Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools. This article has been indexed from Securelist Read the original article: Mirage Kitten targets Middle East and Africa…
Multiple FFmpeg Vulnerabilities Allow Attackers to Corrupt Memory Via Malicious Video File
Multiple high-severity vulnerabilities have been identified in FFmpeg, the widely used open-source multimedia framework. These flaws impact media parsing, decoding, filtering, and encoding components and can be triggered when an application processes malicious files. Several issues can lead to heap…
Apple Delays First Smart Glasses to WWDC 2027 Over Privacy Concerns
Apple has postponed the reveal of its first smart glasses to WWDC in June 2027, with sales anticipated later that year, according to Bloomberg analyst Mark Gurm Thank you for being a Ghacks reader. This article has been indexed from…
Operation STANDOFF Hides Command-and-Control Traffic Behind GitHub Redirects
Operation STANDOFF is a Russian-speaking cybercrime campaign that turns a single infection into a wider compromise. Its installer delivers information stealers, loaders, a cryptocurrency miner, and botnet components, while operators can later focus on selected victims for direct network intrusion.…
Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks
A rapidly evolving IoT botnet dubbed “Dysphoria” has emerged as a significant global threat, leveraging blockchain-based domain resolution and a hybrid command-and-control (C2) architecture to sustain large-scale distributed denial-of-service (DDoS) operations. Dysphoria’s evolution has been unusually aggressive, transitioning from early…
SpaceX Starship Rocket Splashes Down After Successful Test
Forty-storey-tall Starship vessel carries out sub-orbital flight and splashes down in Indian Ocean in latest test This article has been indexed from Silicon UK Read the original article: SpaceX Starship Rocket Splashes Down After Successful Test
Top 10 Best VPN Alternatives For Secure Remote Access in 2026
In the rapidly evolving landscape of 2026, the traditional VPN is increasingly showing its age. While a VPN creates a secure, encrypted tunnel to a private network, it often functions like an “all-access key,” granting users broad, undifferentiated access once…
AutoIT Payload Injector , (Tue, Jul 28th)
For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote…
PortSwigger Introduces Burp AT Agentic AI for Automated Penetration Testing
PortSwigger has launched Burp AT, an agentic AI system that allows penetration testers to delegate web security investigation tasks while maintaining direct control over the testing scope, approvals, and final conclusions. The public beta is currently available for Burp Suite…
Nvidia opens AI security tent, Microsoft adds cyber sprinter to MDASH, Fairlife ransomware spills data
Nvidia opens the AI security tent Microsoft puts a cyber sprinter in MDASH Fairlife ransomware spills data Get the show notes here: https://cisoseries.com/cybersecurity-news-nvidia-opens-ai-security-tent-microsoft-adds-cyber-sprinter-to-mdash-fairlife-ransomware-spills-data/ Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and…
Unpatched Fastjson Vulnerability Exploited in Attacks
The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. This article has been indexed from SecurityWeek Read the original article: Unpatched Fastjson Vulnerability Exploited in Attacks
Command Injection Cheatsheet: OS Payloads And Prevention (2026)
OS Command Injection is a critical vulnerability (CWE-78) where an attacker executes arbitrary operating system commands via a… This article has been indexed from Hackers Online Club Read the original article: Command Injection Cheatsheet: OS Payloads And Prevention (2026)
Shein Sees $99m Loss Ahead Of Hong Kong IPO
China-founded e-commerce company sees US market contract, falls to loss in first quarter as it prepares to list in Hong Kong This article has been indexed from Silicon UK Read the original article: Shein Sees $99m Loss Ahead Of Hong…
Houston City College – 831,642 breached accounts
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic…
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor
An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.” Active since January 2026, the activity is assessed to be linked to an…
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. This article has been indexed from SecurityWeek Read the original article: Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
IT Security News Hourly Summary 2026-07-28 09h : 3 posts
3 posts were published in the last hour 6:31 : Multiple FFmpeg Flaws Allow Arbitrary Memory Corruption via Malicious Videos 6:31 : Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost 6:31 : Shadow AI…
Multiple FFmpeg Flaws Allow Arbitrary Memory Corruption via Malicious Videos
Multiple high-severity vulnerabilities in FFmpeg could allow attackers to corrupt memory, disclose process data, or exhaust system resources. This can happen if users or automated media-processing services are manipulated into handling specially crafted video, audio, image, or subtitle files. The…
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best…
Shadow AI incident response begins with logs that may already be gone
In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI…
Hugging Face Has a Deepfake Nudes Problem
Researchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts show how people use the software. This article has been indexed from Security Latest Read the original article: Hugging…
Apple iOS 26.6 Update Fixes Flaws Allowing Kernel-Level Code Execution and Root Access
Apple has released iOS 26.6 and iPadOS 26.6, a significant security update that addresses numerous vulnerabilities across core operating system components, media frameworks, WebKit, wireless services, and application frameworks. Released on July 27, 2026, this update is available for iPhone…
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the…
AI took more than junior developer jobs and the bill comes later
A ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. Describe it to Claude and…