Bridewell’s BCON Collective has uncovered an active phishing infrastructure spanning more than 100 malicious domains after investigating what initially…
Europol and Frontex strengthen cooperation with new Working Arrangement
The new arrangement replaces the agreement signed in 2015 and reflects the significantly expanded mandates that both agencies have received in recent…
Threats Making WAVs – Incident Response to a Cryptomining Attack
Guardicore security researchers describe and uncover a full analysis of a cryptomining attack, which hid a cryptominer inside WAV files. The report…
Europol-led action against nihilistic violent extremist network “The Com”
An estimated 4 340 URLs related to nihilistic violent extremism were referred during the initiative organised by Europol’s EU Internet Referral Unit – EU…
BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations
BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion…
Five arrests for smuggling migrants across the Bulgarian-Serbian green border
The action day led to:5 arrests (1 High Value Target, 2 police officers and 2 associates)5 locations searched;Seizures include: 3 vehicles used for…
The Nansh0u Campaign – Hackers Arsenal Grows Stronger
In the beginning of April, three attacks detected in the Guardicore Global Sensor Network (GGSN) caught our attention. All three had source IP addresses…
Critical SolarWinds Web Help Desk Flaw Lets Attackers Bypass SAML Authentication
SolarWinds has released Web Help Desk (WHD) version 2026.2.1 to address a critical authentication bypass vulnerability. This flaw could allow attackers to…
Traefik Labs introduces Distro Zero secure runtime for API and AI gateways
Traefik Labs has introduced the Distro Zero image, a hardened, vendor-supported secure runtime delivered as Traefik Hub in proxy mode. It gives platform…
ICE’s New Detention Center Contracts Declare State Laws ‘Shall Not Apply’
One day after a federal judge ordered an ICE detention center opened to state health inspectors, the agency posted new contract terms that would void…
Horizon3.ai expands NodeZero with automated web application attack path testing
Horizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting. The platform can now autonomously test web applications and…
Europol supports operation against amphetamine producers
As part of an extensive investigation led by the German Krefeld Public Prosecutor’s Office and Mönchengladbach Police, officers from the North…
AttackIQ targets CTEM execution with AVA Agentic OS
AttackIQ has announced AVA Agentic OS, an agentic operating system designed to operationalize Continuous Threat Exposure Management. CTEM has emerged as…
Recon-Only SSH Attack Leaves No Malware but Signals a Second-Stage Intrusion
Recon-only activity on SSH is not harmless background noise. A recent honeypot session shows an automated Go-based bot logging in as root, exhaustively…
Researchers Warn of AI-Enhanced Phone Fraud Ecosystem
AI is dramatically reducing the barriers to entry for scam phone farm operators, Human Security warns
SilverFox Targets Japanese Manufacturer With Advanced ValleyRAT Campaign
SilverFox targeted a Japanese manufacturer with new DLL sideloading techniques, kernel drivers, and resilient ValleyRAT persistence mechanisms. Cato CTRL…
CareCloud Data Breach Impacts Over 350,000
In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment.
Resecurity expands threat intelligence integration ecosystem with IBM QRadar
Resecurity has announced the availability of native integration with IBM QRadar SIEM, a widely used Security Information and Event Management (SIEM)…
New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn…
22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking
Researchers found 24,650 public BMC interfaces leaking IPMI password hashes, exposing servers to offline password cracking through a decades-old protocol…
Analog Devices breach, Copilot AI worm, Teams ransomware vishing
Semiconductor firm Analog Devices discloses data breach Copilot for Word POC copies hidden prompts into new documents Microsoft Teams vishing attacks lead…
IT Security News Hourly Summary 2026-07-31 09h : 7 posts
7 posts were published in the last hour 7:2 : Critical Code Execution Vulnerability Patched in TeamCity 7:2 : PHP Patches 3 Security Flaws Enabling SQL Injection, Memory Corruption and DoS Attacks 7:2 : Public PoC Released for Exploited Check…
Critical Code Execution Vulnerability Patched in TeamCity
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.
PHP Patches 3 Security Flaws Enabling SQL Injection, Memory Corruption and DoS Attacks
PHP maintainers have released security updates to address three vulnerabilities affecting the PostgreSQL, BCMath, and Phar extensions. These…