Threat Intelligence

Advanced threat analysis and intelligence reports.

Critical Next.js Flaws Let Attackers Bypass Authentication and Launch SSRF Attacks
News
3 min read

Critical Next.js Flaws Let Attackers Bypass Authentication and Launch SSRF Attacks

Vercel has disclosed nine security vulnerabilities in Next.js, the widely used React framework, including two critical-severity flaws that allow attackers to bypass authentication middleware and hijac

CyberShield TeamRead More
Hackers Weaponize Notepad++ 8.8.3 to Silently Install MATCHBOIL.V2 Malware
News
4 min read

Hackers Weaponize Notepad++ 8.8.3 to Silently Install MATCHBOIL.V2 Malware

CERT-UA has disclosed a significant shift in the tactics of threat cluster UAC-0099, revealing a novel infection chain that abuses a legitimate Notepad++ 8.8.3 executable to sideload malware, alongsid

CyberShield TeamRead More
Hackers Allegedly Claim Breach of Decathlon Customer Database With 160 Million Records
Cybersecurity
4 min read

Hackers Allegedly Claim Breach of Decathlon Customer Database With 160 Million Records

A threat actor is allegedly claiming to possess and sell a Decathlon customer database containing approximately 160 million records. The database was advertised on a cybercrime forum, where the seller

CyberShield TeamRead More
Microsoft 365 Services Outage Impacted Teams, Copilot, Purview and Other Services
Cybersecurity
4 min read

Microsoft 365 Services Outage Impacted Teams, Copilot, Purview and Other Services

A Microsoft 365 outage disrupted access to several widely used enterprise services, including Microsoft Teams, SharePoint Online, OneDrive, Copilot Chat, Microsoft Purview, and Power BI. The incident

CyberShield TeamRead More
Chick-fil-A Data Breach Exposes Personal Information and Stored Account Credit
News
3 min read

Chick-fil-A Data Breach Exposes Personal Information and Stored Account Credit

Chick-fil-A has notified customers of a data security incident in which unauthorized parties gained access to Chick-fil-A One loyalty accounts through a credential stuffing attack, exposing personal i

CyberShield TeamRead More
China-Nexus JadeProx Uses New TriBack Loader to Target Governments, Hospitals, and Universities
News
4 min read

China-Nexus JadeProx Uses New TriBack Loader to Target Governments, Hospitals, and Universities

An exposed directory on an operator-controlled Alibaba Cloud server revealed the inner workings of the JadeProx intrusion set, including bash history, webshell paths, phishing kits, and a full post-ex

CyberShield TeamRead More
Claude Security Plugin Uses AI to Find, Validate, and Patch Software Flaws
News
4 min read

Claude Security Plugin Uses AI to Find, Validate, and Patch Software Flaws

Anthropic has expanded its AI-driven vulnerability detection capabilities by launching Claude Security as a native Claude Code plugin, now available in beta for all Claude Code users. The move brings

CyberShield TeamRead More
Critical FreePBX Flaws Let Unauthenticated Attackers Execute Commands and Hijack Admin Accounts
News
3 min read

Critical FreePBX Flaws Let Unauthenticated Attackers Execute Commands and Hijack Admin Accounts

Sangoma has patched two critical vulnerabilities in FreePBX that allow unauthenticated remote attackers to execute arbitrary commands and take over administrator accounts, prompting a “Red&#8221

CyberShield TeamRead More
Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code
News
4 min read

Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code

A newly disclosed heap buffer overflow in the FreeRDP Windows client’s clipboard channel allows a malicious RDP server to corrupt heap memory and potentially achieve remote code execution (RCE) on con

CyberShield TeamRead More
Critical XFS Race Condition Enables Linux Privilege Escalation to Root
News
4 min read

Critical XFS Race Condition Enables Linux Privilege Escalation to Root

A newly disclosed CVE-2026-64600, dubbed “RefluXFS,” a critical race condition in the Linux kernel’s XFS filesystem that allows unprivileged local users to escalate to full root priv

CyberShield TeamRead More
Exim Directory Traversal Vulnerability Exposes Files Outside the Mail Spool
News
3 min read

Exim Directory Traversal Vulnerability Exposes Files Outside the Mail Spool

A newly disclosed vulnerability in Exim, one of the most widely deployed mail transfer agents (MTAs) on Unix-like systems, allows local attackers to escalate privileges by accessing files outside the

CyberShield TeamRead More
GitHub Actions Abuse Exploits cPanel CVE-2026-41940 to Steal Server Credentials
News
4 min read

GitHub Actions Abuse Exploits cPanel CVE-2026-41940 to Steal Server Credentials

GitHub Actions abuse is powering a large-scale attack campaign that exploits the cPanel CVE-2026-41940 authentication bypass to steal server credentials and other sensitive secrets from internet-facin

CyberShield TeamRead More
KARR Car Alarm Flaw Lets Nearby Attackers Unlock and Immobilize Vehicles
News
4 min read

KARR Car Alarm Flaw Lets Nearby Attackers Unlock and Immobilize Vehicles

A critical Bluetooth vulnerability in the dealer-installed KARR Security System exposes more than 2.2 million vehicles across the United States to remote unlocking, immobilization, and horn/light mani

CyberShield TeamRead More
Kimi K3 AI Agent Finds Redis RCE Vulnerabilities in Just 27 Minutes
News
3 min read

Kimi K3 AI Agent Finds Redis RCE Vulnerabilities in Just 27 Minutes

Moonshot AI’s newly released Kimi K3, a 2.8-trillion-parameter mixture-of-experts model, has demonstrated the growing offensive capability of autonomous AI agents by independently uncovering rem

CyberShield TeamRead More
Anthropic Launches Claude Security Plugin to Scan Code for Vulnerabilities
Cybersecurity
4 min read

Anthropic Launches Claude Security Plugin to Scan Code for Vulnerabilities

Anthropic has released the Claude Security plugin in beta, bringing AI-powered vulnerability scanning directly into Claude Code for developers who want to catch high-severity flaws before they ship. T

CyberShield TeamRead More
Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel
Cybersecurity
5 min read

Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel

Chaos ransomware has introduced a new way to hide attacker activity inside everyday web browsing. The group’s msaRAT remote-access tool turns Chrome or Microsoft Edge into a covert channel for receivi

CyberShield TeamRead More
CISA Warns of Check Point Authentication Vulnerability Exploited in Attacks
Cybersecurity
4 min read

CISA Warns of Check Point Authentication Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited

CyberShield TeamRead More
Exim Directory Traversal Vulnerability Enables Privilege Escalation Attacks
Cybersecurity
3 min read

Exim Directory Traversal Vulnerability Enables Privilege Escalation Attacks

A newly disclosed high-severity vulnerability in the Exim mail transfer agent allows local attackers to exploit a directory traversal flaw to escalate privileges on affected systems. Tracked as EXIM-S

CyberShield TeamRead More
Fake Bahrain Civil Defense App Deploys Android RAT to Steal PINs, OTPs, and Banking Credentials
Cybersecurity
4 min read

Fake Bahrain Civil Defense App Deploys Android RAT to Steal PINs, OTPs, and Banking Credentials

A sophisticated Android malware campaign is exploiting heightened geopolitical tensions in the Gulf region by masquerading as an official Bahrain Civil Defense emergency alert application. Security re

CyberShield TeamRead More
Google’s New “Selfie Video” Identity Verification Feature to Gain Access to Locked Accounts
Cybersecurity
4 min read

Google’s New “Selfie Video” Identity Verification Feature to Gain Access to Locked Accounts

Google has introduced a new identity verification feature called “selfie video” designed to help users regain access to locked accounts, marking a significant step in account recovery and authenticati

CyberShield TeamRead More
Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials
Cybersecurity
5 min read

Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials

A large-scale cyber campaign is abusing GitHub Actions to turn trusted open source projects into weapons against web hosting servers. Attackers plant malicious workflow files inside compromised reposi

CyberShield TeamRead More
Hackers Abuse Notepad++ Plugins to Compromise Your System Silently
Cybersecurity
3 min read

Hackers Abuse Notepad++ Plugins to Compromise Your System Silently

A stealthy new campaign in which the UAC-0099 threat cluster hijacks a legitimate Notepad++ plugin to quietly plant malware on victim machines, marking a significant evolution in the group’s tac

CyberShield TeamRead More
Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware
Cybersecurity
5 min read

Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware

A simple mistake by cyber spies has pulled back the curtain on a wide ranging espionage effort. It reached hospitals, government offices, and schools across several continents in early 2026. In mid Ap

CyberShield TeamRead More
Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks
Cybersecurity
3 min read

Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks

Vercel has disclosed and patched nine security vulnerabilities in Next.js, the widely used React framework, addressing flaws that could enable server-side request forgery (SSRF), middleware authentica

CyberShield TeamRead More
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
Hacking News
1 min read

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager

CyberShield TeamRead More
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
Hacking News
1 min read

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahe

CyberShield TeamRead More
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Hacking News
1 min read

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under a

CyberShield TeamRead More
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Hacking News
1 min read

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Lati

CyberShield TeamRead More
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Hacking News
1 min read

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which th

CyberShield TeamRead More
Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
Hacking News
1 min read

Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing reco

CyberShield TeamRead More
How Synthetic Identity Fraud is Coming for Machine Identities
Hacking News
1 min read

How Synthetic Identity Fraud is Coming for Machine Identities

Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real

CyberShield TeamRead More
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
Hacking News
1 min read

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

RefluXFS, a Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualy

CyberShield TeamRead More
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Hacking News
1 min read

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organizat

CyberShield TeamRead More
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Hacking News
1 min read

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Othe

CyberShield TeamRead More
Apple Fixes Hide My Email Flaw That Exposed Users’ Real Email Addresses
News
3 min read

Apple Fixes Hide My Email Flaw That Exposed Users’ Real Email Addresses

Apple has patched a long-standing vulnerability in its iCloud+ Hide My Email feature that allowed anyone to unmask a user’s real email address. The patch, applied on July 3, 2026, comes more tha

CyberShield TeamRead More
AWS Kiro IDE Flaw Lets Hidden Web Prompts Execute Code on Developer Machines
News
3 min read

AWS Kiro IDE Flaw Lets Hidden Web Prompts Execute Code on Developer Machines

A critical vulnerability in AWS’s agentic IDE Kiro lets attackers hide malicious instructions inside ordinary web pages, tricking the AI agent into rewriting its own configuration file and execu

CyberShield TeamRead More
CISA Warns of Actively Exploited WordPress Flaws Enabling Pre-Auth RCE
News
3 min read

CISA Warns of Actively Exploited WordPress Flaws Enabling Pre-Auth RCE

CISA has added two chained WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaws enable unauthenticated, pre-a

CyberShield TeamRead More
Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands
News
3 min read

Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands

ASUS has patched a critical router vulnerability, tracked as CVE-2026-13385, that allows remote man‑in‑the‑middle (MITM) attackers to force affected devices to download and execute arbitrary commands

CyberShield TeamRead More
Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases
News
3 min read

Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases

A critical broken access control vulnerability in Meta’s customer support infrastructure allowed attackers to read private support emails, chats, and case data belonging to other users, and even

CyberShield TeamRead More
Critical Zimbra SNMP Flaw Lets Attackers Execute Malicious Commands
News
3 min read

Critical Zimbra SNMP Flaw Lets Attackers Execute Malicious Commands

Zimbra has released Zimbra Collaboration Suite (ZCS) version 10.1.20, addressing a critical command injection vulnerability in its SNMP monitoring component along with multiple cross-site scripting (X

CyberShield TeamRead More
Google Chrome Update Fixes 12 High-Severity Browser Vulnerabilities
News
3 min read

Google Chrome Update Fixes 12 High-Severity Browser Vulnerabilities

Google has rolled out a Stable channel update for Chrome Desktop, patching 12 security vulnerabilities, all rated High severity. The update brings Chrome to version 150.0.7871.181/.182 for Windows and

CyberShield TeamRead More
Google Launches Gemini 3.5 Flash Cyber to Find and Patch Vulnerabilities at Scale
News
4 min read

Google Launches Gemini 3.5 Flash Cyber to Find and Patch Vulnerabilities at Scale

Google has unveiled Gemini 3.5 Flash Cyber, a lightweight cybersecurity model fine-tuned to detect, validate, and patch software vulnerabilities faster and more efficiently than mainline Flash models.

CyberShield TeamRead More
Hackers Abuse Microsoft Device Code Flow to Bypass MFA and Hijack Microsoft 365 Accounts
News
3 min read

Hackers Abuse Microsoft Device Code Flow to Bypass MFA and Hijack Microsoft 365 Accounts

Hackers are increasingly abusing Microsoft’s legitimate device code flow to bypass multi-factor authentication (MFA) and hijack Microsoft 365 accounts, turning trusted identity controls into a covert

CyberShield TeamRead More
Iran-Linked Hackers Exploit Trusted Access and Exposed OT Systems for Espionage and Disruption
News
4 min read

Iran-Linked Hackers Exploit Trusted Access and Exposed OT Systems for Espionage and Disruption

Iran-linked hackers are quietly building long-term, flexible access into critical networks and exposed operational technology (OT), using trusted pathways to pivot between espionage and selective disr

CyberShield TeamRead More
A Hidden Line of Website Text Can Turn AWS Kiro Into a Remote Code Execution Tool
Cybersecurity
4 min read

A Hidden Line of Website Text Can Turn AWS Kiro Into a Remote Code Execution Tool

A recently disclosed vulnerability in AWS Kiro, an AI-powered Integrated Development Environment (IDE), reveals how a hidden line of text on a webpage can be exploited for remote code execution on a d

CyberShield TeamRead More
Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users
Cybersecurity
4 min read

Adobe Acrobat Extension Flaw Lets Attackers Steal WhatsApp Chats From 329 Million Users

A newly disclosed flaw in the Adobe Acrobat Chrome extension allowed attackers to silently harvest WhatsApp Web chats, contacts, and profile data from any user who simply visited a malicious webpage n

CyberShield TeamRead More
ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution
Cybersecurity
3 min read

ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution

ASUS has released critical security updates to address a high-severity router vulnerability that could allow remote attackers to execute arbitrary commands on affected devices. The flaw, tracked as CV

CyberShield TeamRead More
Google Chrome Update Fixes 12 Vulnerabilities That Could Enable Browser Attacks
Cybersecurity
3 min read

Google Chrome Update Fixes 12 Vulnerabilities That Could Enable Browser Attacks

Google has rolled out a new Stable channel update for Chrome, patching 12 security vulnerabilities, including nine rated “High” severity. The update brings Chrome to version 150.0.7871.181

CyberShield TeamRead More
Hackers are Actively Exploiting ServiceNow Vulnerability in the Wild
Cybersecurity
3 min read

Hackers are Actively Exploiting ServiceNow Vulnerability in the Wild

A critical ServiceNow vulnerability, tracked as CVE-2026-6875, is being actively exploited to allow unauthenticated attackers to escape the script sandbox and execute code on affected systems. The vul

CyberShield TeamRead More
Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session
Cybersecurity
5 min read

Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session

Multi-factor authentication is meant to stop stolen-password attacks. A newly documented phishing technique instead persuades users to approve a real Microsoft sign-in, allowing attackers to take over

CyberShield TeamRead More
Kali365 Phishing Kit Abuses Microsoft Device Codes to Hijack Microsoft 365 Accounts
Cybersecurity
4 min read

Kali365 Phishing Kit Abuses Microsoft Device Codes to Hijack Microsoft 365 Accounts

A phishing kit known as Kali365 is targeting U.S. organizations through device code phishing attacks that abuse Microsoft’s legitimate authentication process to hijack Microsoft 365 accounts. Unlike c

CyberShield TeamRead More
OpenAI’s GPT Agents Exploit Zero-Days and Hacked Hugging Face Servers
Cybersecurity
4 min read

OpenAI’s GPT Agents Exploit Zero-Days and Hacked Hugging Face Servers

Hugging Face has disclosed a security incident that security researchers are calling a watershed moment for AI safety: an autonomous AI agent, built on OpenAI models, independently discovered and chai

CyberShield TeamRead More
Public PoC Released for Windows NT OS Kernel Privilege Escalation Vulnerability
Cybersecurity
3 min read

Public PoC Released for Windows NT OS Kernel Privilege Escalation Vulnerability

Public proof-of-concept (PoC) exploit code was released for CVE-2026-42980, a local privilege escalation vulnerability in the Windows NT OS Kernel. This vulnerability occurs due to an integer underflo

CyberShield TeamRead More
RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access
Cybersecurity
5 min read

RefluXFS Linux Kernel Vulnerability Lets Attackers Gain Root Access

A new Linux vulnerability dubbed “RefluXFS” is a race condition in the Linux kernel’s XFS filesystem copy-on-write path that lets an ordinary local user silently overwrite protected

CyberShield TeamRead More
What 434 AI-Generated Vulnerabilities Reveal About Secure Software Development
Cybersecurity
8 min read

What 434 AI-Generated Vulnerabilities Reveal About Secure Software Development

New research finds that modern AI coding models frequently generate insecure code that exposes AI-generated applications to denial-of-service attacks, hardcoded secrets and authorization failures. The

CyberShield TeamRead More
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Hacking News
1 min read

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a sil

CyberShield TeamRead More
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
Hacking News
1 min read

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent i

CyberShield TeamRead More
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
Hacking News
1 min read

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS sco

CyberShield TeamRead More
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
Hacking News
1 min read

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what

CyberShield TeamRead More
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
Hacking News
1 min read

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugg

CyberShield TeamRead More
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
Hacking News
1 min read

Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authori

CyberShield TeamRead More
The Fastest Path to AI Adoption Runs Through Security
Hacking News
1 min read

The Fastest Path to AI Adoption Runs Through Security

Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, empl

CyberShield TeamRead More
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Hacking News
1 min read

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live ga

CyberShield TeamRead More
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Hacking News
1 min read

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete c

CyberShield TeamRead More
Why Modern SOCs Need Multi-Layered Detections
Hacking News
1 min read

Why Modern SOCs Need Multi-Layered Detections

The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defen

CyberShield TeamRead More
Craneware Data Breach Exposes Employee and US Healthcare Customer Records
News
3 min read

Craneware Data Breach Exposes Employee and US Healthcare Customer Records

Craneware plc (AIM: CRW.L), the Edinburgh-headquartered healthcare financial performance software provider, disclosed on 20 July 2026 that it suffered a cybersecurity incident resulting in unauthorize

CyberShield TeamRead More
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide RATs and Infostealers
News
3 min read

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide RATs and Infostealers

The tool combines payload encryption with advanced Windows evasion methods, helping attackers bypass endpoint defenses and complicate incident response. Cruciferra is a Mono-based crypter marketed on

CyberShield TeamRead More
Hackers Use Microsoft 365 Calendar Events as Dead Drops for Malware Commands
News
4 min read

Hackers Use Microsoft 365 Calendar Events as Dead Drops for Malware Commands

A newly identified Windows malware sample, dubbed HOLLOWGRAPH, is abusing the Microsoft Graph API to turn a compromised Microsoft 365 calendar into a covert two-way command-and-control channel. Group-

CyberShield TeamRead More
Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
News
3 min read

Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries

A newly disclosed detection gap in Microsoft Defender XDR could be causing security teams to silently miss command-and-control (C2) traffic and other malicious external communications, according to re

CyberShield TeamRead More
Microsoft Discontinues Copilot Podcasts and Removes Access to Previously Created Content
News
3 min read

Microsoft Discontinues Copilot Podcasts and Removes Access to Previously Created Content

Microsoft has confirmed that the Podcasts feature within its Copilot app will be officially discontinued starting August 18, 2026, cutting off access for users to create new podcasts or retrieve previ

CyberShield TeamRead More
Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data
News
3 min read

Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data

A massive data breach at gig economy platform Paidwork has compromised the personal and financial information of over 23 million users, marking one of the largest breaches to hit the gig work sector t

