Newly Revealed TLS Weakness Can Gradually Exhaust Server Resources
Security researchers have disclosed a newly identified denial-of-service (DoS) vulnerability in OpenSSL that allows attackers to gradually exhaust server memory using specially crafted 11-byte TLS requests, potentially causing affected services to become unavailable.
🔗 Read More
Security researchers have disclosed a newly identified denial-of-service (DoS) vulnerability in OpenSSL that allows attackers to gradually exhaust server memory using specially crafted 11-byte TLS requests, potentially causing affected services to become unavailable.
🔗 Read More
🔴 Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov.
His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side room. His lawyers say Washington has the wrong man.
The Ermakov the U.S. wants is Aleksandr Gennadievich Ermakov, sanctioned by Australia, the US, and the UK in January 2024 for stealing 9.7 million records from Medibank Private, one of Australia's largest private health insurers, and dumping some on the dark web.
Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov.
His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side room. His lawyers say Washington has the wrong man.
The Ermakov the U.S. wants is Aleksandr Gennadievich Ermakov, sanctioned by Australia, the US, and the UK in January 2024 for stealing 9.7 million records from Medibank Private, one of Australia's largest private health insurers, and dumping some on the dark web.
Blockchain-Powered Malware Campaign Targets JavaScript Developers Through Fake Packages
Security researchers have uncovered a new software supply chain campaign in which seven malicious npm packages impersonating tools for the Vite JavaScript framework were used to infect developers with a remote access trojan (RAT) delivered through an advanced blockchain-based command-and-control (C2) infrastructure.
🔗 Read More
Security researchers have uncovered a new software supply chain campaign in which seven malicious npm packages impersonating tools for the Vite JavaScript framework were used to infect developers with a remote access trojan (RAT) delivered through an advanced blockchain-based command-and-control (C2) infrastructure.
🔗 Read More
🔴 Odyssey’ director Christopher Nolan calls AI an obvious ‘Trojan horse’
Christopher Nolan, the Oscar-winning director whose new version of “The Odyssey” is currently conquering the box office, said it’s been “pretty encouraging” to see deep skepticism of AI, especially from young people.
Nolan was responding to a question from interviewer Hugo Travers, who publishes on YouTube under the name HugoDécrypte. Travers brought up the legendary Trojan horse, which plays a key role in Nolan’s film — just as the horse was a gift concealing murderous Greek invaders, he wondered if AI might be something “that you welcome in your daily life” only to see it become “something else and something darker.”
Christopher Nolan, the Oscar-winning director whose new version of “The Odyssey” is currently conquering the box office, said it’s been “pretty encouraging” to see deep skepticism of AI, especially from young people.
Nolan was responding to a question from interviewer Hugo Travers, who publishes on YouTube under the name HugoDécrypte. Travers brought up the legendary Trojan horse, which plays a key role in Nolan’s film — just as the horse was a gift concealing murderous Greek invaders, he wondered if AI might be something “that you welcome in your daily life” only to see it become “something else and something darker.”
🔴 WP2Shell WordPress Vulnerabilities Exploited in the Wild
Two newly patched WordPress vulnerabilities are being exploited in the wild, with attacks beginning shortly after they came to light.
The vulnerabilities have been dubbed WP2Shell and they are officially tracked as CVE-2026-60137 and CVE-2026-63030.
According to Searchlight Cyber, whose researchers discovered the flaws, WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected.
“The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” the security firm warned.
Two newly patched WordPress vulnerabilities are being exploited in the wild, with attacks beginning shortly after they came to light.
The vulnerabilities have been dubbed WP2Shell and they are officially tracked as CVE-2026-60137 and CVE-2026-63030.
According to Searchlight Cyber, whose researchers discovered the flaws, WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected.
“The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” the security firm warned.
