π¨ Ruflo left 233 MCP tools exposed without authentication by default, including shell command execution.
On any network-reachable deployment, one request could expose LLM keys, conversations, and persistent AI memory.
How one POST turns into full compromise: https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html
On any network-reachable deployment, one request could expose LLM keys, conversations, and persistent AI memory.
How one POST turns into full compromise: https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html
π8π₯3β‘1
β‘ UPDATE β The HAWK team has withdrawn its post-quantum digital-signature scheme from NISTβs standardization process after confirming #Anthropic's key-recovery attack sharply reduced its security margin.
NIST now lists HAWK as withdrawn.
Read the updated story: https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
NIST now lists HAWK as withdrawn.
Read the updated story: https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html
π9π€4π₯2β‘1
βΌοΈ WARNING -- Critical Rails flaw CVE-2026-66066 could let unauthenticated attackers read server files through crafted image uploads.
The bug affects apps using Active Storage with Vips. Stolen Rails keys, database credentials, cloud keys, and API tokens could enable RCE.
Patch now. Read the full story - https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
The bug affects apps using Active Storage with Vips. Stolen Rails keys, database credentials, cloud keys, and API tokens could enable RCE.
Patch now. Read the full story - https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
π7π₯4π€2β‘1
π¨ UPDATE: A third-party PoC now claims to reproduce the full Rails Active Storage file-read-to-RCE chain.
The Rails Security Team told The Hacker News it is not aware of any exploitation, confirmed the affected-version range, and said Rails 7.1 and earlier will receive no backport.
Read the updated story: https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
The Rails Security Team told The Hacker News it is not aware of any exploitation, confirmed the affected-version range, and said Rails 7.1 and earlier will receive no backport.
Read the updated story: https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
π₯6β‘1
β οΈ Attackers are exploiting Cisco FMC zero-day CVE-2026-20316.
The flaw lets unauthenticated remote attackers use static credentials to access sensitive data through a low-privilege account.
Cisco warns it can be chained with other FMC flaws to elevate privileges.
Here's what admins should check: https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html
The flaw lets unauthenticated remote attackers use static credentials to access sensitive data through a low-privilege account.
Cisco warns it can be chained with other FMC flaws to elevate privileges.
Here's what admins should check: https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html
π₯3π±3β‘1π€―1
π¨ Amazon links the 2025 'debug' and 'chalk' npm hijack to North Koreaβs Sapphire Sleet.
The wallet-draining attack reached at least 18 packages with more than 2 billion weekly downloads.
Read the full report: https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html
The wallet-draining attack reached at least 18 packages with more than 2 billion weekly downloads.
Read the full report: https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html
π€―10π₯6π±5π2β‘1
β‘ The FCC is restricting U.S. approval for new foreign-produced robots and networked power inverters over fears they could be remotely shut down, hijacked, or used for surveillance.
Previously approved models can still be sold and used.
Read the full story: https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html
Previously approved models can still be sold and used.
Read the full story: https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html
π₯5π€3
π¨ ALERT - Russian hackers are exploiting a Microsoft OWA flaw to deploy OWAReaper.
The browser backdoor can preserve mailbox access after credential rotation and full device re-imaging.
Here's how it stays embedded: https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html
The browser backdoor can preserve mailbox access after credential rotation and full device re-imaging.
Here's how it stays embedded: https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html
π₯9β‘1
βΌοΈ ALERT >> One visit. No prompt. A compromised South Korean website could infect systems running vulnerable AnySign4PC versions.
State-sponsored hackers used the chain to install SIGNBT or COPPERHEDGE backdoors.
Learn how the page-to-backdoor chain worked: https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
State-sponsored hackers used the chain to install SIGNBT or COPPERHEDGE backdoors.
Learn how the page-to-backdoor chain worked: https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
π€―10π₯4
π¨ Silver Fox is using 3 vulnerable drivers to impair security controls and deploy ValleyRAT against a Japanese manufacturer.
Stopping one component may not stop the intrusion. A second recovery path can bring it back.
How the attack stays alive: https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html
Stopping one component may not stop the intrusion. A second recovery path can bring it back.
