Cyber Security
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
SMOKE#SCREEN Deploys ScreenConnect via Fake Adobe, Zoom Lures
Claude Mythos 5 Tried to Backdoor a Project in UK AI Security Test
Google Deletes Three ADK AI Workflows After Prompt-Injection Attack
cPanel Patches Critical Flaw Letting Customers Run SQL as Root
TP-Link Omada Provisioning Flaws Enable Full Network Takeover
Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts
XCSSET v40 Malware Targets macOS Developers via Xcode Projects
tl;dv AI Notetaker Flaw Exposes Government, Corporate Calls
US Water Sector Attacks Hit 12 States, Georgia Confirmed
Unit 42 Details Pass-ta-key Attacks on Google-Synced Passkeys
Malicious npm Packages Deliver RAT to Alibaba Developer Tools
Poisoned Xanadu mrmustard Package Steals SSH Keys and AWS Credentials
Leaked DarkSword Kit Deploys GHOSTBLADE Stealer on iOS Devices
ExfilSquad Leaks Contact Data of 100,000 UK Police Officers
DOUBLECUP ClickFix Loader Hides Malware in Browser Cache Images
Fake Roblox Xeno Executor Installers Deliver Info-Stealer RAT
Liechtenstein Register Breach Exposes Data of 31,000 People
UKGI Left Officials’ Contact Details Exposed for 40 Hours
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
Thermo Fisher Patches DNA File Tampering Flaw CVE-2026-17583
FaceHugger Flaws in Hugging Face Diffusers Bypass trust_remote_code
Hackers Poison Adform Script to Rewrite Crypto Wallet Addresses
Coldcard Firmware Flaw Linked to $88.6M Bitcoin Sweep
Microsoft Links Hotel Wi-Fi Attacks to Storm-2945 Midnight Blizzard
N-able Warns Attackers Reached Managed Endpoints via N-central Flaw
US Water Sector Attacks Spread to Seven States as Iran Link Emerges
Cloud Access Security Broker (CASB) Explained: Architecture and Uses
DPRK macOS Malvertising Uses ClickFix to Steal Wallets and Cloud Keys
Wiz CosmosEscape Chain Exposed Azure Cosmos DB Tenant Keys
Cybersecurity
TELESHIM Backdoor Hits Middle East Governments via Telegram C2
Zscaler ThreatLabz uncovered TELESHIM, MIXEDKEY, and BINDCLOAK — three new malware families an East Asia-linked APT used against Middle Eastern governments.
Cybersecurity
DentaQuest Breach Affects 23.4 Million, PHI and SSNs Exposed
DentaQuest's breach notification confirms up to 23.4 million Medicaid dental enrollees potentially affected, with SSNs and dental PHI stolen in a network hack.
Cybersecurity
PEAR Ransomware Breach at MCBS Hits 1.26 Million Patients
PEAR ransomware group claimed 3 TB stolen from MCBS, a medical billing firm whose breach exposed 1.26 million patients at seven healthcare organizations.
Application Security
SourTrade Malvertising Assembles Malware in Browser Memory
SourTrade malvertising downloads encrypted fragments and assembles a Windows executable in browser memory, evading file-based detection across 12 countries.
Cybersecurity
ShinyHunters Breach Data Fuels $2,000 Bitcoin Sextortion Wave
Attackers are sending $2,000 Bitcoin sextortion emails that cite specific ShinyHunters-breached companies to make false surveillance threats appear credible.
Cybersecurity
Steam ClickFix Campaign Installs SYSTEM-Level XMRig Miner
Attackers target Steam discussion forums with ClickFix social engineering, tricking players into running PowerShell that installs a SYSTEM-level XMRig miner.
Application Security
GitHub and PyPI Add Time-Based Defenses Against Supply Chain Poisoning
GitHub's new Dependabot 72-hour cooldown and PyPI's 14-day release lock target two supply chain attack vectors that compromised major package ecosystems.
Application Security
Rockwell Patches Four Arena Code Execution Flaws Across Sectors
Rockwell Automation patched four memory corruption CVEs in Arena, its simulation software used by hospitals, supply chain firms, and defense contractors.
