Telegram’s widely used t.me shortlinks experienced a complete outage lasting roughly one day after the .ME domain registry suspended the domain in response to US sanctions targeting a VPN service popular with cybercriminals. This article has been indexed from CyberMaterial…
AI Bug-Finding Tools Need Human Validation
Security teams are increasingly using AI-powered tools to accelerate offensive security work, but industry experts warn that human validation remains non-negotiable. This article has been indexed from CyberMaterial Read the original article: AI Bug-Finding Tools Need Human Validation
IT Security News Hourly Summary 2026-07-16 15h : 16 posts
16 posts were published in the last hour 12:34 : Inside Microsoft’s Record-Breaking 622-Bug Release 12:34 : Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes 12:34 : Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM…
Inside Microsoft’s Record-Breaking 622-Bug Release
Record-Breaking Fixes Tackle Two Exploited Zero-Days On July 14, 2026, Microsoft dropped a record-shattering Patch Tuesday update that delivered 622 security fixes in a single day. This unprecedented volume, which… The post Inside Microsoft’s Record-Breaking 622-Bug Release appeared first on…
Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes
A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI) In more than 200 sessions between March…
Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin (“srt64.sys”), as the kernel-mode rootkit is referred to, was…
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands
Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click “Buy Now” instead. Ask a coding assistant to apply a maintainer’s fix from a GitHub thread, and a fake…
20+ Hijacked Government Websites Became an Attack Channel
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions. The investigation revealed previously undocumented backdoor behavior,…
“Selfish Bravado” Behind TfL Cyber-Attack, Judge Says as Pair Jailed
The perpetrators of the 2024 TfL cyber-attack have been jailed for five and a half years each after pleading guilty to Computer Misuse Act offences This article has been indexed from www.infosecurity-magazine.com Read the original article: “Selfish Bravado” Behind TfL…
OkoBot Malware Uses ClickFix, Hidden Browser Extensions to Steal Crypto Data
Kaspersky says OkoBot targets crypto users through fake software, stealing wallet files, seed phrases and passwords while recording activity inside wallet apps. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original…
OpenAI Unveils GPT-Red AI Model That Automatically Finds Prompt Injection Vulnerabilities
OpenAI has introduced GPT-Red, an automated safety red-teaming model trained to identify and exploit prompt injection weaknesses in AI agents. Prompt injection occurs when malicious instructions hidden in webpages, emails, local files, code repositories, or tool outputs manipulate an AI…
Next.js Announces July Security Release to Fix 4 High-Severity and 5 Medium Flaws
Next.js maintainers have announced a scheduled security release for July to address nine vulnerabilities, four rated high severity and five rated medium severity. The patches are expected to be released on July 20, 2022, and will include updated versions for…
TuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and All
TuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes…
GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia. This article has been indexed from Securelist Read the original article: GoSerpent: a persistent threat evolves with sophisticated…
CISA Warns Russian FSB Hackers Are Targeting Critical Infrastructure Routers
Who Is Affected and Next Steps The Russian Federal Security Service (FSB)-affiliated cyber outfit Center 16 is actively scanning the internet for vulnerable and poorly configured networking devices, particularly routers… The post CISA Warns Russian FSB Hackers Are Targeting Critical…
Inside “Gold Eagle”: The White House’s New AI-Driven Clearinghouse for Critical Infrastructure
What is Gold Eagle? A new federal cybersecurity hub called Gold Eagle was created to combat the growing threat of cyberattacks powered by artificial intelligence. The initiative is led through… The post Inside “Gold Eagle”: The White House’s New AI-Driven…
Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investment Playbook
Marlinspike Co-Founder Neil Keegan and Vice President Nick Snoad sat down with Cyber Defense Magazine to discuss how the firm is navigating the increasingly complex intersection of national security, artificial… The post Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity…
Intruder brings AI-powered, on-demand penetration testing to web applications
Intruder has announced the launch of AI Pentesting for web applications, providing on-demand penetration testing. Following its initial release of issue-level investigations last quarter, the platform now allows organizations to securely connect their codebases via GitHub or GitLab to automatically…
ValorC3 extends SaaS protection with immutable cloud backups
ValorC3 Data Centers today announced the general availability of Backup as a Service, a fully managed offering that protects the SaaS data businesses rely on most, including Microsoft 365, Entra ID and Salesforce. Every backup is immutable, so data stays…
‘Selfish Bravado’ Behind TfL Cyber-Attack, Judge Says as Pair Jailed
The perpetrators of the 2024 TfL cyber-attack have been jailed for five and a half years each after pleading guilty to Computer Misuse Act offences This article has been indexed from www.infosecurity-magazine.com Read the original article: ‘Selfish Bravado’ Behind TfL…
Kratos PhaaS Attacking Microsoft 365 Users Across the US, Europe to Steal Credentials
Kratos is a phishing-as-a-service operation built to steal Microsoft 365 credentials. It is targeting organizations across the United States, Europe, and other regions by using believable document, invoice, and file-sharing lures that lead victims to fake login pages. The campaign…
GPT-Red – A Red Teamer to Find Prompt Injection Vulnerabilities in GPT 5.6 Sol
OpenAI has introduced GPT-Red, an internal automated red-teaming model designed to identify and remediate prompt injection vulnerabilities in GPT-5.6. This approach aims to tackle a growing safety challenge. While human red-team exercises are valuable, they cannot generate adversarial test cases…
Windows 10 refuses to die, and the security bill is coming due
One in six machines still run the old OS as migration stalls and patch deadlines creep closer This article has been indexed from www.theregister.com – Articles Read the original article: Windows 10 refuses to die, and the security bill is…
Oak Emerges From Stealth Mode With $60 Million in Funding
The startup has built an AI-powered Identity Operating System that governs all identities across an organization’s environment. The post Oak Emerges From Stealth Mode With $60 Million in Funding appeared first on SecurityWeek. This article has been indexed from SecurityWeek…