CyberShield TeamRead More
Qilin Ransomware Exploits Palo Alto GlobalProtect Flaw for Initial Access
News
4 min read

Qilin Ransomware Exploits Palo Alto GlobalProtect Flaw for Initial Access

Threat actors deploying Qilin ransomware exploited a Palo Alto Networks GlobalProtect authentication bypass flaw, CVE-2026-0257, as the consistent initial access vector across multiple June 2026 intru

CyberShield TeamRead More
Ransomware Groups Claim Record 7,551 Victims as Qilin Activity Jumps 443%
News
4 min read

Ransomware Groups Claim Record 7,551 Victims as Qilin Activity Jumps 443%

Ransomware groups publicly named 7,551 victims from April 2025 through March 2026, a 24.9% rise from the previous reporting period. The surge was led by Qilin, which claimed 1,358 victims up 443% year

CyberShield TeamRead More
Trump’s AI Security Agency Chief Resigns After Just Three Months
News
3 min read

Trump’s AI Security Agency Chief Resigns After Just Three Months

Chris Fall, director of the Center for AI Standards and Innovation (CAISI), has resigned from his post just three months after being appointed by the Trump administration. The departure adds fresh ins

CyberShield TeamRead More
When Trusted Gov Infrastructure Becomes an Attack Channel: PhantomEnigma Puts Banks at Risk
News
5 min read

When Trusted Gov Infrastructure Becomes an Attack Channel: PhantomEnigma Puts Banks at Risk

A recent attack investigated by ANY.RUN experts revealed how attackers used more than 20 hijacked Brazilian government websites to support a campaign targeting banking organizations.  By hid

CyberShield TeamRead More
Furtex – Linux Toolkit for Post-Exploitation and Evasion for Security Researchers and Red Teamers
Cybersecurity
4 min read

Furtex – Linux Toolkit for Post-Exploitation and Evasion for Security Researchers and Red Teamers

A new open-source project, Furtex, has emerged as a Linux-focused post-exploitation and evasion research toolkit for authorized security researchers and red-team operators. The project combines raw io

CyberShield TeamRead More
Gemini 3.5 Flash Cyber With Automated Faster Vulnerability Detection and Patch Capabilities
Cybersecurity
3 min read

Gemini 3.5 Flash Cyber With Automated Faster Vulnerability Detection and Patch Capabilities

Google has launched Gemini 3.5 Flash Cyber, a specialized cybersecurity model fine-tuned to find, validate, and patch software vulnerabilities faster and more efficiently than mainline Gemini Flash mo

CyberShield TeamRead More
Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware
Cybersecurity
3 min read

Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware

Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arc

CyberShield TeamRead More
Hackers Hijack 20+ Government Websites to Deliver Malware Through Trusted Links
Cybersecurity
3 min read

Hackers Hijack 20+ Government Websites to Deliver Malware Through Trusted Links

An active malware campaign, dubbed PhantomEnigma, that abuses compromised Brazilian government infrastructure to distribute malicious payloads while evading detection. The operation has hijacked at le

CyberShield TeamRead More
Hackers Turn Fake Games Into Multi-Stage Infostealers That Steal Passwords and Crypto Wallets
Cybersecurity
5 min read

Hackers Turn Fake Games Into Multi-Stage Infostealers That Steal Passwords and Crypto Wallets

Criminals are using fake game downloads to slip a sophisticated information stealer onto Windows computers. The campaign hides behind supposed games, mods, cracks, and other software, exploiting the t

CyberShield TeamRead More
Now You Can teach a Skill to Claude by Just Recording your Screen
Cybersecurity
3 min read

Now You Can teach a Skill to Claude by Just Recording your Screen

Anthropic has rolled out a new capability in Claude Cowork that lets users teach the AI assistant a repeatable skill simply by recording their screen while performing a task. The feature, called &#822

CyberShield TeamRead More
Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record
Cybersecurity
4 min read

Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record

Qilin ransomware has grown from a fast-moving criminal operation into one of the most visible threats in the global extortion landscape. The group encrypts systems and steals data, then pressures vict

CyberShield TeamRead More
This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk
Cybersecurity
6 min read

This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk

A criminal service called Cruciferra is giving malware operators a way to slip past Windows defenses. Sold as a subscription crypter for as much as $2,000 a month, it wraps malicious programs so secur

CyberShield TeamRead More
Trump’s AI Safety Chief Quits Just Three Months After Taking Charge
Cybersecurity
4 min read

Trump’s AI Safety Chief Quits Just Three Months After Taking Charge

Chris Fall has resigned as the director of the Center for AI Standards and Innovation (CAISI), leaving the Trump administration’s AI safety organization without a permanent leader just three mon

CyberShield TeamRead More
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Hacking News
1 min read

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees. 404 Media rep

CyberShield TeamRead More
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
Hacking News
1 min read

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop

CyberShield TeamRead More
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Hacking News
1 min read

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522

CyberShield TeamRead More
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
Hacking News
1 min read

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vul

CyberShield TeamRead More
N-day is Becoming N-Hour. Patching Faster Won't Save You.
Hacking News
1 min read

N-day is Becoming N-Hour. Patching Faster Won't Save You.

Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into

CyberShield TeamRead More
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
Hacking News
1 min read

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim beh

CyberShield TeamRead More
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
Hacking News
1 min read

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same a

CyberShield TeamRead More
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Hacking News
1 min read

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic

CyberShield TeamRead More
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Hacking News
1 min read

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable website

CyberShield TeamRead More
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Hacking News
1 min read

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine secu

CyberShield TeamRead More
23 Million Paidwork Users Have Their Banking and Personal Data Exposed
News
3 min read

23 Million Paidwork Users Have Their Banking and Personal Data Exposed

A massive data breach at gig economy platform Paidwork has exposed the personal and financial information of more than 23 million users, marking one of the largest breaches to hit the gig work sector

CyberShield TeamRead More
Actively Exploited SharePoint Flaws Let Hackers Deploy Web Shells and Steal IIS Machine Keys
News
3 min read

Actively Exploited SharePoint Flaws Let Hackers Deploy Web Shells and Steal IIS Machine Keys

Microsoft SharePoint Server flaws are being actively exploited to deploy web shells, steal IIS machine keys, and maintain long-term access to compromised enterprise environments. The attacks affect on

CyberShield TeamRead More
GPT-5.6 Sol Ultra WordPress Pre-Auth RCE Using a Multi-Agent Exploit Chain
News
3 min read

GPT-5.6 Sol Ultra WordPress Pre-Auth RCE Using a Multi-Agent Exploit Chain

A critical pre-authentication remote code execution (RCE) vulnerability in WordPress has been uncovered not by a human researcher but by an AI system. The discovery, attributed to OpenAI’s GPT-5

CyberShield TeamRead More
LG Monitors Silently Install Full-Access Windows App That Pushes McAfee Ads
News
4 min read

LG Monitors Silently Install Full-Access Windows App That Pushes McAfee Ads

Plugging in a monitor is not supposed to change the software on your computer. According to testing by CyberDigest, LG monitors do exactly that, triggering a silent installation process that ends with

CyberShield TeamRead More
Linux Furtex Toolkit Enables Stealthy Process Injection and Data Exfiltration
News
3 min read

Linux Furtex Toolkit Enables Stealthy Process Injection and Data Exfiltration

A newly disclosed toolkit called Furtex is drawing attention for packaging a wide range of post-exploitation, evasion, and telemetry-blinding techniques into a single project built around raw io_uring

CyberShield TeamRead More
Microsoft Ends OneDrive Sync App Security Updates on Older Windows 10 PCs
News
4 min read

Microsoft Ends OneDrive Sync App Security Updates on Older Windows 10 PCs

Microsoft has announced it will discontinue updates to the OneDrive sync app for devices running Windows 10 version 21H2 and earlier, effective August 15, 2026. The change, detailed in Message Center

CyberShield TeamRead More
Microsoft Releases Emergency Windows 11 Update to Fix Intel Driver Performance Issues
News
3 min read

Microsoft Releases Emergency Windows 11 Update to Fix Intel Driver Performance Issues

Microsoft has shipped an out-of-band (OOB) emergency update for Windows 11 to resolve performance regressions tied to an Intel Innovation Platform Framework (Intel IPF) driver. The update, tracked as

CyberShield TeamRead More
PENTDEM AI Pentesting Daemon Uses 34 Security Tools to Automate Attack Chains
News
3 min read

PENTDEM AI Pentesting Daemon Uses 34 Security Tools to Automate Attack Chains

A newly surfaced open-source project called PENTDEM is drawing attention for packaging 34 real-world penetration testing tools into an autonomous, LLM-guided daemon that can run full attack chains wit

CyberShield TeamRead More
ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands
Cybersecurity
5 min read

ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands

A new malware operation is using ClickFix pages to trick Windows users into running malicious commands themselves. The campaign delivers TELEPUZ, a lightweight but capable remote-access malware that c

CyberShield TeamRead More
Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details
Cybersecurity
10 min read

Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details

Overview A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus webs

CyberShield TeamRead More
GPT-5.6 Sol Ultra Found Wp2shell RCE Flaw That Could Be Worth $500,000 for About $25
Cybersecurity
4 min read

GPT-5.6 Sol Ultra Found Wp2shell RCE Flaw That Could Be Worth $500,000 for About $25

GPT-5.6 Sol Ultra has reportedly uncovered a critical pre-authentication remote code execution (RCE) vulnerability in WordPress after approximately $25 worth of AI usage. This highlights how advanced

CyberShield TeamRead More
Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels
Cybersecurity
3 min read

Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels

A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. HOLLOWGRAPH is a

CyberShield TeamRead More
Microsoft to End OneDrive Sync App Updates for Windows 10
Cybersecurity
3 min read

Microsoft to End OneDrive Sync App Updates for Windows 10

Microsoft will stop delivering OneDrive sync app updates to systems running Windows 10 version 21H2 and earlier on August 15, 2026, creating a new support concern for organizations still operating leg

CyberShield TeamRead More
Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data
Cybersecurity
3 min read

Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data

A massive data breach has hit Paidwork, a popular gig economy platform, exposing sensitive banking and personal information belonging to more than 23 million users worldwide. The incident, first surfa

