] The Mad Hacker [

online
mad hacker

Collecting all the news about Cybersecurity, computer security, cracking, hacking, infosec, netsec, & security vunerabilities in one convenient place

Whitehat, greyhat, blackhat, tinker, tailor, solider, spy
We trawl the web so you don't have to
Since 2000

the mad hacker overlay

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

(Monday July 20, 2026)
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. "FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

(Monday July 20, 2026)
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

(Monday July 20, 2026)
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it more than a

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

(Monday July 20, 2026)
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks

An AI SOC Evaluation Guide for Security Leaders

(Monday July 20, 2026)
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness. [...]

What Does the Cyber Industry Want to See From the New UK Government?

(Monday July 20, 2026)

Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed ‘Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including plans for a dedicated AI Minister, the scrapping of the hotly debated digital ID programme, […]

The post What Does the Cyber Industry Want to See From the New UK Government? appeared first on IT Security Guru.

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

(Monday July 20, 2026)
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is the full

Recover Hacked Google Account [closed]

(Monday July 20, 2026)
Ask Question [/questions/ask] Asked today Modified today [/?lastactivity] Viewed 33 times 0 [/posts/287127/timeline] CLOSED. This question is off-topic [/help/closed-questions]. It is not currently accepting answers. This question does not appear to be about Information security within the scope defined in the help center Closed 4 hours ago. Improve this question [/posts/287127/edit] I need help in recovering my Google account which was hacked 8 days ago. The hackers then...

Salt Security tackles AI governance challenge with 100 pre-built agentic security policies

(Monday July 20, 2026)

Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments. The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance […]

The post Salt Security tackles AI governance challenge with 100 pre-built agentic security policies appeared first on IT Security Guru.

New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

(Monday July 20, 2026)

Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve. […]

The post New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience appeared first on IT Security Guru.

A Vulnerability Chain in WordPress Core Could Allow for Remote Code Execution

(Monday July 20, 2026)

A vulnerability chain has been discovered in WordPress Core that could allow for remote code execution. WordPress is an open-source content management system (CMS) used to design, build, and publish personal and commercial websites. Successful exploitation of vulnerability chain could allow for remote code execution in the context of the affected service account. Depending on the privileges associated with the service account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Services whose accounts are configured to have less rights on the system could be less impacted than those who operate with administrative user rights.

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

(Monday July 20, 2026)
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence

Hugging Face warns an autonomous AI agent hacked its network

(Monday July 20, 2026)
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. [...]

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

(Monday July 20, 2026)
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

(Monday July 20, 2026)

Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly published Threat Report H1 2026. The report, Gen’s first half-yearly threat publication after previously reporting […]

The post Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust appeared first on IT Security Guru.

On Flock License Plate Tracking Cameras

(Monday July 20, 2026)
A recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral. The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM. But when the police report was created and the plate was entered into Flock’s system, it was just recorded as 34 DTM. Just the five large characters, no little number in the middle. And Flock’s AI tech wasn’t registering that non-standard little number when it began picking up the Range Rover around town. It just saw ...

Microsoft confirms Windows Server Update Services sync delays

(Monday July 20, 2026)
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. [...]

Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites

(Monday July 20, 2026)

A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB. The malware, dubbed HOLLOWGRAPH, was detailed […]

The post Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites appeared first on IT Security Guru.

How to mount a USB flash drive with a dirty NTFS file system?

(Monday July 20, 2026)
Question feed To subscribe to this RSS feed, copy and paste this URL into your RSS reader. UNIX & LINUX [/] Site design / logo © 2026 Stack Exchange Inc; user contributions rev 2026.7.20.44457 Linux is a registered trademark of Linus Torvalds. UNIX is a registered trademark of The Open Group. This site is not affiliated with Linus Torvalds or The Open Group in any way.

Windows KB5121767 OOB update fixes shutdowns on some Dell PCs

(Monday July 20, 2026)
Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. [...]

Critical ServiceNow code execution flaw now exploited in attacks

(Monday July 20, 2026)
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

(Monday July 20, 2026)
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets an attacker "execute code in the context of the current process," per the

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

(Monday July 20, 2026)
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential

Does Apple’s iCloud web access (with Advanced Data Protection) ever expose the E2EE service key to Apple’s servers, even wrapped?

