Generative AI scams, rapid-fire ransomware, and non-consensual deepfakes: The tactical shift driving aggressive new law enforcement and local government intervention. This article has been indexed from CyberMaterial Read the original article: Cyber Briefing: 2026.07.17
New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets
A financially motivated, Russian-speaking threat actor tracked as UAT-11795, orchestrating a large-scale campaign since at least June 2025. A sophisticated Python-based remote access trojan dubbed “Starland RAT,” alongside a stealthy in-memory PowerShell implant known as the “WLDR agent.” The operation…
The State of Hybrid SASE: Built-In vs. Bolted-On
Hybrid SASE is not a label – it is an architectural commitment. Many enterprises pay twice for SASE: once for the platform, and again for the overhead of integrating and managing components never designed to work as one architecture. Check…
Hackers Hide Lua Loaders in Fake TTF Files to Deploy Remcos, XWorm, and Agent Tesla
Hackers are increasingly abusing trusted file formats and lightweight scripting environments to evade detection, with a newly observed campaign leveraging Lua-based loaders. Disguised as TrueType (.ttf) font files to deploy commodity malware, including Remcos RAT, Agent Tesla, XWorm, and Snake…
AWS Cost Explorer Bug Shows Trillion-Dollar Billing Estimates
AWS customers worldwide were startled after the AWS Billing and Cost Management Console and Cost Explorer began displaying extraordinarily high projected cloud costs. Some organizations reported estimated monthly bills reaching trillions of dollars, triggering budget alerts and prompting concerns over…
New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access
A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code execution. LegacyHive targets the Windows User Profile Service (ProfSvc), which is responsible for loading and unloading user…
LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives
A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHive GitHub repository, abuses…
Shark vacuum flaw exposes cameras, home maps and Wi-Fi passwords
One compromised Shark robot vacuum could unlock remote access to many others. This article has been indexed from Malwarebytes Read the original article: Shark vacuum flaw exposes cameras, home maps and Wi-Fi passwords
Scammers weaponize FaceTime for social engineering
Apple has alerted iPhone and iPad users to an ongoing social engineering campaign where attackers abuse FaceTime calls to steal credentials and financial information. This article has been indexed from CyberMaterial Read the original article: Scammers weaponize FaceTime for social…
Women’s Care & Pulmonary Sleep Breaches
Two healthcare providers have disclosed significant data breaches exposing sensitive patient information. This article has been indexed from CyberMaterial Read the original article: Women’s Care & Pulmonary Sleep Breaches
Ransomware halts Fairlife dairy production
Coca-Cola-owned Fairlife has suspended production at all its US dairy facilities following a ransomware attack that compromised production-related systems. This article has been indexed from CyberMaterial Read the original article: Ransomware halts Fairlife dairy production
1Password integrates with Claude AI for secure authentication
1Password has released a beta integration with Anthropic’s Claude AI assistant that enables the AI to handle website authentication without accessing user passwords or credentials. This article has been indexed from CyberMaterial Read the original article: 1Password integrates with Claude…
IT Security News Hourly Summary 2026-07-17 15h : 11 posts
11 posts were published in the last hour 12:34 : AWS Billing Bug Displays Trillion-Dollar Cost Estimates to Cloud Customers 12:34 : Hackers Breached an IIS Server and Deployed Ransomware Across the Network the Next Day 12:34 : Podcast: Broken…
AWS Billing Bug Displays Trillion-Dollar Cost Estimates to Cloud Customers
Amazon Web Services (AWS) is currently investigating a significant billing issue affecting its Cost Explorer tool. This problem caused some cloud customers to see alarmingly inflated cost estimates, with figures reportedly reaching into the trillions of dollars. AWS Support acknowledged…
Hackers Breached an IIS Server and Deployed Ransomware Across the Network the Next Day
Hackers leveraged a compromised Microsoft IIS server to gain initial access and deploy a previously unseen ransomware payload across an enterprise network within 24 hours, highlighting a highly coordinated and operationally mature intrusion chain observed in June 2026. The campaign…
Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive
(Video) Artificial intelligence is transforming cybersecurity, but are governance, compliance, and security practices evolving fast enough to keep up? The post Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive appeared first on SecurityWeek. This article has been indexed…
Spirals ransomware locks down victim systems in under 24 hours
A previously unknown ransomware strain called Spirals was used last month in an attack against an IT services company in South Asia, where attackers went from initial access to data theft and encrypting the network in less than 24 hours,…
Attackers target critical FortiSandbox flaws as CISA issues patch order
Command injection vulns land on exploited list after researchers spot abuse attempts This article has been indexed from www.theregister.com – Articles Read the original article: Attackers target critical FortiSandbox flaws as CISA issues patch order
Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday
Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI. The post Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday appeared first on SecurityWeek. This article has been…
Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday
Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI. The post Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday appeared first on SecurityWeek. This article has been…
Beacon Security Raises $13 Million for Security Data Platform
The startup helps organizations detect, hunt, and protect their assets across environments at machine speed. The post Beacon Security Raises $13 Million for Security Data Platform appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original…
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled…
The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
Military forces are under increasing pressure to field autonomous capabilities faster than ever before. Across the U.S., UK, and NATO, new investment, evolving defense strategies, and accelerated acquisition pathways are transforming how capability is delivered, rewarding programs that can move…
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the…