REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
136 reports · page 2 of 4

the_hacker_news · tlp:amber · 7/15/2026, 6:43:08 PM
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. "While the AI complied with their request to generate botnet code, it included a safety disclaimer that the developer failed TuxBot v3 E…
Read original ↗https://thehackernews.com/2026/07/tuxbot-v3-evolution-shows-signs-of-llm.html
the_hacker_news · tlp:amber · 7/15/2026, 3:30:30 PM
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet's own desktop software. Sometimes it waits until you plug the device in first. The page is malicious. The app around it is the real one you installed, and …

the_hacker_news · tlp:amber · 7/15/2026, 1:18:53 PM
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolation in the DOM: Navigation component "We are aware that exploit code for this is public, however we are not aware of Firefox, …
Read original ↗https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware-updates.html
the_hacker_news · tlp:amber · 7/15/2026, 11:50:01 AM
SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough. For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctioned browser extensions, and autonomous agents. Employees routinely paste intellectual property into SASE Has An AI Bl…
Read original ↗https://thehackernews.com/2026/07/sase-has-ai-blind-spot-inspecting.html
the_hacker_news · tlp:amber · 7/15/2026, 11:07:07 AM
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments. "The PoC requires Res…
Read original ↗https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html
the_hacker_news · tlp:amber · 7/15/2026, 11:06:57 AM
New Webinar: Closing the Approval Gap in AI-Era Ad Tech A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reveals how this Approval Gap forms, and gives your team the blueprint to close it before an auditor, regulator, or attacker finds it first. The Reality of the Approval Gap It's a pattern every New Webinar: Closing the Approva…
Read original ↗https://thehackernews.com/2026/07/new-webinar-closing-approval-gap-in-ai.html
the_hacker_news · tlp:amber · 7/15/2026, 10:55:22 AM
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tokens. Cursor keeps re-running it for as long as the project stays open. No prompt Curso…
Read original ↗https://thehackernews.com/2026/07/cursor-flaw-lets-malicious-cloned.html
the_hacker_news · tlp:amber · 7/15/2026, 9:16:13 AM
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below - @asyncapi/generator-helpers@1.1.1 @asyncapi/generator-components@0.7.1 @asyncapi/generator@3.3.1 @asyncapi/specs(v6.11.2, v6.11.2-alpha.1) "The Compromised AsyncAPI npm Packag…
Read original ↗https://thehackernews.com/2026/07/compromised-asyncapi-npm-packages.html
the_hacker_news · tlp:amber · 7/15/2026, 5:30:21 AM
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below - CVE-2026-15409 (CVSS score: 10.0) - A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to Two SonicWa…
Read original ↗https://thehackernews.com/2026/07/two-sonicwall-sma-1000-zero-days.html
the_hacker_news · tlp:amber · 7/14/2026, 8:25:47 PM
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 200. Those two live bugs are the ones to grab first. Microsoft credits incident responders for both. Both are Microsoft…
Read original ↗https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html
the_hacker_news · tlp:amber · 7/14/2026, 6:17:57 PM
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could SAP Patch…
Read original ↗https://thehackernews.com/2026/07/sap-patches-cvss-99-netweaver-abap-flaw.html
the_hacker_news · tlp:amber · 7/14/2026, 5:27:23 PM
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar. Both this and ClaudeBleed need a rogue extension that can already run a script on claude.ai; the difference is scope. Anthropic restricted the arbitrary-prompt path in May as part of its response to the Re…
Read original ↗https://thehackernews.com/2026/07/claude-for-chrome-flaw-lets-other.html
the_hacker_news · tlp:amber · 7/14/2026, 4:52:37 PM
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. "LabubaRAT creates a reusable foothold for hands-on activity," Blackpoint Cyber researchers Sam Decker and Nevan Beal said in an analysis published today. "Once deployed, it can profile the host, LabubaRAT Masquerades …
Read original ↗https://thehackernews.com/2026/07/labubarat-masquerades-as-nvidia.html
the_hacker_news · tlp:amber · 7/14/2026, 1:48:07 PM
