REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
136 reports · page 3 of 4
the_hacker_news · tlp:amber · 7/10/2026, 1:15:23 PM
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that propagates malware via counterfeit installers using SEO poisoning techniques, it belies their true organizational New MODBEACON RAT Uses…
Read original ↗https://thehackernews.com/2026/07/new-modbeacon-rat-uses-grpc-streaming.html
the_hacker_news · tlp:amber · 7/10/2026, 11:47:43 AM
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server Unpatched XRI…

the_hacker_news · tlp:amber · 7/10/2026, 11:39:40 AM
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report, only 45% of organizations consolidate their asset and exposure data into a single view, and every downstream security program inherits whatever the inventory gets wrong. Lumen Technol…
Read original ↗https://thehackernews.com/2026/07/from-17000-to-11-million-assets-how.html
the_hacker_news · tlp:amber · 7/10/2026, 11:30:02 AM
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the exposed files showed researchers how a mass site-hacking operation runs from the inside. The operation, now tracked as …
Read original ↗https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html
the_hacker_news · tlp:amber · 7/10/2026, 10:56:23 AM
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic private and secure. The apps flagged with at least one problem have been installed more than 2.4 billion times. The problems are basic, not sophisticated. 29 apps let user traffic leak outsid…
Read original ↗https://thehackernews.com/2026/07/study-of-281-free-android-vpn-apps.html
the_hacker_news · tlp:amber · 7/10/2026, 10:30:20 AM
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with an aim to carry out data extortion attacks. The threat actor, tracked by Okta under the moniker O-UNC-066, has deployed a panel-controlled phishing kit that's capable of targeting the passkey enrollment process. The …
Read original ↗https://thehackernews.com/2026/07/hackers-use-fake-microsoft-entra.html
the_hacker_news · tlp:amber · 7/10/2026, 9:00:05 AM
Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness, an attacker can work it out and take everything it controls. Coinspect has confirmed one coordinated sw…
Read original ↗https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html
the_hacker_news · tlp:amber · 7/10/2026, 8:10:12 AM
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple victims and working with two other cybersecurity professionals to target additional victims in 2023. In a sentencing memorandum, federal prosecutors described Martino as a " Ransomwa…
Read original ↗https://thehackernews.com/2026/07/ransomware-negotiator-gets-70-months-in.html
the_hacker_news · tlp:amber · 7/9/2026, 6:38:49 PM
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub 'ghost' accounts that are often years old, or compromised OAuth tokens and personal Dormant …
Read original ↗https://thehackernews.com/2026/07/dormant-github-accounts-help-attackers.html
the_hacker_news · tlp:amber · 7/9/2026, 6:08:07 PM
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from. Each is a different way to break a machine: wipe the whole disk, overwrite the Windows drive, or run fake "ransomware" that scrambles files with a key it never saves N…
Read original ↗https://thehackernews.com/2026/07/new-gigawiper-windows-backdoor-bundles.html
the_hacker_news · tlp:amber · 7/9/2026, 4:49:02 PM
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The Microsoft-owned subsidiary noted that the following npm install behaviors that used to run automatically before have been made opt-in - allowScripts defaults to off, meaning npm 12 Disables…
Read original ↗https://thehackernews.com/2026/07/npm-12-disables-install-scripts-by.html
the_hacker_news · tlp:amber · 7/9/2026, 3:09:28 PM
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it all looks until the bill arrives. The full ThreatsDay list is below. Global ThreatsDay: …
Read original ↗https://thehackernews.com/2026/07/threatsday-cloud-bucket-hijacking.html
the_hacker_news · tlp:amber · 7/9/2026, 12:26:58 PM
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up AI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the next host before your team clears the first alert. That is the gap, and it is not your fault. The tools and runbooks most teams run on were built for attackers who work at human speed. AI-driven AI …
Read original ↗https://thehackernews.com/2026/07/ai-attacks-move-in-minutes-join-this.html
the_hacker_news · tlp:amber · 7/9/2026, 11:00:00 AM
Summer of Clearinghouses Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quietly months earlier, heads down, taking findings and shipping fixes, because customers kept asking us to. We only announced it now because everyone else started announcing theirs, Summer of Clearinghouses #1 Trusted Cybersecurity News…