CyberShield TeamRead More
Where a CBOM solution actually sits: fitting cryptographic inventory into your architecture
Cybersecurity
11 min read

Where a CBOM solution actually sits: fitting cryptographic inventory into your architecture

Most teams meet the idea of a cryptographic bill of materials (CBOM) as a compliance requirement or a post-quantum talking point, and then run straight into a practical question that nobody answered f

CyberShield TeamRead More
Windows Bind Link Abuse Lets Attackers Blind EDR and Bypass AMSI, AppLocker, and Sysmon
Cybersecurity
5 min read

Windows Bind Link Abuse Lets Attackers Blind EDR and Bypass AMSI, AppLocker, and Sysmon

Windows defenders are facing a new way for attackers to hide activity after gaining administrator access. The technique abuses Windows bind links, a legitimate feature that redirects one file path to

CyberShield TeamRead More
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Hacking News
1 min read

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed syst

CyberShield TeamRead More
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
Hacking News
1 min read

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder

CyberShield TeamRead More
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Hacking News
1 min read

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to

CyberShield TeamRead More
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Hacking News
1 min read

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar e

CyberShield TeamRead More
Mythos Didn't Break Your Security Program. Your Exposure Window Could.
Hacking News
1 min read

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI

CyberShield TeamRead More
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
Hacking News
1 min read

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend

CyberShield TeamRead More
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Hacking News
1 min read

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipmen

CyberShield TeamRead More
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
Hacking News
1 min read

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The fi

CyberShield TeamRead More
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Hacking News
1 min read

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of s

CyberShield TeamRead More
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
Hacking News
1 min read

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected

CyberShield TeamRead More
NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure
Cybersecurity
5 min read

NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure

A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. This

CyberShield TeamRead More
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
Hacking News
1 min read

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched

CyberShield TeamRead More
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
Hacking News
1 min read

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public dis

CyberShield TeamRead More
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Hacking News
1 min read

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to

CyberShield TeamRead More
Citrix Secure Access Client Flaw Lets Low-Privileged Users Gain SYSTEM Privileges
News
3 min read

Citrix Secure Access Client Flaw Lets Low-Privileged Users Gain SYSTEM Privileges

Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, the more severe of which allows a sta

CyberShield TeamRead More
Critical WordPress wp2shell Flaw Lets Anonymous Attackers Execute Remote Code
News
3 min read

Critical WordPress wp2shell Flaw Lets Anonymous Attackers Execute Remote Code

A critical pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed “wp2shell.” The flaw requires no preconditions and can be exploited by an anonymous attack

CyberShield TeamRead More
Hackers Breach EY Third-Party IT Support Platform and Steal Client Tax Documents
News
3 min read

Hackers Breach EY Third-Party IT Support Platform and Steal Client Tax Documents

Ernst & Young LLP, one of the world’s Big Four professional services firms, has disclosed a data breach in which an unauthorized third party infiltrated a vendor-managed IT service platform

CyberShield TeamRead More
OpenSSL DoS Flaw Lets Unauthenticated Attackers Trigger Massive Memory Allocation
News
3 min read

OpenSSL DoS Flaw Lets Unauthenticated Attackers Trigger Massive Memory Allocation

A newly disclosed critical weakness in OpenSSL lets an attacker crash a server without ever completing a handshake or proving their identity. Documented by the Okta Red Team, named “HollowByte,&

CyberShield TeamRead More
Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation
Cybersecurity
3 min read

Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation

Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, with one flaw allowing low-privileged

CyberShield TeamRead More
Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI
Cybersecurity
4 min read

Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI

Hugging Face disclosed this week that it detected and contained a production infrastructure intrusion, driven end-to-end by an autonomous AI agent system, and defended against it using its own AI-base

CyberShield TeamRead More
New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours
Cybersecurity
4 min read

New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours

A previously unseen ransomware family dubbed “Spirals” struck an IT services company in South Asia in June 2026. Symantec’s Threat Hunter Team reports that the attackers moved from t

CyberShield TeamRead More
New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released
Cybersecurity
3 min read

New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released

A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full

CyberShield TeamRead More
AWS Cost Explorer Bug Shows Customers Trillion-Dollar Billing Estimates
News
4 min read

AWS Cost Explorer Bug Shows Customers Trillion-Dollar Billing Estimates

Amazon Web Services (AWS) confirmed on July 17, 2026, that a defect in its Cost Explorer tool caused some customers to see massively inflated billing projections, with reports showing estimated charge

CyberShield TeamRead More
GPT-5.6 Codex Reportedly Deletes Files From Users’ Home Directories
News
3 min read

GPT-5.6 Codex Reportedly Deletes Files From Users’ Home Directories

OpenAI has confirmed that its GPT-5.6 Codex model has, in a handful of documented cases, unexpectedly deleted files from users’ home directories, raising fresh concerns about the operational saf

CyberShield TeamRead More
LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives
News
4 min read

LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives

A newly disclosed local privilege escalation technique allows non-administrator Windows users to tamper with an administrator’s registry hive, opening the door to code execution at the administr

CyberShield TeamRead More
Spirals Attackers Disable Windows Defender and Kill Backup Services Before Encrypting Systems
News
3 min read

Spirals Attackers Disable Windows Defender and Kill Backup Services Before Encrypting Systems

A newly identified ransomware family, Spirals, was used in a double-extortion attack against an IT services company in South Asia in June 2026. Researchers from Symantec’s Threat Hunter Team said the

CyberShield TeamRead More
TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Location Data
News
3 min read

TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Location Data

TP-Link has disclosed two security vulnerabilities affecting its Kasa EC70 v4 and EC71 v4 smart camera models, which could let attackers on the same local network intercept administrative credentials

CyberShield TeamRead More
UAT-11795 Deploys Starland RAT and WLDR Backdoor Through Trojanized Software Installers
News
3 min read

UAT-11795 Deploys Starland RAT and WLDR Backdoor Through Trojanized Software Installers

Cisco Talos has uncovered a new financially motivated threat cluster, tracked as UAT-11795, that has been conducting a large-scale malware campaign targeting users across the United States and parts o

CyberShield TeamRead More
EY Data Breach – Hackers Gain Access to IT Support System and Download Documents
Cybersecurity
3 min read

EY Data Breach – Hackers Gain Access to IT Support System and Download Documents

Ernst & Young LLP (EY) is notifying clients that an unauthorized third party breached a support ticket platform used by its IT staff, downloading documents containing client tax data during a roug

CyberShield TeamRead More
New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access
Cybersecurity
5 min read

New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access

A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code exe

CyberShield TeamRead More
OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes
Cybersecurity
4 min read

OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes

A newly disclosed vulnerability in OpenSSL, dubbed “HollowByte,” allows a remote, unauthenticated attacker to trigger a denial-of-service (DoS) condition using a malicious payload as small

CyberShield TeamRead More
PentestCode – New AI Agent That Automates Penetration Testing with 18 Specialized Tools
Cybersecurity
3 min read

PentestCode – New AI Agent That Automates Penetration Testing with 18 Specialized Tools

A new open-source tool is bringing autonomous AI agents into offensive security workflows. PentestCode, a hard fork of OpenCode rebuilt specifically for penetration testing, runs security tools, analy

CyberShield TeamRead More
Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States
Cybersecurity
4 min read

Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States

Coca-Cola has reported a ransomware attack affecting its dairy subsidiary, Fairlife, resulting in a temporary shutdown of production operations across the United States. This incident was disclosed in

CyberShield TeamRead More
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
Hacking News
1 min read

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced One

CyberShield TeamRead More
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Hacking News
1 min read

Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man

Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yu

CyberShield TeamRead More
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
Hacking News
1 min read

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that

CyberShield TeamRead More
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
Hacking News
1 min read

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job

CyberShield TeamRead More
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Hacking News
1 min read

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described

CyberShield TeamRead More
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
Hacking News
1 min read

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with Comf

CyberShield TeamRead More
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Hacking News
1 min read

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story bel

CyberShield TeamRead More
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Hacking News
1 min read

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts.

CyberShield TeamRead More
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Hacking News
1 min read

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campa

CyberShield TeamRead More
The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
Hacking News
1 min read

The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?

Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acqu

CyberShield TeamRead More
F5 Patches Multiple NGINX Vulnerabilities Enabling Heap Buffer Overflow and Code Execution Attacks
Cybersecurity
3 min read

F5 Patches Multiple NGINX Vulnerabilities Enabling Heap Buffer Overflow and Code Execution Attacks

F5 has disclosed three high-severity vulnerabilities affecting NGINX Plus and NGINX Open Source, warning that unauthenticated attackers could exploit them to trigger memory corruption, crash worker pr

CyberShield TeamRead More
11 Malicious NuGet Packages Pose as Game Cheats to Deploy Windows Surveillance Malware
News
4 min read

11 Malicious NuGet Packages Pose as Game Cheats to Deploy Windows Surveillance Malware

Socket’s Threat Research Team has uncovered 11 malicious NuGet packages masquerading as game cheats, bots, and “panels” that deliver a Windows surveillance-capable payload named pepesoft.exe. The pack

CyberShield TeamRead More
Dell PowerProtect Data Domain Flaws Enable Unauthenticated System Takeover
News
4 min read

Dell PowerProtect Data Domain Flaws Enable Unauthenticated System Takeover

A critical batch of vulnerabilities in its PowerProtect Data Domain product line, including two flaws with the maximum-severity CVSS score of 9.8, allows completely unauthenticated attackers to seize

CyberShield TeamRead More
DOJ Indicts Russian Bulletproof Hosting Operators Over $62 Million Cybercrime Losses
News
3 min read

DOJ Indicts Russian Bulletproof Hosting Operators Over $62 Million Cybercrime Losses

The U.S. Department of Justice unsealed an indictment on July 14, 2026, charging three Russian nationals and two affiliated “bulletproof hosting” companies for running criminal infrastruct

CyberShield TeamRead More
Google Chrome Update Fixes 15 Security Flaws, Including Critical Ozone UAF Flaws
News
3 min read