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. Miggo's security team, which discovered and reported the flaws, said one "leaks the broker's confidential OAuth RabbitM…
Read original ↗https://thehackernews.com/2026/07/rabbitmq-flaws-could-leak-oauth-secrets.html
the_hacker_news · tlp:amber · 7/14/2026, 12:46:18 PM
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard. "An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware," 11 …
Read original ↗https://thehackernews.com/2026/07/11-old-microsoft-signed-linux-uefi.html
the_hacker_news · tlp:amber · 7/14/2026, 11:55:00 AM
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way these wallets talk to websites and blockchain servers can tie a person's separate addresses together and let outsiders follow them from site to site. And on a site that already holds a name or…
Read original ↗https://thehackernews.com/2026/07/study-of-85-crypto-wallet-extensions.html
the_hacker_news · tlp:amber · 7/14/2026, 11:30:00 AM
How Pentera Turns AI Security Workflows into Validation Engines AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragmented risk signals: scanner output, severity scores, threat intelligence, configuration findings, and exposure data. That fragmentation matters because attackers do not move through environments one How Pentera Turns …
Read original ↗https://thehackernews.com/2026/07/how-pentera-turns-ai-security-workflows.html
the_hacker_news · tlp:amber · 7/14/2026, 11:21:35 AM
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments, without ever generating a successful sign-in event that would otherwise alert defenders. And bad actors have begu…
Read original ↗https://thehackernews.com/2026/07/oauth-client-id-spoofing-lets-attackers.html
the_hacker_news · tlp:amber · 7/14/2026, 9:02:48 AM
Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out of the intercepted request, and pulled back a file the agent had been told in plain terms not G…
Read original ↗https://thehackernews.com/2026/07/grok-build-uploads-entire-git.html
the_hacker_news · tlp:amber · 7/14/2026, 8:02:33 AM
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious activities, including ransomware attacks against Americans. The VPN, named First VPN Service (1VPNS), has been accused of offering its tools to ransomware groups, along with its 45-year-old Ukrainia…
Read original ↗https://thehackernews.com/2026/07/us-sanctions-first-vpn-service-and.html
the_hacker_news · tlp:amber · 7/14/2026, 7:08:36 AM
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog. The packages did not go after the developers who might install them. The operators used the registry as free hosting for a booby-trapped proxy site and let the students who came to dodge 148…
Read original ↗https://thehackernews.com/2026/07/148-npm-packages-disguised-as-student.html
the_hacker_news · tlp:amber · 7/14/2026, 6:19:24 AM
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organization had already extended, usually through the OAuth connections that tie Salesforce to the apps and third-party vendors around it. In Mic…
Read original ↗https://thehackernews.com/2026/07/microsoft-maps-year-long-shinyhunters.html
the_hacker_news · tlp:amber · 7/13/2026, 5:36:12 PM
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is implemented in native C++, according to Jamf Threat Labs. "It validates the victim's login password locally before CrashS…
Read original ↗https://thehackernews.com/2026/07/crashstealer-macos-malware-uses.html
the_hacker_news · tlp:amber · 7/13/2026, 5:17:24 PM
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version. The collector was dormant. An empty allow-list kept it switched off, and no proof has emerged that it ever gathered or sent a single browsing domain. T…
Read original ↗https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html
the_hacker_news · tlp:amber · 7/13/2026, 3:05:57 PM
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets. That's the shape of this week. Trusted code turns on the people who installed it. Old bugs from last year are still landing because the fix sat in a qu…
Read original ↗https://thehackernews.com/2026/07/weekly-recap-sharefile-threat-citrix.html
the_hacker_news · tlp:amber · 7/13/2026, 1:49:48 PM
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false "fact" about the user, hide the change, and quietly steer its answers in later sessions. When it works, the person reads an ordinary-looking reply and never learns their assistant was tampered with. The Ne…
Read original ↗https://thehackernews.com/2026/07/new-memghost-attack-plants-persistent.html
