β‘ Microsoft says MAI-Cyber-1-Flash helps MDASH reach 95.95% on CyberGym at half the cost of its current best model mix.
The cybersecurity-specific model handles up to 90% of tasks, while GPT-5.4 takes the hardest 10%.
Read how the system works: https://thehackernews.com/2026/07/microsoft-says-new-cybersecurity-ai.html
The cybersecurity-specific model handles up to 90% of tasks, while GPT-5.4 takes the hardest 10%.
Read how the system works: https://thehackernews.com/2026/07/microsoft-says-new-cybersecurity-ai.html
π₯7
π A researcher says AI helped turn a #Linux traffic-control race into a root exploit.
CVE-2026-53264 lets a local user gain root on the tested CentOS Stream 9 build, but needs user namespaces, specific kernel options, and build-specific ROP offsets.
Read how the exploit works: https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html
CVE-2026-53264 lets a local user gain root on the tested CentOS Stream 9 build, but needs user namespaces, specific kernel options, and build-specific ROP offsets.
Read how the exploit works: https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html
π₯10
π¨ A critical TeamCity flaw could let attackers run OS commands without logging in.
CVE-2026-63077 affects all on-premises versions and bypasses authentication through the agent polling protocol. JetBrains has released fixes and reports no known exploitation.
Full details - https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html
CVE-2026-63077 affects all on-premises versions and bypasses authentication through the agent polling protocol. JetBrains has released fixes and reports no known exploitation.
Full details - https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html
π₯8π€―5
AI agents do not need to break permissions to act outside their intended role.
Lasso says its platform builds a behavioral baseline for each agent and can block intent drift in under 50ms, linking red team findings directly to runtime controls.
How the closed loop works: https://thehackernews.com/expert-insights/2026/07/a-look-inside-lassos-ai-security.html
Lasso says its platform builds a behavioral baseline for each agent and can block intent drift in under 50ms, linking red team findings directly to runtime controls.
How the closed loop works: https://thehackernews.com/expert-insights/2026/07/a-look-inside-lassos-ai-security.html
π₯6π€2
π¨ Iranian state-backed Nimbus Manticore is turning compromised systems into covert network relays.
NightLedger executes commands, uploads files, and captures screenshots, while BridgeHead and ArcBridge tunnel traffic through victim networks.
Read more: https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html
NightLedger executes commands, uploads files, and captures screenshots, while BridgeHead and ArcBridge tunnel traffic through victim networks.
Read more: https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html
π11β‘2π€2π₯1
β οΈ ALERT - OpenWrt users, this one needs attention.
A critical pre-auth DHCPv6 flaw could let an attacker who can reach the service send a crafted request and run code as root on the router.
A separate audit also found 7 more flaws, including three pre-auth paths to device compromise.
What users need to update now: https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html
A critical pre-auth DHCPv6 flaw could let an attacker who can reach the service send a crafted request and run code as root on the router.
A separate audit also found 7 more flaws, including three pre-auth paths to device compromise.
What users need to update now: https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html
π₯10β‘1
π₯ JFrog confirms OpenAI models exploited a zero-day in self-hosted "Artifactory," escalated privileges, and moved laterally until they reached the open internet.
From there, the models targeted #HuggingFace and obtained ExploitGym solutions from its production database via a separate attack path.
Here's how it happened: https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html
From there, the models targeted #HuggingFace and obtained ExploitGym solutions from its production database via a separate attack path.
Here's how it happened: https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html
π₯7π€3π€―3β‘1
βΌοΈ 24,650 internet-exposed BMCs are leaking IPMI authentication hashes before login, giving attackers what they need to crack passwords offline.
More than 30% matched recoverable passwords, including factory-issued credentials.
Read what exposed servers need to lock down: https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html
More than 30% matched recoverable passwords, including factory-issued credentials.
Read what exposed servers need to lock down: https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html
π4π€―3π₯1
π¨ A new Mirai-derived botnet called Tengu can reboot compromised #Linux devices when defenders kill its main process, giving the malware another chance to return.
It also supports 25 DDoS methods, SOCKS5 proxying, shell commands, and additional ELF or APK payloads.
See how Tengu resists removal: https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html
It also supports 25 DDoS methods, SOCKS5 proxying, shell commands, and additional ELF or APK payloads.
See how Tengu resists removal: https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html
π₯9β‘1
π΅οΈ Your network tool sees traffic to an LLM provider's API. Your browser extension sees an employee building an agent in Copilot Studio. Neither one sees the Agentforce bot quietly holding API access to your CRM.
That's the real problem with shadow AI agent discovery: every method has a blind spot, and most vendors don't say so upfront.
Nudge Security's new guide breaks down the most common discovery approaches: network traffic analysis, browser extensions, endpoint agents, identity signals, SaaS API discovery, and more; what each one actually catches, and where the coverage gaps are.
π See how the methods stack up side by side
π Understand what each one misses (and why)
π Get the questions to ask any vendor claiming "full" agent coverage
Read the Guide: https://thn.news/ai-discovery-methods
That's the real problem with shadow AI agent discovery: every method has a blind spot, and most vendors don't say so upfront.
Nudge Security's new guide breaks down the most common discovery approaches: network traffic analysis, browser extensions, endpoint agents, identity signals, SaaS API discovery, and more; what each one actually catches, and where the coverage gaps are.
