A PoC exploit has been available since public disclosure, and the first exploitation attempts were observed last week. The post Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read…
Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and…
Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic
Adobe fixed multiple critical flaws, including max severity bugs in ColdFusion and Campaign Classic that could lead to remote code execution Adobe has released security updates for ColdFusion and Campaign Classic, fixing multiple critical vulnerabilities, including seven maximum-severity issues (CVSS…
WinRAR 7.23 Fixes Heap Overflow Vulnerability that Leads to Application Crashes
WinRAR 7.23 addresses a newly disclosed heap overflow vulnerability in the RAR5 recovery volume processing code, tracked as CVE-2026-14191. Closing a memory-corruption flaw that could be triggered by malicious recovery volume (.rev) data and potentially lead to application crashes or…
Medtronic Confirms Data Breach – Hackers Gained Access to Corporate IT Systems
Medical technology giant Medtronic Inc. has disclosed a cybersecurity incident involving unauthorized access to its corporate IT systems, potentially affecting sensitive personal and health-related information of patients using Medtronic medical devices. Medtronic detected unusual activity in certain corporate IT systems…
Multiple ClamAV Vulnerabilities Allow Remote Attacker to Cause a DoS Condition
Multiple high-severity vulnerabilities in Cisco’s ClamAV engine allow remote attackers to crash the antivirus scanning process, causing a denial-of-service (DoS) on affected Cisco Secure Endpoint Connector deployments. The flaws affect Windows, Linux, and macOS, with the highest impact on Windows,…
Browser-Only Ransomware Abuses Chrome File System Access API to Encrypt Android Photos
A new ransomware technique can now run entirely inside a web browser, with no app installation or root access required. It targets Android photo directories by abusing a legitimate Chrome feature meant for photo editing. The attack begins with something…
CISA Warns of Microsoft SharePoint Server Code Execution Vulnerability Exploited in Attacks
CISA has added a newly disclosed Microsoft SharePoint Server vulnerability, tracked as CVE-2026-45659, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is actively being exploited in real-world attacks. The vulnerability is a deserialization of untrusted data issue…
JetBrains Patches Critical Hub Authentication Bypass and Account Takeover Vulnerabilities
JetBrains has released patches for several critical vulnerabilities in JetBrains Hub that could allow for full authentication bypass, account takeover, and unauthorized privilege escalation across integrated JetBrains services. Administrators are urged to update their Hub instances immediately. Critical Hub Vulnerabilities…
Hackers Use Geofenced Webpages to Deliver Ousaban Banking Trojan in Spain and Portugal
A targeted phishing campaign delivering the Ousaban banking Trojan to users in Spain and Portugal, notable for its use of geofenced webpages, layered evasion techniques, and a modular delivery chain. The threat actor repurposes a playbook seen previously in Brazil…
“We’ve struck a chord with the new partner programme”
Specialist retailers and resellers are increasingly acting as IT security service providers and strategic partners for businesses. G DATA CyberDefense has therefore completely overhauled its partner programme. In future, it will reward not only turnover but also commitment. In this…
NCSC Shares Tips on How to Make a Pen Tester’s Job Harder
The NCSC has shared best practice advice from pen testers which could help improve system resilience This article has been indexed from www.infosecurity-magazine.com Read the original article: NCSC Shares Tips on How to Make a Pen Tester’s Job Harder
IT Security News Hourly Summary 2026-07-02 12h : 9 posts
9 posts were published in the last hour 9:34 : ValleyRAT Uses RC4 Encryption, Donut Shellcode, and rundll32 Injection for Stealth 9:34 : FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations 9:34 : AI Agent Exploits Langflow RCE…
ValleyRAT Uses RC4 Encryption, Donut Shellcode, and rundll32 Injection for Stealth
A recent surge in ValleyRAT activity that combines RC4-encrypted payloads, Donut-generated shellcode, and in-memory execution via suspended rundll32 processes to evade detection. First named by Proofpoint in 2023, ValleyRAT continues to evolve: LevelBlue’s telemetry shows a marked increase in successful…
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. “An operator tied to FortiBleed’s infrastructure was found actively working negotiation panels for both…
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job:…
Valar Atomics Works With Nvidia On Data Centre Pilot
Start-up Valar says small nuclear reactors can be used with closed-loop cooling systems to reduce data centre power, water needs This article has been indexed from Silicon UK Read the original article: Valar Atomics Works With Nvidia On Data Centre…
Meta Developing Plans To Sell AI Infrastructure
Facebook parent reportedly considering selling access to the compute power it has stockpiled at great expense in recent years This article has been indexed from Silicon UK Read the original article: Meta Developing Plans To Sell AI Infrastructure
Oxmiq Raises $35m To Develop Custom AI Tech Stack
California-based start-up founded by former Intel GPU chief aims to be ARM of AI era, licensing tech from GPU accelerators to software This article has been indexed from Silicon UK Read the original article: Oxmiq Raises $35m To Develop Custom…
Apple Hide My Email Vulnerability Lets Attackers Reveal Users’ Real Email Addresses
Apple’s Hide My Email privacy feature currently faces a significant flaw that may expose users’ real email addresses, compromising one of iCloud+’s core anonymity protections. According to 404 Media and independent tests, this issue has reportedly remained unaddressed for over…
Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects
Kaspersky Compromise Assessment specialists analyze trends from the service’s 2025 projects and provide tips on how to enhance your organization’s security. This article has been indexed from Securelist Read the original article: Missed incidents, persistent threats, and response gaps: Insights…
Alleged Scattered Spider Member Extradited to US
A teenager accused of hacking as part of Scattered Spider has been arrested This article has been indexed from www.infosecurity-magazine.com Read the original article: Alleged Scattered Spider Member Extradited to US
Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges
Alleged Scattered Spider member Peter Stokes, 19, was extradited from Finland to the U.S. over hacking, fraud, and extortion charges. Peter Stokes, 19, an alleged Scattered Spider member known online as “Bouquet,” has been extradited from Finland to the U.S.…
JADEPUFFER Agentic Ransomware Uses LLM to Automate Database Extortion
The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host environment to harvest cloud and API credentials, and pivoted…