(Monday July 20, 2026)
Question feed To subscribe to this RSS feed, copy and paste this URL into your RSS reader. INFORMATION SECURITY [/] Site design / logo © 2026 Stack Exchange Inc; user contributions rev 2026.7.20.44457

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

(Monday July 20, 2026)
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. "We identified unauthorized access to a limited set of internal datasets and to several credentials used by

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

(Monday July 20, 2026)
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) -

sqlmap through proxychains + MSF SOCKS proxy fails with "unable to connect to the target URL" while curl works fine

(Monday July 20, 2026)
Question feed To subscribe to this RSS feed, copy and paste this URL into your RSS reader. INFORMATION SECURITY [/] Site design / logo © 2026 Stack Exchange Inc; user contributions rev 2026.7.20.44457

How do I zoom out my whole operating system on KDE Linux?

(Sunday July 19, 2026)
Question feed To subscribe to this RSS feed, copy and paste this URL into your RSS reader. UNIX & LINUX [/] Site design / logo © 2026 Stack Exchange Inc; user contributions rev 2026.7.20.44457 Linux is a registered trademark of Linus Torvalds. UNIX is a registered trademark of The Open Group. This site is not affiliated with Linus Torvalds or The Open Group in any way.

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

(Sunday July 19, 2026)
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade. Triggering it can crash or restart the worker, causing a denial of

What Is the Common Approach to L3VPN Label Allocation on PE Routers for Internet

(Sunday July 19, 2026)
Question feed To subscribe to this RSS feed, copy and paste this URL into your RSS reader. NETWORK ENGINEERING [/] Site design / logo © 2026 Stack Exchange Inc; user contributions rev 2026.7.20.44457

Hackers abuse ViPNet software to target Russian govt agencies

(Sunday July 19, 2026)
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]

Is an app that uses play integrity and incongnia breakable ? And if so what exploit threat actors uses

(Sunday July 19, 2026)
Click the link for more details on Is an app that uses play integrity and incongnia breakable ? And if so what exploit threat actors uses

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

(Sunday July 19, 2026)
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

(Sunday July 19, 2026)
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this

I made a cyber phone

(Saturday July 18, 2026)
Click the link for more details on I made a cyber phone

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

(Saturday July 18, 2026)
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

(Saturday July 18, 2026)
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...]

Imperva Customers Protected Against “wp2shell” Pre-Authentication RCE in WordPress Core

(Saturday July 18, 2026)

TL;DR: A critical pre-authentication Remote Code Execution (RCE) vulnerability, dubbed “wp2shell” (CVE-2026-63030), has been identified in WordPress Core. This vulnerability allows an unauthenticated attacker to execute arbitrary code on a vulnerable WordPress installation without any preconditions, such as plugins or specific configurations. Given that WordPress powers over 500 million websites, this vulnerability poses a significant risk to the global web ecosystem.  […]

The post Imperva Customers Protected Against “wp2shell” Pre-Authentication RCE in WordPress Core appeared first on Blog.

Is It Common to Advertise Only a Default Route to Downstream Routers in an L3VPN

(Saturday July 18, 2026)
Question feed To subscribe to this RSS feed, copy and paste this URL into your RSS reader. NETWORK ENGINEERING [/] Site design / logo © 2026 Stack Exchange Inc; user contributions rev 2026.7.20.44457

Microsoft warns of surge in ACR Stealer attacks on customers

(Saturday July 18, 2026)
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...]

The Future of Age Verification: Your Face Never Leaves Your Device

(Saturday July 18, 2026)
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting compliance. [...]

How are PipeWire modules supposed to work?

(Saturday July 18, 2026)
Question feed To subscribe to this RSS feed, copy and paste this URL into your RSS reader. UNIX & LINUX [/] Site design / logo © 2026 Stack Exchange Inc; user contributions rev 2026.7.20.44457 Linux is a registered trademark of Linus Torvalds. UNIX is a registered trademark of The Open Group. This site is not affiliated with Linus Torvalds or The Open Group in any way.

