π₯ European Union (EU) has ordered Google to open #Android features to rival AI assistants, including the camera, microphone, screen contents, locked-screen hotwords, and background app control.
Consent still applies. For six features, Google cannot require certification.
Here's what changes, and when - https://thehackernews.com/2026/07/eu-orders-google-to-open-android-mic.html
Consent still applies. For six features, Google cannot require certification.
Here's what changes, and when - https://thehackernews.com/2026/07/eu-orders-google-to-open-android-mic.html
π±6π₯5π€5π€―3π1
Military autonomy is not just a platform race. It is an information infrastructure challenge.
Drones, vessels, satellites, AI systems, and allies must exchange trusted mission data across platforms and security domains.
Why the future force depends on what connects it: https://thehackernews.com/2026/07/the-race-to-field-military-autonomy-is.html
Drones, vessels, satellites, AI systems, and allies must exchange trusted mission data across platforms and security domains.
Why the future force depends on what connects it: https://thehackernews.com/2026/07/the-race-to-field-military-autonomy-is.html
π3π₯2
π¨ A fake coding test can be the whole attack.
North Korea-linked hackers are hiding malware across ordinary-looking SVG flag images. Run the project, and it assembles an OtterCookie-aligned toolkit that steals browser credentials, crypto wallet data, files, and clipboard contents, then opens a SocketIO backdoor.
Read the full attack chain: https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html
North Korea-linked hackers are hiding malware across ordinary-looking SVG flag images. Run the project, and it assembles an OtterCookie-aligned toolkit that steals browser credentials, crypto wallet data, files, and clipboard contents, then opens a SocketIO backdoor.
Read the full attack chain: https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html
π₯9π€―7β‘4π4
This media is not supported in your browser
VIEW IN TELEGRAM
π¨ Attackers are targeting the datacenters that train, host, and serve AI, not just the AI models themselves.
Lava has released FORGE: The Top 10 Data Center & AI Infrastructure Security Risks: https://thn.news/forge-framework
Built with security leaders and practitioners across neoclouds, HPC, and enterprise security β open, free, and made to evolve.
Lava has released FORGE: The Top 10 Data Center & AI Infrastructure Security Risks: https://thn.news/forge-framework
Built with security leaders and practitioners across neoclouds, HPC, and enterprise security β open, free, and made to evolve.
π12π₯2
π¨ CylindricalCanine breached two DigiCert support workstations with a fake screenshot ZIP.
The group obtained EV code-signing certificates to sign Zhong Stealer. DigiCert revoked 60, including 27 linked to the group.
Read how the support chat breach led to signed malware: https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html
The group obtained EV code-signing certificates to sign Zhong Stealer. DigiCert revoked 60, including 27 linked to the group.
Read how the support chat breach led to signed malware: https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html
π₯6
π New NadMesh botnet malware hunts exposed AI services for AWS keys and Kubernetes tokens.
It targets ComfyUI, Ollama, n8n, Gradio, and MCP deployments, pulling cloud credentials, Docker configs, and model access from compromised hosts.
How the botnet works and survives removal: https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
It targets ComfyUI, Ollama, n8n, Gradio, and MCP deployments, pulling cloud credentials, Docker configs, and model access from compromised hosts.
How the botnet works and survives removal: https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
π₯5π1
β οΈ Seven malicious npm packages are targeting Vite developers.
They stay quiet during installation. Import one, and it starts a RAT delivery chain that can steal credentials, exfiltrate files, and open a reverse shell.
The attacker stores the delivery path in public blockchain transactions.
See the affected packages and full attack chain: https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
They stay quiet during installation. Import one, and it starts a RAT delivery chain that can steal credentials, exfiltrate files, and open a reverse shell.
The attacker stores the delivery path in public blockchain transactions.
See the affected packages and full attack chain: https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
π₯3π3
π OpenSSL quietly fixed HollowByte, a flaw where an 11-byte TLS request can reserve up to 131 KB of server memory per connection.
On the glibc systems researchers tested, that memory remained frozen until restart.
Full details: https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
On the glibc systems researchers tested, that memory remained frozen until restart.
Full details: https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
π₯9π1
π URGENT - A single anonymous HTTP request can run code on an unpatched #WordPress 6.9 or 7.0 site, even on a default install with zero plugins.
The new wp2shell flaw sits in core and still has no CVE for scanners to match.
Affected releases and mitigations π https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
The new wp2shell flaw sits in core and still has no CVE for scanners to match.
Affected releases and mitigations π https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
π₯25π5π±2π1
β‘ UPDATE: #wp2shell now has two CVEs, and a working proof-of-concept is public.
> CVE-2026-63030 breaks REST batch routing
> CVE-2026-60137 injects SQL
Chained, they give an anonymous attacker code execution on affected WordPress sites.
How the exploit path works: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
> CVE-2026-63030 breaks REST batch routing
> CVE-2026-60137 injects SQL
Chained, they give an anonymous attacker code execution on affected WordPress sites.
