FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

An AI SOC Evaluation Guide for Security Leaders

What Does the Cyber Industry Want to See From the New UK Government?

Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed ‘Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including plans for a dedicated AI Minister, the scrapping of the hotly debated digital ID programme, […]
The post What Does the Cyber Industry Want to See From the New UK Government? appeared first on IT Security Guru.
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

Recover Hacked Google Account [closed]

Salt Security tackles AI governance challenge with 100 pre-built agentic security policies

Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments. The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance […]
The post Salt Security tackles AI governance challenge with 100 pre-built agentic security policies appeared first on IT Security Guru.
New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve. […]
The post New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience appeared first on IT Security Guru.
A Vulnerability Chain in WordPress Core Could Allow for Remote Code Execution

A vulnerability chain has been discovered in WordPress Core that could allow for remote code execution. WordPress is an open-source content management system (CMS) used to design, build, and publish personal and commercial websites. Successful exploitation of vulnerability chain could allow for remote code execution in the context of the affected service account. Depending on the privileges associated with the service account, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Services whose accounts are configured to have less rights on the system could be less impacted than those who operate with administrative user rights.
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

Hugging Face warns an autonomous AI agent hacked its network

Mythos Didn't Break Your Security Program. Your Exposure Window Could.
Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust
Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly published Threat Report H1 2026. The report, Gen’s first half-yearly threat publication after previously reporting […]
The post Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust appeared first on IT Security Guru.
On Flock License Plate Tracking Cameras

Microsoft confirms Windows Server Update Services sync delays

Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites

A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB. The malware, dubbed HOLLOWGRAPH, was detailed […]
The post Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites appeared first on IT Security Guru.
How to mount a USB flash drive with a dirty NTFS file system?

Windows KB5121767 OOB update fixes shutdowns on some Dell PCs

Critical ServiceNow code execution flaw now exploited in attacks

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

Does Apple’s iCloud web access (with Advanced Data Protection) ever expose the E2EE service key to Apple’s servers, even wrapped?

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
sqlmap through proxychains + MSF SOCKS proxy fails with "unable to connect to the target URL" while curl works fine

How do I zoom out my whole operating system on KDE Linux?

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
What Is the Common Approach to L3VPN Label Allocation on PE Routers for Internet
Hackers abuse ViPNet software to target Russian govt agencies

Is an app that uses play integrity and incongnia breakable ? And if so what exploit threat actors uses

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

I made a cyber phone
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Imperva Customers Protected Against “wp2shell” Pre-Authentication RCE in WordPress Core

TL;DR: A critical pre-authentication Remote Code Execution (RCE) vulnerability, dubbed “wp2shell” (CVE-2026-63030), has been identified in WordPress Core. This vulnerability allows an unauthenticated attacker to execute arbitrary code on a vulnerable WordPress installation without any preconditions, such as plugins or specific configurations. Given that WordPress powers over 500 million websites, this vulnerability poses a significant risk to the global web ecosystem. […]
The post Imperva Customers Protected Against “wp2shell” Pre-Authentication RCE in WordPress Core appeared first on Blog.
Is It Common to Advertise Only a Default Route to Downstream Routers in an L3VPN
Microsoft warns of surge in ACR Stealer attacks on customers

The Future of Age Verification: Your Face Never Leaves Your Device

How are PipeWire modules supposed to work?

Google’s Gemini lets strangers send messages from your locked Android phone

Data Center Bootstrapping from Scratch Procedure [closed]
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Friday Squid Blogging: Squid Washing Up on Cape Cod Beach
Abbott probes two cyber incidents amid extortion claims
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

Where is this configuration setting for gthumb?

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks

Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception.
The post Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks appeared first on Microsoft Security Blog.
Ernst & Young discloses data breach after support system hack

Inside the Search for "Clean" Residential Proxies for Carding

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
Please help me know if my site is vulnerable
Why does my router's NAT table use an expired ARP entry after a soft‑reload, forwarding traffic to a ghost IP? [closed]
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
Details of Alan Turing’s Voice Encryption System
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

CISOs say boardrooms still don’t grasp the human cyber risk AI is supercharging

More than three-quarters of European CISOs believe their C-suite doesn’t fully understand the cyber risk posed by their own employees, a gap that’s widening just as AI makes attacks on human judgement faster, more convincing and harder to spot. That’s according to new research from MetaCompliance, the human cyber risk management firm, which polled 200 […]
The post CISOs say boardrooms still don’t grasp the human cyber risk AI is supercharging appeared first on IT Security Guru.
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

Cisco Launches 40 Communities Johannesburg: A New Chapter of Community-Led Transformation in South Africa
FreeBSD Released the Most Security Advisories in Project History in June 2026
Apache openssl configuration: SSL_ERROR_RX_RECORD_TOO_LONG [closed]

ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments.
The post ACR Stealer: Two observed intrusion chains amid increased threat activity appeared first on Microsoft Security Blog.
Anubis ransomware: what you need to know

How can the ISP detect the use of Tor if VPN is used on the host machine?
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack

Least privilege for AI agents: Identity, access, and tool binding

As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure.
The post Least privilege for AI agents: Identity, access, and tool binding appeared first on Microsoft Security Blog.
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

Phantomdrive: My open source USB drive for privacy
How Robotics is Entering Everyday Home Life: Transforming Our Daily Routines
The integration of robotics into everyday home life is transforming how people manage their daily routines. From vacuuming to cooking, robotic devices are becoming essential tools that enhance convenience and efficiency in households. Homeowners can now enjoy increased leisure time and reduced everyday tasks thanks to the advancements in robotic technology. Robots are designed to […]
The post How Robotics is Entering Everyday Home Life: Transforming Our Daily Routines appeared first on Chris Brenton.
Protecting Privacy in an AI Era

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

20+ Hijacked Government Websites Became an Attack Channel
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

AI Can Find Bugs, But Human Knowledge Still Proves Them

AI Appreciation Day: Security Leaders Say the Celebration Needs an Asterisk

Today marks AI Appreciation Day, the annual moment set aside to reflect on how far artificial intelligence has come. For the security industry, that reflection looks less like a party and more like a stocktake. AI has quietly become embedded in almost every layer of enterprise IT: writing code, triaging alerts, hunting threats, running backups, […]
The post AI Appreciation Day: Security Leaders Say the Celebration Needs an Asterisk appeared first on IT Security Guru.
Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide

Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers

OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol
Delay in revealing theft of medical data labelled 'unacceptable'
Zoom Patches Critical Windows Flaw That Could Enable Account Takeover

Terrorists using AI to build weapons and plan attacks, report finds

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses.
The post Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery appeared first on Microsoft Security Blog.
Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
Q-Day is coming and it might break the entire internet
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

How does tmux determine which session is in the currently active window?

Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider
Moona Ederveen-Schneider is a cybersecurity expert (and Most Inspiring Woman in Cyber Award winner 2026) with more than 20 years of experience across financial services, risk and cyber resilience. She has held senior roles at Deutsche Bank, JPMorgan Chase, UBS, Nomura and ABN Amro, and previously served as Executive Director EMEA at FS-ISAC. As the founder of Resilia Connect […]
The post Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider appeared first on IT Security Guru.
Turning threat intelligence into decisive action with Defender Experts

Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools.
The post Turning threat intelligence into decisive action with Defender Experts appeared first on Microsoft Security Blog.