Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro’s Zero Day Initiative (ZDI) detailed…
Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders
Two chiefs of UK policing agencies said the Transport for London prosecution demonstrates the need for Cybercrime Risk Orders This article has been indexed from www.infosecurity-magazine.com Read the original article: Police Chiefs Cite TfL Hack in Push for Cybercrime Risk…
IT Security News Hourly Summary 2026-07-20 12h : 9 posts
9 posts were published in the last hour 9:48 : Apps Marketed to US Troops Are Shipping Chinese and Russian Code 9:46 : AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign 9:44 : GoldenEyeDog Hackers Group Behind…
Apps Marketed to US Troops Are Shipping Chinese and Russian Code
A first-of-its-kind analysis found more than one in eight apps built for US service members carried foreign code—some from firms in nations the Pentagon designates as adversaries. This article has been indexed from Security Latest Read the original article: Apps…
AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can…
GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates
GoldenEyeDog, a Chinese cybercrime group linked to the Golden Gh0st malware family, is back in focus after an intrusion at DigiCert exposed the risks around code-signing certificates. The attackers used the access to intercept customer certificate activation codes and sign…
Threat Actors Allegedly Listed Starbucks Data on Hacker Forums
Starbucks has allegedly been listed on a cybercrime forum by a threat actor using the handle “anes2010,” who claims to be selling a database containing 176 million unique user records reportedly extracted in June 2026. Starbucks has not publicly confirmed…
The secret problem in AI infrastructure: Why MCP security starts with secrets
AI changes how infrastructure is accessed. Here’s what to secure. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: The secret problem in AI infrastructure: Why MCP security starts with secrets
How agentic endpoint security shuts down IDE-based supply chain attacks
Attention shifts from EDR to Agentic Endpoint Security to close visibility gaps that AI can exploit. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: How agentic endpoint security shuts down IDE-based supply chain…
Your attack surface is bigger than you think
New data reveals where attack surfaces are hiding the most risk. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: Your attack surface is bigger than you think
The Windows 10 hangover is becoming a security problem
Windows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered…
FBI Arrests Florida Man Accused of Distributing Malware Through Steam Games in $220,000 Crypto Theft
The FBI has arrested a 21-year-old Florida resident accused of running a cybercrime operation that infected around 8,000 PCs with malware spread through video g Thank you for being a Ghacks reader. The post FBI Arrests Florida Man Accused of…
Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances…
Chrome 150 Update Patches Severe Memory Safety Bugs
The fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: Chrome 150 Update Patches…
North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers
North Korean-linked hackers are hiding OTTERCOOKIE-aligned malware inside ordinary SVG flag images, turning a familiar part of a web project into a concealed delivery channel. The operation targets software developers who believe they are completing a coding test for a…
U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses
Federal prosecutors have charged three Russian nationals over infrastructure that allegedly enabled ransomware, malware, phishing, and other cyberattacks against organizations in the United States and abroad. The seven-year investigation links the activity to more than $62 million in victim losses…
The Rise of Calendar Phishing
Internet users have been reporting an increase in calendar phishing (CalPhishing). The scam technique has been on the rise over the last 24 months and… The post The Rise of Calendar Phishing appeared first on Panda Security Mediacenter. This article…
Google’s Next-Gen Gemini Delayed Over Coding Disappointment
Gemini 3.5 reportedly months behind schedule as Google seeks to improve coding performance to compete with Anthropic, OpenAI This article has been indexed from Silicon UK Read the original article: Google’s Next-Gen Gemini Delayed Over Coding Disappointment
A week in security (July 13 – July 19)
A list of topics we covered in the week of July 13 to July 19 of 2026 This article has been indexed from Malwarebytes Read the original article: A week in security (July 13 – July 19)
Fairlife dairy cyberattack, ACR Stealer surge, Abbott Labs incidents
Dairy company Fairlife suffers cyberattack Microsoft warns of surge in ACR Stealer attacks on customers Abbott Labs investigates two cyber incidents amid extortion claims Get the show notes here: https://cisoseries.com/cybersecurity-news-fairlife-dairy-cyberattack-acr-stealer-surge-abbott-labs-incidents/ Huge thanks to our sponsor, QuilrAI AI agents don’t ask…
IT Security News Hourly Summary 2026-07-20 09h : 11 posts
11 posts were published in the last hour 7:4 : Global Users Turn To Chinese AI As Costs Soar 7:4 : U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million 6:32 : Start-Ups Shift AI…
Global Users Turn To Chinese AI As Costs Soar
Rising costs and the improving performance of Chinese open-weight models has led Chinese start-ups to overtake US rivals on worldwide token use This article has been indexed from Silicon UK Read the original article: Global Users Turn To Chinese AI…
U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million
U.S. federal prosecutors have unsealed a sweeping indictment charging three Russian nationals and two St. Petersburg–based companies for operating a global “bulletproof hosting” infrastructure. That enabled widespread cyberattacks against critical sectors, causing losses exceeding $62 million across at least 21…
Start-Ups Shift AI Tasks To Smartphones
Firms in US, China gaining attention as they run increasingly powerful AI tasks on devices, in boost to performance, security This article has been indexed from Silicon UK Read the original article: Start-Ups Shift AI Tasks To Smartphones
