Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer. The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek. This article has…
Shufti simplifies cross-border compliance with the Glocal Platform
Shufti has launched the Shufti Glocal Platform, a compliance lifecycle management solution designed to help organizations manage identity verification, fraud prevention, risk assessment, and regulatory compliance through a single platform across every industry, every region, and every use case. For…
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high‑value AI and ML artifacts across an entire stack. A missing‑authentication bug in the /api/v1/validate/code endpoint…
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
Threat actors are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform. This vulnerability allows attackers to escape a restricted server-side script sandbox and execute code without valid credentials. Reports from Defused indicate observed…
Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers
Gitea users are urged to update immediately after a critical vulnerability was disclosed that allows public-only repository access tokens to indirectly write to private pull request branches and trigger private Actions workflows. Tracked as CVE-2026-58443, the vulnerability affects Gitea versions…
Linux Patches 400+ Kernel Vulnerabilities in 24 Hours With AI-Powered Detection
The Linux kernel project has released fixes for over 400 vulnerabilities within approximately 24 hours. These vulnerabilities span various areas, including networking, filesystems, memory management, Bluetooth, virtualization, drivers, and security components. This rapid wave of Common Vulnerabilities and Exposures (CVE)…
One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files
A single security alert has exposed an unusually detailed view of how a threat actor builds, tests, and delivers malware. The exposed WebDAV server held more than 1,000 files, including phishing lures, shortcut files, droppers, testing notes, and tools used…
Microsoft Defender XDR Blind Spot Can Hide Public Connections Behind FourToSixMapping
Security teams relying on Microsoft Defender XDR’s DeviceNetworkEvents table for hunting and detection may be missing critical external network connections due to a lesser-known IP address classification quirk. The issue centers on FourToSixMapping, a RemoteIPType value that can cause public…
SonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware
Attackers actively exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) VPN appliances to gain root access and deploy custom malware. In early July 2026, the cybersecurity firm Volexity was involved in investigating an intrusion related to the SonicWall…
SonicWall SMA zero-days were exploited weeks before disclosure
Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June…
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars. This article has been indexed from Security Latest Read the…
95% of Security Teams Blindsided by Vulnerabilities Between Tests
The vast majority of enterprise security teams are being blindsided by vulnerabilities that scheduled testing never catches, according to new research from Synack, which describes itself as the provider of the first AI-powered continuous pentest for enterprises. The company’s new…
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article:…
Fake FBI agents target people who already got scammed
Scammers are impersonating FBI personnel who supposedly handle Internet Crime Complaint Center (IC3) complaints, using that disguise to deceive and revictimize people who already lost money once. The IC3 published the update on July 20, 2026, building on an earlier…
IT Security News Hourly Summary 2026-07-21 12h : 8 posts
8 posts were published in the last hour 10:3 : AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows 10:3 : AI nudify apps spark legal scrutiny of Apple and Google’s profits 10:2 : Clover Health Investments Discloses…
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma‑associated Node.js backdoor through trusted GitHub Actions–driven release workflows and exposing high‑value developer and CI/CD environments to remote access, credential theft, and further lateral movement.…
AI nudify apps spark legal scrutiny of Apple and Google’s profits
Instead of fighting over what app stores host, the San Francisco City Attorney is targeting how they make money from AI nudify apps. This article has been indexed from Malwarebytes Read the original article: AI nudify apps spark legal scrutiny…
Clover Health Investments Discloses Data Breach
Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: Clover Health Investments…
US Hospital Finance Software Provider Craneware Reports Data Theft
Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theft This article has been indexed from www.infosecurity-magazine.com Read the original article: US Hospital Finance Software Provider Craneware Reports Data…
Estée Lauder discloses data breach tied to Oracle EBS vulnerability
Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée Lauder is one of the largest beauty companies in the world, known for its prestige…
AWS wants GuardDuty to automate the first steps of threat investigations
Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is available at no additional…
Researchers Uncover North Korean ‘ClickFake’ Campaign Targeting Web3 Pros
In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans This article has been indexed from www.infosecurity-magazine.com Read the original article: Researchers Uncover North Korean ‘ClickFake’ Campaign Targeting…
Meta Addictiveness Trial Begins In Tennessee
In latest case, state of Tennessee accuses Meta of knowingly offering harmful product to youths, lying about safety This article has been indexed from Silicon UK Read the original article: Meta Addictiveness Trial Begins In Tennessee
Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials
Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather than just endpoints. Recent activity shows tightly integrated social engineering, cloud abuse, and fileless PowerShell tradecraft…