On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a coordinated vulnerability disclosure (CVD) program. Six days earlier, CISA published a blog post explaining how…
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
ClickLock Stealer, a new macOS infostealer, answers a victim’s refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system…
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that’s been spreading via websites infected with ClickFix lures since late April 2026. “The malware is full-featured, lightweight, and modular,” Elastic Security Labs researcher Cyril François said in…
Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers Claim
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackers This article has been indexed from www.infosecurity-magazine.com Read the original article: Single Prompt Enables ChatGPT to…
Modular macOS Stealer Uses Kill Loops to Force Password Entry
New ClickLock macOS stealer locked victims out of their own system until they surrendered a password This article has been indexed from www.infosecurity-magazine.com Read the original article: Modular macOS Stealer Uses Kill Loops to Force Password Entry
New Framework Redefines AI Penetration Testing Around Prompt Injection and Behavioral Objective Violations
A newly proposed framework argues that AI penetration testing must move beyond conventional infrastructure compromise and assess whether an adversary can make an AI-enabled system act against its intended operational purpose. Traditional penetration testing typically measures compromise through outcomes such…
Hackers Exploit SonicWall SMA1000 Zero-Days to Execute Commands as Root
Hackers are actively exploiting two zero-day vulnerabilities in the SonicWall SMA 1000 Series remote access appliances. They are chaining a critical server-side request forgery flaw with a local code injection bug to execute commands with root privileges. Rapid7’s Managed Detection…
Specter Turns Your Flipper Zero Into a Pocket Skimmer Detector
A new Flipper Zero app called Specter aims to turn the handheld device into a passive counter-surveillance tool for finding active 13.56 MHz NFC readers, including potentially suspicious readers hidden near payment terminals, access-control panels, desks, or other equipment. Unlike…
JetBrains Patched 6 Vulnerabilities Across TeamCity, YouTrack and IntelliJ IDEA
JetBrains has addressed six security vulnerabilities in its software development and project management products. The affected applications include IntelliJ IDEA, TeamCity, and YouTrack. The most critical vulnerability, tracked as CVE-2026-59792, is an improper path handling (CWE-23) flaw that could allow…
WhatsApp GhostPairing Lets Scammers Hijack Accounts Without Stealing Passwords
WhatsApp users are being targeted by a social-engineering technique called GhostPairing that can give scammers access to an account without requiring a password or one-time verification code. Instead of breaking into the service directly, the scam abuses WhatsApp’s legitimate device-linking…
Hackers Don’t Crack Telegram 2FA—They Copy Your Already Logged-In Session
A macOS information-stealing malware is turning stolen Telegram desktop data into immediate account access. Instead of guessing passwords or breaking two-factor authentication, it copies the local files that prove a user has already logged in. When those files are restored…
Brit Scattered Spider duo handed tickets to prison over Transport for London attack
Sentencing bookends the biggest cybercrime conviction in UK history This article has been indexed from www.theregister.com – Articles Read the original article: Brit Scattered Spider duo handed tickets to prison over Transport for London attack
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency. The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read…
AI Data Centers Are Being Built Faster Than They Can Be Secured
AI infrastructure introduces new security risks that traditional data center designs were never built to handle. The post AI Data Centers Are Being Built Faster Than They Can Be Secured appeared first on SecurityWeek. This article has been indexed from…
CISA Orders Feds to Patch Oracle Flaw
The Cybersecurity and Infrastructure Security Agency has issued an emergency directive requiring federal agencies to patch a critical vulnerability in Oracle E-Business Suite financial applications by Saturday. This article has been indexed from CyberMaterial Read the original article: CISA Orders…
AWS CloudFront outage disrupts multiple services
Amazon Web Services suffered a significant CloudFront outage on the morning of the incident, beginning at 0945 UTC and affecting customers using VPC Origins. This article has been indexed from CyberMaterial Read the original article: AWS CloudFront outage disrupts multiple…
CISA urges vendors to formalize vulnerability disclosure
The Cybersecurity and Infrastructure Security Agency (CISA) and four international partners have released guidance calling on software manufacturers and online service providers to formalize coordinated vulnerability disclosure (CVD) programs. This article has been indexed from CyberMaterial Read the original article:…
Telegram t.me links disrupted over sanctioned VPN
Telegram’s widely used t.me shortlinks experienced a complete outage lasting roughly one day after the .ME domain registry suspended the domain in response to US sanctions targeting a VPN service popular with cybercriminals. This article has been indexed from CyberMaterial…
AI Bug-Finding Tools Need Human Validation
Security teams are increasingly using AI-powered tools to accelerate offensive security work, but industry experts warn that human validation remains non-negotiable. This article has been indexed from CyberMaterial Read the original article: AI Bug-Finding Tools Need Human Validation
IT Security News Hourly Summary 2026-07-16 15h : 16 posts
16 posts were published in the last hour 12:34 : Inside Microsoft’s Record-Breaking 622-Bug Release 12:34 : Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes 12:34 : Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM…
Inside Microsoft’s Record-Breaking 622-Bug Release
Record-Breaking Fixes Tackle Two Exploited Zero-Days On July 14, 2026, Microsoft dropped a record-shattering Patch Tuesday update that delivered 622 security fixes in a single day. This unprecedented volume, which… The post Inside Microsoft’s Record-Breaking 622-Bug Release appeared first on…
Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes
A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI) In more than 200 sessions between March…
Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin (“srt64.sys”), as the kernel-mode rootkit is referred to, was…
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click “Buy Now” instead. Ask a coding assistant to apply a maintainer’s fix from a GitHub thread, and a fake…