Cybersecurity
Scattered Spider TfL Hackers Sentenced to Five and a Half Years
UK authorities sentenced two Scattered Spider members to five-and-a-half years each for the 2024 Transport for London attack, the UK's largest cybercrime case.
Cybersecurity
ClickLock macOS Stealer Uses App-Kill Loop to Coerce Passwords
Group-IB documented ClickLock, a macOS stealer using a 210ms app-kill loop to coerce macOS passwords, hitting more than 100 victims across 33 countries.
Cybersecurity
Elastic Exposes TELEPUZ: C Malware Sold as MaaS via ClickFix Chain
Elastic Security Labs disclosed TELEPUZ, a C-based malware distributed through a ClickFix-to-Vidar chain with VirusTotal volumes indicating a MaaS operation.
Cybersecurity
Russian Threat Actor Uses Gemini CLI to Run Dental Clinic Botnet
Trend Micro documented Russian actor 'bandcampro' using Gemini CLI as a hacking assistant in a dental clinic botnet attack on an OpenDental patient database.
Cybersecurity
DragonForce Posts Eighteen Victims Across Eight Countries in 48 Hours
DragonForce posted eighteen victims across eight countries in 48 hours, including a US defense subcontractor, four law firms, and chemical manufacturers.
Cybersecurity
Coca-Cola Files SEC 8-K After Ransomware Hits Fairlife Dairy
Coca-Cola filed an SEC Form 8-K disclosing a ransomware attack on Fairlife dairy that suspended all U.S. production. No group has yet claimed the attack.
Application Security
CISA Adds SharePoint CVE-2026-58644 to KEV After Zero-Day Confirmed
CISA added SharePoint CVE-2026-58644, a CVSS 9.8 deserialization flaw, to KEV after Microsoft confirmed zero-day exploitation. Federal deadline is July 19.
CVE Vulnerability Alerts
CISA Issues Sunday Patch Deadline for Fortinet FortiSandbox RCE Flaws
CISA added CVE-2026-25089 and CVE-2026-39808 in Fortinet FortiSandbox to KEV, ordering FCEB agencies to patch by July 19 amid confirmed active exploitation.
Cybersecurity
23andMe Pays $18M to 43 State AGs Over Genetic Data Breach
Coalition of 43 state AGs reaches $18M settlement with 23andMe successor Chrome Holding Co. over its genetic data breach; total penalties exceed $50 million.
Cybersecurity
Italy Fines WINDTRE €1.7M for Breaches Exposing 365K Customers
Italy's Garante fined telecom operator WINDTRE €1.7 million for two 2024 data breaches in which social engineering attacks exposed data on 365,000 customers.
Cybersecurity
Interlock Hits DC Housing Authority; Play, Nova Post New Victims
Interlock ransomware targeted DC's public housing agency; Play posted five victims across four countries; Nova added three more in a multi-group batch.
Cybersecurity
Nightmare Eclipse Drops LegacyHive PoC on Fully Patched Windows
Security group Nightmare Eclipse released LegacyHive, a PoC targeting an unpatched Windows privilege escalation flaw that survived July Patch Tuesday.
Application Security
Open VSX Purges 77 Evil-Twin Extensions Stealing Developer Data
Application Security
ChainDrop npm Worm Poisons 440 Packages, Steals Cloud Credentials

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Application Security
Claude Models Breached 3 Real Firms During Anthropic Cyber Tests
Cybersecurity
South Korea Fines KT $39 Million Over 11-Month Breach
CVE Vulnerability Alerts
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
Application Security
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
SourTrade Malvertising Assembles Malware in Browser Memory
SourTrade malvertising downloads encrypted fragments and assembles a Windows executable in browser memory, evading file-based detection across 12 countries.
ShinyHunters Breach Data Fuels $2,000 Bitcoin Sextortion Wave
Attackers are sending $2,000 Bitcoin sextortion emails that cite specific ShinyHunters-breached companies to make false surveillance threats appear credible.
Steam ClickFix Campaign Installs SYSTEM-Level XMRig Miner
Attackers target Steam discussion forums with ClickFix social engineering, tricking players into running PowerShell that installs a SYSTEM-level XMRig miner.
