π¨ Two SonicWall SMA 1000 zero-days were exploited before disclosure to gain root access.
Researchers link the activity to UTA0533, which planted custom malware and sniffed unencrypted LDAP credentials from compromised VPN appliances.
Full attack chain: https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html
Researchers link the activity to UTA0533, which planted custom malware and sniffed unencrypted LDAP credentials from compromised VPN appliances.
Full attack chain: https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html
π₯11β‘1
β οΈ Russian state-backed hackers are using fake CAPTCHA checks to trick Ukrainian targets into running malware on their own Windows systems.
The same campaign also uses fake security apps to backdoor #Android devices.
Read the full attack chain: https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html
The same campaign also uses fake security apps to backdoor #Android devices.
Read the full attack chain: https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html
π₯16π€―7β‘5π4π3π2
π WARNING - A new critical NGINX vulnerability that has existed for 15-years lets unauthenticated attackers crash worker processes with crafted HTTP requests.
CVE-2026-42533 affects specific regex map configurations.
F5 says it may also allow pre-auth RCE if ASLR is disabled or bypassed.
Read how the bug works: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
CVE-2026-42533 affects specific regex map configurations.
F5 says it may also allow pre-auth RCE if ASLR is disabled or bypassed.
Read how the bug works: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
π€11β‘2π₯2
π WARNING - A new critical NGINX vulnerability that has existed for 15-years lets unauthenticated attackers crash worker processes with crafted HTTP requests.
CVE-2026-42533 affects specific regex map configurations.
F5 says it may also allow pre-auth RCE if ASLR is disabled or bypassed.
Read how the bug works: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
CVE-2026-42533 affects specific regex map configurations.
F5 says it may also allow pre-auth RCE if ASLR is disabled or bypassed.
Read how the bug works: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
π9π₯6π€3β‘2π2
β οΈ Three malicious RubyGems packages avoid CI runners and target developer machines.
One impersonates Microsoft Git Credential Manager. Two resurfaced after years dormant, then fetched native payloads and added persistence.
See the SleeperGem attack chain: https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html
One impersonates Microsoft Git Credential Manager. Two resurfaced after years dormant, then fetched native payloads and added persistence.
See the SleeperGem attack chain: https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html
π±11π₯1π1
π Hugging Face, the worldβs largest AI model repository, says an autonomous AI agent breached its production systems through a malicious dataset.
It accessed internal data and service credentials, then moved across several clusters through thousands of actions in short-lived sandboxes.
Full story: https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
It accessed internal data and service credentials, then moved across several clusters through thousands of actions in short-lived sandboxes.
Full story: https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
π₯13β‘5π4π1
β οΈ A Russian-speaking hacker used Google Gemini CLI to control eight compromised PCs at a dental clinic.
The AI moved the botnetβs C&C to a new VPS in six minutes, then handled commands, coding, and debugging.
Full attack chain: https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html
The AI moved the botnetβs C&C to a new VPS in six minutes, then handled commands, coding, and debugging.
Full attack chain: https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html
β‘7π7π€―6π₯2
π¨ ALERT: A newly disclosed 7-Zip vulnerability could let attackers run code when a user opens a crafted XZ archive.
CVE-2026-14266 is a high-severity heap overflow in the XZ decoder. The code runs with the same privileges as 7-Zip.
Details: https://thehackernews.com/2026/07/new-7-zip-vulnerability-could-let.html
CVE-2026-14266 is a high-severity heap overflow in the XZ decoder. The code runs with the same privileges as 7-Zip.
Details: https://thehackernews.com/2026/07/new-7-zip-vulnerability-could-let.html
π₯12β‘2
UPDATE: OpenSSL told THN that it views HollowByte as a server configuration issue, not a protocol flaw.
But key questions remain: whether the shipped fix improves glibcβs memory behavior and whether extended-support branches received the fix.
Okta still advises users running affected versions to upgrade.
Read: https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
But key questions remain: whether the shipped fix improves glibcβs memory behavior and whether extended-support branches received the fix.
Okta still advises users running affected versions to upgrade.
Read: https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
π₯8
π¨ A Russian intelligence service is hijacking exposed IP cameras across Europe and Ukraine to track military routes and weapons shipments.
In Ukraine, the feeds have aided attempts to neutralize troops and destroy equipment.
Read here: https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
In Ukraine, the feeds have aided attempts to neutralize troops and destroy equipment.
Read here: https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
π€17π₯5π€―3
Attackers can move in 29 minutes. High and critical application flaws take 55 days on average to fix.
The real problem is not how many vulnerabilities AI finds. It is how long those vulnerabilities stay exposed.
Read why mobilization now matters most: https://thehackernews.com/2026/07/mythos-didnt-break-your-security.html
The real problem is not how many vulnerabilities AI finds. It is how long those vulnerabilities stay exposed.
Read why mobilization now matters most: https://thehackernews.com/2026/07/mythos-didnt-break-your-security.html
π€―4π1
Starting the week with a fresh batch of security problems to track.
