OS Command Injection is a critical vulnerability (CWE-78) where an attacker executes arbitrary operating system commands via a… This article has been indexed from Hackers Online Club Read the original article: Command Injection Cheatsheet: OS Payloads And Prevention (2026)
Shein Sees $99m Loss Ahead Of Hong Kong IPO
China-founded e-commerce company sees US market contract, falls to loss in first quarter as it prepares to list in Hong Kong This article has been indexed from Silicon UK Read the original article: Shein Sees $99m Loss Ahead Of Hong…
Houston City College – 831,642 breached accounts
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic…
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor
An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.” Active since January 2026, the activity is assessed to be linked to an…
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. This article has been indexed from SecurityWeek Read the original article: Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
IT Security News Hourly Summary 2026-07-28 09h : 3 posts
3 posts were published in the last hour 6:31 : Multiple FFmpeg Flaws Allow Arbitrary Memory Corruption via Malicious Videos 6:31 : Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost 6:31 : Shadow AI…
Multiple FFmpeg Flaws Allow Arbitrary Memory Corruption via Malicious Videos
Multiple high-severity vulnerabilities in FFmpeg could allow attackers to corrupt memory, disclose process data, or exhaust system resources. This can happen if users or automated media-processing services are manipulated into handling specially crafted video, audio, image, or subtitle files. The…
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best…
Shadow AI incident response begins with logs that may already be gone
In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI…
Hugging Face Has a Deepfake Nudes Problem
Researchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts show how people use the software. This article has been indexed from Security Latest Read the original article: Hugging…
Apple iOS 26.6 Update Fixes Flaws Allowing Kernel-Level Code Execution and Root Access
Apple has released iOS 26.6 and iPadOS 26.6, a significant security update that addresses numerous vulnerabilities across core operating system components, media frameworks, WebKit, wireless services, and application frameworks. Released on July 27, 2026, this update is available for iPhone…
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the…
AI took more than junior developer jobs and the bill comes later
A ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. Describe it to Claude and…
How DCSync Attack Helps Hackers Steal Password Hashes Silently from Active Directory
Active Directory is the beating heart of identity in most enterprises, and its single most valuable secret is the password hash of every user, service, and machine account. A DCSync attack lets an adversary walk out with those hashes without…
Operation STANDOFF Uses GitHub Redirects Across 44 Servers to Hide Multi-Malware C2 Traffic
Operation STANDOFF is a Russian‑speaking cybercriminal campaign that uses a cluster of at least 44 TimeWeb‑hosted servers that all masquerade as benign GitHub redirectors to conceal multi‑malware command‑and‑control (C2) and proxy traffic. This infrastructure underpins a full ecosystem: a pay‑per‑install…
CISA Warns of Fortinet FortiOS Vulnerability Exploited in Attacks
CISA has added the actively exploited Fortinet FortiOS vulnerability CVE-2025-68686 to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of active attacks. The vulnerability affects Fortinet FortiOS, the operating system used across FortiGate firewalls and other Fortinet security products.…
Download: The High-Performance Team Playbook
Get practical insight from teams who’ve built, scaled and handed over engineering functions at enterprise level. Most engineering teams don’t fail because of bad engineers. They fail because performance is assumed. This playbook shows how high-performance teams are built intentionally…
Operation BlueDash Maintains Redundant Remote Access Even After One RMM Tool Is Removed
A newly analyzed phishing-driven intrusion set tracked as Operation BlueDash demonstrates how threat actors are operationalizing legitimate remote monitoring and management (RMM) tools to maintain persistent and redundant access to compromised environments. The infection chain begins with a Microsoft Teams-themed…
Origin Energy Data Breach Affects 900,000 Australians
The hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems. This article has been indexed from SecurityWeek Read the original article: Origin Energy Data Breach Affects 900,000 Australians
OpenAI CEO Sam Altman Claims AI Has Reached Singularity as Systems Begin Improving Themselves
OpenAI CEO Sam Altman has stated that artificial intelligence has entered the long-discussed stage of technological singularity, referring to the current period as the point where AI systems can increasingly improve future AI capabilities. His remarks, made during the “Relentless”…
Europol Targets the Online Network Turning Teen Hackers Into Extortionists and Violent Offenders
Europol is enhancing its response to “The Com,” a dangerous online ecosystem that allegedly recruits and manipulates minors into cyberattacks, extortion schemes, sexual exploitation, and violent offenses. This initiative, called Project COMPASS, brings together law enforcement agencies from EU Member…
ShinyHunters Claims EY Data Breach, Threatens to Leak Stolen Client Tax Data
ShinyHunters has claimed responsibility for the data breach at Ernst & Young (EY) and is threatening to publish allegedly stolen client tax information unless the professional services firm engages in negotiations before July 31, 2026. The extortion group posted about…
Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts
Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned. Victims are asked to log in with their email address and password to claim free…
Cybersecurity jobs available right now: July 28, 2026
Cloud Security Engineer Toyota Automated Logistics | USA | On-site – View job details As a Cloud Security Engineer, you will design and enforce security controls across Azure and on-premises environments, strengthen identity and access management, and maintain cloud security…