Google Chrome Update Fixes 15 Security Flaws, Including Critical Ozone UAF Flaws

Google has rolled out a new Chrome Stable channel update addressing 15 security vulnerabilities, including two critical-severity use-after-free (UAF) flaws in the Ozone platform layer. The update brin

CyberShield TeamRead More
Malicious LNK Files and PowerShell Deploy Dual Remote-Access Tools Against Indian Applicants
News
3 min read

Malicious LNK Files and PowerShell Deploy Dual Remote-Access Tools Against Indian Applicants

Indian government job seekers are being targeted in a multi-stage malware campaign that uses a fake Cabinet Secretariat recruitment notice to deploy both a legitimate remote-management tool and a cust

CyberShield TeamRead More
Microsoft Active Directory FS Privilege Escalation Flaw Exploited in Active Attacks
News
3 min read

Microsoft Active Directory FS Privilege Escalation Flaw Exploited in Active Attacks

Microsoft has disclosed an actively exploited elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS), tracked as CVE-2026-56155. The flaw was released on July 14, 2026, a

CyberShield TeamRead More
Microsoft Patches Multiple Windows RDP Flaws That Expose Sensitive Data
News
3 min read

Microsoft Patches Multiple Windows RDP Flaws That Expose Sensitive Data

Microsoft has addressed five information disclosure vulnerabilities affecting the Windows Remote Desktop Protocol (RDP) in its July 2026 Patch Tuesday release, each carrying an “Important”

CyberShield TeamRead More
New LabubaRAT Masquerades as NVIDIA Software to Execute Commands and Proxy Malicious Traffic
News
4 min read

New LabubaRAT Masquerades as NVIDIA Software to Execute Commands and Proxy Malicious Traffic

Blackpoint’s Adversary Pursuit Group has identified a new Rust-based remote access trojan, dubbed LabubaRAT, masquerading as NVIDIA software. The malware, delivered as nvidia-sysruntime.exe, uses NVID

CyberShield TeamRead More
SonicWall SMA1000 Flaws Actively Exploited for SSRF and Remote Code Execution
News
3 min read

SonicWall SMA1000 Flaws Actively Exploited for SSRF and Remote Code Execution

SonicWall has issued an urgent security advisory (SNWLID-2026-0008) confirming active, in-the-wild exploitation of two critical vulnerabilities affecting its SMA1000 Series appliances. The flaws, trac

CyberShield TeamRead More
Windows 11 Update Causes Performance, Heat, and Battery Issues on Some Dell PCs
News
3 min read

Windows 11 Update Causes Performance, Heat, and Battery Issues on Some Dell PCs

Microsoft has confirmed a new compatibility issue affecting select Dell PCs after installing a recent Windows 11 preview update, causing unexpected shutdowns, degraded performance, overheating, and ra

CyberShield TeamRead More
Critical Cursor 0-Day Flaw Allows Malicious Git Repos to Trigger Automatic Windows Code Execution
Cybersecurity
4 min read

Critical Cursor 0-Day Flaw Allows Malicious Git Repos to Trigger Automatic Windows Code Execution

A critical unpatched vulnerability in Cursor, the popular AI-powered code editor used by over 7 million developers, allows attackers to achieve arbitrary code execution on Windows systems. Simply open

CyberShield TeamRead More
GPT-5.6 Sol Ultra Builds Full Chrome Exploit Chain From Security Patches
Cybersecurity
3 min read

GPT-5.6 Sol Ultra Builds Full Chrome Exploit Chain From Security Patches

OpenAI’s GPT-5.6 Sol Ultra model independently constructed a complete, working exploit chain for Google Chrome, using nothing but publicly available security patch commits as its starting point.

CyberShield TeamRead More
Hacker Used Gemini CLI to Build a Live C&C Botnet in 6 Minutes
Cybersecurity
7 min read

Hacker Used Gemini CLI to Build a Live C&C Botnet in 6 Minutes

A Russian-speaking threat actor known as “bandcampro” has weaponized Google’s Gemini CLI AI agent to migrate, deploy, and operate a live command-and-control (C&C) botnet. Remarka

CyberShield TeamRead More
Hackers Abuse Shared Claude Chats and Google Ads to Deploy MacSync Stealer on macOS
Cybersecurity
3 min read

Hackers Abuse Shared Claude Chats and Google Ads to Deploy MacSync Stealer on macOS

Threat actors are hijacking Anthropic’s Claude AI platform and Google Ads to trick Mac users into infecting themselves with a dangerous new information-stealing malware called MacSync Stealer, a

CyberShield TeamRead More
Hackers Expanding Destiny Stealer Across the US and Europe. Is Your Organization Ready to Defend?
Cybersecurity
5 min read

Hackers Expanding Destiny Stealer Across the US and Europe. Is Your Organization Ready to Defend?

Destiny Stealer activity is rising across Europe and the US, putting corporate accounts, remote access, email data, and sensitive business information at risk. A single infected endpoint can expose pa

CyberShield TeamRead More
Insignary Launches Clarity On-Demand: SBOMs, No Annual Commitment Required
Cybersecurity
4 min read

Insignary Launches Clarity On-Demand: SBOMs, No Annual Commitment Required

Toronto, Canada, July 15th, 2026, CyberNewswire Enterprise-grade binary software verification for one project, one team, or one compliance deadline — without an annual commitment. According to Insigna

CyberShield TeamRead More
Multiple Dell PowerProtect Vulnerabilities Allow Hackers to Gain Full System Access Remotely
Cybersecurity
3 min read

Multiple Dell PowerProtect Vulnerabilities Allow Hackers to Gain Full System Access Remotely

Dell has released security updates to address multiple critical vulnerabilities in its PowerProtect Data Domain products that could allow an unauthenticated remote attacker to gain complete control of

CyberShield TeamRead More
Multiple Windows RDP Vulnerabilities Allow Attackers to Access Sensitive Data
Cybersecurity
4 min read

Multiple Windows RDP Vulnerabilities Allow Attackers to Access Sensitive Data

Microsoft has released security updates to address a series of information disclosure vulnerabilities in the Windows Remote Desktop Protocol (RDP). These vulnerabilities could allow attackers to read

CyberShield TeamRead More
US Charges Two “Bulletproof Hosting” Companies for Helping Hackers Steal Tens of Millions of Dollars
Cybersecurity
3 min read

US Charges Two “Bulletproof Hosting” Companies for Helping Hackers Steal Tens of Millions of Dollars

The Department of Justice has unsealed an indictment in the Northern District of Ohio charging three Russian nationals and two Russia-based “bulletproof hosting” companies. The entities ar

CyberShield TeamRead More
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Hacking News
1 min read

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The aff

CyberShield TeamRead More
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
Hacking News
1 min read

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to exe

CyberShield TeamRead More
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
Hacking News
1 min read

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws

Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointe

CyberShield TeamRead More
New Webinar: Closing the Approval Gap in AI-Era Ad Tech
Hacking News
1 min read

New Webinar: Closing the Approval Gap in AI-Era Ad Tech

A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reve

CyberShield TeamRead More
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
Hacking News
1 min read

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC,

CyberShield TeamRead More
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Hacking News
1 min read

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive

CyberShield TeamRead More
SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
Hacking News
1 min read

SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.

For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now live ac

CyberShield TeamRead More
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
Hacking News
1 min read

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance fro

CyberShield TeamRead More
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
Hacking News
1 min read

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command ex

CyberShield TeamRead More
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Hacking News
1 min read

11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the moder

CyberShield TeamRead More
Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read
Hacking News
1 min read

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publi

CyberShield TeamRead More
How Pentera Turns AI Security Workflows into Validation Engines
Hacking News
1 min read

How Pentera Turns AI Security Workflows into Validation Engines

AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help teams move faster. But most still rely on fragment

CyberShield TeamRead More
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Hacking News
1 min read

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. "Labub

CyberShield TeamRead More
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Hacking News
1 min read

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Upda

CyberShield TeamRead More
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Hacking News
1 min read

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate

CyberShield TeamRead More
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Hacking News
1 min read

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enter

CyberShield TeamRead More
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Hacking News
1 min read

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar. Both this and

CyberShield TeamRead More
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
Hacking News
1 min read

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in quest

CyberShield TeamRead More
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Hacking News
1 min read

Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that the wallets themselves leak enough to link and track the people using them. The way

CyberShield TeamRead More
Apple Sues OpenAI and Former Employees for Alleged Theft of Trade Secrets
Cybersecurity
4 min read

Apple Sues OpenAI and Former Employees for Alleged Theft of Trade Secrets

Apple has filed a federal lawsuit against OpenAI, accusing the ChatGPT maker of orchestrating a systematic campaign to steal confidential hardware designs, manufacturing processes, and supplier relati

CyberShield TeamRead More
AWS GovCloud Credential Leak Prompts CISA to Publish Key Cyber Incident Lessons
News
3 min read

AWS GovCloud Credential Leak Prompts CISA to Publish Key Cyber Incident Lessons

The Cybersecurity and Infrastructure Security Agency (CISA) has publicly detailed an internal security incident involving the exposure of AWS GovCloud credentials in a public code repository, offering

CyberShield TeamRead More
Dell BIOS Flaw Lets Attackers Recover Passwords From SPI Flash
News
3 min read

Dell BIOS Flaw Lets Attackers Recover Passwords From SPI Flash

A newly disclosed critical flaw in how Dell stores BIOS administrator and user passwords allows full recovery of plaintext credentials from a flash dump in milliseconds. Tracked as CVE-2026-40639 (DSA

CyberShield TeamRead More
New Trojan Turns Visual Studio Projects Into a Software Supply Chain Attack Vector
News
4 min read

New Trojan Turns Visual Studio Projects Into a Software Supply Chain Attack Vector

A multi-stage Trojan is turning ordinary software development workflows into a supply chain attack vector by weaponizing Visual Studio project files. Documented by Doctor Web researchers, first detect

CyberShield TeamRead More
Zimbra 10.1.19 Fixes Stored XSS Flaw Triggered by Crafted Emails
News
3 min read

