173 posts were published in the last hour
- 21:46 : Cruciferra Crypter Evades Detection to Deliver Malware
- 21:46 : Cisco’s open-weight bug busters take on Google and OpenAI
- 20:34 : Linux Kernel Published 440 Security Advisories— In 24hrs Here’s Why
- 20:34 : Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention
- 20:34 : Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record
- 20:34 : Hackers Turn Fake Games Into Multi-Stage Infostealers That Steal Passwords and Crypto Wallets
- 20:34 : Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
- 20:4 : AI’s cheatin’ heart will make you weep
- 19:34 : Wansview IoT Camera Flaw Exposes Supply Chain Security Risks
- 19:34 : Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug
- 19:5 : IT Security News Hourly Summary 2026-07-21 21h : 6 posts
- 18:35 : Trump’s AI Safety Chief Quits Just Three Months After Taking Charge
- 18:34 : Hackers Hijack 20+ Government Websites to Deliver Malware Through Trusted Links
- 18:34 : This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk
- 18:34 : Gemini 3.5 Flash Cyber With Automated Faster Vulnerability Detection and Patch Capabilities
- 18:34 : Now You Can teach a Skill to Claude by Just Recording your Screen
- 18:34 : Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
- 18:2 : Hardening MCP Gateways: Mitigating July 28 Security Risks in Java Applications
- 18:2 : AI Cybercrime Report Warns of Emerging AI-Powered Threats
- 18:2 : Cisco Launches Low-Cost AI Models for Source Code Security
- 17:34 : Volume Is Not Risk: Making Sense of the “Vulnpocalypse”
- 17:34 : Why Do Some Proxies Work Fine for Search But Fail Once You Start Filtering Results?
- 17:34 : Behavioral biometrics: How to detect nonhuman threat actors
- 17:33 : Do more with AWS WAF labels using dynamic label interpolation
- 17:4 : Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
- 17:4 : AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
- 16:34 : A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
- 16:34 : Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access
- 16:34 : Kratos phishing-as-a-service kit loses its battle with international law enforcement
- 16:5 : IT Security News Hourly Summary 2026-07-21 18h : 9 posts
- 16:4 : Craneware Confirms Data Theft After Cyberattack, Investigations Underway
- 16:4 : UK Biobank Data Breach Rekindles Debate Over Research Data Security
- 15:34 : Don’t Trust the Lock: Chrome Browser Vulnerability That Spoofs Trusted URLs
- 15:33 : Top 10 Malware Used by Hackers Last Week to Launch Cyberattacks
- 15:33 : Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild
- 15:33 : APT42 Uses AI-Assisted Phishing and TAMECAT Malware to Target Government and Defense Officials
- 15:32 : What happens if you visit a WordPress site hacked through wp2shell?
- 15:32 : Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
- 15:31 : Ransomware victims fail to fix flaws that exposed them
- 15:3 : Akamai Recognized as a Customers’ Choice in the 2026 Gartner® Peer Insights™ Voice of the Customer for Edge Distribution Platforms
- 15:3 : Fig Expands SecOps Engineering Lifecycle as Security Teams Seek More Resilient Infrastructure
- 15:3 : Behavioral biometrics: How to detect non-human threat actors
- 15:3 : AI music generator Suno breach affects 55M users, per Have I Been Pwned
- 15:3 : KeeperPAM strengthens privileged access management for global construction SaaS provider Asite
- 15:2 : Why AI Agents Are Challenging Identity Security
- 15:2 : Regular Website Maintenance: Why It Matters
- 15:2 : AI Agents Expose Growing Identity Security Gaps in Enterprise Environments
- 15:2 : AI agents tricked into recommending malicious GitHub repositories
- 14:35 : Teleport enhances Identity Security platform with new AI agent behavior controls
- 14:35 : Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
- 14:34 : Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
- 14:34 : Cyber Briefing: 2026.07.21
- 14:7 : Captive Portal Detection, (Tue, Jul 21st)
- 14:7 : Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers
- 14:7 : AI music platform Suno hits bum note as 55M users exposed in data breach, claims infosec expert
- 14:7 : JadePuffer returns with ransomware built to target AI models and infrastructure
