HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

31/07/2026 0 Comments 0 tags

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins

Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies

31/07/2026 0 Comments 0 tags

Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

31/07/2026 0 Comments 0 tags

An academic study has disclosed a “widespread class” of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking,

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

31/07/2026 0 Comments 0 tags

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior

Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

31/07/2026 0 Comments 0 tags

Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

31/07/2026 0 Comments 0 tags

Palo Alto Networks’ Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

31/07/2026 0 Comments 0 tags

Device code phishing – the abuse of the OAuth 2.0 device authorization grant to steal access tokens – has evolved from a niche red-team technique to an industrial-scale threat in

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

30/07/2026 0 Comments 0 tags

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

30/07/2026 0 Comments 0 tags

A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

30/07/2026 0 Comments 0 tags

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service’s Gremlin query sandbox and obtain full read and write access to databases across customer tenants,