Cyber Security
Application Security
CMU Research: Copilot’s Safety Refusals Fail 100% in Workflow Mode
Andrew Doyle
July 10, 2026
Carnegie Mellon researchers found GitHub Copilot refuses harmful prompts 99% of the time in chat but produced harmful code in all 816 workflow-mode tests across ...
Application Security
Friendly Fire PoC Turns Claude Code and Codex Into Malware Launchers
Mitchell Langley
July 10, 2026
AI Now Institute's Friendly Fire PoC shows Claude Code and Codex in security-audit mode will execute disguised malware when seeded with strings from a legitimate ...
Cybersecurity
DigitalMint Employee Sentenced for BlackCat Ransomware Conspiracy
Mitchell Langley
July 10, 2026
A former DigitalMint employee received 70 months in prison for conspiring with BlackCat ransomware operators while posing as a trusted victim recovery advisor.
Application Security
Ill Bloom Flaw Drained $3.1M by Breaking Wallet Seed Randomness
Gabby Lee
July 10, 2026
Coinspect disclosed Ill Bloom, a weak entropy flaw in cryptocurrency wallet seed phrase generation that let attackers drain $3.1 million from affected wallets.
Cybersecurity
Threat Actors Use Aged GitHub Accounts to Map Corporate Orgs
Gabby Lee
July 10, 2026
Datadog Security Labs found threat actors using aged GitHub accounts to map corporate organization members and repositories before launching targeted attacks.
Cybersecurity
Microsoft Discloses GigaWiper: Disk Wiper Hidden Behind Fake Ransom
Andrew Doyle
July 10, 2026
Microsoft disclosed GigaWiper, a Windows backdoor combining a real disk wiper, fake ransomware encryption, and multi-pass file overwriting in a single payload.
Cybersecurity
GodDamn Ransomware Uses PoisonX Driver to Kill EDR Before Encrypting
Mitchell Langley
July 10, 2026
Symantec identified GodDamn ransomware using a kernel driver named PoisonX via the BYOVD technique to kill security software before file encryption begins.
Application Security
Injective Labs’ npm SDK Poisoned to Steal Crypto Wallet Credentials
Gabby Lee
July 10, 2026
Attackers compromised Injective Labs' repository and injected credential-stealing code into the authentic npm SDK packages used by DeFi blockchain developers.
Cybersecurity
Helix Group Uses Vishing and Device Code Flow to Steal SharePoint Data
Gabby Lee
July 10, 2026
New threat group Helix chains vishing with Microsoft's OAuth Device Code Flow to harvest M365 tokens and exfiltrate SharePoint data for corporate extortion.
Cybersecurity
Forg365 PhaaS Combines AiTM and Device Code Flow to Target M365
Mitchell Langley
July 10, 2026
Forg365 is a new phishing-as-a-service platform combining AiTM session hijacking and Device Code Flow abuse with AI-generated lures for mass targeting.
Cybersecurity
200 GitHub Repos Used as Dead Drop C2 Network for Windows Malware
Gabby Lee
July 10, 2026
Researchers exposed a network of 200 GitHub repositories serving as C2 dead drops for Windows malware, delivered via a malicious Go module and PowerShell chain.
CVE Vulnerability Alerts
Palo Alto Networks Patches 13 PAN-OS Flaws Including Auth Bypass
Mitchell Langley
July 10, 2026
Palo Alto Networks patched 13 PAN-OS vulnerabilities including buffer overflow, command injection, SSRF, and authentication bypass in its firewall platform.
Cybersecurity
NHS Forth Valley Employee Emails Maternity Data to Personal Account
Mitchell Langley
July 10, 2026
NHS Forth Valley disclosed a breach after a staff member emailed maternity patient data, including NHS numbers and pregnancy records, to a personal account.
Cybersecurity
EU Parliament Falls Short of Votes to Block Chat Control Return
Mitchell Langley
July 10, 2026
European Parliament voted 314-276 against EU Chat Control but fell short of the 360-seat absolute majority needed to block the message scanning law's return.
Application Security
OpenMandriva Linux Contributor Attempted Code Sabotage After Dispute
Mitchell Langley
July 10, 2026
OpenMandriva Linux caught a contributor sabotage attempt before production, disclosing the insider supply chain attack after an internal community dispute.
CVE Vulnerability Alerts
Seven FatFs Flaws Threaten Cameras, Drones, and Crypto Wallets
Andrew Doyle
July 10, 2026
runZero disclosed seven unpatched vulnerabilities in the FatFs filesystem library affecting hundreds of millions of IoT devices, drones, and hardware wallets.
Cybersecurity
Microsoft Warns AI Tools Will Accelerate Windows Patch Volumes
Andrew Doyle
July 10, 2026
Microsoft warned enterprises that its AI-assisted vulnerability discovery tools will produce higher Windows patch volumes and more frequent out-of-band updates.
Cybersecurity
IPNetwork Monitor Adds Native PostgreSQL Monitoring and One-Click Zabbix Import to Its Self-Hosted Platform
Mitchell Langley
July 10, 2026
IPNetwork Monitor LLC has released a major update to its self-hosted network and server monitoring platform, adding native PostgreSQL database ...
Application Security
CISA Adds ColdFusion, Langflow, Two Joomla CVEs to KEV
Andrew Doyle
July 8, 2026
CISA added four actively exploited flaws to KEV on July 7, requiring federal agencies to patch ColdFusion, Langflow, and two Joomla extensions by July 10.
CVE Vulnerability Alerts
Ubiquiti Patches Seven Critical UniFi OS Flaws, 100K at Risk
Mitchell Langley
July 8, 2026
Ubiquiti patched seven critical-to-maximum severity flaws in UniFi OS, led by CVE-2026-50746, a command injection requiring only network access to exploit.
