the_hacker_news · tlp:amber · 7/20/2026, 1:32:26 PM
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is t…
Read original ↗https://thehackernews.com/2026/07/weekly-recap-wordpress-rce-sonicwall-0.html
the_hacker_news · tlp:amber · 7/20/2026, 12:13:39 PM
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and milit…
Read original ↗https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
the_hacker_news · tlp:amber · 7/20/2026, 11:30:00 AM
Mythos Didn't Break Your Security Program. Your Exposure Window Could. The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of Mythos Didn't …
Read original ↗https://thehackernews.com/2026/07/mythos-didnt-break-your-security.html
the_hacker_news · tlp:amber · 7/20/2026, 9:10:56 AM
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets an attacker "execute code in the context of the current process," per the New 7-…
Read original ↗https://thehackernews.com/2026/07/new-7-zip-vulnerability-could-let.html
the_hacker_news · tlp:amber · 7/20/2026, 9:07:11 AM
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a re…
Read original ↗https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html
the_hacker_news · tlp:amber · 7/20/2026, 5:27:26 AM
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. "We identified unauthorized access to a limited set of internal datasets and to several credentials used by …
Read original ↗https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
the_hacker_news · tlp:amber · 7/20/2026, 5:15:39 AM
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) - SleeperGem Us…
Read original ↗https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html
the_hacker_news · tlp:amber · 7/19/2026, 8:42:49 PM
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade. Triggering it can crash or restart the worker, causing a denial of…
Read original ↗https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
the_hacker_news · tlp:amber · 7/19/2026, 1:30:55 PM
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's UAC-0145 Uses …
Read original ↗https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html
the_hacker_news · tlp:amber · 7/19/2026, 1:18:56 PM
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this SonicWall SMA…
Read original ↗https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html
the_hacker_news · tlp:amber · 7/17/2026, 9:20:10 PM
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system. Adam Kues at Assetnote, Searchlight Cyber's attack surface management arm, found the flaw and reported New wp2s…
Read original ↗https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
the_hacker_news · tlp:amber · 7/17/2026, 8:20:53 PM
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denial-of-service bug and named it, published the OpenSSL…
Read original ↗https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
the_hacker_news · tlp:amber · 7/17/2026, 6:54:51 PM
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron, Seven Malic…
Read original ↗https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
the_hacker_news · tlp:amber · 7/17/2026, 5:12:23 PM
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter …
Read original ↗https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
the_hacker_news · tlp:amber · 7/17/2026, 4:39:16 PM
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using Golde…
Read original ↗https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html
the_hacker_news · tlp:amber · 7/17/2026, 1:48:56 PM
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. "Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto wallet stealer, a file stealer, a Fake Codi…
Read original ↗https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html
the_hacker_news · tlp:amber · 7/17/2026, 11:44:41 AM
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing. Google has to ship it in the next major release, Android 18, and by 1 August 2027 at …
Read original ↗https://thehackernews.com/2026/07/eu-orders-google-to-open-android-mic.html
the_hacker_news · tlp:amber · 7/17/2026, 11:30:00 AM
The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace? Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move from concept to operational deployment at commercial speed. Now the focus shifts to the tr…
Read original ↗https://thehackernews.com/2026/07/the-race-to-field-military-autonomy-is.html
the_hacker_news · tlp:amber · 7/17/2026, 10:53:31 AM
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a s…
Read original ↗https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html
the_hacker_news · tlp:amber · 7/17/2026, 8:56:39 AM
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains on Thursday. Its Defender Experts team, the …
Read original ↗https://thehackernews.com/2026/07/acr-stealer-uses-clickfix-lures-to.html
the_hacker_news · tlp:amber · 7/17/2026, 8:46:45 AM
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering. Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities …
Read original ↗https://thehackernews.com/2026/07/new-goserpent-malware-targets-southeast.html
the_hacker_news · tlp:amber · 7/17/2026, 6:42:23 AM
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization CISA Adds Exploi…
Read original ↗https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html
the_hacker_news · tlp:amber · 7/16/2026, 5:09:25 PM
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority's employees into an office to get their passwords reset in person. Both the NCA and the CPS put TfL's losses and recovery Two Scatter…
Read original ↗https://thehackernews.com/2026/07/two-scattered-spider-hackers-get-55.html
the_hacker_news · tlp:amber · 7/16/2026, 3:41:15 PM
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation. Old bugs are back, weak defaults are earning their keep, and some attack paths are so plain they barely feel like research. Here’s th…
Read original ↗https://thehackernews.com/2026/07/threatsday-game-cheat-spyware-24-hour.html
the_hacker_news · tlp:amber · 7/16/2026, 1:33:25 PM
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss. A valid token from issuer A carrying a sub that belongs to someone under issuer B logged you in as them. Their password never n8n …
Read original ↗https://thehackernews.com/2026/07/n8n-token-exchange-flaw-could-let.html
the_hacker_news · tlp:amber · 7/16/2026, 12:50:13 PM
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026. "The malware is full-featured, lightweight, and modular," Elastic Security Labs researcher Cyril François said in a technical report. "While the number of C2 [command-and-control] domains is currently small, the daily New TELEPUZ M…
Read original ↗https://thehackernews.com/2026/07/new-telepuz-malware-spreads-via.html
the_hacker_news · tlp:amber · 7/16/2026, 12:33:42 PM
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password ClickLock Stealer, a new macOS infostealer, answers a victim's refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim cancels, installs two LaunchAgents and quietly exits. At the next login, Finder, the Dock, Spotlight, Terminal, Activity Monitor, and…
Read original ↗https://thehackernews.com/2026/07/new-clicklock-macos-stealer-kills-apps.html
the_hacker_news · tlp:amber · 7/16/2026, 11:58:00 AM
20+ Hijacked Government Websites Became an Attack Channel More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation revealed previously undocumented backdoor behavior, hidden infrastructure relationships, and multiple attack arms behind a campaign 20+ Hijacked Government Web…
Read original ↗https://thehackernews.com/2026/07/20-hijacked-government-websites.html
the_hacker_news · tlp:amber · 7/16/2026, 11:32:28 AM
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click "Buy Now" instead. Ask a coding assistant to apply a maintainer's fix from a GitHub thread, and a fake comment can make it run a stranger's command on your computer. Neither trick hijacks the agent's task. Each one just corrupts the facts it trusts and lets it carry on with the job you …
Read original ↗https://thehackernews.com/2026/07/new-agent-data-injection-attack-can.html
the_hacker_news · tlp:amber · 7/16/2026, 11:17:23 AM
Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin ("srt64.sys"), as the kernel-mode rootkit is referred to, was first documented by Broadcom-owned Symantec in March 2022, with evidence indicating its use in targeted attacks aimed Daxin Resurf…
Read original ↗https://thehackernews.com/2026/07/daxin-resurfaces-in-taiwan-alongside.html
the_hacker_news · tlp:amber · 7/16/2026, 10:10:00 AM
AI Can Find Bugs, But Human Knowledge Still Proves Them Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive testing workflows at impressive speed. That is a real advantage for security teams. It also AI Can Find Bugs, But Human Kn…
Read original ↗https://thehackernews.com/2026/07/ai-can-find-bugs-but-human-knowledge.html
the_hacker_news · tlp:amber · 7/16/2026, 9:23:19 AM
Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people's Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext. A researcher publishing under the handle tokay0 put the method online on Monday, having tested it only against vacuums he …
Read original ↗https://thehackernews.com/2026/07/unpatched-shark-vacuum-flaw-could-let.html
the_hacker_news · tlp:amber · 7/16/2026, 8:42:31 AM
OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely. "GPT‑Red is a strong red-teamer, and our previous models are highly vulnerable to its prompt injection attacks," the artificial intelligence (AI) company said. "We use GPT‑Red to adversarially train OpenAI&…
Read original ↗https://thehackernews.com/2026/07/openais-gpt-red-automates-prompt.html
the_hacker_news · tlp:amber · 7/16/2026, 7:22:44 AM
Zoom Patches Critical Windows Flaw That Could Enable Account Takeover Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. "Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Zoom Patches Cri…
Read original ↗https://thehackernews.com/2026/07/zoom-patches-critical-windows-flaw-that.html