A previously unknown Windows malware strain is exploiting Microsoft 365 calendar functionality to conduct covert espionage operations, according to research published by Group-IB. This article has been indexed from CyberMaterial Read the original article: HOLLOWGRAPH malware hides in M365 calendar…
Craneware data breach affects 2,000+ US hospitals
Craneware, a healthcare technology company headquartered in Edinburgh and listed on London’s AIM market, has disclosed a data breach affecting more than 2,000 hospitals across the United States. This article has been indexed from CyberMaterial Read the original article: Craneware…
Microsoft releases Dusseldorf OAST platform
Microsoft has released Dusseldorf, an open-source platform for out-of-band application security testing (OAST) that provides researchers with ready-made infrastructure for detecting a class of vulnerabilities that often go unnoticed. This article has been indexed from CyberMaterial Read the original article:…
Federal employees can download TikTok on work phones
Federal employees can now download TikTok on government devices following a Department of Justice memo that lifts restrictions imposed by a 2022 law. This article has been indexed from CyberMaterial Read the original article: Federal employees can download TikTok on…
Capital One Open Sources AI VulnHunter Tool
Capital One has released VulnHunter as an open-source project, making its AI-powered vulnerability analysis tool available to the broader security community. This article has been indexed from CyberMaterial Read the original article: Capital One Open Sources AI VulnHunter Tool
Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
Hugging Face is urging users to rotate any access tokens stored on the platform and review account activity. This article has been indexed from Security News | TechCrunch Read the original article: Hugging Face confirms breach affected internal datasets and…
New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience
Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously…
Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft
Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution, install persistent web shells, and steal cryptographic keys from exposed systems. The attacks put on-premises SharePoint deployments at risk of data theft, network compromise, ransomware, and prolonged…
Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts
Kimai users utilizing the official Docker image are strongly urged to update their installations following the disclosure of a critical vulnerability that could allow unauthenticated attackers to forge authentication cookies and potentially take over accounts, including super administrator accounts. This…
OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original…
IT Security News Hourly Summary 2026-07-20 15h : 4 posts
4 posts were published in the last hour 13:4 : Mythos Didn’t Break Your Security Program. Your Exposure Window Could. 13:4 : Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine 12:34 : The…
Mythos Didn’t Break Your Security Program. Your Exposure Window Could.
The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long…
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of…
The Hidden Risk in Enterprise AI Agents: Ungoverned Context
Enterprises are handing AI agents real access to customer records, financial systems, internal documents, and the tools that… This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: The Hidden Risk…
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel This article has been indexed from www.infosecurity-magazine.com Read the original article: New HollowGraph Malware…
New Index Tracks Material Breaches — And Refuses to Add Up the Losses
Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek. This article has been indexed…
FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case
FBI agents arrested a Florida man accused of spreading Steam game malware that stole $220,000 in crypto, including $32,000 from a terminally ill cancer patient. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More…
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files. 7-Zip released version 26.02 to address a remote code execution vulnerability in its handling of XZ-compressed data. The flaw, discovered by…
On Flock License Plate Tracking Cameras
A recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral. The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10…
Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust
Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly…
Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding
We look into how attackers are using the legitimate Ren’Py game engine to spread a malware loader that ultimately delivers Amatera Stealer. This article has been indexed from Malwarebytes Read the original article: Fake games spread stealers with RenPy Loader,…
Ernst & Young Data Breach Affects Personal, Financial Information
Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek. This article has been indexed from SecurityWeek…
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor
A newly disclosed cluster of Microsoft SharePoint Server vulnerabilities is actively being exploited in the wild, allowing attackers to convert a single crafted web request into full remote code execution and long-term persistence across enterprise environments. Security updates released in…
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier
Microsoft will stop delivering feature updates, bug fixes, and security patches for the OneDrive sync app on systems running Windows version 21H2 and earlier on August 15, 2026. This change was announced in the Microsoft 365 Message Center notification MC1426708…