Malware hides commands in appointments set for 2050 and uses Redmond’s own cloud to phone home This article has been indexed from www.theregister.com – Articles Read the original article: Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software
Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others. The post Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software appeared first on SecurityWeek. This article has…
ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code…
Paidwork breach exposes sensitive data of 23 million user
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets itself as a way to earn money through simple tasks like watching ads,…
Cruciferra Crypter Uses Process Ghosting to Evade Detection
Cruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors This article has been indexed from www.infosecurity-magazine.com Read the original article: Cruciferra Crypter Uses Process Ghosting to Evade Detection
Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage
Dutch intelligence says Russia hacks IP cameras to monitor NATO military logistics and weapons shipments to Ukraine. The Netherlands’ AIVD and MIVD, the civilian and military intelligence services, published a joint advisory on July 10 confirming that at least one…
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek. This article has been indexed from SecurityWeek…
JadePuffer Returns With Ransomware Designed to Wipe AI Models
JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts This article has been indexed from www.infosecurity-magazine.com Read the original article: JadePuffer Returns With Ransomware Designed to Wipe AI Models
Cyber Briefing: 2026.07.20
Over 2,000 hospitals hit in a major billing software breach, while a sophisticated new malware strain evades EDR tools by routing stolen corporate data through Microsoft 365 calendars. This article has been indexed from CyberMaterial Read the original article: Cyber…
What Does the Cyber Industry Want to See From the New UK Government?
Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed ‘Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including…
An ordinary laptop solved a problem thought to require a quantum computer
A quantum problem once described as impossible for classical computers has now been solved using relatively modest hardware. Researchers used tensor networks to compress the overwhelming wave function created by hundreds of entangled qubits, allowing some calculations to run on…
Ransomware in the Dairy Aisle: A Look at Fairlife’s Cyberattack
Operational Impact and Response The Coca-Cola Company revealed a cyber incident impacting its Fairlife dairy business on July 16, 2026. The disruption forced an immediate nationwide pause on U.S. processing… The post Ransomware in the Dairy Aisle: A Look at…
Sri Lanka Treasury’s USD 2.5 Million Loss Ruled Cybercrime Fraud
Sri Lanka’s recent finding that a USD 2.5 million Treasury loss was the result of cybercrime highlights how vulnerable government financial systems have become in the age of digital debt repayments. The case underlines that cybersecurity failures are no…
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake…
Researchers Build WordPress Exploit Using OpenAI’s GPT
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain This article has been indexed from www.infosecurity-magazine.com Read the original article: Researchers Build WordPress Exploit Using OpenAI’s GPT
GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE
A critical vulnerability chain in WordPress, called wp2shell, that allegedly allows unauthenticated attackers to exploit a pre-authentication SQL injection flaw to achieve remote code execution (RCE) on typical WordPress installations running MySQL. Security researcher Adam Kues discovered this vulnerability chain…
TELEPUZ Web Injector Can Steal Cookies, Execute JavaScript, and Replace IBAN Details
A rapidly evolving malware family dubbed TELEPUZ, a modular and lightweight threat that is gaining traction through a ClickFix–VIDAR infection chain. Despite a relatively small command-and-control (C2) footprint, the pace of development and distribution suggests an emerging large-scale operation. The…
Salt Security tackles AI governance challenge with 100 pre-built agentic security policies
Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments. The company says the milestone creates one of the industry’s largest libraries of governance…
Italy fines WINDTRE €1.7 million over security flaws behind two data breaches
Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging to more than 365,000 customers. The regulator…
HOLLOWGRAPH malware hides in M365 calendar invites
A previously unknown Windows malware strain is exploiting Microsoft 365 calendar functionality to conduct covert espionage operations, according to research published by Group-IB. This article has been indexed from CyberMaterial Read the original article: HOLLOWGRAPH malware hides in M365 calendar…
Craneware data breach affects 2,000+ US hospitals
Craneware, a healthcare technology company headquartered in Edinburgh and listed on London’s AIM market, has disclosed a data breach affecting more than 2,000 hospitals across the United States. This article has been indexed from CyberMaterial Read the original article: Craneware…
Microsoft releases Dusseldorf OAST platform
Microsoft has released Dusseldorf, an open-source platform for out-of-band application security testing (OAST) that provides researchers with ready-made infrastructure for detecting a class of vulnerabilities that often go unnoticed. This article has been indexed from CyberMaterial Read the original article:…
Federal employees can download TikTok on work phones
Federal employees can now download TikTok on government devices following a Department of Justice memo that lifts restrictions imposed by a 2022 law. This article has been indexed from CyberMaterial Read the original article: Federal employees can download TikTok on…
Capital One Open Sources AI VulnHunter Tool
Capital One has released VulnHunter as an open-source project, making its AI-powered vulnerability analysis tool available to the broader security community. This article has been indexed from CyberMaterial Read the original article: Capital One Open Sources AI VulnHunter Tool