🔴 New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering.
Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities in the region. GoSerpent is designed to contact an external server and deploy secondary payloads on sensitive data collection and credential dumping on the system.
Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering.
Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities in the region. GoSerpent is designed to contact an external server and deploy secondary payloads on sensitive data collection and credential dumping on the system.
🔴 Receita Federal (RFB) Data Breach Exposes 279 Million Brazilian CPFs
Receita Federal, Brazil's federal tax authority, has been compromised, leading to the exposure of personal data for 279 million Brazilian citizens. An anonymous entity claims to have initially discovered a legacy system backup from 2019 containing 248 million CPFs. Following the government's denial of this initial claim, the entity states they subsequently extracted 279 million rows directly from the government's active system, alleging this newer data is current and not recycled. The group also criticized the Receita Federal for dismissing the initial claims as "fake news" and for not opening an investigation, despite inconsistencies noted in the data management.
The Receita Federal has a history of denying data leaks, even when extensive CPF data has been exposed in the past, such as the 2021 incident involving 223 million Brazilians.
Receita Federal, Brazil's federal tax authority, has been compromised, leading to the exposure of personal data for 279 million Brazilian citizens. An anonymous entity claims to have initially discovered a legacy system backup from 2019 containing 248 million CPFs. Following the government's denial of this initial claim, the entity states they subsequently extracted 279 million rows directly from the government's active system, alleging this newer data is current and not recycled. The group also criticized the Receita Federal for dismissing the initial claims as "fake news" and for not opening an investigation, despite inconsistencies noted in the data management.
The Receita Federal has a history of denying data leaks, even when extensive CPF data has been exposed in the past, such as the 2021 incident involving 223 million Brazilians.
Customer Support Platform Incident Prompts Investigation at Global Consulting Firm
Ernst & Young (EY) is investigating a data security incident involving a third-party customer support platform after unauthorized actors gained access to support tickets containing client information.
🔗 Read More
Ernst & Young (EY) is investigating a data security incident involving a third-party customer support platform after unauthorized actors gained access to support tickets containing client information.
🔗 Read More
🔴 Federal employees can download TikTok on their work phones again
The Department of Justice says that federal employees can now download TikTok on their government devices.
A 2022 law banned federal employees from using the short-form video app on those devices, but the DOJ reportedly says the law no longer applies, thanks to a deal transferring ownership of TikTok’s U.S. operations to a joint venture backed by Oracle, Silver Lake, and MGX. (Oracle serves as the security partner for the new joint venture, while previous owner ByteDance retains a 19.9% stake.)
The Department of Justice says that federal employees can now download TikTok on their government devices.
A 2022 law banned federal employees from using the short-form video app on those devices, but the DOJ reportedly says the law no longer applies, thanks to a deal transferring ownership of TikTok’s U.S. operations to a joint venture backed by Oracle, Silver Lake, and MGX. (Oracle serves as the security partner for the new joint venture, while previous owner ByteDance retains a 19.9% stake.)
Unauthenticated Exploit Chain Places Countless Websites at Immediate Risk
Security researchers have disclosed a critical vulnerability in WordPress core that could allow unauthenticated attackers to execute arbitrary code on vulnerable websites, placing millions of installations at risk if they remain unpatched.
🔗 Read More
Security researchers have disclosed a critical vulnerability in WordPress core that could allow unauthenticated attackers to execute arbitrary code on vulnerable websites, placing millions of installations at risk if they remain unpatched.
🔗 Read More
🔴 Statement issued by the “Cyber Support Front”
🔻 The Cyber Attribution Front announces its new report on its cyber operations against financial institutions affiliated with the occupying entity.
🔻 With the aim of disrupting the financial system of the Zionist entity, the Front announces its successful attacks against prominent Israeli financial institutions such as “Oren Levy CPA (ISR),” “Finco Financial Services,” and “Milikowski Consulting and Investments Ltd.”
🔻The Front attacked these institutions, obtained valuable and confidential data, and thus dealt a strategic blow to the entity’s financial and tax systems, inflicting losses on them that can never be compensated.
🔻 The Cyber Attribution Front announces its new report on its cyber operations against financial institutions affiliated with the occupying entity.
🔻 With the aim of disrupting the financial system of the Zionist entity, the Front announces its successful attacks against prominent Israeli financial institutions such as “Oren Levy CPA (ISR),” “Finco Financial Services,” and “Milikowski Consulting and Investments Ltd.”
🔻The Front attacked these institutions, obtained valuable and confidential data, and thus dealt a strategic blow to the entity’s financial and tax systems, inflicting losses on them that can never be compensated.
Newly Revealed TLS Weakness Can Gradually Exhaust Server Resources
Security researchers have disclosed a newly identified denial-of-service (DoS) vulnerability in OpenSSL that allows attackers to gradually exhaust server memory using specially crafted 11-byte TLS requests, potentially causing affected services to become unavailable.
