Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructure in…
TfL Hackers Sentenced To Years In Prison
UK men who hacked Transport for London as teenagers sentenced to more than five years in prison, following numerous earlier offences This article has been indexed from Silicon UK Read the original article: TfL Hackers Sentenced To Years In Prison
Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection
A newly published Linux toolkit named Furtex showcases a wide range of concepts related to post-exploitation, persistence, data access, and monitoring evasion. It is built around io_uring, eBPF, BPF maps, and raw system calls. The project includes over 100 tools…
North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images
A sophisticated North Korean threat campaign dubbed “Contagious Interview” has resurfaced with new delivery techniques, leveraging weaponized SVG image files to deploy the OTTERCOOKIE malware while coinciding with a separate supply chain intrusion targeting the Ruby ecosystem. Security researchers tracking…
Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover
Kimai users who are running the official Docker image are strongly urged to update their installations after a critical vulnerability, tracked as CVE-2026-52824 and GHSA-jr9p-4h4j-6c58, was discovered. This vulnerability exposes installations to the risk of account takeover due to a…
More alerts are making your team slower, and an outcome-based SOC fixes that
In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware.…
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below – git_credential_manager…
World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production…
WP2Shell WordPress Vulnerabilities Exploited in the Wild
Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: WP2Shell…
A forensic tool for backdoored code completions in AI assistants
Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some…
Hugging Face Security Breach Exposes Internal Datasets, Credentials, and Tokens
Hugging Face has disclosed a security incident involving unauthorized access to certain parts of its production infrastructure, affecting a limited set of internal datasets and several service credentials. The AI platform made this disclosure on July 16, 2026, noting that…
Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security
ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs through the…
15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution
A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan Shaw reported the bug to F5 SIRT, which coordinated a fix…
Nearly half of open-source AI projects never reach production
Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as…
ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)
This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Monday, July 20th, 2026…
WordPress RCE, New Windows 0-day and Coca-Cola’s Fairline ransomed
New Windows zero-day, Coca-Cola’s Fairlife hit by ransomware, and a core WordPress RCE David Shipley covers a new Windows zero-day disclosure from “Nightmare Eclipse” called LegacyHive, a local privilege escalation flaw in the Windows User Profile Service that could be…
IT Security News Hourly Summary 2026-07-20 03h : 1 posts
1 posts were published in the last hour 0:34 : Paidwork – 23,272,765 breached accounts
Paidwork – 23,272,765 breached accounts
In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M…
IT Security News Hourly Summary 2026-07-20 00h : 3 posts
3 posts were published in the last hour 21:58 : IT Security News Weekly Summary 29 21:55 : IT Security News Daily Summary 2026-07-19 21:40 : Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
IT Security News Weekly Summary 29
210 posts were published in the last hour 21:55 : IT Security News Daily Summary 2026-07-19 21:40 : Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution 16:34 : Connecting AI agents to outside services explodes the…
IT Security News Daily Summary 2026-07-19
21 posts were published in the last hour 21:40 : Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution 16:34 : Connecting AI agents to outside services explodes the risk radius 16:34 : Hidden Wi‑Fi Killers: Everyday…
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3…
Connecting AI agents to outside services explodes the risk radius
Connect all the things and watch what happens This article has been indexed from www.theregister.com – Articles Read the original article: Connecting AI agents to outside services explodes the risk radius
Hidden Wi‑Fi Killers: Everyday Things Quietly Ruining Your Home Internet
Many everyday objects can quietly wreck your Wi‑Fi, and understanding them is the first step to a more stable home network. From kitchen gadgets to building materials, the invisible radio waves carrying your data are constantly competing with physical…