How the attack stays alive: https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html
π₯3β‘1
Traditional firewalls can see an AI connection. They cannot see the prompt, upload, model call, or agent action inside it.
Check Point has launched what it calls the industryβs first AI Network Firewall to inspect that activity, block prompt injection, data exfiltration, and API abuse, and govern MCP servers.
Read more: https://thehackernews.com/2026/07/the-network-has-become-control-plane.html
Check Point has launched what it calls the industryβs first AI Network Firewall to inspect that activity, block prompt injection, data exfiltration, and API abuse, and govern MCP servers.
Read more: https://thehackernews.com/2026/07/the-network-has-become-control-plane.html
π₯6β‘2
π¨ Microsoft 365 Copilot can quietly alter figures during a Word drafting or editing operation, then copy the hidden instructions into the document it creates.
That generated file can carry the manipulation into a later Copilot session.
Hereβs how the chain works: https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html
That generated file can carry the manipulation into a later Copilot session.
Hereβs how the chain works: https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html
π€8π±1
π¨ One crafted Gremlin query. A sandbox escape.
... a platform-wide key that researchers say could retrieve the key for any Azure Cosmos DB account, giving full read and write access across tenants and APIs.
Read how "CosmosEscape" attack crossed the boundary https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html
... a platform-wide key that researchers say could retrieve the key for any Azure Cosmos DB account, giving full read and write access across tenants and APIs.
Read how "CosmosEscape" attack crossed the boundary https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html
π4π₯2
β‘ AI is pushing code into production faster than security teams can review it.
Join this next webinar to learn where traditional AppSec and CVE-based remediation break down, how AI expands the attack surface, and what secure-by-default development looks like in practice.
Register now: https://thehacker.news/secure-ai-development
Join this next webinar to learn where traditional AppSec and CVE-based remediation break down, how AI expands the attack surface, and what secure-by-default development looks like in practice.
Register now: https://thehacker.news/secure-ai-development
π₯3
A threat actor used AI agents to pick targets, find exploit code, and launch attacks.
Also this week: SonicWall credential stuffing, DNS hijacking, fake Claude malware, 900K records accessed, real-time phishing pages, and a hidden-desktop RAT.
25 stories. Read ThreatsDay: https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html
Also this week: SonicWall credential stuffing, DNS hijacking, fake Claude malware, 900K records accessed, real-time phishing pages, and a hidden-desktop RAT.
25 stories. Read ThreatsDay: https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html
π3β‘1π₯1
An enterprise thought Copilot was its entire AI footprint. Recoβs scan found Claude ranked first.
Reco co-founder Gal Nakash maps six places Claude shows up, from connected apps and MCP servers to Claude Code, and the access paths security tools often miss.
Read the article: https://thehackernews.com/expert-insights/2026/07/claude-runs-across-six-surfaces-in-your.html
Reco co-founder Gal Nakash maps six places Claude shows up, from connected apps and MCP servers to Claude Code, and the access paths security tools often miss.
Read the article: https://thehackernews.com/expert-insights/2026/07/claude-runs-across-six-surfaces-in-your.html
π₯3π2
β οΈ A sponsored search result leads to a fake macOS update that fills the screen, copies a command to the clipboard, and tells the victim to run it in Terminal.
The DPRK-linked campaign then installs a backdoor that fetches a stealer targeting 157 crypto wallets and cloud credentials.
Read the full attack chain: https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html
The DPRK-linked campaign then installs a backdoor that fetches a stealer targeting 157 crypto wallets and cloud credentials.
Read the full attack chain: https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html
π€4π2β‘1π1
β‘ Anthropic says Claude models breached three organizations after a misconfigured CTF gave them live internet access.
The test was simulated. The internet was not.
One model accessed production data. Another published a PyPI package downloaded by 15 real systems.
Full report: https://thehackernews.com/2026/07/anthropic-says-claude-mistook-open.html
The test was simulated. The internet was not.
One model accessed production data. Another published a PyPI package downloaded by 15 real systems.
Full report: https://thehackernews.com/2026/07/anthropic-says-claude-mistook-open.html
π₯9π4π€2β‘1π€―1