Application Security
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
Gabby Lee
August 12, 2026
Application Security
CISA Adds Metabase SQL Injection Zero-Day to KEV With Aug 14 Deadline
Gabby Lee
August 12, 2026
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
Gabby Lee
August 12, 2026
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
Mitchell Langley
August 12, 2026
TOP CYBERSECURITY HEADLINES
This Week’s Security Spotlight
Cybersecurity
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
Andrew Doyle
August 11, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Ill Bloom Flaw Drained $3.1M by Breaking Wallet Seed Randomness
July 10, 2026
Coinspect disclosed Ill Bloom, a weak entropy flaw in cryptocurrency wallet seed phrase generation that let attackers drain $3.1 million from affected wallets.
Threat Actors Use Aged GitHub Accounts to Map Corporate Orgs
July 10, 2026
Datadog Security Labs found threat actors using aged GitHub accounts to map corporate organization members and repositories before launching targeted attacks.
Microsoft Discloses GigaWiper: Disk Wiper Hidden Behind Fake Ransom
July 10, 2026
Microsoft disclosed GigaWiper, a Windows backdoor combining a real disk wiper, fake ransomware encryption, and multi-pass file overwriting in a single payload.
GodDamn Ransomware Uses PoisonX Driver to Kill EDR Before Encrypting
July 10, 2026
Symantec identified GodDamn ransomware using a kernel driver named PoisonX via the BYOVD technique to kill security software before file encryption begins.
Injective Labs’ npm SDK Poisoned to Steal Crypto Wallet Credentials
July 10, 2026
Attackers compromised Injective Labs' repository and injected credential-stealing code into the authentic npm SDK packages used by DeFi blockchain developers.
Helix Group Uses Vishing and Device Code Flow to Steal SharePoint Data
July 10, 2026
New threat group Helix chains vishing with Microsoft's OAuth Device Code Flow to harvest M365 tokens and exfiltrate SharePoint data for corporate extortion.
Forg365 PhaaS Combines AiTM and Device Code Flow to Target M365
July 10, 2026
Forg365 is a new phishing-as-a-service platform combining AiTM session hijacking and Device Code Flow abuse with AI-generated lures for mass targeting.
200 GitHub Repos Used as Dead Drop C2 Network for Windows Malware
July 10, 2026
Researchers exposed a network of 200 GitHub repositories serving as C2 dead drops for Windows malware, delivered via a malicious Go module and PowerShell chain.
Palo Alto Networks Patches 13 PAN-OS Flaws Including Auth Bypass
July 10, 2026
Palo Alto Networks patched 13 PAN-OS vulnerabilities including buffer overflow, command injection, SSRF, and authentication bypass in its firewall platform.
NHS Forth Valley Employee Emails Maternity Data to Personal Account
July 10, 2026
NHS Forth Valley disclosed a breach after a staff member emailed maternity patient data, including NHS numbers and pregnancy records, to a personal account.
EU Parliament Falls Short of Votes to Block Chat Control Return
July 10, 2026
European Parliament voted 314-276 against EU Chat Control but fell short of the 360-seat absolute majority needed to block the message scanning law's return.
OpenMandriva Linux Contributor Attempted Code Sabotage After Dispute
July 10, 2026
OpenMandriva Linux caught a contributor sabotage attempt before production, disclosing the insider supply chain attack after an internal community dispute.
Seven FatFs Flaws Threaten Cameras, Drones, and Crypto Wallets
July 10, 2026
runZero disclosed seven unpatched vulnerabilities in the FatFs filesystem library affecting hundreds of millions of IoT devices, drones, and hardware wallets.
Microsoft Warns AI Tools Will Accelerate Windows Patch Volumes
July 10, 2026
Microsoft warned enterprises that its AI-assisted vulnerability discovery tools will produce higher Windows patch volumes and more frequent out-of-band updates.
IPNetwork Monitor Adds Native PostgreSQL Monitoring and One-Click Zabbix Import to Its Self-Hosted Platform
July 10, 2026
IPNetwork Monitor LLC has released a major update to its self-hosted network and server monitoring platform, adding native PostgreSQL database monitoring, a simplified way to ...
CISA Adds ColdFusion, Langflow, Two Joomla CVEs to KEV
July 8, 2026
CISA added four actively exploited flaws to KEV on July 7, requiring federal agencies to patch ColdFusion, Langflow, and two Joomla extensions by July 10.
Ubiquiti Patches Seven Critical UniFi OS Flaws, 100K at Risk
July 8, 2026
Ubiquiti patched seven critical-to-maximum severity flaws in UniFi OS, led by CVE-2026-50746, a command injection requiring only network access to exploit.
Accenture Confirms Breach After Hacker Lists 35 GB for Sale
July 8, 2026
Threat actor '888' listed 35 GB of Accenture source code, RSA keys, SSH keys, and Azure access tokens for sale on a criminal forum in ...
Cisco Talos Exposes UAT-7810 LONGLEASH Backdoor on Ruckus Routers
July 8, 2026
Cisco Talos disclosed UAT-7810, a China-linked APT building the LapDogs ORB relay network using LONGLEASH malware on compromised Ruckus and ASUS routers.
UK NCSC Publishes Cyber Shield Blueprint for AI Defense
July 8, 2026
The UK NCSC published its Cyber Shield blueprint on July 7, outlining autonomous AI agents to discover and remediate vulnerabilities across government networks.





































