Microsoft has introduced a new capability in Defender for Office 365 to protect against prompt injection attacks, which target AI-powered email workflows, such as Microsoft 365 Copilot. This update reflects the evolving threat landscape, where attackers increasingly attempt to manipulate…
Ubuntu snap-confine Race Condition Enables Local Privilege Escalation to Root
Ubuntu systems are at risk from a new local privilege escalation vulnerability in snap-confine, which could enable any local user to gain full root access on certain desktop installations. Qualys researchers discovered a race condition in snap-confine, the helper program…
Google Launches CodeMender AI Agent to Find, Validate, and Patch Vulnerabilities
Google has introduced CodeMender, a new AI-powered code security agent designed to find, validate automatically, and patch vulnerabilities at machine speed, as organizations face a surge in AI-driven cyber threats targeting software supply chains. The launch marks a shift from…
New Dolphin X Malware Steals Credentials From 300+ Apps and Profiles Victims With AI
A newly identified Windows malware called Dolphin X is raising concerns because it can steal far more than browser passwords. The tool is marketed to criminals as both an information stealer and a remote access trojan, giving operators a broad…
IT Security News Hourly Summary 2026-07-23 15h : 10 posts
10 posts were published in the last hour 13:4 : Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models 13:4 : Cobalt adds Autonomous Pentest to scale application security testing 12:34 : Google Released Gemini 3.5 Flash Cyber AI, a…
Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models
SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek. This article has been indexed…
Cobalt adds Autonomous Pentest to scale application security testing
Cobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization’s application portfolio by delivering actionable penetration testing results in as little as 24 hours. AI-assisted development enables organizations to ship software faster than…
Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting
Google DeepMind unveiled Gemini 3.5 Flash Cyber, an AI model for vulnerability discovery and patching, available only to governments and trusted partners. Google DeepMind announced Gemini 3.5 Flash Cyber on Tuesday, a security-focused AI model built on top of the…
If you get knocked on the head and get all your devices stolen and have amnesia, Google will let you back in with a selfie
You’ll need to be able to move your head side to side to make sure you’re not a deepfake This article has been indexed from www.theregister.com – Articles Read the original article: If you get knocked on the head and…
Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log…
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions spanning 10 packages associated with…
How Synthetic Identity Fraud is Coming for Machine Identities
Most people understand identity theft as an attacker stealing a real person’s sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several…
WhatsApp Web chats exposed by Adobe’s Acrobat extension flaw
HermeticReader is a now-patched vulnerability in Adobe’s popular Acrobat Chrome extension that could have been used to spy on WhatsApp Web users. This article has been indexed from Malwarebytes Read the original article: WhatsApp Web chats exposed by Adobe’s Acrobat…
Millions of cars could be tracked and unlocked by a hidden security flaw
A hidden flaw in a dealer-installed car alarm could let attackers unlock vehicles and track their locations. Many owners don’t know they have one. This article has been indexed from Malwarebytes Read the original article: Millions of cars could be…
Swiss train maker tells ransomware crooks to get off at the next stop
Stadler refuses $12.3 demand after thieves swipe technical data through supplier platform This article has been indexed from www.theregister.com – Articles Read the original article: Swiss train maker tells ransomware crooks to get off at the next stop
OpenAI behind Hugging Face hack, TrickBot tunnels through DNS, Acrobat extension opens WhatsApp
OpenAI behind Hugging Face hack TrickBot tunnels through DNS Acrobat extension opens WhatsApp Get the show notes here: Huge thanks to our sponsor, QuilrAI AI agents don’t ask permission. They act — moving data, triggering workflows, changing systems. QuilrAI is…
Exim Vulnerability Lets Attackers Access Files Outside the Mail Spool
A high-severity directory traversal vulnerability has been discovered in the Exim mail transfer agent. This flaw allows local attackers to access files outside the intended mail spool directory and potentially escalate their privileges. It is tracked as EXIM-Security-2026-06-22.1 and assigned…
Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers
Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicious development…
Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code
A critical heap buffer overflow vulnerability in FreeRDP’s Windows client could allow a malicious Remote Desktop Protocol (RDP) server to corrupt memory and potentially execute arbitrary code on a connecting client. This flaw specifically affects the Clipboard Redirection (CLIPRDR) virtual…
Critical FreePBX Flaws Let Unauthenticated Attackers Execute Code and Take Over Administrator Accounts
Critical security vulnerabilities in FreePBX have been disclosed, exposing organizations to risks of unauthenticated remote code execution and the takeover of administrator accounts. These flaws, tracked under GitHub advisories GHSA-37j8-fhxx-9vhp and GHSA-g27h-xf3q-h3rm, affect FreePBX versions 16 and 17, carrying a…
End-to-End Encryption and “Going Dark”
New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“: Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of…
The EU AI Act Deadline Is Approaching. Is Your Workforce Ready?
The EU AI Act deadline is approaching but the attack surface is already here. Is your workforce ready to secure it? The post The EU AI Act Deadline Is Approaching. Is Your Workforce Ready? appeared first on OffSec. This article…
Months-long breach exposes South Korean diplomats’ personal data
South Korea’s Foreign Ministry has disclosed that attackers breached the Korea National Diplomatic Academy’s online education system, compromising personal data belonging to current and former ministry staff and diplomats stationed abroad. The Korea National Diplomatic Academy launched the online training…
AI Agents Now the Enterprises Fastest Growing Exposed Attack Surface
Sophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threats This article has been indexed from www.infosecurity-magazine.com Read the original article: AI Agents Now the Enterprises Fastest Growing…