The Chaos ransomware group uses new malware “msaRAT” that hijacks browsers. The malware doesn’t communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker’s IP from victims via WebRTC over TURN. This…
Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root
A recently disclosed vulnerability in Ubuntu’s snap ecosystem, identified as CVE-2026-8933, presents a critical local privilege escalation flaw. This vulnerability allows unprivileged users to execute arbitrary code with root privileges. Qualys discovered the issue in snap-confine, a core component used…
Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication
A critical authentication bypass vulnerability affecting Check Point SmartConsole has been actively exploited in the wild, allowing attackers to gain unauthorized access to security management systems under specific configurations. The flaw, tracked as CVE-2026-16232, carries a CVSS score of 9.3…
IT Security News Hourly Summary 2026-07-23 12h : 15 posts
15 posts were published in the last hour 10:4 : Assaf Keren Appointed New CISO of Meta 10:4 : PyPI hardens package security with new upload restrictions 10:4 : Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL…
Assaf Keren Appointed New CISO of Meta
He replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: Assaf Keren…
PyPI hardens package security with new upload restrictions
The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users…
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux…
KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars
A critical Bluetooth vulnerability in dealer-installed KARR Security Systems is putting over 2 million vehicles at risk of unauthorized access and immobilization. This situation has prompted urgent calls for drivers to update affected devices. Researchers at the University of California,…
Microsoft Adds Prompt Injection Protection to Defender for Office 365
Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats. As organizations increasingly adopt AI assistants like Microsoft 365 Copilot to summarize, triage, and respond to…
Check Point patches actively exploited SmartConsole authentication bypass flaw
Check Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is being actively exploited. Check Point has released security updates to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentication bypass flaw affecting…
New Check Point Zero-Day Vulnerability Exploited in the Wild
The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: New…
Login Theft Becomes Top Factor In Ransomware Attacks
Hackers get around multi-factor authentication to use compromised credentials in 79 percent of 2025 ransomware attacks This article has been indexed from Silicon UK Read the original article: Login Theft Becomes Top Factor In Ransomware Attacks
Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data
Chick-fil-A has confirmed a data breach affecting an undisclosed number of Chick-fil-A One loyalty accounts. This breach occurred as threat actors executed credential-stuffing attacks on its website and mobile application. The incident underscores the ongoing risk associated with password reuse,…
CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited in the wild, prompting organizations to take immediate defensive action. Tracked as CVE-2026-16232,…
CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure
Iran-linked hackers are targeting internet-connected industrial controllers used across U.S. critical infrastructure. The campaign has disrupted programmable logic controllers, or PLCs, in government, water, wastewater, and energy facilities. Some victims suffered operational disruption and financial losses after attackers altered the…
Chick-fil-A Urges Customers to Change Chick-fil-A One Passwords After Unauthorized Access
Chick-fil-A has warned customers to update their Chick-fil-A One passwords after detecting unauthorized access to a subset of loyalty accounts during a credential stuffing attack in June 2026. After conducting an internal investigation, the company confirmed that attackers used an…
July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws
A new infrastructure security review has exposed a busy month for defenders. Fourteen infrastructure vendors issued 61 relevant advisories worldwide during the 30 days ending July 17, including 26 flaws that attackers can reach remotely without logging in. Six advisories…
Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks
A recently disclosed Bluetooth vulnerability in the aftermarket KARR Security System exposes approximately 2.2 million vehicles to remote attacks that could allow unauthorized door unlocking, alarm control, and vehicle immobilization. This issue, uncovered by researchers at the University of California,…
GitHub revamps bug bounty program with new VIP tier, payout changes
GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will take effect on July 27, 2026. Reports submitted before that date will be honored under the previous bounty…
Swiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattack
Cybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after breaching a data exchange platform shared with one of its suppliers through compromised credentials. Stadler operates 16 production and component plants and…
Adobe Patches Acrobat Chrome Extension Flaw That Exposed WhatsApp Web Chats to Any Website
Adobe has patched a series of vulnerabilities in its Acrobat Chrome extension that previously allowed any website to access conversations in WhatsApp Web withou Thank you for being a Ghacks reader. The post Adobe Patches Acrobat Chrome Extension Flaw That…
EU Informs JD.com Of Concerns Over Ceconomy Buyout
European Commission hands Chinese e-commerce giant formal notice over concerns that state subsidies played role in €2.2bn deal This article has been indexed from Silicon UK Read the original article: EU Informs JD.com Of Concerns Over Ceconomy Buyout
The Trust Economy: Why Transparency and Data Privacy Are Becoming Core Parts of Customer Experience
Discover why privacy, transparency and ethical AI are becoming essential to customer trust, loyalty and enterprise customer experience. This article has been indexed from Silicon UK Read the original article: The Trust Economy: Why Transparency and Data Privacy Are Becoming…
The Trust Economy: Head-to-Head
Has trust now become a measurable part of the customer experience, and what evidence is there that transparency and responsible data use directly influence loyalty, retention and purchasing decisions? “Trust has become one of the most measurable elements of customer…