the_hacker_news · tlp:amber · 7/13/2026, 1:03:33 PM
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365 accounts. Distributed via Telegram and costing $400 a month (or $3,800 per year), attack chains leverage phishing Forg36…
Read original ↗https://thehackernews.com/2026/07/forg365-phaas-targets-microsoft-365.html
the_hacker_news · tlp:amber · 7/13/2026, 11:54:46 AM
Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read. Each read gets pinned to the moment it happened: the time, your location, what you were doing, even how you were using your phone. Some versions in the filing would listen all day; others would Meta F…
Read original ↗https://thehackernews.com/2026/07/meta-files-patent-for-ai-that-can.html
the_hacker_news · tlp:amber · 7/13/2026, 11:37:05 AM
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as we mapped out the broader architecture, something kept nagging at me. The design they w…
Read original ↗https://thehackernews.com/2026/07/thinking-fast-and-slow-in-soc-case-for.html
the_hacker_news · tlp:amber · 7/13/2026, 11:02:33 AM
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. "The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD_Report.html to measure the success of the Attacker Us…
Read original ↗https://thehackernews.com/2026/07/attacker-uses-suspected-ai-generated.html
the_hacker_news · tlp:amber · 7/13/2026, 7:30:00 AM
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history. From that one lapse, French security firm Lexfo lifted the operator's entire toolkit and pivoted through it to two more …
Read original ↗https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html
the_hacker_news · tlp:amber · 7/13/2026, 5:36:02 AM
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below - CVE-2026-48939 - A vulnerability in the iCagenda and …
Read original ↗https://thehackernews.com/2026/07/icagenda-and-balbooa-forms-joomla-flaws.html
the_hacker_news · tlp:amber · 7/11/2026, 5:59:26 PM
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook that drops and executes a native binary, one build each for Windows, macOS, and Linux. Socket flagged the release six minutes after it was published. If you or one of your Com…
Read original ↗https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html
the_hacker_news · tlp:amber · 7/11/2026, 5:49:31 PM
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026. "At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and Hackers …
Read original ↗https://thehackernews.com/2026/07/hackers-weaponize-balochistan-police.html
the_hacker_news · tlp:amber · 7/11/2026, 6:45:55 AM
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to execute malicious scripts in a user's session. It has yet to be assigned a CVE identifier. "The Cr…
Read original ↗https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html
the_hacker_news · tlp:amber · 7/10/2026, 4:30:00 PM
URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a "credible external security threat." The company has temporarily disabled access to the affected accounts, a step it says it took "out of an abundance of caution" while it works with internal and ext…
Read original ↗https://thehackernews.com/2026/07/urgent-progress-tells-sharefile.html
the_hacker_news · tlp:amber · 7/10/2026, 4:29:00 PM
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was Injective …
Read original ↗https://thehackernews.com/2026/07/injective-labs-github-compromise-pushes.html
the_hacker_news · tlp:amber · 7/10/2026, 3:57:14 PM
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs can crash a device. The other two could let an attacker who slips a malicious image in front of the bootloader run their own code, before the device S…
Read original ↗https://thehackernews.com/2026/07/six-new-u-boot-flaws-could-let.html
the_hacker_news · tlp:amber · 7/10/2026, 2:51:49 PM
Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to anything the attacker picks. No old password. No backup card. Once it is reset, whoever did it controls the wallet and can move the coins out. This is not an emergency for most owners. The attack needs Laser A…
Read original ↗https://thehackernews.com/2026/07/laser-attack-resets-tangem-wallet.html
the_hacker_news · tlp:amber · 7/10/2026, 2:19:50 PM
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vulnerabilities is as follows - GHSA-hjr6-g723-hmfm (CVSS score: 8.8) - An operating system Researcher D…
Read original ↗https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.html