β οΈ Attackers are exploiting Cisco FMC zero-day CVE-2026-20316.
The flaw lets unauthenticated remote attackers use static credentials to access sensitive data through a low-privilege account.
Cisco warns it can be chained with other FMC flaws to elevate privileges.
Here's what admins should check: https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html
The flaw lets unauthenticated remote attackers use static credentials to access sensitive data through a low-privilege account.
Cisco warns it can be chained with other FMC flaws to elevate privileges.
Here's what admins should check: https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html
π₯3π±3β‘1π€―1
π¨ Amazon links the 2025 'debug' and 'chalk' npm hijack to North Koreaβs Sapphire Sleet.
The wallet-draining attack reached at least 18 packages with more than 2 billion weekly downloads.
Read the full report: https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html
The wallet-draining attack reached at least 18 packages with more than 2 billion weekly downloads.
Read the full report: https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html
π€―11π₯6π±5π2β‘1
β‘ The FCC is restricting U.S. approval for new foreign-produced robots and networked power inverters over fears they could be remotely shut down, hijacked, or used for surveillance.
Previously approved models can still be sold and used.
Read the full story: https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html
Previously approved models can still be sold and used.
Read the full story: https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html
π₯5π€3
π¨ ALERT - Russian hackers are exploiting a Microsoft OWA flaw to deploy OWAReaper.
The browser backdoor can preserve mailbox access after credential rotation and full device re-imaging.
Here's how it stays embedded: https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html
The browser backdoor can preserve mailbox access after credential rotation and full device re-imaging.
Here's how it stays embedded: https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html
π₯9β‘1
βΌοΈ ALERT >> One visit. No prompt. A compromised South Korean website could infect systems running vulnerable AnySign4PC versions.
State-sponsored hackers used the chain to install SIGNBT or COPPERHEDGE backdoors.
Learn how the page-to-backdoor chain worked: https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
State-sponsored hackers used the chain to install SIGNBT or COPPERHEDGE backdoors.
Learn how the page-to-backdoor chain worked: https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
π€―10π₯4
π¨ Silver Fox is using 3 vulnerable drivers to impair security controls and deploy ValleyRAT against a Japanese manufacturer.
Stopping one component may not stop the intrusion. A second recovery path can bring it back.
How the attack stays alive: https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html
Stopping one component may not stop the intrusion. A second recovery path can bring it back.
How the attack stays alive: https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html
π₯3β‘1
Traditional firewalls can see an AI connection. They cannot see the prompt, upload, model call, or agent action inside it.
Check Point has launched what it calls the industryβs first AI Network Firewall to inspect that activity, block prompt injection, data exfiltration, and API abuse, and govern MCP servers.
Read more: https://thehackernews.com/2026/07/the-network-has-become-control-plane.html
Check Point has launched what it calls the industryβs first AI Network Firewall to inspect that activity, block prompt injection, data exfiltration, and API abuse, and govern MCP servers.
Read more: https://thehackernews.com/2026/07/the-network-has-become-control-plane.html
π₯6β‘2
π¨ Microsoft 365 Copilot can quietly alter figures during a Word drafting or editing operation, then copy the hidden instructions into the document it creates.
That generated file can carry the manipulation into a later Copilot session.
Hereβs how the chain works: https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html
That generated file can carry the manipulation into a later Copilot session.
Hereβs how the chain works: https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html
π€8π±1
π¨ One crafted Gremlin query. A sandbox escape.
... a platform-wide key that researchers say could retrieve the key for any Azure Cosmos DB account, giving full read and write access across tenants and APIs.
Read how "CosmosEscape" attack crossed the boundary https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html
... a platform-wide key that researchers say could retrieve the key for any Azure Cosmos DB account, giving full read and write access across tenants and APIs.
Read how "CosmosEscape" attack crossed the boundary https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html
π4π₯3π1
β‘ AI is pushing code into production faster than security teams can review it.
Join this next webinar to learn where traditional AppSec and CVE-based remediation break down, how AI expands the attack surface, and what secure-by-default development looks like in practice.
Register now: https://thehacker.news/secure-ai-development
Join this next webinar to learn where traditional AppSec and CVE-based remediation break down, how AI expands the attack surface, and what secure-by-default development looks like in practice.
Register now: https://thehacker.news/secure-ai-development
π₯4
A threat actor used AI agents to pick targets, find exploit code, and launch attacks.
Also this week: SonicWall credential stuffing, DNS hijacking, fake Claude malware, 900K records accessed, real-time phishing pages, and a hidden-desktop RAT.
25 stories. Read ThreatsDay: https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html
Also this week: SonicWall credential stuffing, DNS hijacking, fake Claude malware, 900K records accessed, real-time phishing pages, and a hidden-desktop RAT.