Zimbra 10.1.19 Fixes Stored XSS Flaw Triggered by Crafted Emails

Zimbra has released version 10.1.19 of its Collaboration Suite (ZCS), codenamed “Daffodil,” addressing a stored cross-site scripting (XSS) vulnerability in the Classic Web Client. The patc

CyberShield TeamRead More
281 Popular VPN Apps from the Google Play Store Leak Sensitive Data, Transfer Data Unencrypted
Cybersecurity
4 min read

281 Popular VPN Apps from the Google Play Store Leak Sensitive Data, Transfer Data Unencrypted

A new security study has found serious privacy and security issues in 281 popular Android VPN applications available on the Google Play Store. Researchers discovered that dozens of these apps transfer

CyberShield TeamRead More
CISA Details “Lessons from a Cyber Incident” After AWS GovCloud Credentials Leak
Cybersecurity
3 min read

CISA Details “Lessons from a Cyber Incident” After AWS GovCloud Credentials Leak

CISA has published a candid after-action account revealing that a contractor accidentally exposed the agency’s own AWS GovCloud credentials and Infrastructure-as-Code repositories in a personal,

CyberShield TeamRead More
Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds
Cybersecurity
4 min read

Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds

A critical flaw in how Dell stores BIOS administrator and user passwords allows full password recovery from a flash dump in milliseconds, with no brute force required. The vulnerability, tracked as CV

CyberShield TeamRead More
Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts
Cybersecurity
4 min read

Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts

Forg365 is a phishing-as-a-service platform that targets Microsoft accounts, combining AI-powered phishing, session theft, and post-compromise mailbox access in a single operator panel The platform is

CyberShield TeamRead More
Microsoft Teams on macOS Screen Sharing Bug Causing Blank Screens
Cybersecurity
3 min read

Microsoft Teams on macOS Screen Sharing Bug Causing Blank Screens

Microsoft has confirmed a known issue in Teams on macOS that causes screen sharing to fail, freeze, or show a blank black screen during meetings. The bug affects users running macOS versions older tha

CyberShield TeamRead More
New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents
Cybersecurity
4 min read

New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents

A novel supply chain attack called “Ghostcommit” that conceals prompt-injection instructions within PNG images to bypass AI code reviewers and trick coding agents into leaking secrets such

CyberShield TeamRead More
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
Hacking News
1 min read

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook th

CyberShield TeamRead More
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Hacking News
1 min read

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been desc

CyberShield TeamRead More
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Hacking News
1 min read

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat a

CyberShield TeamRead More
281 Google Play VPN Apps Expose Sensitive Information Through Cleartext Data Transmission
News
3 min read

281 Google Play VPN Apps Expose Sensitive Information Through Cleartext Data Transmission

A new disclosure of widespread security and privacy failures across popular Android VPN applications, revealing that dozens of apps transmit sensitive data in plaintext and fail to deliver the fundame

CyberShield TeamRead More
Best Next-Generation Firewall (NGFW) Solutions for Every Business Size (2026)
News
14 min read

Best Next-Generation Firewall (NGFW) Solutions for Every Business Size (2026)

There is no single best next-generation firewall there’s a best one for your size, your team, and your regulatory reality. A 40-person company buying a Palo Alto chassis wastes money; a bank running a

CyberShield TeamRead More
Citrix NetScaler MCP Gateway Adds Unified Security for Agentic AI Traffic
News
4 min read

Citrix NetScaler MCP Gateway Adds Unified Security for Agentic AI Traffic

Citrix, a Cloud Software Group company, has introduced Model Context Protocol (MCP) Gateway capabilities for NetScaler, extending its application delivery and security platform to govern enterprise ag

CyberShield TeamRead More
Fake Braintree Package Steals Credit Cards Only in Production to Avoid Detection
News
3 min read

Fake Braintree Package Steals Credit Cards Only in Production to Avoid Detection

A highly sophisticated malware campaign was recently discovered lurking within the NuGet ecosystem, targeting developers who use the popular Braintree payment gateway. Security researchers at Socket f

CyberShield TeamRead More
Forg365 PhaaS Abuses Microsoft Device-Code Flow to Hijack M365 Sessions
News
4 min read

Forg365 PhaaS Abuses Microsoft Device-Code Flow to Hijack M365 Sessions

A newly identified phishing-as-a-service (PhaaS) platform, Forg365, is abusing Microsoft’s device code authentication flow to hijack Microsoft 365 sessions at scale. ZeroBEC researchers uncovere

CyberShield TeamRead More
GNU Guix Flaws Enable Remote Privilege Escalation and Store Corruption
News
4 min read

GNU Guix Flaws Enable Remote Privilege Escalation and Store Corruption

Multiple critical security flaws in GNU Guix could allow malicious substitute servers or network attackers to achieve remote privilege escalation, corrupt the Guix store, and potentially expose sensit

CyberShield TeamRead More
Hackers Abuse CitrixBleed 2 to Steal Session Tokens and Bypass MFA Protections
News
4 min read

Hackers Abuse CitrixBleed 2 to Steal Session Tokens and Bypass MFA Protections

Hackers are exploiting the CitrixBleed 2 vulnerability to steal active session tokens, bypass multi-factor authentication, and deploy ransomware in targeted Citrix NetScaler environments. Huntress Tac

CyberShield TeamRead More
Linux FUSE Page Cache Overflow Lets Local Attackers Gain Root Access
News
4 min read

Linux FUSE Page Cache Overflow Lets Local Attackers Gain Root Access

A newly disclosed Linux kernel vulnerability in the Filesystem in Userspace (FUSE) subsystem could allow unprivileged local attackers to gain root privileges on affected systems. Tracked as CVE-2026-3

CyberShield TeamRead More
Microsoft Uses AI to Accelerate Windows Vulnerability Discovery and Patching
News
3 min read

Microsoft Uses AI to Accelerate Windows Vulnerability Discovery and Patching

Microsoft has unveiled a major expansion of AI-driven security tooling across Windows, aiming to find vulnerabilities earlier, fix them faster, and deliver more reliable patches at scale. The initiati

CyberShield TeamRead More
Multiple U-Boot FIT Signature Flaws Enable Code Execution and DoS Attacks
News
4 min read

Multiple U-Boot FIT Signature Flaws Enable Code Execution and DoS Attacks

A newly disclosed six vulnerabilities in U-Boot, one of the most widely deployed bootloaders in embedded systems, routers, IoT devices, and Baseboard Management Controllers (BMCs) used in data center

CyberShield TeamRead More
OpenClaw Vulnerabilities Let Attackers Turn WhatsApp Messages Into Host-Level Code Execution
News
4 min read

OpenClaw Vulnerabilities Let Attackers Turn WhatsApp Messages Into Host-Level Code Execution

Security researchers have disclosed three high-severity vulnerabilities in OpenClaw, the popular open-source AI coding assistant with over 381,000 GitHub stars, that allow attackers to achieve full re

CyberShield TeamRead More
Roundcube Webmail 1.7.2 Fixes Zero-Click XSS, SSRF Bypass, and DoS Flaws
News
3 min read

Roundcube Webmail 1.7.2 Fixes Zero-Click XSS, SSRF Bypass, and DoS Flaws

Roundcube has released version 1.7.2, a security-focused update addressing six vulnerabilities, including two CVE-tracked flaws that could allow attackers to execute stored cross-site scripting (XSS)

CyberShield TeamRead More
Wireshark 4.6.7 Fixes 12 Security Flaws Causing Crashes and Infinite Loops
News
4 min read

Wireshark 4.6.7 Fixes 12 Security Flaws Causing Crashes and Infinite Loops

Wireshark has released version 4.6.7, addressing 12 security vulnerabilities that could lead to application crashes, information disclosure, and resource exhaustion via maliciously crafted network tra

CyberShield TeamRead More
GNU Guix Vulnerabilities Allow Remote Privilege Escalation via Malicious Binary Substitutes
Cybersecurity
3 min read

GNU Guix Vulnerabilities Allow Remote Privilege Escalation via Malicious Binary Substitutes

GNU Guix has disclosed four serious security vulnerabilities affecting its package substitution and channel-management features. Three flaws in the guix substitute utility can enable remote privilege

CyberShield TeamRead More
Hackers Can Go From CitrixBleed 2 Exploitation to Ransomware in Under an Hour
Cybersecurity
5 min read

Hackers Can Go From CitrixBleed 2 Exploitation to Ransomware in Under an Hour

A critical Citrix flaw is giving intruders a fast route from an internet-facing gateway to a ransomware event. The activity centers on CitrixBleed 2, tracked as CVE-2025-5777, which can expose memory

CyberShield TeamRead More
Malicious Windows Shortcuts Use PowerShell and Node.js to Enable Remote Code Execution
Cybersecurity
9 min read

Malicious Windows Shortcuts Use PowerShell and Node.js to Enable Remote Code Execution

A malicious Windows shortcut is being used to turn a routine download into a full remote-code-execution foothold. The campaign begins with convincing booking-themed spam and steers victims toward a ZI

CyberShield TeamRead More
One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers
Cybersecurity
3 min read

One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers

Three high-severity vulnerabilities in OpenClaw, the open-source AI coding assistant with 381,000 GitHub stars, that allow attackers to achieve remote code execution through a single WhatsApp message.

