The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host environment to harvest cloud and API credentials, and pivoted…
Critical Flaws Double as Elevation of Privilege Dominates the Cyber Threats – Analysis of Microsoft Vulnerabilities Report 2026
Microsoft’s vulnerability landscape just sent a mixed signal that every security team needs to understand. According to the newly released Microsoft Vulnerabilities Report 2026 — the 13th annual edition published by BeyondTrust — the total number of disclosed Microsoft vulnerabilities…
Opera blocks ClickFix attacks with new clipboard protection feature
Opera has launched Paste Protect, a clipboard protection feature designed to prevent clipboard-based attacks such as hijacking and pastejacking. Paste Protect includes built-in protection and warnings against ClickFix-based cyberattacks, which accounted for more than half of malware-delivery attacks in 2025.…
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs. Run…
Taiwan Detains Two Super Micro Staff In GPU Smuggling Probe
Authorities detain two staff from server maker Super Micro, release two others on bail amid probe into illicit Nvidia GPU exports to China This article has been indexed from Silicon UK Read the original article: Taiwan Detains Two Super Micro…
Swedish Court Orders Google To Pay Klarna $2bn In Damages
Klarna wins record payout of nearly $2bn from search giant over decade of unfair self-preferencing around shopping services This article has been indexed from Silicon UK Read the original article: Swedish Court Orders Google To Pay Klarna $2bn In Damages
Under Pressure: Insights from the 2026 Exposure Gap Report
Risk is concentrating. The 2026 Exposure Gap Report shows vulnerabilities claiming a larger share of critical exposure, and that shift has real implications for how security teams prioritize their response. Two findings are central to this change. Vulnerabilities now represent…
How Attackers Weaponize AI
Last Updated on July 2, 2026 Bundled Page This page requires JavaScript to display. AI THREAT INTELLIGENCE Unpacking… This article has been indexed from HACKMAGEDDON Read the original article: How Attackers Weaponize AI
Hide My Email bug shows real addresses, Fable 5 gets the greenlight, Microsoft Teams hits back on AI bots
Hide My Email bug shows real addresses Fable 5 gets the greenlight DHS confirms hackers breached HSIN Get the show notes here: https://cisoseries.com/cybersecurity-news-hide-my-email-shows-real-addresses-fable-5-gets-greenlight-microsoft-teams-hits-back-on-bots/ Huge thanks to our sponsor, Silent Push Most cybersecurity approaches are completely reactive. Victim organizations are hit…
Anthropic Restores Access After US Restrictions Lifted
Anthropic begins restoring customer access to Fable 5 and Mythos 5 models after US Commerce Department says security issues addressed This article has been indexed from Silicon UK Read the original article: Anthropic Restores Access After US Restrictions Lifted
ChocoPoC Campaign Abuses GitHub PoC Repositories to Steal Browser Credentials
A coordinated supply-chain campaign has been weaponizing GitHub proof-of-concept (PoC) repositories to compromise vulnerability researchers and penetration testers, delivering a stealthy Python Remote Access Trojan (RAT) dubbed “ChocoPoC.” The lure is simple and effective: newly disclosed high-severity CVEs create urgency…
Hackers shoveled snow for company, were rewarded with network admin access
Fortunately, they were professional red teamers. Unfortunately, they pwned the network This article has been indexed from www.theregister.com – Articles Read the original article: Hackers shoveled snow for company, were rewarded with network admin access
IT Security News Hourly Summary 2026-07-02 09h : 5 posts
5 posts were published in the last hour 7:4 : SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation 6:34 : The endpoint recovery gap many teams discover during an incident 6:5 : Royal Navy To Build Drone Warships…
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a…
The endpoint recovery gap many teams discover during an incident
In this interview with Help Net Security, IGEL CTO Matthias Haas explains why backups alone do not equal recovery. He makes the case that endpoint recovery is often overlooked, leaving organizations exposed when thousands of devices go down at once.…
Royal Navy To Build Drone Warships
Ministry of Defence plans hybrid approach for naval development, with crewed vessels directing range of drone platforms This article has been indexed from Silicon UK Read the original article: Royal Navy To Build Drone Warships
LSHIY Password Spray Attack Hits Microsoft 365 Accounts With 81 Million Login Attempts
A large-scale password spray campaign linked to the infrastructure provider LSHIY LLC has targeted Microsoft 365 environments, resulting in over 81 million login attempts. This campaign has led to at least 78 confirmed account compromises across 64 organizations between June…
Attackers Downgrade WDigest Protection to Dump Plaintext Credentials With Mimikatz
An incident that began with innocuous enumeration commands but quickly escalated into a focused, multi-stage effort to impair detection and extract credentials. The intruder uploaded a steganographic webshell to an IIS server, used the process w3wp.exe to run OS reconnaissance…
Review: CTRL+ALT+PWN
Hacking gear that once sat in well-funded labs now ships to anyone with a credit card and a video tutorial. Frank Riccardi builds his consumer guide, CTRL+ALT+PWN: The Hacker’s Playbook (And How to Beat It), on that one condition. He…
Critical Cursor IDE Flaws Let Attackers Execute Code via Zero-Click Prompt Injection
Two significant remote code execution (RCE) vulnerabilities in the widely used Cursor ID expose developers to zero-click attacks driven by prompt injection. These vulnerabilities, tracked as CVE-2026-50548 and CVE-2026-50549, collectively known as “DuneSlide,” carry a CVSS score of 9.8. They…
Browser-Only Ransomware Uses File System Access API to Encrypt Files Without Malware Installation
A novel, practical ransomware technique that runs entirely inside the browser by abusing the File System Access API, demonstrating how AI can turn high-level malicious ideas into operational attack chains without any native payload. The proof-of-concept leverages a social engineering…
Catching ransomware on the wire before it locks the file server
Corporate networks keep sensitive files off individual workstations and store them on shared servers that staff reach through mapped network drives. That arrangement hands ransomware operators a target worth chasing. A single compromised laptop can begin encrypting files that live…
Scattered Spider Hacker Arrested in Finland and Extradited to U.S. Over Cyber Intrusion Charges
U.S. authorities have announced federal charges against an alleged member of the notorious cybercriminal group Scattered Spider, following his arrest in Finland and extradition to the United States. The defendant, identified as 19-year-old Peter Stokes, a dual national of the…
FortiBleed Campaign Linked to INC and Lynx Ransomware Operations
A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx. This finding provides the first confirmed evidence that mass theft of FortiGate credentials is being integrated into ransomware deployment processes,…
