A Cursor zero-day vulnerability lets a planted git.exe run automatically when a Windows developer opens a repository. Mindgard disclosed it after seven months of silence from Cursor. Cursor’s Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer on Latest…
CVE-2026-14266: Inside the 7-Zip Heap Overflow Hiding in XZ Archives Since 2021
A heap-based buffer overflow in 7-Zip's XZ decoder, patched in version 26.02, let a crafted archive run code on extraction and had gone unnoticed for five years. CVE-2026-14266: Inside the 7-Zip Heap Overflow Hiding in XZ Archives Since 2021 on…
wp2shell: WordPress Patches a Pre-Auth RCE That Needed No Plugins
WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated remote code execution. wp2shell: WordPress Patches a Pre-Auth RCE That Needed No Plugins on Latest Hacking News | Cyber Security News,…
Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories– SonicWall Zero-Day, Cl0p Windchill Attack, AI-Weaponized Threats, Data Breaches & More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from July 20–24, 2026. It was a heavy week: Cl0p turned internet-exposed Windchill servers into a global data-theft campaign,…
The Ill Bloom Vulnerability: How to Check If Your Wallet Is Exposed
A weak random-number generator behind the Ill Bloom vulnerability has let attackers drain over $5 million from crypto wallets. Here's how to check exposure and fix it. The Ill Bloom Vulnerability: How to Check If Your Wallet Is Exposed on…
IT Security News Hourly Summary 2026-07-26 21h : 4 posts
4 posts were published in the last hour 18:31 : Claude AI Shared Chats Reportedly Exposed in Google Search Results 18:31 : AI Moved into the Dev Workflow. Security Didn’t. 18:31 : Weekly Cyber Security Newsletter Bulletin – Certighost Exploit,…
Claude AI Shared Chats Reportedly Exposed in Google Search Results
Anthropic’s Claude share links appeared in public search results, raising fresh privacy concerns for users who shared sensitive conversations. A Reddit post this weekend revealed that hundreds of Claude AI shared chats were publicly discoverable through Google. Users searching queries…
AI Moved into the Dev Workflow. Security Didn’t.
AI coding tools were supposed to sit alongside the development process. Today, they’re increasingly becoming the development process. Many of these systems are also evolving from coding assistants into autonomous development agents… The post AI Moved into the Dev Workflow. Security Didn’t.…
Weekly Cyber Security Newsletter Bulletin – Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 Stories
Threat actors continued to combine classic exploitation techniques with AI-accelerated tooling this week, from a 15-year-old NGINX bug and an actively exploited Check Point authentication flaw to autonomous AI agents chaining zero-days against Hugging Face. Below is a roundup of…
Ransomware Is More Disruptive And Recovery Readiness Matters More Than Ever
Ransomware continues to evolve at a rapid pace, and it is challenging the most common cybersecurity assumptions. Recent findings have revealed a shift in attacker strategy. Modern ransomware is no… The post Ransomware Is More Disruptive And Recovery Readiness Matters…
Steam Forum Scam Uses ClickFix Technique to Infect Gamers With XMRig Cryptominer
Cybercriminals are targeting Steam users through fraudulent troubleshooting posts that exploit the increasingly common ClickFix social engineering technique, tricking gamers into manually executing malicious PowerShell commands that ultimately install cryptocurrency mining malware on Windows systems. Rather than relying on…
Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack
"The first autonomous agent cyberattack is an unprecedented event. It deserves an unprecedented response!" This article has been indexed from Security News | TechCrunch Read the original article: Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack
IT Security News Hourly Summary 2026-07-26 18h : 2 posts
2 posts were published in the last hour 16:1 : AI Is Fueling a New Wave of Cybercrime 15:31 : Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
AI Is Fueling a New Wave of Cybercrime
Cybercriminals are increasingly turning to artificial intelligence, and the biggest barriers that once slowed adoption are rapidly disappearing. According to a recent Axios report, restricted access to models, high costs, and limited incentive to change old hacking methods are…
Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
ESAFENET&#;x26;#;39;s CDG showed up in our data before. The company focused on secure document management and data leakage prevention solutions. The "CDG" stands for "Content Data Guard", and the product appears to be mostly targeting the Chinese market [1]. Sadly,…
OpenAI Explores a Home Device to Make ChatGPT Part of Daily Life
It has been reported that OpenAI is developing the first consumer hardware product, an AI speaker with no screen to turn ChatGPT into a constantly available household companion. Through the use of advanced artificial intelligence capabilities, the device is…
How Pro-Iran Hacktivist Networks Mobilize During Kinetic Conflict
The current conflict between the United States and Iran has become a case study in how asymmetric warfare and coalition building are reshaping the cyber and geopolitical dimensions of modern conflict. Following the United States and Israel’s joint military strikes…
US Indicts Three Russian Nationals Over Bulletproof Hosting Network Linked to Global Cybercrime
The EU sanctioned nine Russian citizens and four entities for engaging in cyber-espionage campaigns and attacks against the EU, member states, Ukraine, and other countries. The sanctions were imposed by the Council of the European Union and coordinated with…
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter UAC-0145 Primary Compromise Vectors as of July 2026 SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor …
Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials
Hackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests toward fake Microsoft…
IT Security News Hourly Summary 2026-07-26 15h : 1 posts
1 posts were published in the last hour 12:31 : Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION
Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Iran-Linked…
IT Security News Hourly Summary 2026-07-26 12h : 1 posts
1 posts were published in the last hour 9:31 : Top 10 Best Active Directory Management Tools 2026
Top 10 Best Active Directory Management Tools 2026
Managing Active Directory with native tools alone can become time-consuming as an organization grows. Routine tasks such as provisioning users, resetting passwords, managing group memberships, auditing permissions, and maintaining compliance can place a heavy burden on IT teams. Manual processes…