GitHub is cutting public bug bounty payouts by at least half.
The reset comes as AI floods programs with low-effort reports while helping skilled researchers find real bugs faster.
Top rewards now move to an invite-only VIP tier.
Read the full story: https://thehackernews.com/2026/07/github-cuts-public-bug-bounty-payouts.html
The reset comes as AI floods programs with low-effort reports while helping skilled researchers find real bugs faster.
Top rewards now move to an invite-only VIP tier.
Read the full story: https://thehackernews.com/2026/07/github-cuts-public-bug-bounty-payouts.html
π€―18π₯4π2π±2π€1
β οΈ Attackers are exploiting a Check Point SmartConsole flaw that can grant full administrative access.
CVE-2026-16232 affects management servers exposed directly to the internet under a specific configuration. Check Point says a small number of customers were targeted.
Read: https://thehackernews.com/2026/07/check-point-patches-exploited.html
CVE-2026-16232 affects management servers exposed directly to the internet under a specific configuration. Check Point says a small number of customers were targeted.
Read: https://thehackernews.com/2026/07/check-point-patches-exploited.html
π₯5
π A newly disclosed, 9-year-old #Linux flaw lets unprivileged users overwrite root-owned files and gain persistent root access.
On affected XFS systems, the overwrite survives reboot without changing ownership, permissions, timestamps, or the setuid bit.
Read: https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html
On affected XFS systems, the overwrite survives reboot without changing ownership, permissions, timestamps, or the setuid bit.
Read: https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html
π₯9β‘3π2
π₯ Google now lets users RECOVER LOCKED ACCOUNTS with a selfie video.
Users save a face clip, then record another when they need to prove the account is theirs. An optional setting can expand how Google uses that data beyond sign-in.
What is stored and how it may be used: https://thehackernews.com/2026/07/google-adds-selfie-video-recovery-for.html
Users save a face clip, then record another when they need to prove the account is theirs. An optional setting can expand how Google uses that data beyond sign-in.
What is stored and how it may be used: https://thehackernews.com/2026/07/google-adds-selfie-video-recovery-for.html
π±16π€8β‘4π₯1
π¨ Attackers turned GitHub-hosted runners into cPanel attack infrastructure.
They planted 583 malicious workflows to target cPanel and WHM servers exposed to CVE-2026-41940, hunting for cloud keys, API tokens, SSH data, and other secrets.
How the campaign worked: https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html
They planted 583 malicious workflows to target cPanel and WHM servers exposed to CVE-2026-41940, hunting for cloud keys, API tokens, SSH data, and other secrets.
How the campaign worked: https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html
π₯6π3
Social engineering is now a margin game.
Convincing lures cost 95% less to produce. Median time to click: 21 seconds.
Doppelβs Josh Bartolomie says defenders should stop chasing lures and make attacks too costly to scale.
Learn how to break the economics: https://thehackernews.com/expert-insights/2026/07/how-to-make-social-engineering.html
Convincing lures cost 95% less to produce. Median time to click: 21 seconds.
Doppelβs Josh Bartolomie says defenders should stop chasing lures and make attacks too costly to scale.
Learn how to break the economics: https://thehackernews.com/expert-insights/2026/07/how-to-make-social-engineering.html
π₯5
π China-nexus JadeProx breached a Vietnamese hospitalβs medical imaging server and targeted Malaysiaβs foreign ministry with a new Windows loader.
The same operation also hid malware inside a fake Claude installer.
How the campaign worked: https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html
The same operation also hid malware inside a fake Claude installer.
How the campaign worked: https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html
π₯5π1
βΌοΈ Chaos Hid Its C2 Inside Chrome.
Instead of connecting directly to its command server, Chaos #ransomwareβs msaRAT launches Chrome or Edge in hidden mode and uses the browser to send encrypted commands over WebRTC, making the malicious traffic look like normal browser activity.
Read: https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html
Instead of connecting directly to its command server, Chaos #ransomwareβs msaRAT launches Chrome or Edge in hidden mode and uses the browser to send encrypted commands over WebRTC, making the malicious traffic look like normal browser activity.
Read: https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html
π±7π5π€―1
This media is not supported in your browser
VIEW IN TELEGRAM
π¨ Researchers say one short message let Claude Cowork escape its Linux VM and access files across the host Mac.
The SharedRoot chain used CVE-2026-46331 to gain guest root, then crossed through Coworkβs read-write host mount.
Read how it worked: https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html
The SharedRoot chain used CVE-2026-46331 to gain guest root, then crossed through Coworkβs read-write host mount.
Read how it worked: https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html
π10
This media is not supported in your browser
VIEW IN TELEGRAM
π¨ Attackers are targeting the datacenters that train, host, and serve AI, not just the AI models themselves.
Lava has released FORGE: The Top 10 Data Center & AI Infrastructure Security Risks: https://thn.news/forge-risk-guide
Built with security leaders and practitioners across neoclouds, HPC, and enterprise security β open, free, and made to evolve.
Lava has released FORGE: The Top 10 Data Center & AI Infrastructure Security Risks: https://thn.news/forge-risk-guide
Built with security leaders and practitioners across neoclouds, HPC, and enterprise security β open, free, and made to evolve.
π₯8π2
β‘ Spyware on Phones, Malware in Code, Attacks on Factories
This weekβs #ThreatsDay roundup covers 15 security stories spanning mobile surveillance, software supply-chain attacks, AI abuse, and industrial systems.