Google’s Gemini lets strangers send messages from your locked Android phone

(Friday July 17, 2026)
Gemini, Google's AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone. Read more in my article on the Hot for Security blog.

Data Center Bootstrapping from Scratch Procedure [closed]

(Friday July 17, 2026)
Ask Question [/questions/ask] Asked 2 days ago Modified 2 days ago [/?lastactivity] Viewed 24 times -1 [/posts/88908/timeline] CLOSED. This question is opinion-based [/help/closed-questions]. It is not currently accepting answers. WANT TO IMPROVE THIS QUESTION? Because this question may lead to opinionated discussion, debate, and answers, it has been closed. You may edit the question [/posts/88908/edit] if you feel you can improve it so that it requires answers that include...

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

(Friday July 17, 2026)
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until

Friday Squid Blogging: Squid Washing Up on Cape Cod Beach

(Friday July 17, 2026)
Lots of articles about this. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

Abbott probes two cyber incidents amid extortion claims

(Friday July 17, 2026)
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. [...]

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

(Friday July 17, 2026)
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denial-of-service bug and named it, published the

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

(Friday July 17, 2026)
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron,

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

(Friday July 17, 2026)
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. [...]

Where is this configuration setting for gthumb?

(Friday July 17, 2026)
Question feed To subscribe to this RSS feed, copy and paste this URL into your RSS reader. UNIX & LINUX [/] Site design / logo © 2026 Stack Exchange Inc; user contributions rev 2026.7.20.44457 Linux is a registered trademark of Linus Torvalds. UNIX is a registered trademark of The Open Group. This site is not affiliated with Linus Torvalds or The Open Group in any way.

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

(Friday July 17, 2026)
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

(Friday July 17, 2026)
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using

Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks

(Friday July 17, 2026)

Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception.

The post Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks appeared first on Microsoft Security Blog.

Ernst & Young discloses data breach after support system hack

(Friday July 17, 2026)
Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. [...]

Inside the Search for "Clean" Residential Proxies for Carding

(Friday July 17, 2026)
Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection. [...]

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

(Friday July 17, 2026)
North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. "Any user who ran the project ended up with a four-stage payload aligned with OtterCookie: a browser credential and crypto wallet stealer, a file stealer, a

Please help me know if my site is vulnerable

(Friday July 17, 2026)
Click the link for more details on Please help me know if my site is vulnerable

Why does my router's NAT table use an expired ARP entry after a soft‑reload, forwarding traffic to a ghost IP? [closed]

(Friday July 17, 2026)
Ask Question [/questions/ask] Asked 3 days ago Modified 2 days ago [/?lastactivity] Viewed 16 times 0 [/posts/88907/timeline] CLOSED. This question is off-topic [/help/closed-questions]. It is not currently accepting answers. NE is a site for to ask and provide answers about professionally managed networks in a business environment. Your question falls outside the areas our community decided are on topic. Please visit the help center details. If you disagree with this...

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

(Friday July 17, 2026)
The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing. Google has to ship it in the next major release, Android 18, and by 1 August 2027 at

The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?

(Friday July 17, 2026)
Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move from concept to operational deployment at commercial speed. Now the focus shifts to the trusted

Details of Alan Turing’s Voice Encryption System

(Friday July 17, 2026)
Really interesting piece of cryptographic history: In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-secret “Delilah” engineering project from 1943 to 1945. Delilah was Turing’s portable voice-encryption system, named after the biblical deceiver of men. There is also material written by Bayley, often in the form of notes he took while Turing was speaking. It is thanks to Bayley that the papers survived: He kept them until he died in 2020, 66 years after Turing passed away...

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

(Friday July 17, 2026)
Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side

CISOs say boardrooms still don’t grasp the human cyber risk AI is supercharging

(Friday July 17, 2026)

More than three-quarters of European CISOs believe their C-suite doesn’t fully understand the cyber risk posed by their own employees, a gap that’s widening just as AI makes attacks on human judgement faster, more convincing and harder to spot. That’s according to new research from MetaCompliance, the human cyber risk management firm, which polled 200 […]

The post CISOs say boardrooms still don’t grasp the human cyber risk AI is supercharging appeared first on IT Security Guru.