🔗 Read More
Security researchers have disclosed a newly identified denial-of-service (DoS) vulnerability in OpenSSL that allows attackers to gradually exhaust server memory using specially crafted 11-byte TLS requests, potentially causing affected services to become unavailable.
🔗 Read More
🔴 Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov.
His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side room. His lawyers say Washington has the wrong man.
The Ermakov the U.S. wants is Aleksandr Gennadievich Ermakov, sanctioned by Australia, the US, and the UK in January 2024 for stealing 9.7 million records from Medibank Private, one of Australia's largest private health insurers, and dumping some on the dark web.
Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov.
His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side room. His lawyers say Washington has the wrong man.
The Ermakov the U.S. wants is Aleksandr Gennadievich Ermakov, sanctioned by Australia, the US, and the UK in January 2024 for stealing 9.7 million records from Medibank Private, one of Australia's largest private health insurers, and dumping some on the dark web.
Blockchain-Powered Malware Campaign Targets JavaScript Developers Through Fake Packages
Security researchers have uncovered a new software supply chain campaign in which seven malicious npm packages impersonating tools for the Vite JavaScript framework were used to infect developers with a remote access trojan (RAT) delivered through an advanced blockchain-based command-and-control (C2) infrastructure.
🔗 Read More
Security researchers have uncovered a new software supply chain campaign in which seven malicious npm packages impersonating tools for the Vite JavaScript framework were used to infect developers with a remote access trojan (RAT) delivered through an advanced blockchain-based command-and-control (C2) infrastructure.
🔗 Read More
🔴 Odyssey’ director Christopher Nolan calls AI an obvious ‘Trojan horse’
Christopher Nolan, the Oscar-winning director whose new version of “The Odyssey” is currently conquering the box office, said it’s been “pretty encouraging” to see deep skepticism of AI, especially from young people.
Nolan was responding to a question from interviewer Hugo Travers, who publishes on YouTube under the name HugoDécrypte. Travers brought up the legendary Trojan horse, which plays a key role in Nolan’s film — just as the horse was a gift concealing murderous Greek invaders, he wondered if AI might be something “that you welcome in your daily life” only to see it become “something else and something darker.”
Christopher Nolan, the Oscar-winning director whose new version of “The Odyssey” is currently conquering the box office, said it’s been “pretty encouraging” to see deep skepticism of AI, especially from young people.
Nolan was responding to a question from interviewer Hugo Travers, who publishes on YouTube under the name HugoDécrypte. Travers brought up the legendary Trojan horse, which plays a key role in Nolan’s film — just as the horse was a gift concealing murderous Greek invaders, he wondered if AI might be something “that you welcome in your daily life” only to see it become “something else and something darker.”
🔴 WP2Shell WordPress Vulnerabilities Exploited in the Wild
Two newly patched WordPress vulnerabilities are being exploited in the wild, with attacks beginning shortly after they came to light.
The vulnerabilities have been dubbed WP2Shell and they are officially tracked as CVE-2026-60137 and CVE-2026-63030.
According to Searchlight Cyber, whose researchers discovered the flaws, WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected.
“The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” the security firm warned.
Two newly patched WordPress vulnerabilities are being exploited in the wild, with attacks beginning shortly after they came to light.
The vulnerabilities have been dubbed WP2Shell and they are officially tracked as CVE-2026-60137 and CVE-2026-63030.
According to Searchlight Cyber, whose researchers discovered the flaws, WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected.
“The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” the security firm warned.
❤1
🔴 SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
The rogue gems are listed below -
git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026
Dendreo (versions 1.1.3, 1.1.4) - Published on October 14, 2017
fastlane-plugin-run_tests_firebase_testlab (version 0.3.2) - Published on February 06, 2018
"Each malicious release is a loader," StepSecurity said in an analysis. "It fetches a second stage from an attacker controlled Forgejo host, checks whether it is running in a build system and skips if it is, and on a developer machine it drops a native daemon and installs persistence."
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
The rogue gems are listed below -
git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026
Dendreo (versions 1.1.3, 1.1.4) - Published on October 14, 2017
fastlane-plugin-run_tests_firebase_testlab (version 0.3.2) - Published on February 06, 2018
"Each malicious release is a loader," StepSecurity said in an analysis. "It fetches a second stage from an attacker controlled Forgejo host, checks whether it is running in a build system and skips if it is, and on a developer machine it drops a native daemon and installs persistence."
🔴 World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.
The company said it detected and responded to the incident targeting its production infrastructure earlier last week.
"We identified unauthorized access to a limited set of internal datasets and to several credentials used by our services," the company said in a statement.
