PPHM HACKER NEWS
9.6K subscribers
2.2K photos
5 videos
1.33K links
PPHM Hacker News is a reliable news outlet that brings you the latest and most credential cyber news.

Website:
https://pphmnews.com/
Download Telegram
🔴 X relaunches a rebuilt Android app after year-long effort

Nearly a year ago, Elon Musk-owned X announced it would begin rebuilding the Android version of its app, which had not held up well compared with its iOS counterpart. On Monday, the company shipped the refreshed app, which is now available to download.

The new Android version of X was built from scratch and promises improvements to loading, scrolling, notifications, and more, X said in its announcement.
🔴 Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies

U.K.-based healthcare billing software maker Craneware is responding to a cyberattack in which hackers stole a “significant volume” of customer data from its systems, the company said on Monday.

The company said the hackers appear to have been expelled from its systems, but its investigation into the breach is ongoing, according to a statement filed with the London Stock Exchange.
🔴 Salt Security tackles AI governance challenge with 100 pre-built agentic security policies

Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments.

The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance and runtime behaviour. The announcement comes as organisations rapidly adopt AI agents that can interact with enterprise systems and perform tasks autonomously. Because these agents rely on APIs to access data and invoke tools, Salt argues that traditional API governance has become an essential part of governing AI systems.
🔴 SEBI Fines CDSL Rs 1 Crore Over 2022 Malware Attack, Cybersecurity Lapses

India's markets regulator has imposed a cumulative penalty of Rs 1 crore on Central Depository Services (India) Ltd (CDSL) for cybersecurity lapses that led to the November 2022 malware attack, holding that the breach was "foreseeable" and could have been prevented through compliance with mandatory security standards.

In an 88-page order, the Securities and Exchange Board of India (SEBI) levied a Rs 90 lakh penalty under the SEBI Act and Rs 10 lakh under the Depositories Act, while disposing of proceedings against CDSL's former Chief Information Security Officer Rajesh Nadkarni and former Chief Technology Officer Amit Mahajan without imposing monetary penalties
🔴 Why blocking AI models won’t stop the cyber threats they create

2026 has turned out to be the year when predictions about AI-powered cyberattacks, long hypothesized as a potential risk associated with AI improvement, seem to be coming true. New models have capabilities on par with the best human hackers, marking a pivotal window of opportunity in both AI and cybersecurity policy. This is a transitional period where new technologies are pushing existing American cybersecurity infrastructure to the brink. The real question isn’t whether cybersecurity still matters, but rather: How will the risks that AI introduces be managed before they outpace defenses, and who will step up to lead this challenge?
Browser Manipulation Module Enables Financial Theft and Account Hijacking

Security researchers have uncovered a powerful web injection module used by the TELEPUZ malware family that enables attackers to manipulate banking sessions, steal browser data, execute malicious JavaScript, and modify financial transactions in real time.

🔗 Read More
🔴 Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software

American-Israeli cybersecurity startup Neo emerged from stealth mode on Monday with $100 million in funding for a platform that enables enterprises to control and secure AI software.

Neo received the investment across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, Craft Ventures, and Merlin Ventures. The company will use the money to grow its engineering and go-to-market teams.

Neo’s platform serves as a control layer that governs AI agents, AI-enabled applications, and traditional software across enterprise environments.
🔴 Healthcare giant Abbott probes two cyber incidents amid extortion claims

Abbott Laboratories, one of the world’s largest healthcare and medical device companies, is investigating two apparently unrelated cyber incidents after confirming unauthorized access to internal systems. While Abbott says there has been no impact on manufacturing, laboratory operations, or patient care, cybercriminal groups ShinyHunters and ShadowByt3$ claim the breaches were far more extensive. Those claims remain unverified at the time of writing and, so far, unsupported by publicly leaked data.

The incidents reportedly involve Abbott’s Cancer Diagnostics business and its LabCentral customer portal for core laboratory diagnostics.
🔴 New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month.

The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.

The entry point did not change. Langflow versions before 1.3.0 expose the /api/v1/validate/code endpoint without authentication, allowing any remote attacker to execute arbitrary Python on the server. The flaw, CVE-2025-3248, carries a CVSS score of 9.8 and has been in CISA's Known Exploited Vulnerabilities catalog since May 5, 2025.
🔴 Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875

Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances.

Searchlight Cyber researchers disclosed a critical pre-authentication remote code execution vulnerability, tracked as CVE-2026-6875, in the ServiceNow AI Platform on July 14. The same day, ServiceNow released patches for self-hosted instances. Since July 17, attackers have started exploiting it in the wild.

“After finding our first pre-auth critical bug almost two years ago and having a much better understanding of the ServiceNow architecture, we decided to return and focus our efforts on a different corner of the codebase.” reads the report published by Searchlight Cyber. “Our efforts led to us finding a completely unauthenticated RCE, which allowed full compromise of the ServiceNow instance as well as all connected proxy servers.”
🔴 Windows LegacyHive zero-day flaw gets free, unofficial patches

Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems.

The vulnerability (dubbed LegacyHive and without a CVE ID for easy tracking) was found by a security researcher using the "Nightmare Eclipse" handle in the Windows User Profile Service.