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

(Friday July 17, 2026)
ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains on Thursday. Its Defender Experts team, the

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

(Friday July 17, 2026)
Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering. Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities in

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

(Friday July 17, 2026)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization

Cisco Launches 40 Communities Johannesburg: A New Chapter of Community-Led Transformation in South Africa

(Friday July 17, 2026)
Cisco Launches Johannesburg as its new 40 Communities destination and introduces Masibambisane, an initiative to revitalize the local community.

FreeBSD Released the Most Security Advisories in Project History in June 2026

(Friday July 17, 2026)
Collapse all comments Expand all comments Load more To leave a comment, click the button on the top of this page to sign in with Google. Comment as: Select Profile: Google Account  Edit Enter Comment Publish Preview This site is protected by reCAPTCHA and the Google Privacy Policy Google apps Main menu

Apache openssl configuration: SSL_ERROR_RX_RECORD_TOO_LONG [closed]

(Thursday July 16, 2026)
Ask Question [/questions/ask] Asked 3 days ago Modified 3 days ago [/?lastactivity] Viewed 31 times 0 [/posts/287121/timeline] CLOSED. This question is off-topic [/help/closed-questions]. It is not currently accepting answers. This question does not appear to be about Information security within the scope defined in the help center Closed 3 days ago. Improve this question [/posts/287121/edit] I am trying to configure HTTPS on my Metasploitable 2 Apache server, but I keep...

ACR Stealer: Two observed intrusion chains amid increased threat activity

(Thursday July 16, 2026)

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments.

The post ACR Stealer: Two observed intrusion chains amid increased threat activity appeared first on Microsoft Security Blog.

Anubis ransomware: what you need to know

(Thursday July 16, 2026)
The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.

How can the ISP detect the use of Tor if VPN is used on the host machine?

(Thursday July 16, 2026)
Question feed To subscribe to this RSS feed, copy and paste this URL into your RSS reader. INFORMATION SECURITY [/] Site design / logo © 2026 Stack Exchange Inc; user contributions rev 2026.7.20.44457

Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack

(Thursday July 16, 2026)
Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority's employees into an office to get their passwords reset in person. Both the NCA and the CPS put TfL's losses and recovery

Least privilege for AI agents: Identity, access, and tool binding

(Thursday July 16, 2026)

As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure.

The post Least privilege for AI agents: Identity, access, and tool binding appeared first on Microsoft Security Blog.

ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

(Thursday July 16, 2026)
A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation. Old bugs are back, weak defaults are earning their keep, and some attack paths are so plain they barely feel like research. Here’s the mess.

Phantomdrive: My open source USB drive for privacy

(Thursday July 16, 2026)
Click the link for more details on Phantomdrive: My open source USB drive for privacy

How Robotics is Entering Everyday Home Life: Transforming Our Daily Routines

(Thursday July 16, 2026)

The integration of robotics into everyday home life is transforming how people manage their daily routines. From vacuuming to cooking, robotic devices are becoming essential tools that enhance convenience and efficiency in households. Homeowners can now enjoy increased leisure time and reduced everyday tasks thanks to the advancements in robotic technology. Robots are designed to […]

The post How Robotics is Entering Everyday Home Life: Transforming Our Daily Routines appeared first on Chris Brenton.

Protecting Privacy in an AI Era

(Thursday July 16, 2026)
Daniel Solove argues in the Wall Street Journal (alternate link) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug companies. Measures such as rigorous data minimization, fiduciary duties, liability for negligent or reckless technological design, liability for algorithms that cause harm, and multi-stakeholder review of technologies will be far more effective. Paper.

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

(Thursday July 16, 2026)
n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss. A valid token from issuer A carrying a sub that belongs to someone under issuer B logged you in as them. Their password never

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

(Thursday July 16, 2026)
Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026. "The malware is full-featured, lightweight, and modular," Elastic Security Labs researcher Cyril François said in a technical report. "While the number of C2 [command-and-control] domains is currently small, the daily

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

(Thursday July 16, 2026)
ClickLock Stealer, a new macOS infostealer, answers a victim's refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim cancels, installs two LaunchAgents and quietly exits. At the next login, Finder, the Dock, Spotlight, Terminal, Activity Monitor, and

