π Government Agencies Falling Victim to Ransomware Daily, Warns Study π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Government organizations are targeted by attackers who know agencies cannot afford disruption to public services.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Government Agencies Falling Victim to Ransomware Daily, Warns Study
Government organizations are targeted by attackers who know agencies cannot afford disruption to public services
π 23andMe Faces New Security Mandates in $18m Data Breach Settlement π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
23andMe has agreed to an 18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
23andMe Faces New Security Mandates in $18m Data Breach Settlement
23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements
π Pentest Preparation Guide and Scoping Questionnaire: Scope, Credentials, RFP, and Attestation Workflow π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Explore a complete pentest preparation checklist scope, credentials, RFP, vendor scoring, and the retest and attestation workflow auditors accept. The post Pentest Preparation Guide and Scoping Questionnaire Scope, Credentials, RFP, and Attestation Workflow appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
Pentest Preparation Guide and Scoping Questionnaire: Scope, Credentials, RFP, and Attestation Workflow
Explore a complete pentest preparation checklist: scope, credentials, RFP, vendor scoring, and the retest and attestation workflow auditors accept.
π Splunk SOC Detection Engineering: Claimed Coverage vs. Measured Coverage π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Compare 12 enterprise SIEM solutions for 2026 by AI detection, pricing, compliance, and deployment. Vendorneutral rankings from 500 SOC environments. Evaluate now. The post Splunk SOC Detection Engineering Claimed Coverage vs. Measured Coverage appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
SIEM Solutions Compared: 12 Top Platforms for Enterprise Security Teams in 2026
Compare 12 enterprise SIEM solutions for 2026 by AI detection, pricing, compliance, and deployment. Vendor-neutral rankings from 500+ SOC environments. Evaluate now.
π’ Health tech firm Craneware admits βsignificant volumeβ of customer and employee data exposed in cyber attack π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
The incident has been contained and Craneware has launched a probe into the breach.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Health tech firm Craneware admits βsignificant volumeβ of customer and employee data exposed in cyber attack
The incident has been contained and Craneware has launched a probe into the breach
π¦Ώ AWS Billion-Dollar Software Bug Explained π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
An AWS software bug showed some customers billing estimates in the billions and trillions. Here is what failed, why invoices were unaffected, and what IT teams should know. The post AWS BillionDollar Software Bug Explained appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
AWS Billion-Dollar Software Bug Explained
An AWS software bug showed some customers billing estimates in the billions and trillions. Here is what failed, why invoices were unaffected, and what IT teams should know.
π¦Ώ Top 5 Disaster Recovery Companies in 2026 π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
This is a comprehensive list of the top Disaster Recovery as a Service providers. Use this guide to compare and choose the best solution for you. The post Top 5 Disaster Recovery Companies in 2026 appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Top 5 Disaster Recovery Companies in 2026
Compare the top 5 disaster recovery companies in 2026. Explore DRaaS pricing, features, pros, cons, and the best options for business continuity.
ποΈ FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence AI skills or Model Context Protocol MCP servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. "FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit 1,048 files spanning lure templates, filenamespoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government IDlookup site over WebDAV. What makes it more than a.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. GroupIB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ β‘ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is the full.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
At least one Russian intelligence service is systematically hijacking internetconnected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Mythos Didn't Break Your Security Program. Your Exposure Window Could. ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AIdriven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Opening a crafted XZ archive in 7Zip could let an attacker run code on the machine. The flaw, CVE202614266, is a heapbased buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative ZDI detailed it on July 15. A fix shipped on June 25 in 7Zip 26.02. The overflow lets an attacker "execute code in the context of the current process," per the.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A solo Russianspeaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's opensource Gemini CLI artificial intelligence AI and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
In an ironic twist, opensource artificial intelligence AI platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. "We identified unauthorized access to a limited set of internal datasets and to several credentials used by.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below gitcredentialmanager versions 2.8.0, 2.8.1, 2.8.2, 2.8.3 Published on July 18, 2026 Dendreo versions 1.1.3, 1.1.4 .π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE202642533 was patched on July 15 in nginx 1.30.4 stable and 1.31.3 mainline, and in NGINX Plus 37.0.3.1 anyone on an earlier build should upgrade. Triggering it can crash or restart the worker, causing a denial of.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π Cruciferra Crypter Uses Process Ghosting to Evade Detection π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Cruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Cruciferra Crypter Uses Process Ghosting to Evade Detection
Cruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors
π€1
π JadePuffer Returns With Ransomware Designed to Wipe AI Models π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
JadePuffer followup campaign deployed ENCFORGE locker built to destroy AI model artifacts.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
JadePuffer Returns With Ransomware Designed to Wipe AI Models
JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts
π Researchers Build WordPress Exploit Using OpenAI's GPT π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A researcher who discovered a critical vulnerability in WordPress has used OpenAIs latest model to develop an exploit chain.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Researchers Build WordPress Exploit Using OpenAI's GPT
A researcher who discovered a critical vulnerability in WordPress has used OpenAIβs latest model to develop an exploit chain