How the exploit path works: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
β‘16π₯5π4π€2
π¨ Two SonicWall SMA 1000 zero-days were exploited before disclosure to gain root access.
Researchers link the activity to UTA0533, which planted custom malware and sniffed unencrypted LDAP credentials from compromised VPN appliances.
Full attack chain: https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html
Researchers link the activity to UTA0533, which planted custom malware and sniffed unencrypted LDAP credentials from compromised VPN appliances.
Full attack chain: https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html
π₯11β‘1
β οΈ Russian state-backed hackers are using fake CAPTCHA checks to trick Ukrainian targets into running malware on their own Windows systems.
The same campaign also uses fake security apps to backdoor #Android devices.
Read the full attack chain: https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html
The same campaign also uses fake security apps to backdoor #Android devices.
Read the full attack chain: https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html
π₯16π€―7β‘5π4π3π2
π WARNING - A new critical NGINX vulnerability that has existed for 15-years lets unauthenticated attackers crash worker processes with crafted HTTP requests.
CVE-2026-42533 affects specific regex map configurations.
F5 says it may also allow pre-auth RCE if ASLR is disabled or bypassed.
Read how the bug works: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
CVE-2026-42533 affects specific regex map configurations.
F5 says it may also allow pre-auth RCE if ASLR is disabled or bypassed.
Read how the bug works: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
π€11β‘2π₯2
π WARNING - A new critical NGINX vulnerability that has existed for 15-years lets unauthenticated attackers crash worker processes with crafted HTTP requests.
CVE-2026-42533 affects specific regex map configurations.
F5 says it may also allow pre-auth RCE if ASLR is disabled or bypassed.
Read how the bug works: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
CVE-2026-42533 affects specific regex map configurations.
F5 says it may also allow pre-auth RCE if ASLR is disabled or bypassed.
Read how the bug works: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
π9π₯6π€3β‘2π2
β οΈ Three malicious RubyGems packages avoid CI runners and target developer machines.
One impersonates Microsoft Git Credential Manager. Two resurfaced after years dormant, then fetched native payloads and added persistence.
See the SleeperGem attack chain: https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html
One impersonates Microsoft Git Credential Manager. Two resurfaced after years dormant, then fetched native payloads and added persistence.
See the SleeperGem attack chain: https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html
π±11π₯1π1
π Hugging Face, the worldβs largest AI model repository, says an autonomous AI agent breached its production systems through a malicious dataset.
It accessed internal data and service credentials, then moved across several clusters through thousands of actions in short-lived sandboxes.
Full story: https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
It accessed internal data and service credentials, then moved across several clusters through thousands of actions in short-lived sandboxes.
Full story: https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
π₯13β‘5π4π1
β οΈ A Russian-speaking hacker used Google Gemini CLI to control eight compromised PCs at a dental clinic.
The AI moved the botnetβs C&C to a new VPS in six minutes, then handled commands, coding, and debugging.
Full attack chain: https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html
The AI moved the botnetβs C&C to a new VPS in six minutes, then handled commands, coding, and debugging.
Full attack chain: https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html
β‘7π7π€―6π₯2
π¨ ALERT: A newly disclosed 7-Zip vulnerability could let attackers run code when a user opens a crafted XZ archive.
CVE-2026-14266 is a high-severity heap overflow in the XZ decoder. The code runs with the same privileges as 7-Zip.
Details: https://thehackernews.com/2026/07/new-7-zip-vulnerability-could-let.html
CVE-2026-14266 is a high-severity heap overflow in the XZ decoder. The code runs with the same privileges as 7-Zip.
Details: https://thehackernews.com/2026/07/new-7-zip-vulnerability-could-let.html
π₯12β‘2
UPDATE: OpenSSL told THN that it views HollowByte as a server configuration issue, not a protocol flaw.
But key questions remain: whether the shipped fix improves glibcβs memory behavior and whether extended-support branches received the fix.
Okta still advises users running affected versions to upgrade.
Read: https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
But key questions remain: whether the shipped fix improves glibcβs memory behavior and whether extended-support branches received the fix.
Okta still advises users running affected versions to upgrade.
Read: https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
π₯8
π¨ A Russian intelligence service is hijacking exposed IP cameras across Europe and Ukraine to track military routes and weapons shipments.
In Ukraine, the feeds have aided attempts to neutralize troops and destroy equipment.
Read here: https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
In Ukraine, the feeds have aided attempts to neutralize troops and destroy equipment.
Read here: https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
π€17π₯5π€―3
Attackers can move in 29 minutes. High and critical application flaws take 55 days on average to fix.
The real problem is not how many vulnerabilities AI finds. It is how long those vulnerabilities stay exposed.
Read why mobilization now matters most: https://thehackernews.com/2026/07/mythos-didnt-break-your-security.html
The real problem is not how many vulnerabilities AI finds. It is how long those vulnerabilities stay exposed.
Read why mobilization now matters most: https://thehackernews.com/2026/07/mythos-didnt-break-your-security.html
π€―4π1