βΌοΈ Bing Images Turned a 1-Pixel SVG Into a SYSTEM Shell on Microsoftβs Servers.
A crafted SVG sent through Bingβs public image search ran commands as NT AUTHORITY\SYSTEM on Microsoftβs Windows servers and root on its Linux servers.
No login, session, or click required.
Read how the image reached a shell: https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html
A crafted SVG sent through Bingβs public image search ran commands as NT AUTHORITY\SYSTEM on Microsoftβs Windows servers and root on its Linux servers.
No login, session, or click required.
Read how the image reached a shell: https://thehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html
π8π€―7π₯3π2
π A public PoC exploit now lets a low-privileged Active Directory user impersonate a Domain Controller.
Certighost obtains a Domain Controller certificate, authenticates as that machine, and uses DCSync to retrieve the krbtgt secret.
Read how it works: https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html
Certighost obtains a Domain Controller certificate, authenticates as that machine, and uses DCSync to retrieve the krbtgt secret.
Read how it works: https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html
π₯16π€2
π Researchers uncovered an actively developed BlueNoroff phishing kit that uses fake Zoom and Teams calls to profile crypto wallets before delivering malware.
It hijacks trusted Telegram accounts, uses AI-generated faces, and pushes a ClickFix βSDK update.β
Read how it works: https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html
It hijacks trusted Telegram accounts, uses AI-generated faces, and pushes a ClickFix βSDK update.β
Read how it works: https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html
π₯6π1
This media is not supported in your browser
VIEW IN TELEGRAM
π¨ A public GitLab RCE PoC lets an authenticated user run commands as the git user on an unpatched 18.11.3 server.
No admin rights, CI runner access, victim interaction, or access to another userβs project.
See how the notebook-diff chain works: https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html
No admin rights, CI runner access, victim interaction, or access to another userβs project.
See how the notebook-diff chain works: https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html
π₯4β‘1π€1
β οΈ DevMan RaaS now runs a full affiliate portal.
Experts (tracking it as Funky Mantis) say the platform handles payload builds, victim records, chat, teams, support, and payouts in one place. Affiliates get structured workflows, deadlines, and an 80/20 cut.
184 victims claimed so far.
Read: https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html
Experts (tracking it as Funky Mantis) say the platform handles payload builds, victim records, chat, teams, support, and payouts in one place. Affiliates get structured workflows, deadlines, and an 80/20 cut.
184 victims claimed so far.
Read: https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html
π₯4β‘1π€1
π¨ Cl0p-linked attackers are actively exploiting a critical unauthenticated RCE in internet-exposed PTC Windchill and FlexPLM systems.
They chain two flaws, drop hex-named JSP webshells, and steal engineering data for double extortion.
Manufacturing, automotive, aerospace, and retail firms are the main targets.
Full details β https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html
They chain two flaws, drop hex-named JSP webshells, and steal engineering data for double extortion.
Manufacturing, automotive, aerospace, and retail firms are the main targets.
Full details β https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html
π₯3π2π€―2β‘1
π¨ Insurance phishing kits are now hijacking accounts while victims are still logging in.
InsureOTP relays stolen credentials and one-time passwords to legitimate insurance portals in real time, letting attackers complete authentication within the same browsing session.
Read how the operation works: https://thehackernews.com/2026/07/ctm360-research-reveals-how-insurance.html
InsureOTP relays stolen credentials and one-time passwords to legitimate insurance portals in real time, letting attackers complete authentication within the same browsing session.
Read how the operation works: https://thehackernews.com/2026/07/ctm360-research-reveals-how-insurance.html
π₯3π€―3
This media is not supported in your browser
VIEW IN TELEGRAM
π ALERT - A malicious JSON request can become unauthenticated RCE on affected Spring Boot fat-JAR apps running Fastjson 1.x.
Fastjson 1.x has no patched release, and ThreatBook and Imperva report attacks targeting the flaw.
Learn how it works and whoβs exposed: https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html
Fastjson 1.x has no patched release, and ThreatBook and Imperva report attacks targeting the flaw.
Learn how it works and whoβs exposed: https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html
π₯9β‘1
π¨ The malware arrives in pieces. The victimβs browser puts it together.
SourTrade malvertising delivers a legitimate Bun runtime, malicious bytecode, and PE components separately, then uses the browser to build the final Windows executable with a different hash each session.
See how the browser-assembled malware chain works: https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html
SourTrade malvertising delivers a legitimate Bun runtime, malicious bytecode, and PE components separately, then uses the browser to build the final Windows executable with a different hash each session.
See how the browser-assembled malware chain works: https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html
π€―9π6π₯6β‘1π1π±1
Commit a Jupyter notebook. Open its diff. Run commands as git on the GitLab server.
depthfirstlabs told The Hacker News its public exploit ports to other x86-64 builds with only offset changes.
Patched in June under bug fixes, no CVE.
Read: https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html
depthfirstlabs told The Hacker News its public exploit ports to other x86-64 builds with only offset changes.
Patched in June under bug fixes, no CVE.
Read: https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html
π₯3π2β‘1
Can a cloud tenant really black out the power grid? We asked the Bit2Watt researchers.
Their answer π the scariest result only works if thousands of GPUs spike their power at the same instant, and in reality they never line up that cleanly, which blunts the attack.
Also notable: they didn't warn any cloud provider first, because there's no product bug to patch.
Read: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html
Their answer π the scariest result only works if thousands of GPUs spike their power at the same instant, and in reality they never line up that cleanly, which blunts the attack.
Also notable: they didn't warn any cloud provider first, because there's no product bug to patch.
Read: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html
π3π€2β‘1π₯1π€―1