Windmill servers are under active attack.
Experts say attackers are exploiting CVE-2026-29059 to read arbitrary server files without logging in. On some systems, the same flaw can lead to superadmin access and code execution.
Full details: https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html
Experts say attackers are exploiting CVE-2026-29059 to read arbitrary server files without logging in. On some systems, the same flaw can lead to superadmin access and code execution.
Full details: https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html
π₯4
76% of employees now use AI at work. Most of those tools were never reviewed by security.
When approval takes six weeks and a workaround takes six minutes, AI use moves out of sight.
How to make the secure path the faster one: https://thehackernews.com/2026/07/the-fastest-path-to-ai-adoption-runs.html
When approval takes six weeks and a workaround takes six minutes, AI use moves out of sight.
How to make the secure path the faster one: https://thehackernews.com/2026/07/the-fastest-path-to-ai-adoption-runs.html
π₯3π3π2
π One visit to a malicious webpage could have been enough to expose your #WhatsApp Web chats.
CVE-2026-48294 in Adobe Acrobatβs Chrome extension could read messages, contact names, chat previews, and profile data without malware, stolen credentials, or session cookies.
The extension has over 314 million users.
See how HermeticReader worked: https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html
CVE-2026-48294 in Adobe Acrobatβs Chrome extension could read messages, contact names, chat previews, and profile data without malware, stolen credentials, or session cookies.
The extension has over 314 million users.
See how HermeticReader worked: https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html
π€5π2π1π₯1
β‘ AI is pushing code output up 10β50x. Security programs still assume humans can review what humans build.
That model breaks at machine speed.
Learn how to govern AI-built software with secure-by-default architecture.
Save your seat: https://thehacker.news/secure-ai-development
That model breaks at machine speed.
Learn how to govern AI-built software with secure-by-default architecture.
Save your seat: https://thehacker.news/secure-ai-development
π₯7π2
π¨ A flaw in Ubuntuβs snap-confine could turn local user access into root.
CVE-2026-8933 chains FUSE and symlink race conditions to plant malicious udev rules and execute commands as root.
Default Ubuntu #Linux Desktop 24.04, 25.10, and 26.04 installations are affected.
Read how the exploit works: https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html
CVE-2026-8933 chains FUSE and symlink race conditions to plant malicious udev rules and execute commands as root.
Default Ubuntu #Linux Desktop 24.04, 25.10, and 26.04 installations are affected.
Read how the exploit works: https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html
π₯5
GitHub is cutting public bug bounty payouts by at least half.
The reset comes as AI floods programs with low-effort reports while helping skilled researchers find real bugs faster.
Top rewards now move to an invite-only VIP tier.
Read the full story: https://thehackernews.com/2026/07/github-cuts-public-bug-bounty-payouts.html
The reset comes as AI floods programs with low-effort reports while helping skilled researchers find real bugs faster.
Top rewards now move to an invite-only VIP tier.
Read the full story: https://thehackernews.com/2026/07/github-cuts-public-bug-bounty-payouts.html
π€―18π₯4π2π±2π€1
β οΈ Attackers are exploiting a Check Point SmartConsole flaw that can grant full administrative access.
CVE-2026-16232 affects management servers exposed directly to the internet under a specific configuration. Check Point says a small number of customers were targeted.
Read: https://thehackernews.com/2026/07/check-point-patches-exploited.html
CVE-2026-16232 affects management servers exposed directly to the internet under a specific configuration. Check Point says a small number of customers were targeted.
Read: https://thehackernews.com/2026/07/check-point-patches-exploited.html
π₯5
π A newly disclosed, 9-year-old #Linux flaw lets unprivileged users overwrite root-owned files and gain persistent root access.
On affected XFS systems, the overwrite survives reboot without changing ownership, permissions, timestamps, or the setuid bit.
Read: https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html
On affected XFS systems, the overwrite survives reboot without changing ownership, permissions, timestamps, or the setuid bit.
Read: https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html
π₯9β‘3π2
π₯ Google now lets users RECOVER LOCKED ACCOUNTS with a selfie video.
Users save a face clip, then record another when they need to prove the account is theirs. An optional setting can expand how Google uses that data beyond sign-in.
What is stored and how it may be used: https://thehackernews.com/2026/07/google-adds-selfie-video-recovery-for.html
Users save a face clip, then record another when they need to prove the account is theirs. An optional setting can expand how Google uses that data beyond sign-in.
What is stored and how it may be used: https://thehackernews.com/2026/07/google-adds-selfie-video-recovery-for.html
π±16π€8β‘4π₯1
π¨ Attackers turned GitHub-hosted runners into cPanel attack infrastructure.
They planted 583 malicious workflows to target cPanel and WHM servers exposed to CVE-2026-41940, hunting for cloud keys, API tokens, SSH data, and other secrets.
How the campaign worked: https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html
They planted 583 malicious workflows to target cPanel and WHM servers exposed to CVE-2026-41940, hunting for cloud keys, API tokens, SSH data, and other secrets.
How the campaign worked: https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html
π₯6π2
Social engineering is now a margin game.
Convincing lures cost 95% less to produce. Median time to click: 21 seconds.
Doppelβs Josh Bartolomie says defenders should stop chasing lures and make attacks too costly to scale.
Learn how to break the economics: https://thehackernews.com/expert-insights/2026/07/how-to-make-social-engineering.html
Convincing lures cost 95% less to produce. Median time to click: 21 seconds.
Doppelβs Josh Bartolomie says defenders should stop chasing lures and make attacks too costly to scale.
Learn how to break the economics: https://thehackernews.com/expert-insights/2026/07/how-to-make-social-engineering.html
π₯5
π China-nexus JadeProx breached a Vietnamese hospitalβs medical imaging server and targeted Malaysiaβs foreign ministry with a new Windows loader.
The same operation also hid malware inside a fake Claude installer.
How the campaign worked: https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html
The same operation also hid malware inside a fake Claude installer.
How the campaign worked: https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html
π₯5π1
βΌοΈ Chaos Hid Its C2 Inside Chrome.
Instead of connecting directly to its command server, Chaos #ransomwareβs msaRAT launches Chrome or Edge in hidden mode and uses the browser to send encrypted commands over WebRTC, making the malicious traffic look like normal browser activity.
Read: https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html
Instead of connecting directly to its command server, Chaos #ransomwareβs msaRAT launches Chrome or Edge in hidden mode and uses the browser to send encrypted commands over WebRTC, making the malicious traffic look like normal browser activity.
Read: https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html
π±7π4
This media is not supported in your browser
VIEW IN TELEGRAM
π¨ Researchers say one short message let Claude Cowork escape its Linux VM and access files across the host Mac.
The SharedRoot chain used CVE-2026-46331 to gain guest root, then crossed through Coworkβs read-write host mount.
Read how it worked: https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html
The SharedRoot chain used CVE-2026-46331 to gain guest root, then crossed through Coworkβs read-write host mount.
Read how it worked: https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html
π10
This media is not supported in your browser
VIEW IN TELEGRAM
π¨ Attackers are targeting the datacenters that train, host, and serve AI, not just the AI models themselves.
Lava has released FORGE: The Top 10 Data Center & AI Infrastructure Security Risks: https://thn.news/forge-risk-guide
Built with security leaders and practitioners across neoclouds, HPC, and enterprise security β open, free, and made to evolve.
Lava has released FORGE: The Top 10 Data Center & AI Infrastructure Security Risks: https://thn.news/forge-risk-guide
Built with security leaders and practitioners across neoclouds, HPC, and enterprise security β open, free, and made to evolve.
π₯8π2
β‘ Spyware on Phones, Malware in Code, Attacks on Factories
This weekβs #ThreatsDay roundup covers 15 security stories spanning mobile surveillance, software supply-chain attacks, AI abuse, and industrial systems.
β’ PyPI Lockdown
β’ PLC Attacks
β’ Fake VPN Malware
β’ Vibe-Code Bugs
β’ AI Jailbreaks
β’ TrickBot DNS
β’ AI Bug Hunter
...and more. Read: https://thehackernews.com/2026/07/threatsday-android-spyware-plc-attacks.html
This weekβs #ThreatsDay roundup covers 15 security stories spanning mobile surveillance, software supply-chain attacks, AI abuse, and industrial systems.
β’ PyPI Lockdown
β’ PLC Attacks
β’ Fake VPN Malware
β’ Vibe-Code Bugs
β’ AI Jailbreaks
β’ TrickBot DNS
β’ AI Bug Hunter
...and more. Read: https://thehackernews.com/2026/07/threatsday-android-spyware-plc-attacks.html
π₯6
Not every dangerous machine identity is stolen. Some are fake from the start.
Fabricated machine identities can blend into NHI sprawl, gain privileges, and evade controls built to catch stolen credentials because no legitimate owner exists to raise the alarm.
See how it works: https://thehackernews.com/2026/07/how-synthetic-identity-fraud-is-coming.html
Fabricated machine identities can blend into NHI sprawl, gain privileges, and evade controls built to catch stolen credentials because no legitimate owner exists to raise the alarm.
See how it works: https://thehackernews.com/2026/07/how-synthetic-identity-fraud-is-coming.html
π3
π No link. No attachment. Just viewing the email.
A Russian state-supported espionage group exploited a Zimbra zero-day for at least 5 months to steal passwords, 2FA recovery codes, organization directories, and 90 days of mail.
Read how ZimReaper worked - https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
A Russian state-supported espionage group exploited a Zimbra zero-day for at least 5 months to steal passwords, 2FA recovery codes, organization directories, and 90 days of mail.
Read how ZimReaper worked - https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
π₯11π€―5π4β‘1
π¨ A malicious Notepad++ plugin is turning the legitimate editor into a malware loader.
CERT-UA links the campaign to Russia-aligned UAC-0099. It establishes persistence and deploys MATCHBOIL.V2 for follow-on malware.
Read more: https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html
CERT-UA links the campaign to Russia-aligned UAC-0099. It establishes persistence and deploys MATCHBOIL.V2 for follow-on malware.
Read more: https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html
π1π€―1
π Kimi K3 AI agents found Redis 0-days. Then they built working RCE exploits.
The authenticated chains abuse RESTORE across multiple #Redis releases. Redis has shipped seven security updates, with no exploitation reported in the wild.
Details: https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html
The authenticated chains abuse RESTORE across multiple #Redis releases. Redis has shipped seven security updates, with no exploitation reported in the wild.
Details: https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html
π4