🔒 Security News Digest - 2026-07-24
📊 8 updates from 4 sources:
🔹 The Hacker News: Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html
🔹 SecurityWeek: Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday
https://www.securityweek.com/industry-reactions-to-openai-models-hacking-hugging-face-feedback-friday/
🔹 The Hacker News: Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
https://thehackernews.com/2026/07/seeing-ai-agents-is-not-enough-security.html
🔹 The Hacker News: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html
🔹 The Hacker News: ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html
🦠 Malwarebytes: Beyond the Play Store: How Android threats really spread
https://www.malwarebytes.com/blog/inside-malwarebytes/2026/07/beyond-the-play-store-how-android-threats-really-spread
🔹 SecurityWeek: AegisAI Raises $36 Million for AI-Powered Email Security
https://www.securityweek.com/aegisai-raises-36-million-for-ai-powered-email-security/
🔹 darkreading: Vatican's Official Prayer App Leaks 700K+ Global Users' PII
https://www.darkreading.com/vulnerabilities-threats/vatican-official-prayer-app-leaks-700k-pii
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-23
📊 5 updates from 3 sources:
🔹 The Hacker News: Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
https://thehackernews.com/2026/07/check-point-patches-exploited.html
🔹 darkreading: Brazilian Banking Trojan Actively Spreading in Portugal
https://www.darkreading.com/cyberattacks-data-breaches/brazilian-banking-trojan-spreading-portugal
🔹 The Hacker News: Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html
🔹 SecurityWeek: New Check Point Zero-Day Vulnerability Exploited in the Wild
https://www.securityweek.com/new-check-point-zero-day-vulnerability-exploited-in-the-wild/
🔹 SecurityWeek: Assaf Keren Appointed New CISO of Meta
https://www.securityweek.com/assaf-keren-appointed-new-ciso-of-meta/
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-22
📊 7 updates from 4 sources:
🔹 The Record from Recorded Future News: French Parliament greenlights social media ban for under-15s
https://therecord.media/france-social-media-ban-parliament
🔹 The Hacker News: Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html
🔹 The Hacker News: GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
https://thehackernews.com/2026/07/github-cuts-public-bug-bounty-payouts.html
🔹 Security News | TechCrunch: How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
https://techcrunch.com/2026/07/22/how-an-openais-human-mistake-led-to-the-ai-powered-hack-on-hugging-face/
🔹 The Record from Recorded Future News: Federal agencies broaden alert on Iran-linked OT attacks
https://therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks
🔹 darkreading: Fake Bahrain Alert App Deploys Android Surveillance Malware
https://www.darkreading.com/mobile-security/fake-bahrain-alert-apps-android-surveillance-malware
🔹 The Record from Recorded Future News: Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill
https://therecord.media/cisa-2015-extension-passes-house-ndaa
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-22
📊 6 updates from 3 sources:
🔹 The Hacker News: Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html
🔹 SecurityWeek: OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face
https://www.securityweek.com/openai-says-its-ai-models-broke-loose-and-hacked-hugging-face/
🔹 SecurityWeek: Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife
https://www.securityweek.com/ransomware-group-threatening-to-leak-data-stolen-from-coca-colas-fairlife/
🔹 SecurityWeek: Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates
https://www.securityweek.com/oracle-patches-over-1400-vulnerabilities-with-quarterly-security-updates/
🔹 Security News | TechCrunch: Glow emerges from stealth at $1.2B valuation to challenge endpoint security in the AI era
https://techcrunch.com/2026/07/22/glow-emerges-from-stealth-at-1-2b-valuation-to-challenge-endpoint-security-in-the-ai-era/
🔹 SecurityWeek: Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation
https://www.securityweek.com/endpoint-security-firm-glow-launches-with-180m-in-funding-at-1-2b-valuation/
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-21
📊 7 updates from 5 sources:
🔹 SecurityWeek: Cisco Launches Low-Cost AI Models for Source Code Security
https://www.securityweek.com/cisco-launches-low-cost-ai-models-for-source-code-security/
🔹 SecurityWeek: Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
https://www.securityweek.com/trump-orders-defense-contractors-to-map-software-suppliers-across-critical-supply-chains/
🔹 darkreading: Hacker Turns AI Jailbreaks Into Offensive Attack Platform
