n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another bypass. The…
OpenAI Model Escapes Containment, Hacks Hugging Face
OpenAI has disclosed a security incident in which one of its AI models went rogue during testing and successfully compromised systems at Hugging Face, an AI infrastructure company. This article has been indexed from CyberMaterial Read the original article: OpenAI…
IT Security News Hourly Summary 2026-07-27 15h : 11 posts
11 posts were published in the last hour 13:2 : Iranian Hackers Are Disabling Industrial Safety Alarms and Hiding It From Operators 13:2 : Wrench Attacks Bypass Encryption by Forcing Victims to Unlock Crypto Wallets 13:2 : Anyone With a…
Iranian Hackers Are Disabling Industrial Safety Alarms and Hiding It From Operators
Iranian-affiliated hackers are targeting internet-connected industrial controllers used across critical infrastructure in the United States. Their activity can disrupt essential processes in water, energy, and government environments, where even a small change to control logic can create serious real-world consequences.…
Wrench Attacks Bypass Encryption by Forcing Victims to Unlock Crypto Wallets
Cryptocurrency theft is increasingly moving beyond the screen. Criminals are using violence, threats, home invasions, and kidnapping attempts to force victims to unlock wallets or approve transfers while under pressure. These incidents are known as wrench attacks, a term that…
Anyone With a Browser Could Access 700,000 Vatican Prayer App Accounts
A critical access control vulnerability in the Vatican’s official “Click to Pray” platform has exposed the personal data of more than 700,000 users, highlighting once again how basic web security misconfigurations continue to put large-scale user bases at risk. The…
Claude Opus 5 Finds Vulnerabilities but Remains Restricted in Generating Exploits
Anthropic has officially released Claude Opus 5, a next-generation large language model (LLM) designed to boost software engineering and complex knowledge-work performance while keeping tight reins on offensive cybersecurity capabilities. Positioned as the default model on Claude Max and the…
Hacked Wi-Fi Gateways Target Corporate Credentials
OCybercriminals have been exploiting compromised public Wi-Fi gateway appliances to harvest Microsoft 365 credentials from corporate employees while traveling. This article has been indexed from CyberMaterial Read the original article: Hacked Wi-Fi Gateways Target Corporate Credentials
Researchers Find 84 Hidden iOS Data Streams Tracking Apps, Locations and Messages
Apple’s Biome framework is drawing fresh attention after researchers identified 84 data streams that can preserve detailed records of how an iPhone is used. The findings do not describe malware or an active intrusion. Instead, they show how built-in iOS…
Booz Allen expands Vellox Suite with AI-driven threat detection platform
Booz Allen Hamilton has announced an expansion of its powerful suite of AI-powered cyber defense products. Now generally available, Vellox Ranger provides automated, environment-specific threat detections, developed on Booz Allen’s proprietary agentic AI framework, that identify exploitable paths and vulnerabilities…
Microsoft Moves Enterprise Windows Activation From Software to Hardware Verification
Microsoft is preparing to transition its enterprise Windows activation from a software-trust model to one based on verified hardware. The company announced KMS Hardware-Secured. A new Key Management Service capability that uses Trusted Platform Module (TPM) attestation to validate KMS…
PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)
Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS is…
Claude Opus 5 Finds Software Vulnerabilities While Blocking Exploit Generation
Claude Opus 5, the latest flagship AI model from Anthropic, represents a significant shift in how advanced systems can be safely utilized in cybersecurity. This model can proactively identify software vulnerabilities while specifically preventing the generation of exploits and offensive…
Nvidia and Tech Giants Launch AI Security Alliance
The Nvidia-led coalition aims to give defenders more open tools for testing, auditing and protecting AI models and agents. This article has been indexed from SecurityWeek Read the original article: Nvidia and Tech Giants Launch AI Security Alliance
Europol Launches Project COMPASS to Disrupt ‘The Com’ Cybercrime Network Targeting Minors
Europol has launched Project COMPASS, a coordinated transnational initiative aimed at disrupting “The Com,” a highly dangerous cybercrime and nihilistic extremist network that systematically targets minors and vulnerable young people across digital platforms. The Com operates as a sprawling transnational…
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra. According to a new analysis by Proofpoint, Cruciferra has…
Ostium Confirms $23.75 Million Vault Exploit After Off-Chain Price Feed Compromise
Ostium, a decentralized trading platform built on the Arbitrum blockchain, has confirmed that hackers stole $23.75 million from its liquidity provider vault after compromising the platform’s off-chain price feed infrastructure.In an update shared by the company, Ostium explained that…
SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims This article has been indexed from www.infosecurity-magazine.com Read the original article: SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
Top 10 Malware Used by Hackers Between July 20-26, 2026, to Launch Cyberattacks
Weekly threat telemetry from ANY.RUN’s interactive sandbox shows Vidar stealer, AsyncRAT, and XWorm remained the three most-uploaded malware samples analyzed by security teams during the week of July 20-26, 2026, collectively accounting for hundreds of sandbox detonations as defenders raced…
vBulletin Pre-Auth RCE Flaw Allows Remote PHP Code Execution
A critical pre-authentication remote code execution vulnerability in vBulletin, tracked as CVE-2026-61511, could allow unauthenticated attackers to execute arbitrary PHP code on vulnerable forum servers. This issue affects vBulletin versions 6.2.1 and earlier, as well as 6.1.6 and earlier, according…
Insight Partners and Glilot Capital Co-Lead $20M Investment in Way Security
Way Security raises $20M from Insight Partners and Glilot Capital to automate costly IAM operations with AI and help enterprises get more from existing tools. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More…
GitLab Users Urged to Patch After Research Reveals Critical RCE Chain
Researchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution exploit for GitLab on July 24, chaining two memory corruption bugs in…
Beelzebub Raises $3.4 Million for Hacker-Trapping Platform
The company plans to expand its research team, open new offices in Rome and San Francisco, and acquire new clients. This article has been indexed from SecurityWeek Read the original article: Beelzebub Raises $3.4 Million for Hacker-Trapping Platform
Cognyte Sells a Mobile Cell Surveillance Van
Yet another Israeli mass surveillance company: Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity …