🚨 Sophos & SonicWall just patched critical RCE flaws—some pre-auth, CVSS 9.8.
One bug affects devices even after patching (via upgrade path). Another was used to plant a backdoor.
Here’s what defenders need to know ↓ https://thehackernews.com/2025/07/sophos-and-sonicwall-patch-critical-rce.html
One bug affects devices even after patching (via upgrade path). Another was used to plant a backdoor.
Here’s what defenders need to know ↓ https://thehackernews.com/2025/07/sophos-and-sonicwall-patch-critical-rce.html
🤔9
🚨 New malware CastleLoader is hijacking systems through fake GitHub repos and phishing sites—469 confirmed infections.
It spreads stealers and RATs, uses PowerShell, and mimics trusted dev tools.
It’s stealthy. It’s spreading.
Here’s how it works ↓ https://thehackernews.com/2025/07/castleloader-malware-infects-469.html
It spreads stealers and RATs, uses PowerShell, and mimics trusted dev tools.
It’s stealthy. It’s spreading.
Here’s how it works ↓ https://thehackernews.com/2025/07/castleloader-malware-infects-469.html
🔥8⚡3
⚠️ A China-linked group breached VMware ESXi & vCenter in a stealthy, years-long cyberespionage campaign.
They killed logs, mimicked forensic tools—and stayed hidden for years.
Most orgs still can’t detect it.
Full report → https://thehackernews.com/2025/07/fire-ant-exploits-vmware-flaw-to.html
They killed logs, mimicked forensic tools—and stayed hidden for years.
Most orgs still can’t detect it.
Full report → https://thehackernews.com/2025/07/fire-ant-exploits-vmware-flaw-to.html
🔥13😱2⚡1
☠️ WARNING: A critical auth bypass flaw in Mitel MiVoice MX-ONE (CVSS 9.4) lets attackers hijack user and admin accounts—no login needed.
It affects versions still widely in use.
Details + fixes → https://thehackernews.com/2025/07/critical-mitel-flaw-lets-hackers-bypass.html
Patch now or risk full compromise.
It affects versions still widely in use.
Details + fixes → https://thehackernews.com/2025/07/critical-mitel-flaw-lets-hackers-bypass.html
Patch now or risk full compromise.
😁17
🔐 AI logins are breaking trust—73% of users say one bad experience, and they’re gone.
Want to keep them?
Learn how top brands are using smart, secure CIAM to win loyalty in the AI era.
Webinar spots are limited → https://thehacker.news/ai-customer-identity
Want to keep them?
Learn how top brands are using smart, secure CIAM to win loyalty in the AI era.
Webinar spots are limited → https://thehacker.news/ai-customer-identity
👏9👍1😁1
🔄 Update on LAMEHUG malware →
Russian hackers used ~270 Hugging Face tokens to run AI-powered attacks — sending prompts to a coding LLM to generate system-hacking commands.
The kicker? It’s likely a live test run, not the final form.
Cato says this is R&D in real time → https://thehackernews.com/2025/07/cert-ua-discovers-lamehug-malware.html
Russian hackers used ~270 Hugging Face tokens to run AI-powered attacks — sending prompts to a coding LLM to generate system-hacking commands.
The kicker? It’s likely a live test run, not the final form.
Cato says this is R&D in real time → https://thehackernews.com/2025/07/cert-ua-discovers-lamehug-malware.html
👏12🤔1
🔄 Update: SharePoint Attacks Escalate
ToolShell exploitation is now global—4,600+ compromise attempts across 300+ orgs, including government and critical infrastructure.
🛑 U.S. leads in targets (13.3%), followed by the UK, France, and Germany.
📌 Attackers are stealing ASP .NET machine keys to persist even after patching.
⚠️ Ivanti EPMM flaws also in use—this is expanding fast.
Here’s what’s unfolding → https://thehackernews.com/2025/07/storm-2603-exploits-sharepoint-flaws-to.html
ToolShell exploitation is now global—4,600+ compromise attempts across 300+ orgs, including government and critical infrastructure.