https://www.darkreading.com/cyber-risk/hacker-ai-jailbreaks-offensive-attack-platform
🔹 The Hacker News: Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html
🔹 The Record from Recorded Future News: DNI nominee Clayton wins Senate panel’s approval
https://therecord.media/jay-clayton-dni-nomination-senate-committee-approval
🔹 Latest Bulletins: CVE-2026-15957 - Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes
https://aws.amazon.com/security/security-bulletins/rss/2026-061-aws/
🔹 Latest Bulletins: CVE-2026-16317 and CVE-2026-16318: Issues with s2n-tls: an open-source implementation of the TLS/SSL protocols
https://aws.amazon.com/security/security-bulletins/rss/2026-062-aws/
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-21
📊 13 updates from 5 sources:
🔹 SecurityWeek: Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
https://www.securityweek.com/estee-lauder-discloses-impact-from-oracle-ebs-zero-day-hack/
🔹 The Hacker News: New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html
🔹 SecurityWeek: CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
https://www.securityweek.com/ciso-conversations-andreas-gaetje-from-economics-to-ciso-at-korber-ag/
🦠 Malwarebytes: Don’t trust that “FBI agent” in your DMs
https://www.malwarebytes.com/blog/news/2026/07/dont-trust-that-fbi-agent-in-your-dms
🔹 The Hacker News: N-day is Becoming N-Hour. Patching Faster Won't Save You.
https://thehackernews.com/2026/07/n-day-is-becoming-n-hour-patching.html
🔹 SecurityWeek: New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
https://www.securityweek.com/new-hollowgraph-malware-abuses-microsoft-365-calendar-for-cc-communication/
🔹 The Hacker News: Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html
🦠 Malwarebytes: New ClickLock Stealer locks your Mac until you hand over your password
https://www.malwarebytes.com/blog/news/2026/07/new-clicklock-stealer-locks-your-mac-until-you-hand-over-your-password
🔹 The Record from Recorded Future News: Kenya probes hack of president's website after bitcoin ransom demand
https://therecord.media/kenya-probes-hack-of-presidents-website-after-ransom-demand
🔹 SecurityWeek: SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
https://www.securityweek.com/securityweek-launches-critical-impact-awards-to-recognize-excellence-in-industrial-cybersecurity/
🔹 SecurityWeek: Empirical Security Raises $25 Million in Series A Funding
https://www.securityweek.com/empirical-security-raises-25-million-in-series-a-funding/
🔹 darkreading: Choose Wisely: AI-Generated Coding Risk Varies, A Lot
https://www.darkreading.com/application-security/choose-wisely-ai-generated-coding-risk-varies
🔹 The Record from Recorded Future News: Taiwan to slow mobile data during national resilience drills
https://therecord.media/taiwan-mobile-5g-speed-reductions-han-kuang
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-20
📊 7 updates from 4 sources:
🔹 The Record from Recorded Future News: India says allegedly leaked nuclear plant files pose no safety risk
https://therecord.media/india-nuclear-plant-kudankulam-world-leaks-documents
🔹 The Hacker News: FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
🔹 darkreading: Attackers Combo Up Evasion Tactics for BEC Phishing
https://www.darkreading.com/endpoint-security/attackers-combo-evasion-tactics-bec-phishing
🔹 darkreading: CISOs Feel the Heat Over AI Risk
https://www.darkreading.com/cybersecurity-operations/cisos-feel-heat-ai-risk
🔹 Have I Been Pwned latest breaches: Suno - 55,282,226 breached accounts
https://haveibeenpwned.com/Breach/Suno
🔹 The Record from Recorded Future News: Flock Safety kills acoustic system designed to detect 'human distress'
https://therecord.media/flock-safety-kills-audio-detection-system-human-distress
🔹 darkreading: Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
https://www.darkreading.com/cybersecurity-operations/remediating-vulnerabilities-llms-ivanti-automation
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-20
📊 12 updates from 6 sources:
🔹 darkreading: Cybersecurity Keeps Events 'Uneventful'
https://www.darkreading.com/cyber-risk/cybersecurity-keeps-events-uneventful
🔹 SecurityWeek: SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
https://www.securityweek.com/sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch/
🔹 Security News | TechCrunch: Watch Flock Safety CEO Garrett Langley discuss the future of surveillance at TechCrunch Disrupt 2026
https://techcrunch.com/2026/07/20/watch-flock-safety-ceo-garrett-langley-discuss-the-future-of-surveillance-at-techcrunch-disrupt-2026/
🦠 Malwarebytes: Healthcare giant Abbott probes two cyber incidents amid extortion claims