Read original ↗https://thehackernews.com/2026/07/summer-of-clearinghouses.html
the_hacker_news · tlp:amber · 7/9/2026, 10:43:09 AM
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According to a new report published by the Threat Hunter Team from Symantec, the ransomware was first publicly spotted in the wild on May 21, 2026. It's assessed to be a rebrand of the Beast ransomware, GodDamn Ransomwar…
Read original ↗https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html
the_hacker_news · tlp:amber · 7/9/2026, 8:48:48 AM
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine ("mpengine.dll"), which provides scanning, detection, and cleaning capabilities for its antivirus and Microsoft Pat…
Read original ↗https://thehackernews.com/2026/07/microsoft-patches-rogueplanet-defender.htmlthe_hacker_news · tlp:amber · 7/9/2026, 7:21:06 AM
Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images Meta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI content, and it's enabled by default. "You can also @-mention Instagram accounts in the Meta AI app to bring specific Instagram profiles right into your images," the social media giant said in a post. "Whether you want to design a custom event invitation…
Read original ↗https://thehackernews.com/2026/07/metas-new-ai-image-tool-lets-others-use.htmlthe_hacker_news · tlp:amber · 7/9/2026, 5:15:02 AM
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls "Friendly Fire." It works against Anthropic's Claude Code and OpenAI's Codex when either is running in an autonomous mode that approves its own Top …
Read original ↗https://thehackernews.com/2026/07/friendly-fire-ai-agents-built-to-catch.htmlthe_hacker_news · tlp:amber · 7/9/2026, 4:27:18 AM
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead. The affected tools are Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf.…
Read original ↗https://thehackernews.com/2026/07/ghostapproval-symlink-flaws-could-let.htmlthe_hacker_news · tlp:amber · 7/9/2026, 4:01:49 AM
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains. The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, involved the Fake 7-Zip Insta…
Read original ↗https://thehackernews.com/2026/07/fake-7-zip-installers-turn-devices-into.htmlthe_hacker_news · tlp:amber · 7/8/2026, 5:02:12 PM
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders. The agents are not malicious. They just do a lot of things that, to a behavioral engine, look exactly like an attack. Decrypting browser credentials, listing what sits in Windows' credential store, AI C…
Read original ↗https://thehackernews.com/2026/07/ai-coding-agents-found-triggering.htmlthe_hacker_news · tlp:amber · 7/8/2026, 3:07:24 PM
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist. New research, which its authors call HalluSquatting, turns that habit into an attack: work out the fake names an AI reliably invents, register them first, and wait for the assistant to fetch your trap on a us…
Read original ↗https://thehackernews.com/2026/07/new-hallusquatting-attack-could-trick.htmlthe_hacker_news · tlp:amber · 7/8/2026, 2:38:05 PM
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution. The list of vulnerabilities is as follows - CVE-2026-50746 (CVSS score: 10.0) - An improper access control vulnerability in UniFi Connect Application that an attacker …
Read original ↗https://thehackernews.com/2026/07/ubiquiti-patches-critical-unifi-flaws.htmlthe_hacker_news · tlp:amber · 7/8/2026, 1:00:00 PM
New Ghost Phishing Wave Is Breaking Traditional Email Security A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365 access, sensitive data, and response time New Ghost Phishing W…
Read original ↗https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.htmlthe_hacker_news · tlp:amber · 7/8/2026, 12:52:15 PM
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed SCMBANKER …
Read original ↗https://thehackernews.com/2026/07/scmbanker-malware-uses-clickfix-lures.htmlthe_hacker_news · tlp:amber · 7/8/2026, 11:51:24 AM
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps "Verified." Everything a reviewer would check matches. The commit's hash does not. That matters …
Read original ↗https://thehackernews.com/2026/07/github-verified-commits-can-be.htmlthe_hacker_news · tlp:amber · 7/8/2026, 11:30:00 AM
The Verification Step Is the New ATO Battleground in 2026 For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, scalable, and for defenders, relatively well understood. That era is ending. Not because attackers gave up, but because the front door finally got harder to kick in. Passkeys are now mainstream. The Verification Step Is t…
Read original ↗https://thehackernews.com/2026/07/the-verification-step-is-new-ato.htmlthe_hacker_news · tlp:amber · 7/8/2026, 11:21:07 AM
