Cyber Security
Cybersecurity
DPRK macOS Malvertising Uses ClickFix to Steal Wallets and Cloud Keys
Mitchell Langley
July 31, 2026
North Korea-linked actors use fake macOS update pages and ClickFix prompts to deploy malware that drains crypto wallets and steals SSH, AWS, and Azure keys.
Application Security
Wiz CosmosEscape Chain Exposed Azure Cosmos DB Tenant Keys
Andrew Doyle
July 31, 2026
Wiz researchers showed an Azure Cosmos DB Gremlin sandbox escape could expose a platform-wide signing key that unlocks any tenant account's primary keys.
Application Security
AnySign4PC Zero-Day Watering Holes Hit 72 South Korean Organizations
Andrew Doyle
July 31, 2026
A state-sponsored campaign used hacked South Korean websites to exploit an AnySign4PC zero-day and infect visitors with SIGNBT and COPPERHEDGE backdoors.
Cybersecurity
Silver Fox BYOVD Chain Deploys ValleyRAT at Japanese Manufacturer
Andrew Doyle
July 31, 2026
Silver Fox used a new three-driver BYOVD attack chain and dual watchdog persistence to deliver ValleyRAT at a Japanese manufacturer through invoice lures.
Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Andrew Doyle
July 31, 2026
Anthropic said Claude models breached three real organizations during evaluations, including publishing PyPI malware that stole a security vendor's credentials.
Cybersecurity
South Korea Fines KT $39 Million Over 11-Month Breach
Mitchell Langley
July 31, 2026
South Korea's data regulator fined telecom giant KT KRW 53.979 billion after an 11-month breach exposed 16,647 subscribers' data through a rogue femtocell.
Cybersecurity
ShinyHunters Claims Brinks Home Breach of Up to 4.9 Million Records
Gabby Lee
July 31, 2026
ShinyHunters claims it breached Brinks Home in a Microsoft Entra vishing attack and stole up to 4.9 million Salesforce records and 3.8 million support chats.
Cybersecurity
Teams Vishing Campaigns Hit North American Firms With Chaos Ransomware
Gabby Lee
July 31, 2026
Sophos tracked a Teams vishing campaign as STAC4749, where fake IT support calls led to Chaos ransomware encryption at North American firms in under 17 ...
Cybersecurity
Analog Devices Discloses Breach as ExfilSquad Claims Link
Gabby Lee
July 31, 2026
Analog Devices said unauthorized parties exfiltrated files in a breach detected June 23, while extortion group ExfilSquad separately claimed a connection.
Application Security
Copilot for Word Copy-Paste Attack Still Exploitable
Andrew Doyle
July 31, 2026
Researcher Håkon Måløy showed hidden Word prompts can make Microsoft Copilot alter figures and propagate instructions into new documents despite mitigations.
Cybersecurity
Fengwo Group Ad-Fraud Uses TV Sticks That Spoof as Phones
Mitchell Langley
July 31, 2026
Bitsight found generic TV streaming sticks spoofing as phones and clicking ads on AI-generated sites in a Fengwo Group ad-fraud network worth $50,000 a day.
Application Security
Amazon Ties Debug, Chalk npm Hijacks to North Korean Group
Andrew Doyle
July 30, 2026
Amazon attributed debug and chalk npm hijack to North Korea's Sapphire Sleet, elevating a supply chain attack previously seen as financially motivated.
CVE Vulnerability Alerts
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
Mitchell Langley
July 30, 2026
CISA added the Cisco FMC zero-day CVE-2026-20316 to the KEV after active exploitation began. Cisco is also patching a critical FMC auth bypass rated CVSS ...
Application Security
Critical Rails Active Storage Flaw Lets Attackers Read Server Files
Andrew Doyle
July 30, 2026
The Rails framework patched CVE-2026-66066, a critical Active Storage flaw letting unauthenticated attackers read server files via crafted image uploads.
Application Security
CVSS 10.0 RufRoot Flaw Lets Attackers Hijack AI Agent Systems
Andrew Doyle
July 30, 2026
Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in agent memory.
Application Security
Russian Group Laundry Bear Exploited Exchange Zero-Day in OWA Attack
Andrew Doyle
July 30, 2026
Russian state-sponsored group Laundry Bear used a half-click Exchange zero-day to deploy the OWAReaper backdoor with credential-rotation-proof persistence.
Cybersecurity
Health-ISAC Warns Healthcare Sector of Rising ShinyHunters Attacks
Andrew Doyle
July 30, 2026
Health-ISAC warned of increased ShinyHunters attacks on healthcare using vishing to compromise SSO accounts and steal data from connected cloud platforms.
Cybersecurity
Nine-Year Fraud Campaign Cloned Russian Company Sites for Payments
Mitchell Langley
July 30, 2026
Russian cybersecurity firm F6 disclosed a nine-year fraud campaign cloning industrial company websites to steal advance payments from international firms.
Application Security
OpenAI’s Rogue AI Used JFrog Zero-Days to Breach Hugging Face
Mitchell Langley
July 29, 2026
A new postmortem reveals OpenAI's rogue AI model exploited JFrog Artifactory zero-days to escape its sandbox and breach Hugging Face and four other services.
CVE Vulnerability Alerts
Check Point SmartConsole Auth Bypass PoC Elevates Active Exploit Risk
Mitchell Langley
July 29, 2026
Rapid7 released a public PoC for CVE-2026-16232, a CVSS 9.3 Check Point SmartConsole authentication bypass already under active exploitation in the wild.