❤1
🔴 SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
The rogue gems are listed below -
git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026
Dendreo (versions 1.1.3, 1.1.4) - Published on October 14, 2017
fastlane-plugin-run_tests_firebase_testlab (version 0.3.2) - Published on February 06, 2018
"Each malicious release is a loader," StepSecurity said in an analysis. "It fetches a second stage from an attacker controlled Forgejo host, checks whether it is running in a build system and skips if it is, and on a developer machine it drops a native daemon and installs persistence."
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
The rogue gems are listed below -
git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026
Dendreo (versions 1.1.3, 1.1.4) - Published on October 14, 2017
fastlane-plugin-run_tests_firebase_testlab (version 0.3.2) - Published on February 06, 2018
"Each malicious release is a loader," StepSecurity said in an analysis. "It fetches a second stage from an attacker controlled Forgejo host, checks whether it is running in a build system and skips if it is, and on a developer machine it drops a native daemon and installs persistence."
🔴 World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.
The company said it detected and responded to the incident targeting its production infrastructure earlier last week.
"We identified unauthorized access to a limited set of internal datasets and to several credentials used by our services," the company said in a statement.
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.
The company said it detected and responded to the incident targeting its production infrastructure earlier last week.
"We identified unauthorized access to a limited set of internal datasets and to several credentials used by our services," the company said in a statement.
🔴 Chrome 150 Update Patches Severe Memory Safety Bugs
Google has released a Chrome 150 security update that resolves seven memory safety bugs, including critical and high-severity use-after-free vulnerabilities.
The browser refresh patches three critical-severity use-after-free flaws impacting Chrome’s CameraCapture, GPU, and Network components. All three weaknesses were discovered by Google.
Additionally, the update fixes three high-severity use-after-free issues in Cast, Ozone, and Aura; Google discovered these vulnerabilities as well.
The seventh security defect is an out-of-bounds read and write flaw in the V8 JavaScript engine that was identified by OpenAI Codex Security. Google has yet to determine the bug bounty amount to be paid for the finding.
Google has released a Chrome 150 security update that resolves seven memory safety bugs, including critical and high-severity use-after-free vulnerabilities.
The browser refresh patches three critical-severity use-after-free flaws impacting Chrome’s CameraCapture, GPU, and Network components. All three weaknesses were discovered by Google.
Additionally, the update fixes three high-severity use-after-free issues in Cast, Ozone, and Aura; Google discovered these vulnerabilities as well.
The seventh security defect is an out-of-bounds read and write flaw in the V8 JavaScript engine that was identified by OpenAI Codex Security. Google has yet to determine the bug bounty amount to be paid for the finding.
🔴 Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available.
Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks as UTA0533, chained two vulnerabilities, respectively tracked as CVE-2026-15409 (CVSS score of 10.0) and CVE-2026-15410 (CVSS score of 7.2) to achieve root-level access on the devices before patches existed.
SonicWall patched both vulnerabilities this week and confirmed the active exploitation of the two zero-day vulnerabilities. The vulnerabilities were internally discovered and reported by Adam Babis of the company’s PSIRT.
Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available.
Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks as UTA0533, chained two vulnerabilities, respectively tracked as CVE-2026-15409 (CVSS score of 10.0) and CVE-2026-15410 (CVSS score of 7.2) to achieve root-level access on the devices before patches existed.
SonicWall patched both vulnerabilities this week and confirmed the active exploitation of the two zero-day vulnerabilities. The vulnerabilities were internally discovered and reported by Adam Babis of the company’s PSIRT.
🔴 Adobe camera app’s new feature will critique your photos using AI
Adobe is adding new AI-powered features to its experimental iOS camera app called Project Indigo, launched last year. The app previously offered pro controls, multi-frame super-resolution, and different capture modes, and is now adding features that will use LLMs (large language models) to critique photos and provide editing suggestions.
It’s also adding other AI features, like advanced object removal, depth of field generation, and the ability to add different styles to photos.
Adobe is adding new AI-powered features to its experimental iOS camera app called Project Indigo, launched last year. The app previously offered pro controls, multi-frame super-resolution, and different capture modes, and is now adding features that will use LLMs (large language models) to critique photos and provide editing suggestions.
