Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the…
Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauthenticated attacker can obtain an application login…
FakeAgent Campaign: Malicious Claude Artifact Used to Distribute SectopRAT to 29 Organisations
Researchers at Huntress have disclosed a malvertising campaign that abused a public artifact hosted on Anthropic’s own claude.ai domain to distribute the SectopRAT information-stealing Trojan, compromising at least 29 organisations in the space of two days. The campaign, which Huntress…
France, Germany Summon Russian Envoys Over Alleged Cyber Espionage Campaign
France and Germany have announced diplomatic action against Russia following allegations that a coordinated cyber espionage and sabotage campaign target multiple European countries. In the coming days, the Foreign Minister said France would summon the Russian ambassador to Paris and…
New Dolphin X Stealer Employs AI Profiling to Prioritize Targets
Dolphin X is a new infostealer that uses AI to sort and rank victims, giving cybercriminals a faster way to identify lucrative targets This article has been indexed from www.infosecurity-magazine.com Read the original article: New Dolphin X Stealer Employs AI…
Preview: Cisco Talos at Black Hat USA 2026
Here’s some of the ways Talos is showing up at Black Hat, alongside our friends at Cisco and Splunk. This article has been indexed from Cisco Talos Blog Read the original article: Preview: Cisco Talos at Black Hat USA 2026
Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware “msaRAT” that hijacks browsers. The malware doesn’t communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker’s IP from victims via WebRTC over TURN. This…
Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root
A recently disclosed vulnerability in Ubuntu’s snap ecosystem, identified as CVE-2026-8933, presents a critical local privilege escalation flaw. This vulnerability allows unprivileged users to execute arbitrary code with root privileges. Qualys discovered the issue in snap-confine, a core component used…
Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication
A critical authentication bypass vulnerability affecting Check Point SmartConsole has been actively exploited in the wild, allowing attackers to gain unauthorized access to security management systems under specific configurations. The flaw, tracked as CVE-2026-16232, carries a CVSS score of 9.3…
IT Security News Hourly Summary 2026-07-23 12h : 15 posts
15 posts were published in the last hour 10:4 : Assaf Keren Appointed New CISO of Meta 10:4 : PyPI hardens package security with new upload restrictions 10:4 : Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL…
Assaf Keren Appointed New CISO of Meta
He replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: Assaf Keren…
PyPI hardens package security with new upload restrictions
The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users…
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux…
KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars
A critical Bluetooth vulnerability in dealer-installed KARR Security Systems is putting over 2 million vehicles at risk of unauthorized access and immobilization. This situation has prompted urgent calls for drivers to update affected devices. Researchers at the University of California,…
Microsoft Adds Prompt Injection Protection to Defender for Office 365
Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats. As organizations increasingly adopt AI assistants like Microsoft 365 Copilot to summarize, triage, and respond to…
Check Point patches actively exploited SmartConsole authentication bypass flaw
Check Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is being actively exploited. Check Point has released security updates to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentication bypass flaw affecting…
New Check Point Zero-Day Vulnerability Exploited in the Wild
The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: New…
Login Theft Becomes Top Factor In Ransomware Attacks
Hackers get around multi-factor authentication to use compromised credentials in 79 percent of 2025 ransomware attacks This article has been indexed from Silicon UK Read the original article: Login Theft Becomes Top Factor In Ransomware Attacks
Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data
Chick-fil-A has confirmed a data breach affecting an undisclosed number of Chick-fil-A One loyalty accounts. This breach occurred as threat actors executed credential-stuffing attacks on its website and mobile application. The incident underscores the ongoing risk associated with password reuse,…
CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited in the wild, prompting organizations to take immediate defensive action. Tracked as CVE-2026-16232,…
CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure
Iran-linked hackers are targeting internet-connected industrial controllers used across U.S. critical infrastructure. The campaign has disrupted programmable logic controllers, or PLCs, in government, water, wastewater, and energy facilities. Some victims suffered operational disruption and financial losses after attackers altered the…
Chick-fil-A Urges Customers to Change Chick-fil-A One Passwords After Unauthorized Access
Chick-fil-A has warned customers to update their Chick-fil-A One passwords after detecting unauthorized access to a subset of loyalty accounts during a credential stuffing attack in June 2026. After conducting an internal investigation, the company confirmed that attackers used an…
July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws
A new infrastructure security review has exposed a busy month for defenders. Fourteen infrastructure vendors issued 61 relevant advisories worldwide during the 30 days ending July 17, including 26 flaws that attackers can reach remotely without logging in. Six advisories…
Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks
A recently disclosed Bluetooth vulnerability in the aftermarket KARR Security System exposes approximately 2.2 million vehicles to remote attacks that could allow unauthorized door unlocking, alarm control, and vehicle immobilization. This issue, uncovered by researchers at the University of California,…