Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that https://www.chatirwebdesign.com/tag/data-security GitLab patched six weeks earlier, on June 10. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Confiant’s analysis documents the delivery, not execution of the file inside the browser, and does not establish whether the fina… Its landing pages fingerprint visitors, showing suspected researchers and bots an empty page while selected targets receive a convincing copy of the impersonated service.
As part of Dark Reading’s 20th anniversary special coverage, we profile the CISOs, founders, researchers, criminals, and policymakers who rewrote the enterprise risk playbook. German and U.S. authorities dismantle a major phishing-as-a-service (PhaaS) platform. A Paidwork breach affects over 23 million users. The second story looks at how existing copyright laws are not robust enough to handle how AI models are ingesting content.
The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems. The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. A chain of vulnerabilities in the Adobe Acrobat Chrome extension could have allowed attackers to steal content from a victim’s … Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant’s identity and access others’ data, credentials, and cloud workloads. ” BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet reconnaissance and malware delivery into a repeatable victim acquisition pipeline,” JUMPSEC said in a detailed report shared with The Hacker News. “The portal combined build generation, finance, victim chat, support, victim records, teams, and payout functions,” the company said in an extensive report shared with The Hacker News.
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
More than 2.2 million vehicles equipped with dealer-installed aftermarket anti-theft systems are vulnerable to a Bluetooth … Breaking cybersecurity news, news analysis, commentary, and other content from around the world. Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate privileged users. Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends.
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
- Dark Reading editors reflect on two decades of dramatic change — from perimeter defense to assume-breach strategies — and warn that while AI, cloud, and COVID-19 have transformed the threat landscape, organizations are still failing at fundamental security hygiene that could stop sophisticated attacks in their tracks.
- The conversation explores how supply-chain dependencies can undermine national and regional independence, even when satellites and launch systems are built domestically.
- Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim’s organization.
- Boards and security teams each say they need more support to bridge the divide.
Dolphin X uses AI profiling to find high-value victims. The Feds warn of Iranian agents targeting OT systems. Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer. A researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations. The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company.
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and cryptocurrency investors across 12 countries in 25 languages. The cybersecurity firm said it detected the campaign earlier this month. The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East.
Bluetooth flaw exposes 2.2 million cars to unlocking attacks
The new Mobile Security Exposure Center creates SBOMs https://alabama-news.com/what-are-website-migration-service-and-why-do-you-need-them.html for enterprise mobile apps to uncover vulnerable components, dependencies and hidden risks. The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. Upon gaining an initial foothold, the attackers have been found to conduct file system enumeration, stage engineering/design data, and ultimately carry out double extortion data theft. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose.
- The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
- Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends.
- Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant’s identity and access others’ data, credentials, and cloud workloads.
- A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees.
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. Instead of harvesting credentials for later use, attackers now synchronize their activity with victims in real time, authenticating against legitimate insurance portals as victims unknowingly complete the login process. “Cruciferra is written in Mono and features numerous techniques designed to evade detection, analysis, and incident response efforts,” the enterprise security company said in an analysis published last week. The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra .
The first involves how politicians are trying to combat how AI chatbots spread inaccurate or incomplete information on their campaigns to voters. Ben Yelin explains how political campaigns attempt to influence LLMs. A new benchmark evaluates frontier AI model malware reverse engineering. Extortion group wipes Romania’s land registry database. The conversation explores how supply-chain dependencies can undermine national and regional independence, even when https://openscience.us/repo/other/capec.html satellites and launch systems are built domestically. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
Five things successful IT teams get right about SaaS management
A newly discovered remote access Trojan called MedusaHVNC lets attackers open a hidden virtual desktop on a victim’s own computer, quietly loading their real… Chick-fil-A has notified customers that attackers accessed some Chick-fil-A One loyalty accounts after launching a credential … A newly identified Windows malware called Dolphin X combines information-stealing capabilities with remote access features … Hackers believed to be Cl0p ransomware operatives are exploiting a critical flaw in PTC Windchill and FlexPLM to deploy web … Core issues that slowed down adoption of secure data vaults are being resolved by technology, but artificial intelligence poses new ones. Cutting-edge artificial intelligence models are deploying with more independence and less human oversight.
- The company plans to expand its research team, open new offices in Rome and San Francisco, and acquire new clients.
- According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote access trojans (RATs) and information stealer malware.
- Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.
- A newly discovered remote access Trojan called MedusaHVNC lets attackers open a hidden virtual desktop on a victim’s own computer, quietly loading their real…
- A chain of vulnerabilities in the Adobe Acrobat Chrome extension could have allowed attackers to steal content from a victim’s …
Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis . Targets of the campaign include manufacturing, automotive, aerospace, and retail sectors. As phishing campaigns become more sophisticated, simply identifying malicious websites and impersonation domains is no longer enough. No administrator rights, no CI or runner access, no victim interaction, no access to anyone else’s project.