π΄ WordPress RCE
β οΈ SonicWall Zero-Days
π€ AI Key-Hunting Botnet
ποΈ SharePoint Exploitation
πΎ OpenSSL Memory DoS
π Crypto Wallet Stealer
π EDR-Killing Ransomware
π© Fake GST Malware
π Nuclear Data Leak
π§© Public Code Abuse
Read the full Cybersecurity Recap: https://thehackernews.com/2026/07/weekly-recap-wordpress-rce-sonicwall-0.html
π΄ WordPress RCE
β οΈ SonicWall Zero-Days
π€ AI Key-Hunting Botnet
ποΈ SharePoint Exploitation
πΎ OpenSSL Memory DoS
π Crypto Wallet Stealer
π EDR-Killing Ransomware
π© Fake GST Malware
π Nuclear Data Leak
π§© Public Code Abuse
Read the full Cybersecurity Recap: https://thehackernews.com/2026/07/weekly-recap-wordpress-rce-sonicwall-0.html
π₯8
AI agents are inheriting long-lived secrets, broad access, and accounts that nobody properly manages.
Compromise one, and an attacker gains an identity that can call tools, chain actions, and move through systems at machine speed.
Why securing AI agents starts with privilege, not the model: https://thehackernews.com/expert-insights/2026/07/the-new-insider-has-no-pulse-securing.html
Compromise one, and an attacker gains an identity that can call tools, chain actions, and move through systems at machine speed.
Why securing AI agents starts with privilege, not the model: https://thehackernews.com/expert-insights/2026/07/the-new-insider-has-no-pulse-securing.html
π₯5π1
π¨ This malware hides in Microsoft 365 calendar events dated to 2050.
You would never scroll that far.
HollowGraph counts on it.
The calendar carries attacker commands and stolen files through normal Graph traffic.
Here's how it works: https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html
You would never scroll that far.
HollowGraph counts on it.
The calendar carries attacker commands and stolen files through normal Graph traffic.
Here's how it works: https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html
π₯7π4β‘2π2
π¨ A malware operator left its server wide open, exposing a 1,048-file phishing toolkit.
A live campaign used a fake Mexican government site and WebDAV to drop an in-memory infostealer. The recovered files point to an AI-assisted build-and-test workflow.
Read more: https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html
A live campaign used a fake Mexican government site and WebDAV to drop an in-memory infostealer. The recovered files point to an AI-assisted build-and-test workflow.
Read more: https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html
π16π₯4β‘2
7,600 malicious GitHub repositories are spreading SmartLoader malware.
Researchers found 800+ fake AI Skills and MCP server repos using copied projects, fake profiles, and READMEs to deliver malware.
Read the full analysis: https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
Researchers found 800+ fake AI Skills and MCP server repos using copied projects, fake profiles, and READMEs to deliver malware.
Read the full analysis: https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
β‘8
β οΈ Attackers are exploiting a critical ServiceNow AI Platform flaw in the wild.
CVE-2026-6875 is a pre-authentication sandbox escape that could let an unauthenticated attacker run arbitrary code.
Self-hosted customers should check their patch status now.
Details: https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html
CVE-2026-6875 is a pre-authentication sandbox escape that could let an unauthenticated attacker run arbitrary code.
Self-hosted customers should check their patch status now.
Details: https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html
π₯6
π New ENCFORGE ransomware is built to encrypt AI model weights, vector indexes, and training data.
Deployed via Langflow CVE-2025-3248 (CVSS 9.8, CISA KEV). Experts link it to the same operator from the earlier agentic attack.
Learn how the attack reached host root: https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html
Deployed via Langflow CVE-2025-3248 (CVSS 9.8, CISA KEV). Experts link it to the same operator from the earlier agentic attack.
Learn how the attack reached host root: https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html
π4π2π₯1
UPDATE: SharkNinja has responded to The Hacker News story on the Shark robot vacuum flaw.
The company says it has "completely addressed" the vulnerability, but has not said when the fix shipped, whether it reissued the exposed device certificates or only rescoped the policy, or how many devices were affected.
Full statement in the article: https://thehackernews.com/2026/07/unpatched-shark-vacuum-flaw-could-let.html
The company says it has "completely addressed" the vulnerability, but has not said when the fix shipped, whether it reissued the exposed device certificates or only rescoped the policy, or how many devices were affected.
Full statement in the article: https://thehackernews.com/2026/07/unpatched-shark-vacuum-flaw-could-let.html
β‘4
π ALERT - WordPress sites are under active attack.
Attackers are exploiting the #wp2shell chain to gain unauthenticated RCE on vulnerable stock installations, with no plugins required. Public exploit code is now fueling mass scanning and web shell deployments.
Read what defenders should check: https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html
Attackers are exploiting the #wp2shell chain to gain unauthenticated RCE on vulnerable stock installations, with no plugins required. Public exploit code is now fueling mass scanning and web shell deployments.
Read what defenders should check: https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html
π₯8π3β‘2
Developer laptops are heavily monitored, yet valid credentials still hide in files, caches, logs, and AI tool directories.
Carole Winqwist of GitGuardian explains what endpoint security misses, why those secrets matter, and how teams can find them before an incident.
See what the most monitored device still hides: https://thehackernews.com/expert-insights/2026/07/the-most-monitored-device-in-company-is.html
Carole Winqwist of GitGuardian explains what endpoint security misses, why those secrets matter, and how teams can find them before an incident.
See what the most monitored device still hides: https://thehackernews.com/expert-insights/2026/07/the-most-monitored-device-in-company-is.html
π4π₯3