threat-intel China, India-Linked Hackers Both Targeted Same Pakistani Police Force Chinese and Indian cyber espionage groups have been quietly targeting Pakistani law enforcement networks for over two years, with a particular focus on the Balochistan Police. The intrusions aimed to access sensitive dat… SecurityWeek · Jul 10, 2026 High CHINPAcyberespionagebelt and roadgeopolitics
threat-intel Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers Okta has warned of a sophisticated vishing campaign targeting Microsoft 365 customers, primarily through impersonating legitimate Microsoft Entra ID login pages. The campaign, attributed to the O-UNC-066 threat actor gro… SecurityWeek · Jul 10, 2026 High vishingpasskeyphishing
threat-intel GigaWiper Combines Multiple Malware for System-Level Sabotage Microsoft has identified a sophisticated malware strain called GigaWiper, a Go-based backdoor combining multiple destructive capabilities – including a physical disk wiper, ransomware-like encryption, and persistent C&C… SecurityWeek · Jul 10, 2026 High IRbackdoorransomwarewipe
threat-intel ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism Researchers have discovered a new attack technique called ‘HalluSquatting’ that leverages AI assistants’ tendency to fabricate information to create scalable botnets. Attackers register fake repository names, and when us… SecurityWeek · Jul 10, 2026 High aiprompt injectionhallucination
supply-chain Network of 200 GitHub Repositories Used for Malware Infection A threat actor, linked to previous activity associated with the ‘ischhfd83’ email address, has created a network of over 200 GitHub repositories delivering Windows malware through a Go module disguised as a DNS scanning… SecurityWeek · Jul 10, 2026 High supply chaingithubmalware
threat-intel QIZ Security Raises $17 Million for Cryptographic Governance Platform Israeli cybersecurity startup QIZ Security secured $17 million in seed funding to bolster its cryptographic governance platform, addressing the growing threat of quantum computing and the need for continuous cryptographi… SecurityWeek · Jul 9, 2026 Medium IScryptographypost-quantumquantum computing
threat-intel UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge The UK government is launching a multi-faceted cybersecurity initiative, Cyber Shield, focused on leveraging agentic AI to bolster national cyber defenses against increasingly rapid AI-powered attacks. Simultaneously, th… SecurityWeek · Jul 9, 2026 High UKaicybersecuritynational security
vulnerability Palo Alto Networks Patches 13 Vulnerabilities Palo Alto Networks has released advisories detailing 13 vulnerabilities across its products, including a critical buffer overflow that could lead to arbitrary code execution. While the company reports no active exploitat… SecurityWeek · Jul 9, 2026 High CVE-2026-0288vulnerabilitypatchbuffer overflow
data-breach 12 Million Impacted by Data Breach at Japanese Telco KDDI A data breach at Japanese telecom KDDI has impacted over 12 million users due to a zero-day vulnerability exploited by hackers. The attackers gained access to email addresses and passwords, prompting a company-wide passw… SecurityWeek · Jul 9, 2026 High JPdata breachzero-daypassword reset
vulnerability 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google A 15-year-old Linux kernel vulnerability, dubbed ‘GhostLock,’ has been exploited to earn a security researcher $92,000. The flaw allows for local privilege escalation and container escapes, highlighting the long-term ris… SecurityWeek · Jul 9, 2026 High CVE-2026-43499linuxkernelvulnerability
vulnerability Microsoft Patches Defender ‘RoguePlanet’ Vulnerability Microsoft has released a patch to address a Defender vulnerability, dubbed RoguePlanet, which could allow an attacker to escalate privileges. The vulnerability was initially identified by Nightmare Eclipse (Chaotic Eclip… SecurityWeek · Jul 9, 2026 High CVE-2026-50656CVE-2026-41091CVE-2026-45498vulnerabilitypatchdefender
ransomware Mount Royal University Confirms Data Stolen in Ransomware Attack Mount Royal University in Canada suffered a ransomware attack that resulted in the theft of employee and student data. The attackers, identified as CMD Organization, exfiltrated over 10 terabytes of information and are d… SecurityWeek · Jul 9, 2026 High CAransomwaredata breachtor
vulnerability AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique AI coding assistants like Claude Code, Amazon Q Developer, and Cursor are vulnerable to a decades-old technique called GhostApproval, where attackers can trick the tools into accessing and modifying sensitive system file… SecurityWeek · Jul 9, 2026 High symlinkaicoding
vulnerability Chrome 150 Update Patches 27 Vulnerabilities Google released Chrome 150, addressing 27 security vulnerabilities, including two critical flaws related to use-after-free bugs. The update represents a significant effort to remediate a substantial number of memory safe… SecurityWeek · Jul 9, 2026 Medium memory-safetyvulnerabilitychrome
threat-intel 8Layers Raises $2.9 Million for Identity Security Platform Spanish security startup 8Layers secured $2.9 million in funding to bolster its digital identity protection platform, which combines identity posture management, threat detection, and compliance features. The platform ut… SecurityWeek · Jul 9, 2026 Info ESidentity securitydigital identityrisk management
vulnerability Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices A security researcher discovered an unpatched backdoor in Tenda firmware, granting attackers administrative access to Tenda devices. This vulnerability, tracked as CVE-2026-11405, allows attackers to bypass authenticatio… SecurityWeek · Jul 9, 2026 High CVE-2026-11405CVE-2026-13753backdoorunpatchedwebserver
threat-intel Accenture Confirms Data Breach After Hacker Claims Source Code Theft Accenture has confirmed a data breach following claims from a hacker that 35 gigabytes of data, including sensitive credentials and source code, was stolen. The incident involved a threat actor attempting to sell the all… SecurityWeek · Jul 8, 2026 Medium data breachcredential theftsource code
threat-intel China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors A China-linked advanced persistent threat group, UAT-7810, has expanded its arsenal with new backdoors, including LongLeash, DogLeash, and JarLeash, as part of a long-running espionage campaign. The group primarily targe… SecurityWeek · Jul 8, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717CNbackdooraptespionage
phishing Webinar Today: Why Email Security Keeps Failing The article highlights a persistent and evolving phishing campaign that continues to successfully target organizations despite existing email security measures. The campaign demonstrates a significant gap in current defe… SecurityWeek · Jul 8, 2026 Medium email securityphishingcybersecurity
vulnerability Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations A vulnerability in Google Cloud’s Dialogflow CX service allowed attackers to silently control agents, manipulate conversations, and exfiltrate sensitive information. The flaw stemmed from a permissive configuration withi… SecurityWeek · Jul 8, 2026 High aicloudpython