Cybersecurity
DPRK macOS Malvertising Uses ClickFix to Steal Wallets and Cloud Keys
Mitchell Langley
July 31, 2026
Application Security
Wiz CosmosEscape Chain Exposed Azure Cosmos DB Tenant Keys
Andrew Doyle
July 31, 2026
CVE Vulnerability Alerts
Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass
Mitchell Langley
July 28, 2026
TOP CYBERSECURITY HEADLINES
Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Cybersecurity
South Korea Fines KT $39 Million Over 11-Month Breach
This Week’s Security Spotlight
Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Andrew Doyle
July 31, 2026
CVE Vulnerability Alerts
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
Mitchell Langley
July 30, 2026
Application Security
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Gabby Lee
July 29, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Silver Fox BYOVD Chain Deploys ValleyRAT at Japanese Manufacturer
July 31, 2026
Silver Fox used a new three-driver BYOVD attack chain and dual watchdog persistence to deliver ValleyRAT at a Japanese manufacturer through invoice lures.
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
July 31, 2026
Anthropic said Claude models breached three real organizations during evaluations, including publishing PyPI malware that stole a security vendor's credentials.
South Korea Fines KT $39 Million Over 11-Month Breach
July 31, 2026
South Korea's data regulator fined telecom giant KT KRW 53.979 billion after an 11-month breach exposed 16,647 subscribers' data through a rogue femtocell.
ShinyHunters Claims Brinks Home Breach of Up to 4.9 Million Records
July 31, 2026
ShinyHunters claims it breached Brinks Home in a Microsoft Entra vishing attack and stole up to 4.9 million Salesforce records and 3.8 million support chats.
Teams Vishing Campaigns Hit North American Firms With Chaos Ransomware
July 31, 2026
Sophos tracked a Teams vishing campaign as STAC4749, where fake IT support calls led to Chaos ransomware encryption at North American firms in under 17 ...
Analog Devices Discloses Breach as ExfilSquad Claims Link
July 31, 2026
Analog Devices said unauthorized parties exfiltrated files in a breach detected June 23, while extortion group ExfilSquad separately claimed a connection.
Copilot for Word Copy-Paste Attack Still Exploitable
July 31, 2026
Researcher Håkon Måløy showed hidden Word prompts can make Microsoft Copilot alter figures and propagate instructions into new documents despite mitigations.
Fengwo Group Ad-Fraud Uses TV Sticks That Spoof as Phones
July 31, 2026
Bitsight found generic TV streaming sticks spoofing as phones and clicking ads on AI-generated sites in a Fengwo Group ad-fraud network worth $50,000 a day.
Amazon Ties Debug, Chalk npm Hijacks to North Korean Group
July 30, 2026
Amazon attributed debug and chalk npm hijack to North Korea's Sapphire Sleet, elevating a supply chain attack previously seen as financially motivated.
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
July 30, 2026
CISA added the Cisco FMC zero-day CVE-2026-20316 to the KEV after active exploitation began. Cisco is also patching a critical FMC auth bypass rated CVSS ...
Critical Rails Active Storage Flaw Lets Attackers Read Server Files
July 30, 2026
The Rails framework patched CVE-2026-66066, a critical Active Storage flaw letting unauthenticated attackers read server files via crafted image uploads.
CVSS 10.0 RufRoot Flaw Lets Attackers Hijack AI Agent Systems
July 30, 2026
Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in agent memory.
Russian Group Laundry Bear Exploited Exchange Zero-Day in OWA Attack
July 30, 2026
Russian state-sponsored group Laundry Bear used a half-click Exchange zero-day to deploy the OWAReaper backdoor with credential-rotation-proof persistence.
Health-ISAC Warns Healthcare Sector of Rising ShinyHunters Attacks
July 30, 2026
Health-ISAC warned of increased ShinyHunters attacks on healthcare using vishing to compromise SSO accounts and steal data from connected cloud platforms.
Nine-Year Fraud Campaign Cloned Russian Company Sites for Payments
July 30, 2026
Russian cybersecurity firm F6 disclosed a nine-year fraud campaign cloning industrial company websites to steal advance payments from international firms.
OpenAI’s Rogue AI Used JFrog Zero-Days to Breach Hugging Face
July 29, 2026
A new postmortem reveals OpenAI's rogue AI model exploited JFrog Artifactory zero-days to escape its sandbox and breach Hugging Face and four other services.
Check Point SmartConsole Auth Bypass PoC Elevates Active Exploit Risk
July 29, 2026
Rapid7 released a public PoC for CVE-2026-16232, a CVSS 9.3 Check Point SmartConsole authentication bypass already under active exploitation in the wild.
Firefox JIT Flaw CVE-2026-10702 Exposes Tor Browser to Deanonymization
July 29, 2026
Nebula Security published a full browser-to-kernel exploit chain for Firefox CVE-2026-10702, a JIT flaw that exposes Tor Browser users to deanonymization.
Gitea CVE-2026-60004 Gives Repo Writers Shell Access via Git Hooks
July 29, 2026
CVE-2026-60004 in Gitea 1.17–1.27.0 lets a repository writer execute arbitrary shell commands as the Gitea service account via malicious patch content.
OpenWrt CVE-2026-53921 Lets Attackers Root Routers via DHCPv6 Overflow
July 29, 2026
CVE-2026-53921, a CVSS 9.8 stack buffer overflow in OpenWrt's DHCPv6 server, lets unauthenticated attackers execute arbitrary code as root on affected routers.























