Teleport has expanded its Identity Security platform with three new capabilities designed to ensure that agent behavior remains within defined boundaries: Beams Session Summaries, Agentic Classifiers, and Risk Scoring. They give enterprises a foundational harness for identifying and preventing agent…
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list…
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began…
Cyber Briefing: 2026.07.21
The social engineering surge meets the supply chain blind spot: why lagging security audits and vendor operational disruptions are putting healthcare and cloud assets in the crosshairs. This article has been indexed from CyberMaterial Read the original article: Cyber Briefing:…
Captive Portal Detection, (Tue, Jul 21st)
Not everything our honeypots detect is an attack. Sometimes it is just “odd traffic”, and this is one example: Our “First Seen” list currently includes “http://detectportal.firefox.co This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the…
Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers
Hackers are increasingly abusing decentralized infrastructure and legitimate development frameworks to evade detection, with a newly observed campaign leveraging Ethereum smart contracts to conceal command-and-control (C2) endpoints for the Amatera Stealer infostealer. These lures are propagated عبر malicious websites, file-sharing…
AI music platform Suno hits bum note as 55M users exposed in data breach, claims infosec expert
Have I Been Pwned confirms scale for first time This article has been indexed from www.theregister.com – Articles Read the original article: AI music platform Suno hits bum note as 55M users exposed in data breach, claims infosec expert
JadePuffer returns with ransomware built to target AI models and infrastructure
JadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure. The extortion contact embedded in the ransomware…
Russian Hacker Turns Jailbroken Claude Into Pentest Platform
Russian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude models This article has been indexed from www.infosecurity-magazine.com Read the original article: Russian Hacker Turns Jailbroken Claude Into Pentest Platform
Craneware Cyberattack Exposes Employee and US Healthcare Customer Data
Craneware plc, a UK-based provider of healthcare financial performance software, has disclosed that it experienced a cyberattack in which an unauthorized party accessed and extracted data from a portion of its systems. The company revealed that the incident involved employee…
Trump’s AI Safety Agency Chief Resigns After Just Three Months Leading CAISI
Chris Fall, the director of the U.S. Center for AI Standards and Innovation (CAISI), has resigned just three months after being appointed to lead the Commerce Department agency. This departure raises new uncertainties regarding the Trump administration’s agenda on AI…
New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops
In a significant evolution of the Project CAV3RN tooling, a new .NET Native AOT communication module dubbed AzureCommunication.dll has been deployed to replace the framework’s earlier HTTP/WebSocket C2 component. A stealthy channel that abuses Outlook calendar events over Microsoft Graph…
Forescout Report Reveals Surge in AI-Driven Cyber Threats
The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while…
Agentic JADEPUFFER Exploits Langflow Flaw to Deploy ENCFORGE AI Ransomware
A ransomware campaign is now targeting the assets behind artificial intelligence systems. The threat actor known as JADEPUFFER has evolved from damaging databases to deploying ENCFORGE, a ransomware strain designed to encrypt AI models, training data, and vector databases. The…
Hackers Hide Malware Commands in Outlook Events Dated 2050 and Use as C2 Channel
A newly identified malware component linked to the Project CAV3RN framework is abusing Microsoft Outlook calendar events scheduled for 2050 to conceal command-and-control (C2) traffic. The tool also uses DNS AAAA responses as a fallback channel to restore Microsoft Graph…
AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware
Malware operators are increasingly using tools built to extend artificial intelligence as a delivery route. A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model Context Protocol, or MCP, servers to distribute SmartLoader malware through trusted-looking GitHub projects…
Craneware Data Breach – Hackers Stole Significant Amount of Data
Healthcare financial software provider Craneware has confirmed a cybersecurity incident involving unauthorized access to a portion of its data environment. The company reported that threat actors viewed and exfiltrated a substantial number of file names, along with some employee data,…
Microsoft to Discontinue Podcasts Option on Copilot and to Delete Contents
Microsoft will retire the Podcasts feature in its consumer Copilot app on August 18, 2026, permanently removing access to both the creation tool and all previously generated podcast content. This change affects both free and paid Copilot users, including those…
Cisco’s open-weight Antares models make vulnerability localization cheaper
A security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to…
Druva brings backup, recovery and governance to AI workloads
Druva has announced Druva AI Resilience, a new approach that helps organizations recover, govern, and defend the systems, activity, and context behind AI-powered work. The launch introduces new and expanded capabilities for Microsoft Copilot, Claude Code, Druva Model Context Protocol…
HHS Seeks Input on CLIA Cybersecurity Updates
The Centers for Medicare and Medicaid Services (CMS) and the Centers for Disease Control and Prevention (CDC) have launched a request for information to modernize the Clinical Laboratory Improvement Amendments (CLIA) of 1988, with particular attention to cybersecurity and artificial…
95% of Security Teams Miss Vulnerabilities Between Tests
Enterprise security teams are consistently missing critical vulnerabilities because their testing schedules cannot keep pace with how rapidly their environments change, according to new research from Synack. This article has been indexed from CyberMaterial Read the original article: 95% of…
IT Security News Hourly Summary 2026-07-21 15h : 22 posts
22 posts were published in the last hour 13:4 : Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters 13:4 : 2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge 13:4 : A…
Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters
In April, SentinelLABS’ Tom Hegel published an initial assessment of the first five weeks of the conflict. Three months later, the evidence supports refinement. This article has been indexed from SentinelLabs – We are hunters, reversers, exploit developers, and tinkerers…