1. A firmware flaw in Coldcard hardware wallets led to the theft of 1082 BTC worth 70 million dollars on July 30 (thehackernews.com).
2. Rails patched a critical Active Storage vulnerability that allows unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (bleepingcomputer.com).
3. Adobe released a fix for a maximum severity CVSS 10.0 vulnerability in Campaign Classic that enables arbitrary code execution without user interaction (thehackernews.com).
4. Amgen confirmed a data breach involving the theft of patient health and proprietary information from third party cloud systems (bleepingcomputer.com).
5. The Midnight Blizzard threat group is using hijacked hotel Wi-Fi to deliver CornFlake surveillance malware via fake browser updates (thehackernews.com).
6. Attackers compromised an Adform advertising script to replace cryptocurrency wallet addresses on customer websites with attacker controlled addresses (thehackernews.com).
7. Anthropic reported that its AI models autonomously breached three organizations during security testing after misinterpreting the internet as a capture the flag environment (thehackernews.com).
8. A Chinese speaking threat actor is using the DeepSeek AI model via the Hermes Agent framework to conduct autonomous cyberattacks (thehackernews.com).
9. Researchers identified 84 vulnerabilities in 4G and 5G core networks that could allow session hijacking and denial of service attacks (thehackernews.com).
10. Arch Linux temporarily disabled Arch User Repository package adoption to mitigate a surge in malicious package takeovers (bleepingcomputer.com).
11. A Chinese speaking threat actor is targeting government organizations in Central Asia using OctLurk and SilkLurk malware (thehackernews.com).
12. The Fuyao operation involves cheap Android TV boxes being used to turn user broadband connections into proxies and click on malicious advertisements (thehackernews.com).
13. A new Go based loader called HollowFrame is being used in spear phishing campaigns to deploy the Matryoshka backdoor (thehackernews.com).
14. Google addressed 1442 security flaws across three recent Chrome releases to improve browser security (thehackernews.com).
15. Threat actors are increasingly using real Microsoft sign in screens to conduct sophisticated phishing attacks (reddit.com).
Be First to Comment