It’s also adding other AI features, like advanced object removal, depth of field generation, and the ability to add different styles to photos.
🔴 Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday.
Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it “immediately.” The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress.
Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday.
Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it “immediately.” The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress.
Connected Surveillance Devices Exploited to Monitor Defense Activities Across Europe
Dutch intelligence agencies have warned that a state-sponsored espionage campaign is systematically compromising internet-connected IP cameras across Europe to monitor military logistics, weapons shipments, and defense activities linked to support for Ukraine.
🔗 Read More
Dutch intelligence agencies have warned that a state-sponsored espionage campaign is systematically compromising internet-connected IP cameras across Europe to monitor military logistics, weapons shipments, and defense activities linked to support for Ukraine.
🔗 Read More
🔴 AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials.
Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models.
Hugging Face disclosed that an autonomous AI agent breached part of its production infrastructure last week. The company detected the intrusion, contained it, and found unauthorized access to a limited number of internal datasets and service credentials. The investigation is still ongoing, but there is no evidence the attackers modified public AI models, datasets, Spaces, or the company’s software supply chain.
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials.
Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models.
Hugging Face disclosed that an autonomous AI agent breached part of its production infrastructure last week. The company detected the intrusion, contained it, and found unauthorized access to a limited number of internal datasets and service credentials. The investigation is still ongoing, but there is no evidence the attackers modified public AI models, datasets, Spaces, or the company’s software supply chain.
🔴 Critical ServiceNow code execution flaw now exploited in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows.
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows.
🔴 CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers
F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests.
F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests.
“heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression (CVE-2026-42533).” reads the advisory.
F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests.
F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests.
“heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression (CVE-2026-42533).” reads the advisory.
🔴 Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
Financial services giant Capital One has released an internally developed AI-powered security tool to the public as open source.
Dubbed “VulnHunter”, the tool was designed to find and fix software vulnerabilities at the code level, but Capital One says it is not a traditional, passive vulnerability scanner.
“We designed VulnHunter with a developer-first mindset to solve a massive industry pain point: overwhelming false positives that create friction and slow down daily workflows,” Chris Nims, EVP & Chief Information Security Officer (CISO) at Capital One, explained in a LinkedIn post.
Financial services giant Capital One has released an internally developed AI-powered security tool to the public as open source.
Dubbed “VulnHunter”, the tool was designed to find and fix software vulnerabilities at the code level, but Capital One says it is not a traditional, passive vulnerability scanner.
“We designed VulnHunter with a developer-first mindset to solve a massive industry pain point: overwhelming false positives that create friction and slow down daily workflows,” Chris Nims, EVP & Chief Information Security Officer (CISO) at Capital One, explained in a LinkedIn post.
🔴 Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites
A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB.
The malware, dubbed HOLLOWGRAPH, was detailed by Group-IB‘s Threat Intelligence team, which said it has attributed the tool with high confidence to the Cavern backdoor framework, a modular command-and-control (C2) toolkit previously linked to Iranian-nexus activity. Researchers said the sample abuses the Microsoft Graph API via a compromised Microsoft 365 account traced to Israel, using it to blend malicious communications into legitimate cloud traffic.
A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB.
The malware, dubbed HOLLOWGRAPH, was detailed by Group-IB‘s Threat Intelligence team, which said it has attributed the tool with high confidence to the Cavern backdoor framework, a modular command-and-control (C2) toolkit previously linked to Iranian-nexus activity. Researchers said the sample abuses the Microsoft Graph API via a compromised Microsoft 365 account traced to Israel, using it to blend malicious communications into legitimate cloud traffic.
🔴 YouTube clarifies policies around AI slop and upsetting videos
YouTube already had policies around AI content. Last year, the company announced it was stemming creators’ ability to generate revenue from what it called “inauthentic content,” including mass-produced videos and other types of repetitive content that have become easier to generate with the help of AI technology.
