Researchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution exploit for GitLab on July 24, chaining two memory corruption bugs in…
Beelzebub Raises $3.4 Million for Hacker-Trapping Platform
The company plans to expand its research team, open new offices in Rome and San Francisco, and acquire new clients. This article has been indexed from SecurityWeek Read the original article: Beelzebub Raises $3.4 Million for Hacker-Trapping Platform
Cognyte Sells a Mobile Cell Surveillance Van
Yet another Israeli mass surveillance company: Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity …
ChatGPT joins the most impersonated brands in phishing attacks
Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts…
Claude Code Symlink Import Lets Malicious Repositories Silently Exfiltrate Local Files
Claude Code can load files from outside a repository through a symlinked memory import, which may allow local data to be included in the model’s first outbound request before the model performs any actions. A recently reported Claude Code issue…
Over 70 Fake Windows App Sites Could Turn Trusted Downloads Into Malware
A newly uncovered cluster of more than 70 impersonation domains targeting popular Windows applications is raising fresh concerns about a scalable malware distribution campaign that leverages trust in legitimate software ecosystems. The discovery, triggered by a developer investigating unusual search…
EFF: Most Smart Wearables Still Fall Short on Privacy and Transparency
EFF says most smart wearables lack basic privacy protections, with Apple standing out for end-to-end encryption and transparency. Most smart wearables still treat privacy like an optional extra, and that’s a problem. The Electronic Frontier Foundation (EFF)’s review of major…
Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
The Anubis cybercrime group has taken credit for the attack and is threatening to leak data. This article has been indexed from SecurityWeek Read the original article: Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
Anthropic’s Claude Opus 5 Arrives on AWS With Improved Cybersecurity Capabilities
AWS has introduced Anthropic’s Claude Opus 5 on Amazon Bedrock and the Claude Platform on AWS, bringing a new high-capability AI model to enterprise cloud environments. Anthropic claims that Claude Opus 5 enhances capabilities in coding, document analysis, visual understanding,…
What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out
The new Mobile Security Exposure Center creates SBOMs for enterprise mobile apps to uncover vulnerable components, dependencies and hidden risks. This article has been indexed from SecurityWeek Read the original article: What’s Hiding in Your Mobile Apps? Lookout MSEC Aims…
Hackers are Setting Up Websites Impersonating Popular Windows Apps to Deliver Malware
Hackers are quietly building lookalike websites that pretend to be popular Windows apps, then use those pages to push malware onto unsuspecting users. The scheme already covers more than 70 well known utilities that people trust and download every day.…
Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees. This article has been indexed from SecurityWeek Read the original article: Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies as soon as they are released. This change comes in response to a rise in supply…
Google Indexed Claude AI Shared Chats Before Results Were Removed
Google Search indexed public Claude AI chat links, letting people find shared conversations through the site query before those listings disappeared soon after. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the…
Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits
Binary-based vulnerability scanning, penetration testing, and exploit generation are blocked in Opus 5. The post Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits appeared first on SecurityWeek. This article has been indexed from SecurityWeek…
Java Spring Boot “heapdump” scans, (Mon, Jul 27th)
Spring Boot exposes the endpoint "/actuator/heapdump" to collect debug information. By default, the endpoint will return a file heapdump.hprof, which includes a binary heapdump that can be used to analyze the current state of the application. Non-Java readers may be…
Crypto Criminals Use Social Media Profiling to Select Victims for Violent Wrench Attacks
Crypto criminals are increasingly weaponizing social media intelligence to identify and target high-value individuals in a surge of violent “wrench attacks,” marking a shift from purely digital exploitation to coordinated physical coercion campaigns. Recent threat intelligence indicates that attackers are…
Ransomware Groups Increasingly Deploy EDR Kill Techniques
Halcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight against This article has been indexed from www.infosecurity-magazine.com Read the original article: Ransomware Groups Increasingly Deploy EDR Kill Techniques
IT Security News Hourly Summary 2026-07-27 12h : 12 posts
12 posts were published in the last hour 10:2 : Windows 11’s File Explorer Is Now Faster at Deleting Large Files 10:2 : Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks 10:2 :…
Windows 11’s File Explorer Is Now Faster at Deleting Large Files
Microsoft is rolling out a targeted performance update for Windows 11 designed to resolve one of the platform’s most persistent storage annoyances: sluggish deletion of large, highly fragmented files. The improvement is part of a broader set of File Explorer…
Ransomware Gangs Attack Palo Alto, Fortinet, Citrix, and Check Point VPNs to Target Corporate Networks
A coordinated wave of exploitation targeting edge VPN and firewall appliances from four major vendors Palo Alto Networks, Fortinet, Citrix, and Check Point has emerged as the dominant initial-access vector for ransomware operators in mid-2026. Threat actors, including affiliates of…
BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware Through Fake Zoom Calls
A North Korean hacking unit has refined a scheme that turns everyday chats into malware traps. The BlueNoroff group, linked to the wider Lazarus ecosystem, is taking over real Telegram accounts that belong to trusted industry contacts. Those stolen identities…
DentaQuest Data Breach Potentially Impacts Over 23 Million People
In May 2026, hackers stole personal and dental health information from DentaQuest’s computer network. The post DentaQuest Data Breach Potentially Impacts Over 23 Million People appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article:…
SparkKitty Malware Steals Crypto Wallet Seed Phrases From iOS and Android Photos
A new mobile threat is quietly targeting cryptocurrency users by reading the photos stored on their phones. Known as SparkKitty, this malware works on both iOS and Android devices and focuses on stealing wallet seed phrases hidden inside screenshots and…