The US Cybersecurity and Infrastructure Security Agency (CISA) is warning about yet another Langflow vulnerability (CVE-2026-55255) leveraged by attackers in the wild. The flaw was added to the agency’s Known Exploited Vulnerabilities catalog on Tuesday, July 7, nearly two weeks…
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages…
New Ghost Phishing Wave Is Breaking Traditional Email Security
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. For…
China-Linked APT Expands Proxy Network With New Malware
Cisco Talos said China-linked APT UAT-7810 is growing its proxy relay network with new malware This article has been indexed from www.infosecurity-magazine.com Read the original article: China-Linked APT Expands Proxy Network With New Malware
Cyber Briefing: 2026.07.08
Chinese threat actor UAT-7810 weaponizes edge routers with new “LONGLEASH” malware, healthcare providers are facing a devastating wave of personal data theft This article has been indexed from CyberMaterial Read the original article: Cyber Briefing: 2026.07.08
First fully agentic ransomware attack sparks readiness concerns
<p>The latest cyberattack headlines leave security leaders asking a critical question: Does an AI agent’s successful execution of an end-to-end ransomware attack signal a fundamental shift in threat response strategies, or does it simply underscore the enduring importance of cybersecurity…
China tells devs to ditch Claude Code over ‘backdoor code’ fears
National vulnerability database claims monitoring mechanism can forward Chinese users’ data to remote servers This article has been indexed from www.theregister.com – Articles Read the original article: China tells devs to ditch Claude Code over ‘backdoor code’ fears
Bug in top AI coding agents shows that Unix-era security headaches never really die
‘GhostApproval’ problem highlights human-in-the-loop fails This article has been indexed from www.theregister.com – Articles Read the original article: Bug in top AI coding agents shows that Unix-era security headaches never really die
Blackpoint AI SOC Agent autonomously contains identity-based attacks
Blackpoint Cyber has unveiled the generally available autonomous response capability, Blackpoint AI SOC Agent for identity threat detection and response (ITDR). Using an AI + human hybrid model, the AI SOC Agent acts on high-confidence threats targeting Microsoft 365 and…
Censys Internet Map links real-time DNS data to internet infrastructure
Censys has announced the expansion of the Censys Internet Map to include real-time DNS visibility. Security teams can now seamlessly pivot between domains, names, and the Internet infrastructure behind them on the Censys Platform. With active DNS data now part…
Attackers Can Generate Duplicate Verified GitHub Commits Using Signature Malleability
Attackers can silently clone “Verified” GitHub commits by abusing signature malleability in Git’s commit-signing formats, creating byte‑different commits with identical content, valid signatures, and fresh “Verified” badges under new hashes. This breaks the long‑standing assumption that a verified commit hash…
PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability
Proof-of-concept (PoC) exploit code and deep technical details have now been released for CVE-2025-53770, a critical remote code execution (RCE) vulnerability in on‑premises Microsoft SharePoint Server. This disclosure raises the risk of rapid weaponization and mass exploitation against unpatched SharePoint…
Webinar Today: Why Email Security Keeps Failing
Join the webinar as we break down why email-layer defenses alone can’t keep pace with the modern phishing ecosystem. The post Webinar Today: Why Email Security Keeps Failing appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read…
Business Threat Management: Moving from Isolated to Unified Approach
Shifting away from isolated, technical data, to a continuous risk lifecycle can assist organizations in balancing security controls with actual business impact. A CVSS score of 9.5 may not be significant to a CFO, but when it demonstrates a flaw…
FalconStor Cloud Clean Room enables validated recovery without dedicated infrastructure
FalconStor has announced FalconStor Cloud Clean Room, an on-demand infrastructure platform designed to let organizations perform validated recovery testing in a persistent secure enclave. Each test starts from a known state, reducing the risk of carrying issues over from previous…
First Recon AI Security Runtime helps enterprises govern AI with audit-ready evidence
First Recon AI has announced the public launch and general availability of First Recon’s AI Security Runtime, a security platform that both governs and secures how enterprises use artificial intelligence across an organization. First Recon’s runtime inspects every AI interaction…
OpenMatter Network Joins HOL Initiative to Help Define Standards for Verifiable AI Collaboration and Security
Melbourne, Florida, United States, 8th July 2026, CyberNewswire This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: OpenMatter Network Joins HOL Initiative to Help Define Standards for Verifiable AI Collaboration…
Fancy Bear Uses LSB Steganography and Reflective Loading to Run C# Remote-Control Trojan
A new intrusion campaign attributed to APT‑C‑20 (aka Fancy Bear, APT28) demonstrates the group’s continued refinement of stealthy, fileless techniques: weaponized Office documents that deploy a COM‑hijacking DLL. Extract shellcode hidden via LSB steganography in a PNG, and use reflective…
IonStack Exploit Chain Lets Hackers Root Android 17 Phones With a Single URL Click
Nebula Security has revealed a significant exploit chain known as “IonStack,” demonstrating how attackers could gain full root access on Android 17 devices with just a single click on a malicious URL. This raises serious concerns about browser-to-kernel attack surfaces…
15-Year-Old GhostLock Bug Hits Linux – Grants Root Access
A new report by Nebula Security reveals ‘GhostLock’ (CVE-2026-43499)—one of the most severe local privilege escalation (LPE) flaws… The post 15-Year-Old GhostLock Bug Hits Linux – Grants Root Access appeared first on Hackers Online Club. This article has been indexed…
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying…
Your next car could be watching your face
Driver-monitoring technology is becoming mandatory in new cars, but privacy experts warn it could create new risks alongside the safety benefits. This article has been indexed from Malwarebytes Read the original article: Your next car could be watching your face
DNSFilter makes its DNS threat protection available to OEM partners
DNSFilter has launched an Original Equipment Manufacturing (OEM) program that lets external ISPs, cybersecurity firms, device makers, and other consumer app developers to embed their DNS threat protection, domain analysis, and privacy solutions into their own platforms and solutions. Partners…
IT Security News Hourly Summary 2026-07-08 15h : 14 posts
14 posts were published in the last hour 12:45 : First-Ever 1- Click Android 17 Exploit Allows Attackers to Gain Full Control Over Your Android Phone 12:43 : Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations 12:42 :…