- 14:6 : Russian Hacker Turns Jailbroken Claude Into Pentest Platform
- 13:33 : Craneware Cyberattack Exposes Employee and US Healthcare Customer Data
- 13:33 : Trump’s AI Safety Agency Chief Resigns After Just Three Months Leading CAISI
- 13:33 : New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops
- 13:33 : Forescout Report Reveals Surge in AI-Driven Cyber Threats
- 13:33 : Agentic JADEPUFFER Exploits Langflow Flaw to Deploy ENCFORGE AI Ransomware
- 13:33 : Hackers Hide Malware Commands in Outlook Events Dated 2050 and Use as C2 Channel
- 13:33 : AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware
- 13:33 : Craneware Data Breach – Hackers Stole Significant Amount of Data
- 13:32 : Microsoft to Discontinue Podcasts Option on Copilot and to Delete Contents
- 13:32 : Cisco’s open-weight Antares models make vulnerability localization cheaper
- 13:32 : Druva brings backup, recovery and governance to AI workloads
- 13:32 : HHS Seeks Input on CLIA Cybersecurity Updates
- 13:32 : 95% of Security Teams Miss Vulnerabilities Between Tests
- 13:5 : IT Security News Hourly Summary 2026-07-21 15h : 22 posts
- 13:4 : Iran War Cyber Threat Landscape | A Midyear Assessment on What Matters
- 13:4 : 2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge
- 13:4 : A new extortion cocktail: office printers, small ransoms, and BitLocker
- 13:4 : Intel fortifies Foundry with an actual customer: Fortinet
- 13:4 : Empirical Security Raises $25 Million in Series A Funding
- 13:4 : A New Ransomware Threat Actor Emerges Every Week, Warns Report
- 13:3 : FBI Impersonation Scam Targets Previous Victims
- 13:3 : North Korean ClickFake Campaign Targets Web3 Professionals
- 13:3 : Google Cloud 15-hour outage hits three services
- 13:3 : LG Monitor App Installer Criticized for McAfee Ads
- 12:34 : Fake FBI Agents Use IC3 Complaint Scams to Target Fraud Victims
- 12:33 : Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content
- 12:33 : DigiCert expands its EMEA channel strategy with Ignition Technology
- 12:33 : 1 in 4 businesses hit by cyber attacks through their supply chain in the last year
- 12:33 : New ClickLock Stealer locks your Mac until you hand over your password
- 12:32 : SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
- 12:32 : New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
- 12:32 : N-day is Becoming N-Hour. Patching Faster Won’t Save You.
- 12:32 : Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
- 12:5 : Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT
- 12:5 : Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
- 12:5 : Don’t trust that “FBI agent” in your DMs
- 12:4 : New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
- 12:4 : FBI Warns of Deepfake Videos Impersonating IC3 Leadership
- 11:33 : MIT to Become Hotbed of AI Video Surveillance
- 11:32 : Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
- 11:32 : CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
- 11:32 : Shufti simplifies cross-border compliance with the Glocal Platform
- 11:5 : JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
- 11:5 : Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
- 11:4 : Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers
- 11:4 : Linux Patches 400+ Kernel Vulnerabilities in 24 Hours With AI-Powered Detection
- 11:3 : One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files
- 11:3 : Microsoft Defender XDR Blind Spot Can Hide Public Connections Behind FourToSixMapping
- 11:2 : SonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware
- 11:2 : SonicWall SMA zero-days were exploited weeks before disclosure
- 10:32 : A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
- 10:32 : 95% of Security Teams Blindsided by Vulnerabilities Between Tests
- 10:32 : Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
- 10:32 : Fake FBI agents target people who already got scammed
- 10:5 : IT Security News Hourly Summary 2026-07-21 12h : 8 posts
- 10:3 : AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
- 10:3 : AI nudify apps spark legal scrutiny of Apple and Google’s profits
- 10:2 : Clover Health Investments Discloses Data Breach
- 10:2 : US Hospital Finance Software Provider Craneware Reports Data Theft
