Datacenters tax utilities normally, so just imagine what they could do if workloads were designed to destroy This article has been indexed from www.theregister.com – Articles Read the original article: Malicious cloud customers can bring down the power grid
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
Last week, Searchlight Cyber released details about a vulnerability they are calling “wp2shell”. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is…
IT Security News Hourly Summary 2026-07-20 21h : 5 posts
5 posts were published in the last hour 19:4 : Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels 19:4 : Frontier LLMs couldn’t help Hugging Face fight off evil agents 19:4 : The Odyssey piracy scams…
Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels
A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. HOLLOWGRAPH is a .NET-compiled malware component that abuses the Microsoft Graph API through a compromised Microsoft…
Frontier LLMs couldn’t help Hugging Face fight off evil agents
Chinese open-weight model GLM 5.2 happily obliged This article has been indexed from www.theregister.com – Articles Read the original article: Frontier LLMs couldn’t help Hugging Face fight off evil agents
The Odyssey piracy scams surface hours after its theatrical debut
Christopher Nolan’s The Odyssey had barely reached theaters before scammers began targeting people searching for pirated copies, according to Malwarebytes. Within hours of the film’s release, researchers found two separate scams running on cloned piracy sites: fake browser warnings and…
The 12 Best Identity Threat Detection & Response (ITDR) Solutions, Compared and Priced (2026)
Identity is where breaches start, and ITDR pricing is where budgets get confused platform modules, IdP SKUs, E5 bundles, and managed services all claim the same acronym. The value verdict up front: Huntress is the best published-price ITDR for SMBs…
Hugging Face Stops AI-Driven Cyberattack
The long-forecasted era of the autonomous ai-driven “agentic hacker” has officially shifted from theory to reality. In a… The post Hugging Face Stops AI-Driven Cyberattack appeared first on Hackers Online Club. This article has been indexed from Hackers Online Club…
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in…
Hugging Face Discloses Autonomous AI Agent Attack
Hugging Face disclosed an autonomous AI agent attack that breached its production infrastructure. The post Hugging Face Discloses Autonomous AI Agent Attack appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original article: Hugging…
EU Mandates Driver Distraction Warning Systems in All New Vehicles Amid Privacy and Safety Debate
The European Union has introduced stricter vehicle safety regulations, making Advanced Driver Distraction Warning (ADDW) systems mandatory in all newly registered vehicles across member states from this week. The move is part of the European Commission’s expanded General…
Splunk Report Finds One in Five CISOs Pressured to Hide Cybersecurity Incidents
The Splunk 2026 CISO report makes public the challenges that CISOs face when trying to meet the rising demand to mask security incidents while also complying with tightening disclosure laws. According to the report, which draws its conclusions from…
Ransomware activity climbs in Q2 2026 as leading gangs consolidate attacks and AI streamlines extortion efforts
Ransomware groups claimed responsibility for 2,279 attacks worldwide during the second quarter of 2026, marking a 7% increase from the previous quarter and a 43% jump compared with the same period last year, according to GuidePoint Security’s latest quarterly…
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The malware, which Group-IB calls…
Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data
A massive data breach has hit Paidwork, a popular gig economy platform, exposing sensitive banking and personal information belonging to more than 23 million users worldwide. The incident, first surfacing in March 2026 when hackers listed the stolen data for…
Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details
A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers. The chain combines two separately tracked flaws CVE-2026-63030,…
Windows Bind Link Abuse Lets Attackers Blind EDR and Bypass AMSI, AppLocker, and Sysmon
Windows defenders are facing a new way for attackers to hide activity after gaining administrator access. The technique abuses Windows bind links, a legitimate feature that redirects one file path to another without changing the original file on disk. Rather…
The Odyssey piracy scams appear within hours of the movie’s release
The release of The Odyssey has already sparked a wave of piracy scams, from fake browser errors to malware masquerading as movie files. This article has been indexed from Malwarebytes Read the original article: The Odyssey piracy scams appear within…
2026 ISO and CSA STAR certificates are now available with two additional services
Amazon Web Services (AWS) successfully completed an onboarding audit with no findings for ISO 9001:2015, 27001:2022, 27017:2015, 27018:2019, 27701:2019, 20000-1:2018, and 22301:2019, and Cloud Security Alliance (CSA) STAR Cloud Controls Matrix (CCM) v4.0. EY Certify Point auditors conducted the audit…
Security Is a Platform Property, Not a Pipeline Step
A few weeks ago, I disabled key authentication on an Azure storage account we used for Terraform state management. It was one of the key security recommendations in Microsoft Defender for Cloud. It made sense to use RBAC-only permissions, enforce…
Fix Circular Dependencies in PostgreSQL Row-Level Security With SECURITY DEFINER Functions
Row-level security in PostgreSQL is one of the more useful features for multi-tenant applications. The idea is straightforward: define a policy on a table that tells PostgreSQL which rows a given user is allowed to see or modify, and the…
Researchers trace SonicWall SMA1000 exploitation to late June
Multiple threat actors, including INC ransomware, have targeted vulnerable firewall systems. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: Researchers trace SonicWall SMA1000 exploitation to late June
IT Security News Hourly Summary 2026-07-20 18h : 17 posts
17 posts were published in the last hour 16:5 : Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk 16:4 : Odyssey piracy scams appear within hours of the movie’s release 15:34 : WordPress Remote Code…
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher. This article has been indexed from Security News | TechCrunch Read…