https://www.malwarebytes.com/blog/data-breaches/2026/07/healthcare-giant-abbott-probes-two-cyber-incidents-amid-extortion-claims
🔹 The Hacker News: HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html
🔹 The Record from Recorded Future News: Romania races to restore land registry after cyberattack disrupts property market
https://therecord.media/romania-cyberattack-land-registry
🔹 SecurityWeek: Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software
https://www.securityweek.com/neo-emerges-from-stealth-with-100m-to-control-and-secure-enterprise-ai-software/
🔹 Security News | TechCrunch: Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies
https://techcrunch.com/2026/07/20/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/
🔹 The Record from Recorded Future News: Hackers were inside South Korea's diplomat training system for 9 months
https://therecord.media/south-korea-cyberattack-foreign-ministry
🔹 Security News | TechCrunch: Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/
🦠 Malwarebytes: The Odyssey piracy scams appear within hours of the movie’s release
https://www.malwarebytes.com/blog/threat-intel/2026/07/the-odyssey-piracy-scams-appear-within-hours-of-the-movies-release
🔹 The Record from Recorded Future News: More than 1,000 domains illegally streaming World Cup games seized, DOJ says
https://therecord.media/world-cup-illegal-streams-doj
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-20
📊 9 updates from 5 sources:
🦠 Malwarebytes: Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding
https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding
🔹 The Record from Recorded Future News: Software provider to more than 2,000 US hospitals says hackers stole employee and customer data
https://therecord.media/software-provider-for-us-hospitals-customer-data-breach
🔹 SecurityWeek: Ernst & Young Data Breach Affects Personal, Financial Information
https://www.securityweek.com/ernst-young-data-breach-affects-personal-financial-information/
🔹 The Hacker News: Mythos Didn't Break Your Security Program. Your Exposure Window Could.
https://thehackernews.com/2026/07/mythos-didnt-break-your-security.html
🔹 SecurityWeek: New Index Tracks Material Breaches — And Refuses to Add Up the Losses
https://www.securityweek.com/new-index-tracks-material-breaches-and-refuses-to-add-up-the-losses/
🔹 The Hacker News: Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
🔹 SecurityWeek: OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
https://www.securityweek.com/openssl-silently-fixes-hollowbyte-dos-vulnerability/
🔹 Security News | TechCrunch: Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
https://techcrunch.com/2026/07/20/hugging-face-confirms-breach-affected-internal-datasets-and-credentials-urges-users-to-take-action/
🔹 The Hacker News: ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
https://thehackernews.com/2026/07/weekly-recap-wordpress-rce-sonicwall-0.html
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-17
📊 6 updates from 3 sources:
🔹 The Hacker News: New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
🔹 The Hacker News: Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
🔹 Latest Bulletins: CVE-2026-12283 - Issue with Athena Federated Query Synapse Connector
https://aws.amazon.com/security/security-bulletins/rss/2026-059-aws/
🔹 Latest Bulletins: CVE-2026-15415 - Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server
https://aws.amazon.com/security/security-bulletins/rss/2026-060-aws/
🔹 darkreading: Inc Ransomware Exploits SonicWall SMA Zero-Days
https://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days
🔹 The Hacker News: OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-17
📊 5 updates from 4 sources:
🔹 The Record from Recorded Future News: Dairy company Fairlife suspends production in US after cyber incident
https://therecord.media/dairy-company-fairlife-suspends-production-us-cyber-incident
🔹 The Hacker News: Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html
🔹 SecurityWeek: In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
https://www.securityweek.com/in-other-news-iran-tracks-us-military-phones-crashstealer-macos-malware-cvd-blueprint/
🔹 Security News | TechCrunch: Amazon fixing bug that billed some AWS customers billions of dollars
https://techcrunch.com/2026/07/17/amazon-fixing-bug-that-billed-some-aws-customers-billions-of-dollars/
🔹 Security News | TechCrunch: FBI arrests man accused of using Steam games to drain victims’ crypto wallets
https://techcrunch.com/2026/07/17/fbi-arrests-man-accused-of-using-steam-games-to-drain-victims-crypto-wallets/
#InfoSec #SecurityNews
lobotomyenjoyer
@lobotomyenjoyer@infosec.exchange
infosec.exchange
Been reworking the news section - looking for some feedback.