20+ Hijacked Government Websites Became
an Attack Channel

(Thursday July 16, 2026)
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation revealed previously undocumented backdoor behavior, hidden infrastructure relationships, and multiple attack arms behind a campaign

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

(Thursday July 16, 2026)
Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click "Buy Now" instead. Ask a coding assistant to apply a maintainer's fix from a GitHub thread, and a fake comment can make it run a stranger's command on your computer. Neither trick hijacks the agent's task. Each one just corrupts the facts it trusts and lets it carry on with the job you

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

(Thursday July 16, 2026)
An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin ("srt64.sys"), as the kernel-mode rootkit is referred to, was first documented by Broadcom-owned Symantec in March 2022, with evidence indicating its use in targeted attacks aimed

AI Can Find Bugs, But Human Knowledge Still Proves Them

(Thursday July 16, 2026)
Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive testing workflows at impressive speed. That is a real advantage for security teams. It also

AI Appreciation Day: Security Leaders Say the Celebration Needs an Asterisk

(Thursday July 16, 2026)

Today marks AI Appreciation Day, the annual moment set aside to reflect on how far artificial intelligence has come. For the security industry, that reflection looks less like a party and more like a stocktake. AI has quietly become embedded in almost every layer of enterprise IT: writing code, triaging alerts, hunting threats, running backups, […]

The post AI Appreciation Day: Security Leaders Say the Celebration Needs an Asterisk appeared first on IT Security Guru.

Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide

(Thursday July 16, 2026)
Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people's Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext. A researcher publishing under the handle tokay0 put the method online on Monday, having tested it only against vacuums he

Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers

(Thursday July 16, 2026)
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them at their own game... All this and more in this episode of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White.

OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol

(Thursday July 16, 2026)
OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely. "GPT‑Red is a strong red-teamer, and our previous models are highly vulnerable to its prompt injection attacks," the artificial intelligence (AI) company said. "We use GPT‑Red to adversarially train

Delay in revealing theft of medical data labelled 'unacceptable'

(Thursday July 16, 2026)
Cybersecurity experts have questioned why Partnered Health took more than three weeks to reveal it had been the victim of a data breach.

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

(Thursday July 16, 2026)
Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Workplace for Windows before version 7.0.0 and Zoom Workplace VDI Client for Windows before version 7.0.10, 6.6.15, and 6.5.18 in their respective branches. "Improper Input

Terrorists using AI to build weapons and plan attacks, report finds

(Thursday July 16, 2026)
A report finds AI systems can be tricked into coaching extremists how to make bombs and plan attacks.

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

(Thursday July 16, 2026)

Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses.

The post Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery appeared first on Microsoft Security Blog.

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

(Wednesday July 15, 2026)

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

Q-Day is coming and it might break the entire internet

(Wednesday July 15, 2026)
The countdown is on to Q-Day, when an algorithm written more than 30 years ago could run on a quantum computer and compromise the security of data on the internet. How are we preparing? 

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

(Wednesday July 15, 2026)
Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. "While the AI complied with their request to generate botnet code, it included a safety disclaimer that the developer failed

How does tmux determine which session is in the currently active window?

(Wednesday July 15, 2026)
Question feed To subscribe to this RSS feed, copy and paste this URL into your RSS reader. UNIX & LINUX [/] Site design / logo © 2026 Stack Exchange Inc; user contributions rev 2026.7.20.44457 Linux is a registered trademark of Linus Torvalds. UNIX is a registered trademark of The Open Group. This site is not affiliated with Linus Torvalds or The Open Group in any way.

Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider

(Wednesday July 15, 2026)

Moona Ederveen-Schneider is a cybersecurity expert (and Most Inspiring Woman in Cyber Award winner 2026) with more than 20 years of experience across financial services, risk and cyber resilience. She has held senior roles at Deutsche Bank, JPMorgan Chase, UBS, Nomura and ABN Amro, and previously served as Executive Director EMEA at FS-ISAC.  As the founder of Resilia Connect […]

The post Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider appeared first on IT Security Guru.

Turning threat intelligence into decisive action with Defender Experts

(Wednesday July 15, 2026)

Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools.

The post Turning threat intelligence into decisive action with Defender Experts appeared first on Microsoft Security Blog.