Nightmare Eclipse disclosed it the day Microsoft released its July 2026 Patch Tuesday updates, together with a stripped proof-of-concept exploit designed to make it harder for threat actors to weaponize this security issue in attacks.
🔴 One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files

A single security alert has exposed an unusually detailed view of how a threat actor builds, tests, and delivers malware.

The exposed WebDAV server held more than 1,000 files, including phishing lures, shortcut files, droppers, testing notes, and tools used to track victim activity.

The operation targeted Windows users with fake documents, identity-record downloads, error pages, and familiar business themes.

Victims could be pushed toward remote WebDAV shares, malicious shortcuts, or ClickFix-style instructions that persuade them to run commands themselves, a delivery pattern also seen in Windows File Explorer and WebDAV abuse campaigns.
🔴 Clover Health Investments Discloses Data Breach

Healthcare technology company Clover Health Investments has disclosed a data breach impacting customers’ personal and health information.

Discovered on July 4, the incident was the result of a social engineering attack that compromised three non-managerial health plan employee accounts.

Clover Health Investments says it activated its response plan immediately after discovering the attack, and engaged third-party cybersecurity experts to contain and investigate the intrusion.
🔴 Alleged YouNow Database Containing 22+ Million User Records Posted on Hacking Forum

A threat actor claims to have released a full database allegedly belonging to YouNow, the live-streaming platform, containing more than 22 million user records.

The actor claims the dataset includes user profiles, account metadata, platform activity, and social media linkage information.

* The post advertises the database as available for download.

The actor further alleges the dataset contains:

* Usernames and email addresses
* Facebook, Google, and Twitter account IDs
* Profile information and registration dates
* Device and operating system information
* IP addresses and location-related data
* User activity metrics and moderation-related fields
🔴 Gritt exits stealth with $34 million for robots to build solar plants—then, everything else

One of the most important things happening on Earth today is the solar energy build-out. Around the world, companies and countries are racing to deploy solar and batteries to achieve energy independence and limit the effects of climate change.

That build-out, though, is running into a labor market challenge, with a limited supply of workers to meet a growing demand for installation. Robots could be an answer, but industrial robots have historically struggled in unstructured environments, at least until now. The latest generation of AI models may have changed that equation.
🔴 95% of Security Teams Blindsided by Vulnerabilities Between Tests

The vast majority of enterprise security teams are being blindsided by vulnerabilities that scheduled testing never catches, according to new research from Synack, which describes itself as the provider of the first AI-powered continuous pentest for enterprises.

The company’s new report, The State of Continuous Security Validation, surveyed enterprise security leaders and practitioners and found that 95% had discovered high or critical vulnerabilities outside their scheduled testing windows within the past year. Of those, 42% said this had happened at least once a month, underscoring a widening gap between how quickly enterprise environments change and how infrequently they are actually tested.
🔴 Alleged BeMyEye User Database Containing 728,000+ Records Posted on Hacking Forum

A threat actor claims to have uploaded the complete user database of BeMyEye, a crowdsourcing and mystery shopping platform that connects businesses with field auditors and shoppers.

While the preview does not disclose the full list of exposed fields, databases of this nature may contain:

* Usernames and email addresses
* Password hashes
* Account profile information
* Contact details
* Platform activity and registration metadata
🔴 What the World Cup can teach us about cybersecurity resilience

With the World Cup now complete, its biggest cybersecurity story may be what didn’t happen. While no major public cyber disruption has been reported, that shouldn’t be mistaken for a lack of risk.

In the run-up to the tournament, the FBI’s Internet Crime Complaint Center (IC3) issued a public service announcement warning organizations and fans about fraudulent, spoofed websites impersonating the FIFA event – a reminder that the absence of a headline-grabbing breach doesn’t mean bad actors weren’t trying. In many ways, it’s evidence of the planning, coordination, and resilience required to keep an event of this scale running securely.
🔴 Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.

Palo Alto Networks addressed the vulnerability (CVE-2026-0257) on May 13 and warned that attackers had begun abusing it to breach corporate networks after Rapid7 reported observing it being exploited against numerous customers starting on May 17.

"GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection," the company warned at the time. "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied."
1
🔴 BlaBlaCar Database Offered for Sale

A threat actor has listed a database belonging to BlaBlaCar, the France-based carpooling and mobility platform, for sale on a cybercrime forum:

* Claimed dataset size: 140 million records
* Asking price: $450
* The seller shared screenshots of a sample database.
* The exposed fields shown in the sample allegedly include user IDs, email addresses, password hashes, names, gender, phone numbers, account status, ride statistics, wallet balances, signup dates, and other profile metadata.
🔴 Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

A security researcher says he has received a significant bug bounty from Meta after discovering a critical vulnerability that exposed customer support data.

The vulnerability was discovered and reported to Meta in January 2026 by independent researcher Rony K Roy. The initial report to the social media giant described a security hole of limited severity, but further analysis revealed that the flaw’s impact was much higher than initially believed.

According to Roy, Meta rolled out patches in April and had not found any evidence of malicious exploitation.