Thinking about some filters, more sources like social media and reddit and maybe some categories.
https://uphillsecurity.com/news/
#security #securitynews
🔒 Security News Digest - 2026-07-17
📊 12 updates from 6 sources:
🔹 Unit 42: Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/
🦠 Malwarebytes: How to use GitHub safely
https://www.malwarebytes.com/blog/how-to/2026/07/how-to-use-github-safely
🔹 The Hacker News: Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html
🔹 SecurityWeek: Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday
https://www.securityweek.com/industry-reactions-to-pentagon-suspending-cmmc-phase-2-feedback-friday/
🔹 The Hacker News: The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
https://thehackernews.com/2026/07/the-race-to-field-military-autonomy-is.html
🔹 SecurityWeek: Beacon Security Raises $13 Million for Security Data Platform
https://www.securityweek.com/beacon-security-raises-13-million-for-security-data-platform/
🔹 The Hacker News: E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
https://thehackernews.com/2026/07/eu-orders-google-to-open-android-mic.html
🔹 darkreading: Google Bets 'Agentic Defense' Strategy Can Outpace Attackers
https://www.darkreading.com/cloud-security/google-bets-agentic-defense-strategy-outpace-attackers
🔹 SecurityWeek: Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive
https://www.securityweek.com/podcast-broken-governance-agentic-ai-and-the-mindstone-agent-exclusive/
🦠 Malwarebytes: Shark vacuum flaw exposes cameras, home maps and Wi-Fi passwords
https://www.malwarebytes.com/blog/news/2026/07/shark-vacuum-flaw-exposes-cameras-home-maps-and-wi-fi-passwords
🔹 The Record from Recorded Future News: Zelensky appoints Ukraine's acting security service chief as acting defense minister
https://therecord.media/ukraine-acting-defense-minister-yevhenii-khmara
🔹 darkreading: Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear
https://www.darkreading.com/vulnerabilities-threats/gold-eagle-clearinghouse-targets-security-gap
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-17
📊 5 updates from 2 sources:
🔹 SecurityWeek: Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack
https://www.securityweek.com/coca-cola-suspends-us-fairlife-production-due-to-ransomware-attack/
🔹 The Hacker News: CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html
🔹 SecurityWeek: Fresh SharePoint Vulnerability Exploited Soon After Disclosure
https://www.securityweek.com/fresh-sharepoint-vulnerability-exploited-soon-after-disclosure/
🔹 SecurityWeek: Risk Ledger Raises $32 Million in Series B Funding
https://www.securityweek.com/risk-ledger-raises-32-million-in-series-b-funding/
🔹 SecurityWeek: Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei
https://www.securityweek.com/cyberattack-disrupts-operations-of-japanese-frozen-food-giant-nichirei/
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-16
📊 10 updates from 6 sources:
🔹 The Record from Recorded Future News: Sandworm hackers have a CAPTCHA trick for Ukrainians
https://therecord.media/ukraine-sandworm-hacks-captcha-powershell
🦠 Malwarebytes: The backlash against Flock cameras is spreading
https://www.malwarebytes.com/blog/news/2026/07/the-backlash-against-flock-cameras-is-spreading
🔹 Threat Intelligence: Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management
https://cloud.google.com/blog/topics/threat-intelligence/ai-assisted-vulnerability-management/
🔹 Security News | TechCrunch: How a former DeepMind researcher raised at a $300M pre-seed valuation before launching a product
https://techcrunch.com/2026/07/16/how-a-former-deepmind-researcher-raised-at-a-300m-pre-seed-valuation-before-launching-a-product/
🔹 SecurityWeek: Legacy Systems, Real-World Impacts: The Reality of OT Security
https://www.securityweek.com/legacy-systems-real-world-impacts-the-reality-of-ot-security/
🔹 Security News | TechCrunch: Period tracker Stardust shares users’ health data with analytics firm, says Mozilla research
https://techcrunch.com/2026/07/16/period-tracker-stardust-shares-users-health-data-with-analytics-firm-says-mozilla-research/
🔹 Security News | TechCrunch: UK cops say arrest of two young hackers disrupted the operations of an infamous hacking group
https://techcrunch.com/2026/07/16/uk-cops-say-arrest-of-two-young-hackers-disrupted-the-operations-of-an-infamous-hacking-group/
🔹 The Hacker News: ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
https://thehackernews.com/2026/07/threatsday-game-cheat-spyware-24-hour.html
🔹 The Record from Recorded Future News: Ukrainians rally against dismissal of tech-minded defense minister Fedorov