- 9:34 : Estée Lauder discloses data breach tied to Oracle EBS vulnerability
- 9:34 : AWS wants GuardDuty to automate the first steps of threat investigations
- 9:34 : Researchers Uncover North Korean ‘ClickFake’ Campaign Targeting Web3 Pros
- 9:5 : Meta Addictiveness Trial Begins In Tennessee
- 9:4 : Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials
- 9:4 : Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell
- 9:3 : New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
- 9:3 : Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
- 9:2 : Open-source maintainers still work underfunded as sponsorship crosses $100 million
- 9:2 : WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
- 8:32 : Apple Sends Letters To Dozens Of OpenAI Staff Amid Legal Claims
- 8:32 : Abbott Confirms Cyberattack After Unauthorized Access to Cancer Diagnostics Systems
- 8:32 : Zimbra Update Patches Critical Vulnerabilities
- 8:3 : Ukraine Strikes Target Russian E-Commerce Giant
- 8:3 : Alibaba, Moonshot Release Powerful Open-Weight AI Models
- 8:3 : Snap Reaches Tentative Settlement In Second Addiction Case
- 8:3 : Critical Gitea Flaw Lets Public-Only Tokens Write to Private Repositories and Trigger Actions Workflows
- 8:2 : AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware
- 8:2 : Linux Kernel Team Publishes 440 CVE Security Advisories Within 24 Hours
- 8:2 : The Privilege Paths Attackers See, That You Don’t – A Complete PAM Guide
- 8:2 : Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
- 8:2 : New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
- 7:32 : Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
- 7:32 : Hugging Face fights AI hacks, World Cup streamers get red cards, WordPress enters a patching race
- 7:5 : IT Security News Hourly Summary 2026-07-21 09h : 6 posts
- 7:2 : Fileless Stealer and PureRAT Raid Browser Passwords, Telegram Sessions, and Crypto Wallets
- 7:2 : OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy
- 6:32 : Researchers Advance ‘Flow Batteries’ For Renewable Power
- 6:32 : European Password Manager Passwork Shares Codebase and Updates With FSTEC-Certified Russian Firm
- 6:32 : Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems
- 6:31 : The air gap is a myth and other OT security truths
- 6:4 : EU Fines AliExpress Record €550m Over Illegal, Fake Goods
- 6:4 : Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids
- 6:4 : Employees’ shadow AI use is poorly monitored, survey finds
- 6:3 : Why SSDLC is helping shipping faster and more secure code
- 6:3 : Nobody was checking the drives that encrypt your laptop
- 5:32 : Hackers Hide C2 Traffic Inside Telegram While Targeting Middle East Governments
- 5:32 : HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert Command-and-Control Channels
- 5:32 : Paidwork Data Breach Exposes 23.3 Million Accounts, Banking Data and bcrypt Password Hashes
- 5:32 : PR3TACK preemptive framework maps threats before attackers use them
- 5:5 : AI agents are still logging in as humans
- 4:34 : Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware
- 4:34 : Furtex – Linux Toolkit for Post-Exploitation and Evasion for Security Researchers and Red Teamers
- 4:34 : Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware
- 4:33 : Cybersecurity jobs available right now: July 21, 2026
- 4:5 : OVH reveals semi-secret plan to fix critical Januscape bug with mass reboots – and an Australian crash-test dummy
- 4:5 : AI-generated reports push GNOME to shorten its disclosure window
- 2:8 : ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)
- 23:4 : DocuSign Phishing Kit Delivers RMM Tools to Windows and macOS
- 22:6 : Suno – 55,282,226 breached accounts
- 22:6 : Attackers pummel critical WordPress vuln to create all sorts of mischief
- 22:6 : Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment
- 22:5 : IT Security News Hourly Summary 2026-07-21 00h : 4 posts
- 21:55 : wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade
- 21:55 : IT Security News Daily Summary 2026-07-20
- 21:55 : Hugging Face Says Autonomous AI Agent System Breached Production Infrastructure
- 21:55 : Scaling Row-Level Security With ABAC on Databricks Unity Catalog