25 stories. Read ThreatsDay: https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html
π3π₯2β‘1
An enterprise thought Copilot was its entire AI footprint. Recoβs scan found Claude ranked first.
Reco co-founder Gal Nakash maps six places Claude shows up, from connected apps and MCP servers to Claude Code, and the access paths security tools often miss.
Read the article: https://thehackernews.com/expert-insights/2026/07/claude-runs-across-six-surfaces-in-your.html
Reco co-founder Gal Nakash maps six places Claude shows up, from connected apps and MCP servers to Claude Code, and the access paths security tools often miss.
Read the article: https://thehackernews.com/expert-insights/2026/07/claude-runs-across-six-surfaces-in-your.html
π4π₯3
β οΈ A sponsored search result leads to a fake macOS update that fills the screen, copies a command to the clipboard, and tells the victim to run it in Terminal.
The DPRK-linked campaign then installs a backdoor that fetches a stealer targeting 157 crypto wallets and cloud credentials.
Read the full attack chain: https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html
The DPRK-linked campaign then installs a backdoor that fetches a stealer targeting 157 crypto wallets and cloud credentials.
Read the full attack chain: https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html
π€4π3β‘1π1
β‘ Anthropic says Claude models breached three organizations after a misconfigured CTF gave them live internet access.
The test was simulated. The internet was not.
One model accessed production data. Another published a PyPI package downloaded by 15 real systems.
Full report: https://thehackernews.com/2026/07/anthropic-says-claude-mistook-open.html
The test was simulated. The internet was not.
One model accessed production data. Another published a PyPI package downloaded by 15 real systems.
Full report: https://thehackernews.com/2026/07/anthropic-says-claude-mistook-open.html
π₯14π14π€―4π€3β‘2
π¨ A Chinese-speaking threat actor used DeepSeek to autonomously find exposed systems, choose public exploits, and launch attacks after an initial Telegram command.
Experts say the wider operation attempted to exploit 460+ targets.
Read the full story β https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html
Experts say the wider operation attempted to exploit 460+ targets.
Read the full story β https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html
π€―3
π¨ New from Ethiack: A crafted MATLAB/HDF5 upload can make Rails Active Storage read server secrets.
Attackers could then use a stolen secret_key_base to forge a variation key and reach RCE via CVE-2025-24293.
Rails also released a forensic toolkit to check exposure and hunt for exploitation.
Read the updated story: https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
Attackers could then use a stolen secret_key_base to forge a variation key and reach RCE via CVE-2025-24293.
Rails also released a forensic toolkit to check exposure and hunt for exploitation.
Read the updated story: https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
π Researchers found 84 flaws across seven open-source 4G and 5G cores.
If internal interfaces are exposed, some could crash core components or redirect a subscriberβs uplink traffic. A session-hijacking flaw also turned up in two commercial 5G cores.
Details: https://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.html
If internal interfaces are exposed, some could crash core components or redirect a subscriberβs uplink traffic. A session-hijacking flaw also turned up in two commercial 5G cores.
Details: https://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.html
π1
Passkeys cannot stop an attack that starts after login.
Device code phishing sends victims to Microsoftβs real login page, where one copied code can grant an attacker access. Push now tracks 25+ kits. Barracuda counted 7 million attacks in four weeks.
See how it works: https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html
Device code phishing sends victims to Microsoftβs real login page, where one copied code can grant an attacker access. Push now tracks 25+ kits. Barracuda counted 7 million attacks in four weeks.
See how it works: https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html
π€―4π2
π² Google fixed 1,442 security flaws across three recent Chrome releases.
Versions 149 and 150 alone patched more bugs than the previous 23 milestones combined. Chrome 151 added 370 more, including 7 critical flaws.
Google is now testing twice-weekly security releases as AI speeds up vulnerability discovery and cyberattacks.
Full story: https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html
Versions 149 and 150 alone patched more bugs than the previous 23 milestones combined. Chrome 151 added 370 more, including 7 critical flaws.
Google is now testing twice-weekly security releases as AI speeds up vulnerability discovery and cyberattacks.
Full story: https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html
π3
Malware investigations often stop at the first file.
Stairwell's new Backstory is the first agentic investigation platform that traces related malware variants, identifies affected systems, and maps the full blast radius of an incident in seconds.
Instead of stopping at a single alert, security teams can quickly understand what happened, where malware spread, and what needs to be contained before an incident escalates.
Learn more about Backstory: https://thn.news/demo-stairwell
Stairwell's new Backstory is the first agentic investigation platform that traces related malware variants, identifies affected systems, and maps the full blast radius of an incident in seconds.
Instead of stopping at a single alert, security teams can quickly understand what happened, where malware spread, and what needs to be contained before an incident escalates.
Learn more about Backstory: https://thn.news/demo-stairwell