https://therecord.media/ukraine-fedorov-drones-dismissal
🔹 The Record from Recorded Future News: UK investigates TikTok for alleged age-verification lapses, exposing kids to online harms
https://therecord.media/ofcom-investigation-tiktok-age-verification
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-16
📊 13 updates from 4 sources:
🔹 The Hacker News: AI Can Find Bugs, But Human Knowledge Still Proves Them
https://thehackernews.com/2026/07/ai-can-find-bugs-but-human-knowledge.html
🦠 Malwarebytes: Security updates available for Adobe, Chrome, Firefox, VMWare, and Zoom
https://www.malwarebytes.com/blog/bugs/2026/07/security-updates-available-for-adobe-chrome-firefox-vmware-and-zoom
🔹 SecurityWeek: Splunk, Zoom Patch Critical Vulnerabilities
https://www.securityweek.com/splunk-zoom-patch-critical-vulnerabilities/
🔹 The Hacker News: Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
https://thehackernews.com/2026/07/daxin-resurfaces-in-taiwan-alongside.html
🔹 SecurityWeek: Oak Emerges From Stealth Mode With $60 Million in Funding
https://www.securityweek.com/oak-emerges-from-stealth-mode-with-60-million-in-funding/
🔹 The Hacker News: New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
https://thehackernews.com/2026/07/new-agent-data-injection-attack-can.html
🔹 The Hacker News: 20+ Hijacked Government Websites Became
an Attack Channel
https://thehackernews.com/2026/07/20-hijacked-government-websites.html
🔹 The Record from Recorded Future News: Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack
https://therecord.media/scattered-spider-hackers-tfl-sentenced
🔹 The Hacker News: New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
https://thehackernews.com/2026/07/new-clicklock-macos-stealer-kills-apps.html
🔹 SecurityWeek: ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
https://www.securityweek.com/clicklock-stealer-bypasses-macos-security-with-social-engineering-process-killing/
🔹 The Hacker News: New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
https://thehackernews.com/2026/07/new-telepuz-malware-spreads-via.html
🔹 SecurityWeek: AI Data Centers Are Being Built Faster Than They Can Be Secured
https://www.securityweek.com/ai-data-centers-are-being-built-faster-than-they-can-be-secured/
🔹 SecurityWeek: Two Scattered Spider Hackers Sentenced to Jail in UK
https://www.securityweek.com/two-scattered-spider-hackers-sentenced-to-jail-in-uk/
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-15
📊 9 updates from 6 sources:
🔹 The Record from Recorded Future News: 23andMe reaches $18 million settlement with states for massive breach
https://therecord.media/genetic-testing-settlement-data-breach
🔹 The Record from Recorded Future News: Trump’s DNI pick grilled about election security, voter fraud
https://therecord.media/jay-clayton-odni-nominee-senate-confirmation-hearing
🔹 darkreading: Guten Tag, Bonjour, Hola to Our European Cyber Defenders!
https://www.darkreading.com/threat-intelligence/guten-tag-bonjour-hola-european-cyber-defenders
🔹 The Hacker News: TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
https://thehackernews.com/2026/07/tuxbot-v3-evolution-shows-signs-of-llm.html
🔹 Security News | TechCrunch: Microsoft patches bug in video game Age of Empires II
https://techcrunch.com/2026/07/15/microsoft-patches-bug-in-video-game-age-of-empires-ii/
🔹 Latest Bulletins: CVE-2026-15746 - Credential disclosure in Strands Agents Tools elasticsearch_memory tool
https://aws.amazon.com/security/security-bulletins/rss/2026-056-aws/
🔹 The Record from Recorded Future News: Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities
https://therecord.media/gold-eagle-cybersecurity-vulnerabilities-clearinghouse
🔹 darkreading: Identity Attacks Overtake Exploits as Top Ransomware Cause
https://www.darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause
🔹 iTnews - Security: Pentagon pauses cyber audit rule blamed for supplier exits
https://www.itnews.com.au/news/pentagon-pauses-cyber-audit-rule-blamed-for-supplier-exits-627399?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+Security+feed
#InfoSec #SecurityNews
Yazoul - Cybersecurity Alerts
@Matchbook3469@infosec.exchange
🔐 Yazoul Security — CVE Advisories · Data Breaches · Cyber News Automated security intelligence: daily CVE alerts, breach reports, correlated news, and learning resources. 🌐 www.yazoul.net 📨 Newsletter: www.yazoul.net/ 🔗 @yazoul@infosec.exchange #InfoSec #Cybersecurity #CVE #ThreatIntel #DataBreach
infosec.exchange
🔵 THREAT INTELLIGENCE
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
Vulnerability | CRITICAL
CVEs: CVE-2026-15409, CVE-2026-15410
SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day...