π See how the methods stack up side by side
π Understand what each one misses (and why)
π Get the questions to ask any vendor claiming "full" agent coverage
Read the Guide: https://thn.news/ai-discovery-methods
π€5π2π₯2β‘1
π¨ UPDATE - Public PoC exploit released for CVE-2026-42533, chaining an #nginx memory leak and heap overflow to bypass ASLR and achieve unauthenticated command execution.
Read: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
Read: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html
π₯10β‘1
βΌοΈ BREAKING β Claude AI found a working HAWK-256 key-recovery attack.
HAWK is a NIST post-quantum cryptography candidate. It also made an impractical 7-round AES-128 attack up to 800x faster.
Read this here: https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
HAWK is a NIST post-quantum cryptography candidate. It also made an impractical 7-round AES-128 attack up to 800x faster.
Read this here: https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
π€―34π₯13π6π4π±2β‘1
β οΈ Two compromised joyfill npm beta packages run malware as soon as Node.js imports them. No install hook needed.
The implant fetches a DEV#POPPER-linked RAT through three blockchains, while a detached branch can keep running after builds or tests exit.
Read the full story: https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html
The implant fetches a DEV#POPPER-linked RAT through three blockchains, while a detached branch can keep running after builds or tests exit.
Read the full story: https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html
π5π1π€―1
π¨ OpenAI says the Hugging Face breach was broader than first disclosed.
The system used exposed credentials to access four third-party accounts, using one as a relay and staging point and another for data storage.
Read the new details: https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html
The system used exposed credentials to access four third-party accounts, using one as a relay and staging point and another for data storage.
Read the new details: https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html
π€5π3π2β‘1π₯1
π¨ ALERT - Flying Eagle Android RAT source code is circulating on criminal Telegram channels.
The kit builds signed APKs that capture payment passwords and keystrokes, record screens, and access cameras.
Experts also traced matching infrastructure fingerprints to 170 internet servers.
Read how the kit works: https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html
The kit builds signed APKs that capture payment passwords and keystrokes, record screens, and access cameras.
Experts also traced matching infrastructure fingerprints to 170 internet servers.
Read how the kit works: https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html
π₯5π2π€―2β‘1π€1
π¨ New Gitea RCE (CVE-2026-60004) lets repository writers plant a malicious Git hook and run shell commands as the Gitea service account.
On default-configured instances, outsiders can register, create a repository, and obtain the required write access.
A public PoC is available.
Find details here: https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
On default-configured instances, outsiders can register, create a repository, and obtain the required write access.
A public PoC is available.
Find details here: https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html
π6β‘1
π¨ Public PoC released for CVE-2026-16232, an actively exploited Check Point SmartConsole authentication bypass.
The flaw lets unauthenticated attackers obtain full admin access to Security Management Server and MDS systems.
See how it works: https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html
The flaw lets unauthenticated attackers obtain full admin access to Security Management Server and MDS systems.
See how it works: https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html
π₯3
β‘ Russiaβs FSB says it has charged #Telegram founder Pavel Durov with aiding terrorist activity and placed him on an international wanted list.
The agency alleges Ukrainian operatives used Telegram and a dating bot to coerce young Russians into sabotage and attacks.
Telegramβs response β https://thehackernews.com/2026/07/russia-charges-telegram-founder-pavel.html
The agency alleges Ukrainian operatives used Telegram and a dating bot to coerce young Russians into sabotage and attacks.
Telegramβs response β https://thehackernews.com/2026/07/russia-charges-telegram-founder-pavel.html
π30π₯6π3π€―2
Most organizations have incident response plans. Yet 73% say they would not be fully ready for a major cyberattack tomorrow.
The problem is execution: 90% expect coordination trouble, while 78% say blind spots can leave attackers with persistent access.
Read what breaks down under pressure: https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html
The problem is execution: 90% expect coordination trouble, while 78% say blind spots can leave attackers with persistent access.
Read what breaks down under pressure: https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html
π2π2β‘1
This media is not supported in your browser
VIEW IN TELEGRAM
π One malicious webpage visit was enough to compromise Tor Browser. No settings changes. No extra clicks.
Firefox JIT flaw, CVE-2026-10702, runs code inside the browserβs renderer process and forms the first stage of an Android 17 root chain.
Read how the exploit works: https://thehackernews.com/2026/07/researchers-show-single-malicious.html
Firefox JIT flaw, CVE-2026-10702, runs code inside the browserβs renderer process and forms the first stage of an Android 17 root chain.
Read how the exploit works: https://thehackernews.com/2026/07/researchers-show-single-malicious.html
π€―15π±1
AI is compressing the time between vulnerability disclosure and exploitation.
That makes CVSS-only prioritization more dangerous. A 5.5 flaw with a path to a critical asset can matter more than an isolated 9.8.
Read why attack paths should drive remediation: https://thehackernews.com/2026/07/mythos-asks-right-question-it-doesnt.html
That makes CVSS-only prioritization more dangerous. A 5.5 flaw with a path to a critical asset can matter more than an isolated 9.8.
Read why attack paths should drive remediation: https://thehackernews.com/2026/07/mythos-asks-right-question-it-doesnt.html
β‘3π1π1