CyberShield TeamRead More
OpenAI Releases GPT-5.6 and ChatGPT Work, a New Companion to Handle Your Tasks
Cybersecurity
4 min read

OpenAI Releases GPT-5.6 and ChatGPT Work, a New Companion to Handle Your Tasks

OpenAI has released the GPT-5.6 model family for general availability, introducing three models aimed at different performance and cost requirements: Sol, the flagship system; Terra, a balanced option

CyberShield TeamRead More
Progress Urges ShareFile Admins to Shut Down Servers Over Credible Security Threat
Cybersecurity
3 min read

Progress Urges ShareFile Admins to Shut Down Servers Over Credible Security Threat

Progress Software has issued an urgent advisory instructing customers running on-premises ShareFile Storage Zone Controllers to immediately power down the servers hosting these components, citing a &#

CyberShield TeamRead More
Six U-Boot FIT Signature Verification Flaws Enable Code Execution and DoS Attacks
Cybersecurity
4 min read

Six U-Boot FIT Signature Verification Flaws Enable Code Execution and DoS Attacks

A new security analysis by Binarly Research has uncovered six critical vulnerabilities in the widely used U-Boot bootloader, exposing embedded systems and server management platforms to denial-of-serv

CyberShield TeamRead More
Top 10 Best Unified Threat Management (UTM) Solutions in 2026
Cybersecurity
13 min read

Top 10 Best Unified Threat Management (UTM) Solutions in 2026

If you need one appliance that handles firewalling, intrusion prevention, VPN, antivirus, and web filtering without a security team to run it, Fortinet FortiGate is our top UTM pick for 2026, with Sop

CyberShield TeamRead More
Wireshark 4.6.7 Released With Fixes for Vulnerabilities Allowing Crashes via Malicious Packets
Cybersecurity
4 min read

Wireshark 4.6.7 Released With Fixes for Vulnerabilities Allowing Crashes via Malicious Packets

The Wireshark Foundation has released Wireshark 4.6.7, a security-focused update that fixes multiple vulnerabilities that can cause the popular network protocol analyzer to crash when processing speci

CyberShield TeamRead More
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
Hacking News
1 min read

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking tools, the activity logs, and target lists naming mo

CyberShield TeamRead More
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
Hacking News
1 min read

From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale

Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report,

CyberShield TeamRead More
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Hacking News
1 min read

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and

CyberShield TeamRead More
Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched
Hacking News
1 min read

Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched

Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to anything the attacker

CyberShield TeamRead More
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
Hacking News
1 min read

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the thr

CyberShield TeamRead More
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
Hacking News
1 min read

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege es

CyberShield TeamRead More
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
Hacking News
1 min read

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside da

CyberShield TeamRead More
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
Hacking News
1 min read

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic

CyberShield TeamRead More
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
Hacking News
1 min read

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO resear

CyberShield TeamRead More
URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
Hacking News
1 min read

URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a "credible external secu

CyberShield TeamRead More
Agentic Botnets Attack Uses HalluSquatting to Hijack AI Coding Assistants
News
4 min read

Agentic Botnets Attack Uses HalluSquatting to Hijack AI Coding Assistants

A newly disclosed attack technique, called adversarial hallucination squatting (HalluSquatting), developed by researchers at Tel Aviv University and Technion, exploits the predictable tendency of larg

CyberShield TeamRead More
AI-Assisted Cloud Attack Compromises AWS Environment in Just 72 Hours
News
4 min read

AI-Assisted Cloud Attack Compromises AWS Environment in Just 72 Hours

A threat actor leveraging AI-assisted tooling breached a large AWS-based environment and expanded across applications, cloud infrastructure, source-control repositories, CI/CD pipelines, and runtime s

CyberShield TeamRead More
AI-Coded Malware Uses Vibe Coding to Map Active Directory Environments
News
3 min read

AI-Coded Malware Uses Vibe Coding to Map Active Directory Environments

Threat actors are now weaponizing AI-generated PowerShell scripts to enumerate Active Directory (AD) environments, according to new findings from Huntress. The discovery, tied to an incident on June 3

CyberShield TeamRead More
AssuranceAmerica Data Breach Exposes 6.9 Million Driver’s License Numbers
News
3 min read

AssuranceAmerica Data Breach Exposes 6.9 Million Driver’s License Numbers

U.S. insurer AssuranceAmerica has confirmed a data breach exposing the personal information and driver’s license numbers of roughly 6.9 million people, marking the largest known exposure of Amer

CyberShield TeamRead More
Fake Chinese VPN Drops GoodPersonRAT With Keylogging, Proxying, and Telegram Theft
News
3 min read

Fake Chinese VPN Drops GoodPersonRAT With Keylogging, Proxying, and Telegram Theft

The legitimate VPN service is highly popular for its ability to bypass China’s Great Firewall. However, attackers are exploiting its reputation to deploy hidden malware. This fake installer drop

CyberShield TeamRead More
GitLab Patch Release Fixes Affecting CE and EE Installations
News
3 min read

GitLab Patch Release Fixes Affecting CE and EE Installations

GitLab released versions 19.1.2, 19.0.4, and 18.11.7 on July 8, 2026, patching eight vulnerabilities ranging from high to low severity across Community Edition (CE) and Enterprise Edition (EE). The co

CyberShield TeamRead More
Hackers Use Device Code Phishing to Replay Sessions and Register MFA for Persistence
News
3 min read

Hackers Use Device Code Phishing to Replay Sessions and Register MFA for Persistence

Threat researchers have uncovered a new data extortion group named “Helix” that bypasses traditional security perimeters without deploying a single piece of malware. Emerging from the remn

CyberShield TeamRead More
Nike Alleged Breach: Threat Actors Claim Customer Records Leaked on Dark Web Forum
News
3 min read

Nike Alleged Breach: Threat Actors Claim Customer Records Leaked on Dark Web Forum

A threat actor operating under the alias “Nocturne” has posted a database listing on a dark web forum claiming to have exfiltrated customer data from Nike and confidential records from oph

CyberShield TeamRead More
Palo Alto PAN-OS Buffer Overflow Flaws Could Let Attackers Execute Code
News
3 min read

Palo Alto PAN-OS Buffer Overflow Flaws Could Let Attackers Execute Code

Palo Alto Networks has disclosed multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of PAN-OS. Tracked as CVE-2026-0288, it could allow unauthenticated attac

CyberShield TeamRead More
PoC and Technical Details Released for Linux Kernel Privilege Escalation Vulnerability
News
4 min read

PoC and Technical Details Released for Linux Kernel Privilege Escalation Vulnerability

A researcher has published proof-of-concept exploit code and a full technical breakdown of a Linux kernel vulnerability that lets any logged-in desktop user escalate to root, requiring no special priv

CyberShield TeamRead More
Windows Update Allegedly Installs LG Monitor App Triggering McAfee Popup
News
3 min read

Windows Update Allegedly Installs LG Monitor App Triggering McAfee Popup

A Windows update reportedly triggered the silent installation of an LG-branded application on user systems, which then displayed an unsolicited McAfee promotional pop-up even on machines where McAfee

CyberShield TeamRead More
A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours
Cybersecurity
4 min read

A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours

A large-scale AWS intrusion reveals how AI-assisted attackers can chain familiar cloud techniques to move from initial access to full environmental compromise in roughly 72 hours, not through novel ex

CyberShield TeamRead More
Accenture Confirms Data Breach – Hacker Claims Theft of Internal Source Code
Cybersecurity
3 min read

Accenture Confirms Data Breach – Hacker Claims Theft of Internal Source Code

IT services and consulting giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other sensitive data from the company. A thr

CyberShield TeamRead More
ACSC Warns of Large-Scale CMS Exploitation Campaign Deploys Webshells on Vulnerable Websites
Cybersecurity
4 min read

ACSC Warns of Large-Scale CMS Exploitation Campaign Deploys Webshells on Vulnerable Websites

A large hacking campaign is sweeping across websites worldwide, turning ordinary content management systems into launchpads for attackers. Small and medium sized businesses in Australia and beyond are

CyberShield TeamRead More
Claude, Cursor, and Codex Trigger Endpoint Security Rules Used to Catch Hackers
Cybersecurity
4 min read

Claude, Cursor, and Codex Trigger Endpoint Security Rules Used to Catch Hackers

AI coding agents such as Claude Code, Cursor, and OpenAI Codex are increasingly appearing in enterprise environments, and new telemetry shows they are unintentionally triggering security detections ti

CyberShield TeamRead More
GodDamn Ransomware Rebrands From Beast and Uses PoisonX Driver to Disable Defenses
Cybersecurity
5 min read

GodDamn Ransomware Rebrands From Beast and Uses PoisonX Driver to Disable Defenses

GodDamn ransomware has emerged as a serious threat, marking the third rebrand of a family that has quietly evolved since 2022. What makes this variant stand out is not just its encryption ability but

CyberShield TeamRead More
Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts
Cybersecurity
5 min read

Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts

Cybercriminals have found a new way to hijack corporate Microsoft accounts by exploiting the very feature meant to protect them: passkeys. A threat group tracked as O UNC 066, also called Pink by Palo

CyberShield TeamRead More
Microsoft Adopts AI-Powered Scanning to Find Vulnerabilities Before Attackers
Cybersecurity
4 min read

Microsoft Adopts AI-Powered Scanning to Find Vulnerabilities Before Attackers

Microsoft has formally expanded its use of artificial intelligence in vulnerability discovery, deploying a proprietary multi-model agentic scanning system across the Windows codebase to identify and p

CyberShield TeamRead More
New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents
Cybersecurity
4 min read

New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents

A newly disclosed vulnerability pattern dubbed “GhostApproval” has exposed a critical security flaw in six of the most widely used AI coding assistants: Amazon Q Developer, Anthropic Claud

CyberShield TeamRead More
Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic
Cybersecurity
3 min read

Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic

Palo Alto Networks has disclosed a high-severity vulnerability in PAN-OS that could allow unauthenticated attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition by sending

CyberShield TeamRead More
RedHook Android RAT Abuses ADB Wireless Debugging to Gain Shell-Level Access
Cybersecurity
5 min read

RedHook Android RAT Abuses ADB Wireless Debugging to Gain Shell-Level Access

A resurfaced Android banking trojan called RedHook has returned with a dangerous new trick, hijacking a legitimate developer feature to quietly seize deep control of infected phones. Rather than relyi

CyberShield TeamRead More
RoundCube 0-Click Vulnerability Enables Stored XSS Attack via MIME Type Attachment
Cybersecurity
3 min read

RoundCube 0-Click Vulnerability Enables Stored XSS Attack via MIME Type Attachment

Roundcube has released version 1.7 to patch six security vulnerabilities, including two critical stored cross-site scripting (XSS) flaws that require zero user interaction to exploit. The update addre

CyberShield TeamRead More
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
Hacking News
1 min read

AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up

AI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the ne

CyberShield TeamRead More
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
Hacking News
1 min read

