tomcat
If olive oil comes from olives 🫒 where does baby oil come from? 🤔 🥸
CrashStealer uses a signed and Apple-notarized macOS dropper to pass Gatekeeper checks.
Once launched, it can steal browser credentials, wallet data, password manager records, files, and keychain material.
How the attack chain works: https://thehackernews.com/2026/07/crashstealer-macos-malware-uses.html
🛑 A newly found 15-year-old #Linux kernel flaw, GhostLock (CVE-2026-43499), could let any logged-in user gain root on unpatched distributions.
A working exploit code is now public, and it escaped containers in tests.
Read details here: https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html
⚡ UPDATE: #wp2shell now has two CVEs, and a working proof-of-concept is public.
CVE-2026-63030 breaks REST batch routing CVE-2026-60137 injects SQL
Chained, they give an anonymous attacker code execution on affected WordPress sites.
How the exploit path works: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
🛑 Two Scattered Spider hackers have been sentenced to 5.5 years each for the £29 million TfL attack.
The intrusion left 148 systems inoperable, disrupted Dial-a-Ride and payment services, and forced all 27,000 employees into the office for password resets.
Here's how investigators tied them to the attack: https://thehackernews.com/2026/07/two-scattered-spider-hackers-get-55.html
⚠️ Researchers found raw LLM reasoning and an AI safety disclaimer left inside TuxBot v3 Evolution.
The unfinished IoT botnet packs 1,496 Telnet credential pairs and exploit code for more than 30 device families.
What already works: https://thehackernews.com/2026/07/tuxbot-v3-evolution-shows-signs-of-llm.html
🔥 Microsoft patched a record 622 CVEs, including two exploited zero-days in SharePoint Server and AD FS.
The SharePoint flaw allows remote, unauthenticated privilege escalation. The AD FS bug lets authenticated attackers elevate privileges locally.
Here's what to patch first: https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html
🚨 Zimbra has fixed a critical stored XSS flaw in its Classic Web Client.
A crafted email could run malicious code when opened and expose mailbox information, session data, or account settings.
Read the full story on THN 🠖 https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html
Zimbra has not reported in-the-wild exploitation. Update to version 10.1.19.
🛑 WARNING - Meta’s new Muse Image tool can let others use your public #Instagram photos in AI-generated images UNLESS you opt out.
Users can @-mention public Instagram accounts in Meta AI to pull public photos into new visuals, and existing AI creations may not be deleted after you disable reuse.
Here’s how to turn it off 🠖 https://thehackernews.com/2026/07/metas-new-ai-image-tool-lets-others-use.html