Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

20/07/2026 0 Comments 0 tags

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

20/07/2026 0 Comments 0 tags

A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

20/07/2026 0 Comments 0 tags

A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths

Mythos Didn’t Break Your Security Program. Your Exposure Window Could.

20/07/2026 0 Comments 0 tags

The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

20/07/2026 0 Comments 0 tags

At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

20/07/2026 0 Comments 0 tags

A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

20/07/2026 0 Comments 0 tags

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

20/07/2026 0 Comments 0 tags

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving

World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

20/07/2026 0 Comments 0 tags

In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

20/07/2026 0 Comments 0 tags

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was