The recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging Face, a platform that enables users to share machine learning…
TrickBot Ditches HTTP for DNS Tunneling in Latest Variant
New TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP pattern This article has been indexed from www.infosecurity-magazine.com Read the original article: TrickBot Ditches HTTP for DNS Tunneling in Latest Variant
Security Advisory – Action Required – July 2026 Security Update
As part of Check Point’s Frontier AI Readiness Program, we are releasing a jumbo hotfix with security and hardening fixes for our firewall and management products. This update includes a number of security hardening improvements and fixes, the most significant…
Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek. This article has…
OpenAI Presence connects AI agents to enterprise data with built-in guardrails
OpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat. (Source: OpenAI) The company describes Presence as a deployment platform rather than a standalone model.…
On the “HollowByte” denial-of-service report
Over the past week a denial-of-service (DoS) report against OpenSSL, named “HollowByte” by the Okta Red Team who reported it, has received a good deal of press attention. A number of the articles ask reasonable questions about how we assessed…
When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover
Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. The post When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover appeared first on SecurityWeek. This article has been…
Swimlane AI SOC automates security operations for MSSPs
Swimlane has announced the launch of Swimlane AI SOC for MSSPs, which the company says is designed to empower managed security service providers through agentic AI automation rather than compete for their customers. Some AI SOC providers are moving into…
ThreatDown expands security visibility to AI tools and machine identities
ThreatDown has announced a synchronized expansion of its AI and identity security capabilities to protect organizations from emerging, unmanaged risks. The company launched AI visibility, giving security and managed service provider (MSP) teams a full inventory of the AI tools…
Astelia extends reachability analysis with agentic AI for vulnerability management
Astelia has added agentic capabilities to its reachability analysis platform as organizations face shrinking exploit windows and the growing challenge of managing vulnerabilities. At the core of the platform is Astelia’s reachability analysis, which determines whether a vulnerability can be…
The Fastest Path to AI Adoption Runs Through Security
Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence…
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”). “The…
Inside a TrickBot Variant Using DNS Tunneling for C2
FortiGuard Labs analyzes a TrickBot variant that uses DNS tunneling for C2 communication, modular execution, and employs persistence and obfuscation techniques This article has been indexed from FortiGuard Labs Threat Research Read the original article: Inside a TrickBot Variant…
AppViewX Arms Enterprise CLM Teams for Post-Quantum Migration and AI Adoption in Latest Product Release
New York, United States, 22nd July 2026, CyberNewswire This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More Read the original article: AppViewX Arms Enterprise CLM Teams for Post-Quantum Migration and AI Adoption in Latest…
Critical Meta IDOR Flaw Let Attackers Access Customer Support Cases
Meta has addressed a critical vulnerability involving broken access control that exposed sensitive customer support data across multiple services. This issue highlighted systemic weaknesses in authorization within their shared backend infrastructure. The flaw, categorized as an Insecure Direct Object Reference…
FBI Warns Scammers Use AI Deepfakes and Fake IC3 Sites to Re-Victimize Fraud Victims
The FBI has issued a new Public Service Announcement warning that cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target victims who have already lost money to scams. This advisory, released on July…
Critical Zimbra Flaw Lets Attackers Inject Commands Through the SNMP Monitoring Service
Zimbra fixed a critical Zimbra Collaboration Suite (ZCS) command injection flaw in version 10.1.20 that could allow attackers to abuse the SNMP service and execute arbitrary commands on affected servers. The flaw affects environments where SNMP notifications are enabled, potentially…
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030,…
IT Security News Hourly Summary 2026-07-22 15h : 14 posts
14 posts were published in the last hour 13:5 : Oracle Patches 1,400+ Vulnerabilities, Critical Flaws Expose Enterprise Servers to Remote Attacks 13:4 : New NULLZEREPTOOL Uses Telegram to Launch 20 DDoS Methods With Rotating Proxies 13:4 : Chick-fil-A loyalty…
Oracle Patches 1,400+ Vulnerabilities, Critical Flaws Expose Enterprise Servers to Remote Attacks
Oracle has released its July 2026 Critical Patch Update (CPU), shipping 1,449 security patches that collectively remediate more than 1,200 vulnerabilities across databases, middleware, cloud services, and enterprise applications, in what is now the largest CPU in the company’s history.…
New NULLZEREPTOOL Uses Telegram to Launch 20 DDoS Methods With Rotating Proxies
NULLZEREPTOOL is a newly uncovered attack framework that turns a Telegram bot into a remote control panel for powerful distributed denial of service campaigns backed by rotating proxy infrastructure. The framework came to light when a single Pastebin post was…
Chick-fil-A loyalty accounts hijacked using stolen passwords
If you have a Chick-fil-A One account, now is a good time to change your password—and make sure it’s one you don’t use anywhere else. This article has been indexed from Malwarebytes Read the original article: Chick-fil-A loyalty accounts hijacked…
Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits
Move over Flipper. There’s a new Dophin X in town This article has been indexed from www.theregister.com – Articles Read the original article: Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits
StrongestLayer Raises $4.1 Million in Seed Funding Extension
The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the…