β’ PyPI Lockdown
β’ PLC Attacks
β’ Fake VPN Malware
β’ Vibe-Code Bugs
β’ AI Jailbreaks
β’ TrickBot DNS
β’ AI Bug Hunter
...and more. Read: https://thehackernews.com/2026/07/threatsday-android-spyware-plc-attacks.html
This weekβs #ThreatsDay roundup covers 15 security stories spanning mobile surveillance, software supply-chain attacks, AI abuse, and industrial systems.
β’ PyPI Lockdown
β’ PLC Attacks
β’ Fake VPN Malware
β’ Vibe-Code Bugs
β’ AI Jailbreaks
β’ TrickBot DNS
β’ AI Bug Hunter
...and more. Read: https://thehackernews.com/2026/07/threatsday-android-spyware-plc-attacks.html
π₯6
Not every dangerous machine identity is stolen. Some are fake from the start.
Fabricated machine identities can blend into NHI sprawl, gain privileges, and evade controls built to catch stolen credentials because no legitimate owner exists to raise the alarm.
See how it works: https://thehackernews.com/2026/07/how-synthetic-identity-fraud-is-coming.html
Fabricated machine identities can blend into NHI sprawl, gain privileges, and evade controls built to catch stolen credentials because no legitimate owner exists to raise the alarm.
See how it works: https://thehackernews.com/2026/07/how-synthetic-identity-fraud-is-coming.html
π3
π No link. No attachment. Just viewing the email.
A Russian state-supported espionage group exploited a Zimbra zero-day for at least 5 months to steal passwords, 2FA recovery codes, organization directories, and 90 days of mail.
Read how ZimReaper worked - https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
A Russian state-supported espionage group exploited a Zimbra zero-day for at least 5 months to steal passwords, 2FA recovery codes, organization directories, and 90 days of mail.
Read how ZimReaper worked - https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
π₯12π€―7π4π±2β‘1
π¨ A malicious Notepad++ plugin is turning the legitimate editor into a malware loader.
CERT-UA links the campaign to Russia-aligned UAC-0099. It establishes persistence and deploys MATCHBOIL.V2 for follow-on malware.
Read more: https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html
CERT-UA links the campaign to Russia-aligned UAC-0099. It establishes persistence and deploys MATCHBOIL.V2 for follow-on malware.
Read more: https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html
π7π€―2π₯1π€1
π Kimi K3 AI agents found Redis 0-days. Then they built working RCE exploits.
The authenticated chains abuse RESTORE across multiple #Redis releases. Redis has shipped seven security updates, with no exploitation reported in the wild.
Details: https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html
The authenticated chains abuse RESTORE across multiple #Redis releases. Redis has shipped seven security updates, with no exploitation reported in the wild.
Details: https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html
π8π₯7
β οΈ Eight NodeBB forum software flaws are now public, along with exploit code.
Three need no account. Another let an ordinary member open the admin panel, while separate bugs exposed private messages and private categories.
Read: https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html
Three need no account. Another let an ordinary member open the admin panel, while separate bugs exposed private messages and private categories.
Read: https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html
π₯2π2
π¨ Golden Chickens has resurfaced with four new malware families.
One can control live Chrome sessions. Another loads 14 attack modules only when the operator needs them.
Inside the rebuilt MaaS toolkit: https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html
One can control live Chrome sessions. Another loads 14 attack modules only when the operator needs them.
Inside the rebuilt MaaS toolkit: https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html
π₯3π2
π A hacker switched off Hermes AIβs command approvals and set the agent loose to automate post-exploitation inside Thailandβs Finance Ministry.
It scanned hosts, searched for ways to gain root access, and crawled staff files dating to 2012. The operation surfaced because the attacker left its logs exposed.
Read the full story: https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html
It scanned hosts, searched for ways to gain root access, and crawled staff files dating to 2012. The operation surfaced because the attacker left its logs exposed.
Read the full story: https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html
π10π2π₯1π1
The hard part of AI agent security is not finding the agents. It is controlling what they can do.
Agents can call APIs, access data, change systems, and act without a human in the loop. Static inventories and permissions are not enough to govern that behavior across every platform.
Visibility is the start. Intent-based enforcement is the control.
Read the full analysis: https://thehackernews.com/2026/07/seeing-ai-agents-is-not-enough-security.html
Agents can call APIs, access data, change systems, and act without a human in the loop. Static inventories and permissions are not enough to govern that behavior across every platform.
Visibility is the start. Intent-based enforcement is the control.
Read the full analysis: https://thehackernews.com/2026/07/seeing-ai-agents-is-not-enough-security.html
π₯2
π¨ One phishing link could have planted a rogue ChatGPT Workspace Agent inside an organization.
New AgentForger flaw could attach existing connectors, turn off approval prompts, run every hour, and take new commands from the victimβs mailbox.
Read how it worked: https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html
New AgentForger flaw could attach existing connectors, turn off approval prompts, run every hour, and take new commands from the victimβs mailbox.
Read how it worked: https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html
π₯3π3
βΌοΈ Bing Images Turned a 1-Pixel SVG Into a SYSTEM Shell on Microsoftβs Servers.
A crafted SVG sent through Bingβs public image search ran commands as NT AUTHORITY\SYSTEM on Microsoftβs Windows servers and root on its Linux servers.
No login, session, or click required.
Read how the image reached a shell: https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html
A crafted SVG sent through Bingβs public image search ran commands as NT AUTHORITY\SYSTEM on Microsoftβs Windows servers and root on its Linux servers.
No login, session, or click required.
Read how the image reached a shell: https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html
π8π€―3π₯2