GitHub and PyPI Add Time-Based Defenses Against Supply Chain Poisoning
GitHub's new Dependabot 72-hour cooldown and PyPI's 14-day release lock target two supply chain attack vectors that compromised major package ecosystems.
Rockwell Patches Four Arena Code Execution Flaws Across Sectors
Rockwell Automation patched four memory corruption CVEs in Arena, its simulation software used by hospitals, supply chain firms, and defense contractors.
Scattered Spider TfL Hackers Sentenced to Five and a Half Years
UK authorities sentenced two Scattered Spider members to five-and-a-half years each for the 2024 Transport for London attack, the UK's largest cybercrime case.
ClickLock macOS Stealer Uses App-Kill Loop to Coerce Passwords
Group-IB documented ClickLock, a macOS stealer using a 210ms app-kill loop to coerce macOS passwords, hitting more than 100 victims across 33 countries.
Elastic Exposes TELEPUZ: C Malware Sold as MaaS via ClickFix Chain
Elastic Security Labs disclosed TELEPUZ, a C-based malware distributed through a ClickFix-to-Vidar chain with VirusTotal volumes indicating a MaaS operation.
Russian Threat Actor Uses Gemini CLI to Run Dental Clinic Botnet
Trend Micro documented Russian actor 'bandcampro' using Gemini CLI as a hacking assistant in a dental clinic botnet attack on an OpenDental patient database.
DragonForce Posts Eighteen Victims Across Eight Countries in 48 Hours
DragonForce posted eighteen victims across eight countries in 48 hours, including a US defense subcontractor, four law firms, and chemical manufacturers.
Coca-Cola Files SEC 8-K After Ransomware Hits Fairlife Dairy
Coca-Cola filed an SEC Form 8-K disclosing a ransomware attack on Fairlife dairy that suspended all U.S. production. No group has yet claimed the attack.
CISA Adds SharePoint CVE-2026-58644 to KEV After Zero-Day Confirmed
CISA added SharePoint CVE-2026-58644, a CVSS 9.8 deserialization flaw, to KEV after Microsoft confirmed zero-day exploitation. Federal deadline is July 19.
CISA Issues Sunday Patch Deadline for Fortinet FortiSandbox RCE Flaws
CISA added CVE-2026-25089 and CVE-2026-39808 in Fortinet FortiSandbox to KEV, ordering FCEB agencies to patch by July 19 amid confirmed active exploitation.
23andMe Pays $18M to 43 State AGs Over Genetic Data Breach
Coalition of 43 state AGs reaches $18M settlement with 23andMe successor Chrome Holding Co. over its genetic data breach; total penalties exceed $50 million.
Italy Fines WINDTRE €1.7M for Breaches Exposing 365K Customers
Italy's Garante fined telecom operator WINDTRE €1.7 million for two 2024 data breaches in which social engineering attacks exposed data on 365,000 customers.
Interlock Hits DC Housing Authority; Play, Nova Post New Victims
Interlock ransomware targeted DC's public housing agency; Play posted five victims across four countries; Nova added three more in a multi-group batch.
Nightmare Eclipse Drops LegacyHive PoC on Fully Patched Windows
Security group Nightmare Eclipse released LegacyHive, a PoC targeting an unpatched Windows privilege escalation flaw that survived July Patch Tuesday.
Zoom Patches CVE-2026-53412 Critical Unauthenticated Account Takeover
Zoom patched CVE-2026-53412, a CVSS 9.8 flaw in Zoom Workplace for Windows allowing unauthenticated remote account takeover with no user interaction required.
Cursor AI Code Execution Flaw Left Unpatched Seven Months by Developer
Mindgard researcher Aaron Portnoy disclosed a code execution flaw in Cursor AI editor that silently runs trojanized git.exe files when developers clone malicious repos.
ServiceNow Patches CVE-2026-6875 Unauthenticated RCE in AI Platform
ServiceNow patched CVE-2026-6875, a CVSS 9.5 unauthenticated remote code execution flaw in its AI platform; hosted instances auto-patched, self-hosted require manual update.