7,600 malicious GitHub repositories are spreading SmartLoader malware.
Researchers found 800+ fake AI Skills and MCP server repos using copied projects, fake profiles, and READMEs to deliver malware.
Read the full analysis: https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
Researchers found 800+ fake AI Skills and MCP server repos using copied projects, fake profiles, and READMEs to deliver malware.
Read the full analysis: https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html
β‘7
β οΈ Attackers are exploiting a critical ServiceNow AI Platform flaw in the wild.
CVE-2026-6875 is a pre-authentication sandbox escape that could let an unauthenticated attacker run arbitrary code.
Self-hosted customers should check their patch status now.
Details: https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html
CVE-2026-6875 is a pre-authentication sandbox escape that could let an unauthenticated attacker run arbitrary code.
Self-hosted customers should check their patch status now.
Details: https://thehackernews.com/2026/07/critical-servicenow-ai-platform-flaw.html
π₯6
π New ENCFORGE ransomware is built to encrypt AI model weights, vector indexes, and training data.
Deployed via Langflow CVE-2025-3248 (CVSS 9.8, CISA KEV). Experts link it to the same operator from the earlier agentic attack.
Learn how the attack reached host root: https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html
Deployed via Langflow CVE-2025-3248 (CVSS 9.8, CISA KEV). Experts link it to the same operator from the earlier agentic attack.
Learn how the attack reached host root: https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html
π4π2π₯1
UPDATE: SharkNinja has responded to The Hacker News story on the Shark robot vacuum flaw.
The company says it has "completely addressed" the vulnerability, but has not said when the fix shipped, whether it reissued the exposed device certificates or only rescoped the policy, or how many devices were affected.
Full statement in the article: https://thehackernews.com/2026/07/unpatched-shark-vacuum-flaw-could-let.html
The company says it has "completely addressed" the vulnerability, but has not said when the fix shipped, whether it reissued the exposed device certificates or only rescoped the policy, or how many devices were affected.
Full statement in the article: https://thehackernews.com/2026/07/unpatched-shark-vacuum-flaw-could-let.html
β‘4
π ALERT - WordPress sites are under active attack.
Attackers are exploiting the #wp2shell chain to gain unauthenticated RCE on vulnerable stock installations, with no plugins required. Public exploit code is now fueling mass scanning and web shell deployments.
Read what defenders should check: https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html
Attackers are exploiting the #wp2shell chain to gain unauthenticated RCE on vulnerable stock installations, with no plugins required. Public exploit code is now fueling mass scanning and web shell deployments.
Read what defenders should check: https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html
π₯8π3β‘2
Developer laptops are heavily monitored, yet valid credentials still hide in files, caches, logs, and AI tool directories.
Carole Winqwist of GitGuardian explains what endpoint security misses, why those secrets matter, and how teams can find them before an incident.
See what the most monitored device still hides: https://thehackernews.com/expert-insights/2026/07/the-most-monitored-device-in-company-is.html
Carole Winqwist of GitGuardian explains what endpoint security misses, why those secrets matter, and how teams can find them before an incident.
See what the most monitored device still hides: https://thehackernews.com/expert-insights/2026/07/the-most-monitored-device-in-company-is.html
π4π₯3
β‘ A cloud tenant could threaten the power grid without exploiting a single vulnerability.
New research called Bit2Watt shows how legitimate GPU workloads can be tuned to create rapid power swings, then models how synchronized fleets could destabilize the grid beneath a data center.
Full story: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html
New research called Bit2Watt shows how legitimate GPU workloads can be tuned to create rapid power swings, then models how synchronized fleets could destabilize the grid beneath a data center.
Full story: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html
π₯4π2β‘1
Claude Mythos turned a Firefox security patch into a working code-execution exploit in under an hour.
It built 8 exploits from 18 Firefox patches and chained 8 Windows kernel bugs to SYSTEM.
The patch-to-exploit window is collapsing.
Read why patching faster is no longer enough: https://thehackernews.com/2026/07/n-day-is-becoming-n-hour-patching.html
It built 8 exploits from 18 Firefox patches and chained 8 Windows kernel bugs to SYSTEM.
The patch-to-exploit window is collapsing.
Read why patching faster is no longer enough: https://thehackernews.com/2026/07/n-day-is-becoming-n-hour-patching.html
π11π5π₯4
π¨ Invisible text on an #Android screen can hijack an AI agent and make it run commands on the PC controlling the phone.
Researchers tested 5 open-source frameworks. Every one failed at least six of seven attacks.
Read how the chain works: https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html
Researchers tested 5 open-source frameworks. Every one failed at least six of seven attacks.
Read how the chain works: https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html
π€―7π₯6π3
π¨ A critical Zimbra flaw could allow command injection on servers with SNMP notifications enabled.
Zimbra 10.1.20 also fixes four XSS bugs and a mail-forwarding bypass that could let authenticated users exfiltrate email.
Read the full details: https://thehackernews.com/2026/07/zimbra-patches-critical-snmp-command.html
Zimbra 10.1.20 also fixes four XSS bugs and a mail-forwarding bypass that could let authenticated users exfiltrate email.
Read the full details: https://thehackernews.com/2026/07/zimbra-patches-critical-snmp-command.html
π₯5
π¨ Attackers are exploiting Palo Alto Networks PAN-OS flaw CVE-2026-0257 to deploy Qilin ransomware.