🛑 U.S. leads in targets (13.3%), followed by the UK, France, and Germany.
📌 Attackers are stealing ASP .NET machine keys to persist even after patching.
⚠️ Ivanti EPMM flaws also in use—this is expanding fast.
Here’s what’s unfolding → https://thehackernews.com/2025/07/storm-2603-exploits-sharepoint-flaws-to.html
😁8🤔3
🚨 Two new malware campaigns—Soco404 & Koske—are targeting cloud servers across Linux & Windows to deploy crypto miners.
→ Soco404 hides in fake 404 pages
→ Koske uses malicious panda JPEGs
→ Both run fileless, in-memory attacks
What makes them so dangerous? ↓ https://thehackernews.com/2025/07/soco404-and-koske-malware-target-cloud.html
→ Soco404 hides in fake 404 pages
→ Koske uses malicious panda JPEGs
→ Both run fileless, in-memory attacks
What makes them so dangerous? ↓ https://thehackernews.com/2025/07/soco404-and-koske-malware-target-cloud.html
🤔10🔥5
🚨 1 in 12 employees is quietly using Chinese GenAI tools at work—often to upload sensitive data.
M&A docs, source code, customer records… all sent to platforms with opaque data policies.
It’s already happening.
Details + what to do about it ↓ https://thehackernews.com/2025/07/overcoming-risks-from-chinese-genai.html
M&A docs, source code, customer records… all sent to platforms with opaque data policies.
It’s already happening.
Details + what to do about it ↓ https://thehackernews.com/2025/07/overcoming-risks-from-chinese-genai.html
😁18🤯6🔥3👏2😱1
🚨 Russian defense firms hit by stealth cyberattack!
Hackers deployed a new backdoor—EAGLET—to spy on aerospace targets via fake logistics docs tied to sanctioned rail firms.
Read → https://thehackernews.com/2025/07/cyber-espionage-campaign-hits-russian.html
Hackers deployed a new backdoor—EAGLET—to spy on aerospace targets via fake logistics docs tied to sanctioned rail firms.
Read → https://thehackernews.com/2025/07/cyber-espionage-campaign-hits-russian.html
🔥19🤔6👏4👍1🤯1
🚨 Patchwork hacking group is targeting Turkish missile contractors.
DisguiPatchworkous LNK files to launch a stealthy 5-stage spyware chain—right as Türkiye deepens defense ties with Pakistan.
Full story → https://thehackernews.com/2025/07/patchwork-targets-turkish-defense-firms.html
DisguiPatchworkous LNK files to launch a stealthy 5-stage spyware chain—right as Türkiye deepens defense ties with Pakistan.
Full story → https://thehackernews.com/2025/07/patchwork-targets-turkish-defense-firms.html
😁15🤯5👍3🔥2
⚡ U.S. sanctions hit a North Korean front company and 3 individuals running a fake IT worker scheme—used to infiltrate 300+ U.S. firms and fund Kim’s weapons program.
One U.S. woman helped run it all from a 90-laptop farm in Arizona.
Full story ↓ https://thehackernews.com/2025/07/us-sanctions-firm-behind-n-korean-it.html
One U.S. woman helped run it all from a 90-laptop farm in Arizona.
Full story ↓ https://thehackernews.com/2025/07/us-sanctions-firm-behind-n-korean-it.html
🤯33🔥7😁5🤔4😱2
🛑 In case you missed it — Over 4,600 attacks. 300+ orgs hit.
A China-linked threat group is exploiting SharePoint flaws to drop Warlock ransomware on unpatched systems.
Patch now. Details here → https://thehackernews.com/2025/07/storm-2603-exploits-sharepoint-flaws-to.html
A China-linked threat group is exploiting SharePoint flaws to drop Warlock ransomware on unpatched systems.
Patch now. Details here → https://thehackernews.com/2025/07/storm-2603-exploits-sharepoint-flaws-to.html
😁19🔥8👏7
🚨 Six flaws rated CVSS 9.8 in Honeywell’s Niagara Framework could let attackers hijack smart buildings—HVAC, lighting, even security.