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken into small, ordinary-looking steps inside a code editor. That is the finding of a new study of GitHub Copilot by researchers Abhishek Kumar and Carsten Maple. The models they tested through Copilot, Claude from Anthropic, and Gemini from Google, refused GitHub …
Read original ↗https://thehackernews.com/2026/07/github-copilot-refuses-harmful-requests.htmlthe_hacker_news · tlp:amber · 7/8/2026, 9:04:33 AM
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices. According to findings from Cisco Talos, UAT-7810 is an advanced persistent threat (APT) actor that's responsible for maintaining and proliferating LapDogs, an ORB network that first came to light in June 2025. China-Linked…
Read original ↗https://thehackernews.com/2026/07/china-linked-uat-7810-expands-orb.htmlthe_hacker_news · tlp:amber · 7/8/2026, 6:16:44 AM
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network 15-…
Read original ↗https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.htmlthe_hacker_news · tlp:amber · 7/8/2026, 5:33:12 AM
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-48282 (CVSS score: 10.0) - A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the CISA Adds 4 Active…
Read original ↗https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.htmlthe_hacker_news · tlp:amber · 7/7/2026, 5:10:15 PM
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts. Zimperium's zLabs, which found the operation, says it looks like a new variant of Oblivion, a $300-a-month rent-a-malware tool RedWing MaaS Pack…
Read original ↗https://thehackernews.com/2026/07/redwing-maas-packages-android-bank.htmlthe_hacker_news · tlp:amber · 7/7/2026, 4:37:33 PM
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project. From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a password. Security firm Varonis found it Rog…
Read original ↗https://thehackernews.com/2026/07/rogue-agent-flaw-could-have-let.htmlthe_hacker_news · tlp:amber · 7/7/2026, 3:14:14 PM
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. "The campaign did not depend on a fake Microsoft password page. It used a malicious collaboration-style lure to push users into the legitimate Microsoft device login experience, DEBULL …
Read original ↗https://thehackernews.com/2026/07/debull-tooling-abuses-microsoft-device.htmlthe_hacker_news · tlp:amber · 7/7/2026, 2:04:50 PM
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown. The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access to the organization. If that organization has given the agent read access across its repositories, private ones…
Read original ↗https://thehackernews.com/2026/07/public-github-issue-could-trick-github.htmlthe_hacker_news · tlp:amber · 7/7/2026, 1:27:20 PM
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal complaint. Microsoft records tied that ID first to the account the attackers used to keep access during the May 2025 intrusion, then to online accounts prosecutors say belong to 19-year-old Peter Stokes. Stokes is…
Read original ↗https://thehackernews.com/2026/07/court-filing-reveals-windows-device-id.htmlthe_hacker_news · tlp:amber · 7/7/2026, 1:27:09 PM
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise. The one-click vulnerability has been codenamed WriteOut by the Sand Security Research team. "An outsider could go from having no access to taking over any Writer AI Writer AI …
Read original ↗https://thehackernews.com/2026/07/writer-ai-flaw-could-let-agent-previews.htmlthe_hacker_news · tlp:amber · 7/7/2026, 11:30:00 AM
What Changes When Your Software Supply Chain Includes AI Writing Your Code? Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, "software supply chain security" meant one question: what's in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? SolarWinds, Log4Shell, and XZ Utils all taught the same lesson: the risk lives less in the code a What Chan…
Read original ↗https://thehackernews.com/2026/07/what-changes-when-your-software-supply.htmlthe_hacker_news · tlp:amber · 7/7/2026, 9:10:51 AM
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign. The activity involves the exploitation of now-patched, critical security flaws in the open-source email solution, such as CVE-2024-42009 (CVSS score: 9.3), to siphon credentials, Suspec…
Read original ↗https://thehackernews.com/2026/07/suspected-china-aligned-hackers-exploit.htmlthe_hacker_news · tlp:amber · 7/7/2026, 6:40:47 AM
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices' web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday. "An attacker can exploit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process CERT/CC Warns of H…
Read original ↗https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html