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.
The company said it detected and responded to the incident targeting its production infrastructure earlier last week.
"We identified unauthorized access to a limited set of internal datasets and to several credentials used by our services," the company said in a statement.
🔴 Chrome 150 Update Patches Severe Memory Safety Bugs
Google has released a Chrome 150 security update that resolves seven memory safety bugs, including critical and high-severity use-after-free vulnerabilities.
The browser refresh patches three critical-severity use-after-free flaws impacting Chrome’s CameraCapture, GPU, and Network components. All three weaknesses were discovered by Google.
Additionally, the update fixes three high-severity use-after-free issues in Cast, Ozone, and Aura; Google discovered these vulnerabilities as well.
The seventh security defect is an out-of-bounds read and write flaw in the V8 JavaScript engine that was identified by OpenAI Codex Security. Google has yet to determine the bug bounty amount to be paid for the finding.
Google has released a Chrome 150 security update that resolves seven memory safety bugs, including critical and high-severity use-after-free vulnerabilities.
The browser refresh patches three critical-severity use-after-free flaws impacting Chrome’s CameraCapture, GPU, and Network components. All three weaknesses were discovered by Google.
Additionally, the update fixes three high-severity use-after-free issues in Cast, Ozone, and Aura; Google discovered these vulnerabilities as well.
The seventh security defect is an out-of-bounds read and write flaw in the V8 JavaScript engine that was identified by OpenAI Codex Security. Google has yet to determine the bug bounty amount to be paid for the finding.
🔴 Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available.
Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks as UTA0533, chained two vulnerabilities, respectively tracked as CVE-2026-15409 (CVSS score of 10.0) and CVE-2026-15410 (CVSS score of 7.2) to achieve root-level access on the devices before patches existed.
SonicWall patched both vulnerabilities this week and confirmed the active exploitation of the two zero-day vulnerabilities. The vulnerabilities were internally discovered and reported by Adam Babis of the company’s PSIRT.
Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available.
Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks as UTA0533, chained two vulnerabilities, respectively tracked as CVE-2026-15409 (CVSS score of 10.0) and CVE-2026-15410 (CVSS score of 7.2) to achieve root-level access on the devices before patches existed.
SonicWall patched both vulnerabilities this week and confirmed the active exploitation of the two zero-day vulnerabilities. The vulnerabilities were internally discovered and reported by Adam Babis of the company’s PSIRT.
🔴 Adobe camera app’s new feature will critique your photos using AI
Adobe is adding new AI-powered features to its experimental iOS camera app called Project Indigo, launched last year. The app previously offered pro controls, multi-frame super-resolution, and different capture modes, and is now adding features that will use LLMs (large language models) to critique photos and provide editing suggestions.
It’s also adding other AI features, like advanced object removal, depth of field generation, and the ability to add different styles to photos.
Adobe is adding new AI-powered features to its experimental iOS camera app called Project Indigo, launched last year. The app previously offered pro controls, multi-frame super-resolution, and different capture modes, and is now adding features that will use LLMs (large language models) to critique photos and provide editing suggestions.
It’s also adding other AI features, like advanced object removal, depth of field generation, and the ability to add different styles to photos.
🔴 Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday.
Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it “immediately.” The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress.
Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday.
Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it “immediately.” The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress.
Connected Surveillance Devices Exploited to Monitor Defense Activities Across Europe
Dutch intelligence agencies have warned that a state-sponsored espionage campaign is systematically compromising internet-connected IP cameras across Europe to monitor military logistics, weapons shipments, and defense activities linked to support for Ukraine.
🔗 Read More
Dutch intelligence agencies have warned that a state-sponsored espionage campaign is systematically compromising internet-connected IP cameras across Europe to monitor military logistics, weapons shipments, and defense activities linked to support for Ukraine.
🔗 Read More
🔴 AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials.
Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models.
Hugging Face disclosed that an autonomous AI agent breached part of its production infrastructure last week. The company detected the intrusion, contained it, and found unauthorized access to a limited number of internal datasets and service credentials. The investigation is still ongoing, but there is no evidence the attackers modified public AI models, datasets, Spaces, or the company’s software supply chain.
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials.
Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models.
Hugging Face disclosed that an autonomous AI agent breached part of its production infrastructure last week. The company detected the intrusion, contained it, and found unauthorized access to a limited number of internal datasets and service credentials. The investigation is still ongoing, but there is no evidence the attackers modified public AI models, datasets, Spaces, or the company’s software supply chain.
🔴 Critical ServiceNow code execution flaw now exploited in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows.
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows.
🔴 CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers
F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests.
F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests.
“heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression (CVE-2026-42533).” reads the advisory.
F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests.
F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests.
“heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression (CVE-2026-42533).” reads the advisory.