One mistaken approval inside Salesforce can hand attackers a quiet, durable route into a company’s most sensitive customer records. Recent campaigns tied to tradecraft associated with ShinyHunters show how a trusted application connection, rather than a software flaw, can be…
Category: Cyber Security News
xAI Grok Build CLI Uploaded Entire Git Repositories and Unredacted .env Secrets to Cloud Storage
A wire-level analysis of xAI’s Grok Build CLI revealed that version 0.2.93 transmitted unredacted file contents, including secrets from .env files, and uploaded full Git repositories along with their commit history to cloud storage These findings are based on traffic…
Turkish Banks Targeted by 8,400 Phishing Domains and 6,600 Social Media Scam Ads
Turkey’s banking customers are facing a large fraud campaign built around fake websites and social media advertisements. Criminals are abusing trusted financial brands to draw people into credential theft, fake loan offers, and other scams designed to steal money quickly.…
Maximizing SOC Efficiency: How to Eliminate Alert Overload and Cut MTTR by 21 Minutes Per Case
Security Operations Centers (SOCs) face overwhelming challenges not due to a lack of alerts but because each alert requires a new investigation. Analysts must validate indicators, identify malicious behavior, assess the scope of threats, and determine whether to contain or…
CISA Warns of Decades-Old Cisco IOS Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that attackers are actively exploiting CVE-2008-4128, a cross-site request forgery (CSRF) vulnerability affecting Cisco IOS versions 12.4(12) and 12.4(4). This vulnerability was added to CISA’s Known Exploited Vulnerabilities…
New Qilin Ransomware Attack Uses DCSync Technique to Abuse AD Replication Protocol
A recent Qilin ransomware intrusion has revealed a stealthy privilege escalation technique that abuses Active Directory’s built-in replication protocols to harvest domain credentials, including the coveted KRBTGT hash and NTLM password hashes for every account in the domain. Security researcher…
SAP Security Update July 2026 – Patch for Critical SAP NetWeaver Flaw that Enables Memory Corruption
SAP has released its July 2026 Security Patch Day updates, addressing a critical memory corruption vulnerability in the SAP NetWeaver Application Server ABAP. The most severe issue, tracked as CVE-2026-44747, has a CVSS score of 9.9 and affects multiple SAP…
UK and Allies Warn of Russian Hackers Actively Hacking Organizations’ Routers Worldwide
The UK, joined by international cybersecurity partners, has issued an urgent warning about Russian state-backed hackers targeting poorly secured routers and network devices worldwide. The alert focuses on Center 16, a cyber unit linked to Russia’s Federal Security Service, or…
Chrome Extension Used by 1.6 Million Users Silently Included Data Exfiltration Capabilities
A widely used browser extension, ModHeader, has been removed from the Chrome Web Store after researchers found that its signed release contained a dormant capability to collect, encrypt, and potentially upload users’ browsing-domain data. The extension reportedly had about 1.6…
Telegram’s t.me Domain Suspended, ServerHold Status Breaks Links Worldwide
Telegram’s core t[.]me domain has been placed on serverHold at the .me registry, a registry-level status that removes the domain from the global DNS and breaks every t[.]me short link worldwide. WHOIS records confirm the domain now carries eight status…
New macOS Stealer Mimics Apple’s Crash Report Framework to Steal Browser Credentials
CrashStealer, a native C++ macOS infostealer that disguises itself as Apple’s built-in crash-reporting utility to harvest browser credentials, cryptocurrency wallets, password manager data, and keychain contents before encrypting and exfiltrating everything to a remote command-and-control server. Jamf first spotted a…
NSA Urges Organizations to Disable Cisco Smart Install as Russian Hackers Target Routers
The National Security Agency, alongside 17 international partner agencies, released a joint Cybersecurity Advisory on July 9, 2026, warning that Russian state-sponsored actors continue to exploit vulnerable and poorly configured network infrastructure across critical sectors. The advisory, titled “Improve Router…
AI-Powered ‘Intelligent Worm’ Could Regenerate Exploits and Adapt to Defenses in Real Time
A new threat model is raising hard questions about how quickly self-spreading malware could change during an attack. The proposed Intelligent Worm is not a confirmed strain found in the wild, but a scenario in which a worm uses an…
CISA Warns of Joomla Sites Running iCagenda or Balbooa Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has added two high-risk Joomla extension flaws to its Known Exploited Vulnerabilities (KEV) Catalog. Both vulnerabilities allow unrestricted file uploads, a weakness that attackers can abuse to upload malicious files and potentially take…
Hackers Using Vibe-Coded Generated PowerShell Script to Enumerate Active Directory Accounts
Threat actors have started weaponizing AI-generated PowerShell code to map Active Directory (AD) environments, marking a notable shift from off-the-shelf hacking tools to bespoke, “vibe-coded” malware. Security researchers at Huntress recovered and reconstructed one such script, dubbed Untitled1.ps1, from an…
Debian 13 Released With Security Updates, Bug Fixes and Driver Updates
The Debian Project has released Debian 13.6, the latest maintenance update for Debian 13 “trixie.” The point release focuses on security corrections and fixes for serious software issues across the operating system’s package collection. Debian 13.6 is not a new…
iPhone and MacBook Forensics Investigation Exposes £113,000 Property Fraud Operation
A digital forensics investigation from Belkasoft into an iPhone and a damaged MacBook has helped secure the conviction of Jason Cunningham, a rent-to-rent property operator who defrauded landlords and investors of more than £113,000 through forged contracts and false promises.…
Armored Likho APT Uses AI-Generated Loaders to Deploy BusySnake Stealer Against Government Targets
Armored Likho has launched a phishing campaign that uses AI-generated loaders to deploy the newly identified BusySnake Stealer. The operation has targeted government agencies and electrical power organizations, putting sensitive public-sector data and essential services at risk. Confirmed victims span…
VEXAIoT Multi-Agent System Automates IoT Reconnaissance and Exploit Execution
Security researchers have introduced VEXAIoT, an AI-powered multi-agent framework designed to automate vulnerability discovery and exploit execution against Internet of Things environments. The research shows how large language model agents can coordinate reconnaissance, attack planning, command generation, and result validation…
Critical WordPress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website
A critical security vulnerability has been discovered in the widely used WordPress OAuth Single Sign–On (SSO (OAuth Client) plugin developed by miniOrange, exposing millions of WordPress websites to complete takeover by unauthenticated remote attackers. The flaw, tracked as CVE-2026-57807, carries…