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operato

CyberShield TeamRead More
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Hacking News
1 min read

Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes

Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprisi

CyberShield TeamRead More
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Hacking News
1 min read

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one har

CyberShield TeamRead More
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
Hacking News
1 min read

GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According

CyberShield TeamRead More
Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images
Hacking News
1 min read

Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images

Meta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI content, and it's enabled by default. "You can also @-ment

CyberShield TeamRead More
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Hacking News
1 min read

Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges

Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS sc

CyberShield TeamRead More
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Hacking News
1 min read

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands

CyberShield TeamRead More
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
Hacking News
1 min read

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authenticatio

CyberShield TeamRead More
Summer of Clearinghouses
Hacking News
1 min read

Summer of Clearinghouses

Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we annou

CyberShield TeamRead More
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
Hacking News
1 min read

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of

CyberShield TeamRead More
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Hacking News
1 min read

Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the finding in a proof-of-concept published Wednesday by t

CyberShield TeamRead More
Attackers Can Abuse Claude Desktop to Execute Commands on Victim Machines
News
3 min read

Attackers Can Abuse Claude Desktop to Execute Commands on Victim Machines

A novel attack chain that turns Anthropic’s Claude Desktop application into a remote code execution vector, requiring no phishing email and no traditional malware. The technique instead weaponiz

CyberShield TeamRead More
Claude Cowork Expands to Web and Mobile With Background AI Agent Tasks
News
4 min read

Claude Cowork Expands to Web and Mobile With Background AI Agent Tasks

Anthropic has rolled out Claude Cowork to web and mobile platforms, letting AI agent sessions persist across devices and continue executing tasks even when users step away. The expansion, announced Ju

CyberShield TeamRead More
DuckDuckGo Browser to Block YouTube Ads by Default
News
4 min read

DuckDuckGo Browser to Block YouTube Ads by Default

A native YouTube ad-blocking feature was rolled out by DuckDuckGo across its desktop and mobile browsers, allowing users to watch YouTube videos without pre-roll or mid-roll interruptions. The feature

CyberShield TeamRead More
GitHub Verified Badge Can Appear on Multiple Hashes for Same Signed Commit
News
4 min read

GitHub Verified Badge Can Appear on Multiple Hashes for Same Signed Commit

A new disclosure reveals that a GitHub “Verified” badge does not guarantee that a commit hash uniquely identifies signed content, undermining a core assumption behind hash-based security c

CyberShield TeamRead More
New Research Details How FBI Uncovered Alleged Scattered Spider Member
News
4 min read

New Research Details How FBI Uncovered Alleged Scattered Spider Member

The extradition of an alleged Scattered Spider member from Finland to the United States has drawn attention far beyond the criminal charges themselves. Buried on page 8 of the indictment lies a detail

CyberShield TeamRead More
APT-C-20 Hackers Hide Shellcode in PNG Images to Launch Fileless C# Backdoor
Cybersecurity
5 min read

APT-C-20 Hackers Hide Shellcode in PNG Images to Launch Fileless C# Backdoor

A well known hacking group has found a clever way to sneak malicious code past security tools, using an ordinary picture file. The group, tracked as APT-C-20 and known as APT28 or Fancy Bear, hides sh

CyberShield TeamRead More
ClickFix Campaign Uses Fake Google Verification Page to Infect Mexican Bank Customers
Cybersecurity
6 min read

ClickFix Campaign Uses Fake Google Verification Page to Infect Mexican Bank Customers

A fake Google verification page is being used to infect customers of Mexican banks with a malware toolkit built for fraud, not just espionage. The campaign relies on a familiar ClickFix trick, where a

CyberShield TeamRead More
DuckDuckGo Browser Blocks YouTube Ads by Default Using Community Filter Lists
Cybersecurity
3 min read

DuckDuckGo Browser Blocks YouTube Ads by Default Using Community Filter Lists

DuckDuckGo has rolled out native YouTube ad blocking across its browser applications, automatically stripping pre-roll and mid-roll video ads without requiring users to install third-party extensions.

CyberShield TeamRead More
Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain
Cybersecurity
5 min read

Fake Indian ITR Notice Delivers Dual RAT Malware Through Six-Stage Infection Chain

A new malware campaign is using fake Indian tax notices to trick users into installing not one, but two separate remote access trojans on their computers. The attack disguises itself as an official In

CyberShield TeamRead More
Lurking Lizard Uses Fake 7-Zip Installers to Turn Victim Devices Into Proxy Nodes
Cybersecurity
5 min read

Lurking Lizard Uses Fake 7-Zip Installers to Turn Victim Devices Into Proxy Nodes

A newly uncovered cybercriminal operation has been quietly turning ordinary computers into paid proxy servers for years, hiding behind a fake version of the popular 7-Zip file compression tool. Victim

CyberShield TeamRead More
PromptSpy Android Malware Uses Google Gemini to Adapt During Runtime Execution
Cybersecurity
5 min read

PromptSpy Android Malware Uses Google Gemini to Adapt During Runtime Execution

A newly identified strain of Android spyware called PromptSpy has become the first mobile malware known to call on generative AI while it is actually running on a victim’s device. Rather than re

CyberShield TeamRead More
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
Hacking News
1 min read

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders. The age

CyberShield TeamRead More
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
Hacking News
1 min read

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a s

CyberShield TeamRead More
New Ghost Phishing Wave Is Breaking Traditional Email Security
Hacking News
1 min read

New Ghost Phishing Wave Is Breaking Traditional Email Security

A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypt

CyberShield TeamRead More
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
Hacking News
1 min read

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist. New research, which its

CyberShield TeamRead More
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
Hacking News
1 min read

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. The activity cluster, tracked by Elastic Sec

CyberShield TeamRead More
The Verification Step Is the New ATO Battleground in 2026
Hacking News
1 min read

The Verification Step Is the New ATO Battleground in 2026

For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, s

CyberShield TeamRead More
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Hacking News
1 min read

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and ar

CyberShield TeamRead More
Bad Epoll Zero-Day Linux Kernel Flaw Lets Unprivileged Users Escalate to Root
News
4 min read

Bad Epoll Zero-Day Linux Kernel Flaw Lets Unprivileged Users Escalate to Root

A severe zero-day vulnerability dubbed Bad Epoll has been publicly disclosed in the Linux kernel’s epoll I/O event notification subsystem, allowing any unprivileged local user to escalate privil

CyberShield TeamRead More
Gaslight Malware Abuses Prompt Injection to Trick Automated AI Cybersecurity Agents
News
4 min read

Gaslight Malware Abuses Prompt Injection to Trick Automated AI Cybersecurity Agents

North Korean hackers have launched a sophisticated new macOS malware campaign that targets Mac users, specifically developers and those in the Web3 space. Historically, these threat actors rely on fak

CyberShield TeamRead More
ModSecurity Flaws Let Attackers Bypass WAF Rules and Request-Body Inspection
News
4 min read

ModSecurity Flaws Let Attackers Bypass WAF Rules and Request-Body Inspection

Two newly disclosed vulnerabilities in ModSecurity, the widely deployed open-source Web Application Firewall (WAF) engine, could allow attackers to bypass detection rules entirely. Both flaws affect M

CyberShield TeamRead More
Ousaban Banking Trojan Uses Daily-Changing DDNS Domains to Hide C2 Infrastructure
News
3 min read

Ousaban Banking Trojan Uses Daily-Changing DDNS Domains to Hide C2 Infrastructure

In May 2026, researchers at FortiGuard Labs uncovered a sophisticated new campaign delivering the Ousaban banking Trojan to users in Spain and Portugal. Originally known for targeting Brazil, this lat

CyberShield TeamRead More
Seven FatFs Vulnerabilities Exposing Embedded Devices to Code Execution
News
3 min read

Seven FatFs Vulnerabilities Exposing Embedded Devices to Code Execution

Seven newly disclosed vulnerabilities in FatFs, the ubiquitous FAT/exFAT filesystem library, could let a malicious USB drive, SD card, or firmware update trigger memory corruption and code execution o

CyberShield TeamRead More
Parrot 7.3 Released With Optimized Packages and Updated Tools
Cybersecurity
3 min read

Parrot 7.3 Released With Optimized Packages and Updated Tools

Parrot Security has released Parrot OS 7.3, introducing significant system-level optimizations, updated security tools, and a redesigned application management experience to improve performance and us

CyberShield TeamRead More
Cyber Security News Bulletin Weekly – Mythos is Back, WhatsApp Username, Kali Linux 2026.2, +20 Stories
Cybersecurity
8 min read

Cyber Security News Bulletin Weekly – Mythos is Back, WhatsApp Username, Kali Linux 2026.2, +20 Stories

This week’s roundup covers a major AI security model redeployment, several critical RCE vulnerabilities across popular tools, a landmark WhatsApp privacy update, and the latest Kali Linux releas

CyberShield TeamRead More
Flipper Zero Firmware Development Continues With New Community Contribution Rules
Cybersecurity
3 min read

Flipper Zero Firmware Development Continues With New Community Contribution Rules

Flipper Devices has responded to intense community backlash over perceptions that it had abandoned active development of the Flipper Zero firmware. In a statement addressing the controversy, the compa

CyberShield TeamRead More
Microsoft Releases OOBE Cumulative Update for Windows 11, Versions 24H2 and 25H2
Cybersecurity
3 min read

Microsoft Releases OOBE Cumulative Update for Windows 11, Versions 24H2 and 25H2

Microsoft has rolled out KB5095189, a new cumulative update targeting the Out-of-Box Experience (OOBE) for Windows 11, versions 24H2 and 25H2. Released on June 23, 2026, this update refines the initia

CyberShield TeamRead More
T3MP3ST Security Framework With 35 Tools, Turns AI Coding Agents Into 0-Day Bug Hunters
Cybersecurity
3 min read

T3MP3ST Security Framework With 35 Tools, Turns AI Coding Agents Into 0-Day Bug Hunters

A newly released open-source security framework called T3MP3ST is turning general-purpose AI coding agents like Claude Code, OpenAI’s Codex, and Hermes into autonomous red-teaming operators with

CyberShield TeamRead More