A recent change sees YouTube further cracking down on AI slop by clarifying its policies around how content on its platform can be monetized. To discourage creators from using AI and other tools to make low-quality content, YouTube’s policy now explains that there are three types of videos under the broader category of “inauthentic content” that cannot be monetized.
YouTube already had policies around AI content. Last year, the company announced it was stemming creators’ ability to generate revenue from what it called “inauthentic content,” including mass-produced videos and other types of repetitive content that have become easier to generate with the help of AI technology.
A recent change sees YouTube further cracking down on AI slop by clarifying its policies around how content on its platform can be monetized. To discourage creators from using AI and other tools to make low-quality content, YouTube’s policy now explains that there are three types of videos under the broader category of “inauthentic content” that cannot be monetized.
🔴 Inference startup Infinity raises $15M from Touring Capital, OpenAI and Anthropic researchers
AI infrastructure company Infinity announced a $15 million raise at a $100 million valuation on Monday from investors including Touring Capital, Principal VC, and researchers from companies such as OpenAI and Anthropic.
The startup is building software to make it easier for AI chips to run AI models. One big reason Nvidia became the top player is not just its high-performance chips, but also its CUDA software (Compute Unified Device Architecture), which allows its GPUs (originally designed to run graphics) to act as general-purpose processing CPUs. The largest AI development frameworks PyTorch and TensorFlow have been built on top of CUDA. This allows developers to write their apps in popular languages like Python, use those major AI frameworks and their apps will, by default, run on Nvidia chips.
AI infrastructure company Infinity announced a $15 million raise at a $100 million valuation on Monday from investors including Touring Capital, Principal VC, and researchers from companies such as OpenAI and Anthropic.
The startup is building software to make it easier for AI chips to run AI models. One big reason Nvidia became the top player is not just its high-performance chips, but also its CUDA software (Compute Unified Device Architecture), which allows its GPUs (originally designed to run graphics) to act as general-purpose processing CPUs. The largest AI development frameworks PyTorch and TensorFlow have been built on top of CUDA. This allows developers to write their apps in popular languages like Python, use those major AI frameworks and their apps will, by default, run on Nvidia chips.
🔴 Natural raises $30M to reinvent payments for AI agents — and take on Stripe
AI agents are starting to execute more sophisticated tasks, such as identifying vendors that can deliver freight, comparing prices, and messaging the vendor to organizing a delivery. But when it comes to making a payment for the shipment, they still need to involve a human.
Today’s financial sector relies on financial rails, the underlying infrastructure that moves money and information between a money and financial information between banks, businesses, and consumers. But these financial rails were built for human-initiated transactions, not autonomous AI agents. For example, traditional payment systems like credit cards and ACH rely on human authorization for transactions, which slows down agents engineered to work autonomously.
AI agents are starting to execute more sophisticated tasks, such as identifying vendors that can deliver freight, comparing prices, and messaging the vendor to organizing a delivery. But when it comes to making a payment for the shipment, they still need to involve a human.
Today’s financial sector relies on financial rails, the underlying infrastructure that moves money and information between a money and financial information between banks, businesses, and consumers. But these financial rails were built for human-initiated transactions, not autonomous AI agents. For example, traditional payment systems like credit cards and ACH rely on human authorization for transactions, which slows down agents engineered to work autonomously.
🔴 Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust
Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly published Threat Report H1 2026.
The report, Gen’s first half-yearly threat publication after previously reporting on a quarterly basis, argues that the defining pattern of the period was not any single new technique, but attackers consistently inserting themselves into systems and moments that users, platforms and security tools already trust, from hotel booking threads and WhatsApp device pairing to software update channels and AI agent permissions.
Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly published Threat Report H1 2026.
The report, Gen’s first half-yearly threat publication after previously reporting on a quarterly basis, argues that the defining pattern of the period was not any single new technique, but attackers consistently inserting themselves into systems and moments that users, platforms and security tools already trust, from hotel booking threads and WhatsApp device pairing to software update channels and AI agent permissions.