One misconfig? They steal admin tokens, plant backdoors, and run root code.
Used worldwide. Patch now.
Details here ↓ https://thehackernews.com/2025/07/critical-flaws-in-niagara-framework.html
One misconfig? They steal admin tokens, plant backdoors, and run root code.
Used worldwide. Patch now.
Details here ↓ https://thehackernews.com/2025/07/critical-flaws-in-niagara-framework.html
👍13🤔3🤯3
Scattered Spider is now hijacking VMware ESXi hypervisors—not with malware, but fake help desk calls.
They impersonate admins, reset passwords, and deploy ransomware directly from the hypervisor.
Google says it's fast, stealthy, and crippling.
Full story → https://thehackernews.com/2025/07/scattered-spider-hijacks-vmware-esxi-to.html
They impersonate admins, reset passwords, and deploy ransomware directly from the hypervisor.
Google says it's fast, stealthy, and crippling.
Full story → https://thehackernews.com/2025/07/scattered-spider-hijacks-vmware-esxi-to.html
⚡19👏6😁6
⚡ Zero-days exploited. State-backed schemes exposed. Ransomware shifts.
From insider arrests to AI-powered fraud, here’s what mattered in cyber this week—no fluff, just the signal.
🧵 Read now ↓ https://thehackernews.com/2025/07/weekly-recap-sharepoint-breach-spyware.html
From insider arrests to AI-powered fraud, here’s what mattered in cyber this week—no fluff, just the signal.
🧵 Read now ↓ https://thehackernews.com/2025/07/weekly-recap-sharepoint-breach-spyware.html
🔥14
Phishing filters aren’t enough anymore.
Attackers don’t need malware—just one stolen login to pivot across email, OAuth, chats & files undetected.
It’s time email security caught up to EDR.
Here’s what that looks like ↓ https://thehackernews.com/2025/07/email-security-is-stuck-in-antivirus.html
Attackers don’t need malware—just one stolen login to pivot across email, OAuth, chats & files undetected.
It’s time email security caught up to EDR.
Here’s what that looks like ↓ https://thehackernews.com/2025/07/email-security-is-stuck-in-antivirus.html
👍18
🚨 Update: CISA just added CVE-2025-20281 and CVE-2025-20337 to its Known Exploited Vulnerabilities list.
These Cisco ISE flaws allow remote, unauthenticated attackers to gain root access — and they're already being exploited.
Feds must patch by Aug 18.
Everyone else: don’t wait.
Read → https://thehackernews.com/2025/07/cisco-confirms-active-exploits.html
These Cisco ISE flaws allow remote, unauthenticated attackers to gain root access — and they're already being exploited.
Feds must patch by Aug 18.
Everyone else: don’t wait.
Read → https://thehackernews.com/2025/07/cisco-confirms-active-exploits.html
😁13🔥6🤔2👏1
🔥 ALERT: Toptal's GitHub was HACKED — attackers pushed 10 malicious npm packages.
They stole GitHub tokens, wiped systems silently, and racked up 5,000+ downloads before detection.
Here’s what devs need to know ↓ https://thehackernews.com/2025/07/hackers-breach-toptal-github-publish-10.html
They stole GitHub tokens, wiped systems silently, and racked up 5,000+ downloads before detection.
Here’s what devs need to know ↓ https://thehackernews.com/2025/07/hackers-breach-toptal-github-publish-10.html
😱21😁9🤯8⚡5👏1
🚨 CISA just confirmed active exploitation of a critical PaperCut bug (CVE-2023-2533) — attackers can hijack admin sessions to run code remotely.
It’s being used by ransomware gangs right now.
Patch before August 18 or risk breach.
Full details → https://thehackernews.com/2025/07/cisa-adds-papercut-ngmf-csrf.html
It’s being used by ransomware gangs right now.
Patch before August 18 or risk breach.
Full details → https://thehackernews.com/2025/07/cisa-adds-papercut-ngmf-csrf.html
👏7