Full analysis:
https://www.yazoul.net/news/article/two-sonicwall-sma-1000-zero-days-exploited-one-could-enable-admin-commands
#ThreatIntel #SecurityNews #IncidentResponse
🔒 Security News Digest - 2026-07-15
📊 10 updates from 7 sources:
🔹 Threat Intelligence: The Risk of Exposed Cloud Functions and How to Harden
https://cloud.google.com/blog/topics/threat-intelligence/exposed-cloud-functions-harden/
🔹 SecurityWeek: CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-sharepoint-vulnerabilities/
🔹 The Record from Recorded Future News: Dutch police dismantle global crypto investment scam, arrest alleged mastermind
https://therecord.media/dutch-police-dismantle-global-crypto-investment-scam
🔹 Security News | TechCrunch: US charges Russian ‘bulletproof’ web hosts over cyberattacks that netted $62M from cybercrime victims
https://techcrunch.com/2026/07/15/us-charges-russian-bulletproof-web-hosts-over-cyberattacks-that-netted-62m-from-cybercrime-victims/
🦠 Malwarebytes: Claude for Chrome flaw could let rogue extensions access your Gmail
https://www.malwarebytes.com/blog/news/2026/07/claude-for-chrome-flaw-could-let-rogue-extensions-access-your-gmail
🔹 SecurityWeek: Unpatched Cursor Vulnerability Exposes Users to Code Execution
https://www.securityweek.com/unpatched-cursor-vulnerability-exposes-users-to-code-execution/
🔹 darkreading: Claude Flaw Automatically Sends Malicious Prompts to AI Agents
https://www.darkreading.com/vulnerabilities-threats/claude-flaw-malicious-prompts-ai-agents
🔹 The Hacker News: OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
https://thehackernews.com/2026/07/okobot-malware-framework-injects-seed.html
🔹 Security News | TechCrunch: Microsoft patches record number of security vulnerabilities, citing its use of AI
https://techcrunch.com/2026/07/15/microsoft-patches-record-number-of-security-vulnerabilities-citing-its-use-of-ai/
🔹 darkreading: Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
https://www.darkreading.com/cybersecurity-operations/tech-xit-uk-sovereignty-push-amid-ai-strife
#InfoSec #SecurityNews
🔒 Security News Digest - 2026-07-14
📊 8 updates from 3 sources:
🔹 SecurityWeek: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers
https://www.securityweek.com/us-allies-warn-of-russian-cyberattacks-targeting-critical-infrastructure-routers/
🦠 Malwarebytes: Warning: Scammers are using FaceTime to empty bank accounts
https://www.malwarebytes.com/blog/news/2026/07/warning-scammers-are-using-facetime-to-empty-bank-accounts
🔹 SecurityWeek: SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud
https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloud/
🔹 The Hacker News: OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
https://thehackernews.com/2026/07/oauth-client-id-spoofing-lets-attackers.html
🔹 The Hacker News: How Pentera Turns AI Security Workflows into Validation Engines
https://thehackernews.com/2026/07/how-pentera-turns-ai-security-workflows.html
🔹 The Hacker News: Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
https://thehackernews.com/2026/07/study-of-85-crypto-wallet-extensions.html
🔹 The Hacker News: 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
https://thehackernews.com/2026/07/11-old-microsoft-signed-linux-uefi.html
🔹 SecurityWeek: Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar
https://www.securityweek.com/unpatched-claude-for-chrome-flaw-lets-extensions-read-gmail-calendar/
#InfoSec #SecurityNews