Some intrusions ended in rapid encryption. Others escalated to credential theft, data exfiltration, and double extortion.
How the attacks unfolded: https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html
Some intrusions ended in rapid encryption. Others escalated to credential theft, data exfiltration, and double extortion.
How the attacks unfolded: https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html
π₯4
π¨ Patching your #SharePoint Server may not be enough if it was already exposed.
Attackers are exploiting CVE-2026-50522, a critical RCE flaw, to pull machine keys with a single request and maintain access, watchTowr says.
A public PoC is available, and this is the third SharePoint Server flaw linked to active exploitation in July 2026.
Details: https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html
Attackers are exploiting CVE-2026-50522, a critical RCE flaw, to pull machine keys with a single request and maintain access, watchTowr says.
A public PoC is available, and this is the third SharePoint Server flaw linked to active exploitation in July 2026.
Details: https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html
π5
β‘ Google built an AI that finds and patches software vulnerabilities on its own, and it's capable enough that Google won't release it publicly.
In testing, "Gemini 3.5 Flash Cyber" found more new bugs than rival models and even wrote a working exploit that slipped past standard defenses.
Read more: https://thehackernews.com/2026/07/google-launches-gemini-35-flash-cyber.html
In testing, "Gemini 3.5 Flash Cyber" found more new bugs than rival models and even wrote a working exploit that slipped past standard defenses.
Read more: https://thehackernews.com/2026/07/google-launches-gemini-35-flash-cyber.html
π17π₯3β‘1
π Invisible text on a web page was enough to hijack AWS's Kiro AI coding tool.
Ask it to summarize a page, and hidden instructions make Kiro rewrite its own config and run attacker code. The approval prompt did nothing.
Learn how the attack crossed Kiro's security boundary: https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
Ask it to summarize a page, and hidden instructions make Kiro rewrite its own config and run attacker code. The approval prompt did nothing.
Learn how the attack crossed Kiro's security boundary: https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
π₯11π2β‘1
Appleβs Hide My Email exposed the real address it was designed to hide.
A flaw caused usersβ personal email addresses to appear in mail logs when messages sent to an alias were rejected as spam.
Apple fixed it on July 3, more than a year after disclosure.
Read how the leak worked: https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html
A flaw caused usersβ personal email addresses to appear in mail logs when messages sent to an alias were rejected as spam.
Apple fixed it on July 3, more than a year after disclosure.
Read how the leak worked: https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html
π€―13π7π3π₯2β‘1
π₯ OpenAI says its own AI models broke out of a sandbox, exploited a zero-day, and targeted Hugging Faceβs production infrastructure to cheat a security benchmark.
The incident showed how long-running models can learn and work around approval-system blind spots.
Read the full story: https://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html
The incident showed how long-running models can learn and work around approval-system blind spots.
Read the full story: https://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html
π±17π3π€2β‘1π€―1
β οΈ An attacker does not need the reviewerβs broader Azure DevOps permissions.
In tests, one hidden PR comment steered the reviewerβs AI coding agent into other projects and leaked data the attacker could not access directly.
How the missing MCP guardrail enables the chain: https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html
In tests, one hidden PR comment steered the reviewerβs AI coding agent into other projects and leaked data the attacker could not access directly.
How the missing MCP guardrail enables the chain: https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html
π±7
One extra βtβ hid a package built to rig live betting results.
Newtonsoftt.Json[.]Net worked as a normal JSON library for most users, but targeted Digitainβs FG-Crash backend when the right conditions were present.
Inside the selective attack: https://thehackernews.com/2026/07/trojanized-newtonsoftjson-fork-hides.html
Newtonsoftt.Json[.]Net worked as a normal JSON library for most users, but targeted Digitainβs FG-Crash backend when the right conditions were present.
Inside the selective attack: https://thehackernews.com/2026/07/trojanized-newtonsoftjson-fork-hides.html
π5π₯3
π MFA didnβt stop Kratos.
The phishing kit stole Microsoft 365 session cookies, letting attackers enter accounts without another MFA check. Police took 200+ servers offline and arrested the alleged operator in Indonesia.
But about 1,800 customers may still have the code.
Read: https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html
The phishing kit stole Microsoft 365 session cookies, letting attackers enter accounts without another MFA check. Police took 200+ servers offline and arrested the alleged operator in Indonesia.
But about 1,800 customers may still have the code.
Read: https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html
π₯10π3
Around 79% of attacks are malware-free, CrowdStrike estimates.
Endpoint alerts alone can miss credential theft and lateral movement across identity and cloud systems. AI cannot connect what the SOC never captured.
Why network evidence matters: https://thehackernews.com/2026/07/why-modern-socs-need-multi-layered.html
Endpoint alerts alone can miss credential theft and lateral movement across identity and cloud systems. AI cannot connect what the SOC never captured.
Why network evidence matters: https://thehackernews.com/2026/07/why-modern-socs-need-multi-layered.html
π₯4
Windmill servers are under active attack.
Experts say attackers are exploiting CVE-2026-29059 to read arbitrary server files without logging in. On some systems, the same flaw can lead to superadmin access and code execution.
Full details: https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html
Experts say attackers are exploiting CVE-2026-29059 to read arbitrary server files without logging in. On some systems, the same flaw can lead to superadmin access and code execution.
Full details: https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html
π₯4