threat-intel Europe revives law allowing big tech to scan for CSAM The European Parliament has revived a law allowing big tech companies like Google, Microsoft, and Meta to scan users' messages to detect child sexual abuse material (CSAM). This move, driven by a procedural vote and conc… The Record · Jul 10, 2026 Medium privacyencryptionchild_protection
threat-intel More Countries Jump on the Social Media Ban Wagon More countries are implementing social media bans for minors, driven by concerns about mental health and safety. However, companies are struggling to comply while minimizing user disruption and avoiding intrusive data co… Dark Reading · Jul 10, 2026 Medium AUUNsocial mediaage verificationprivacy
threat-intel Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure Iran's cyber operations, primarily conducted through groups like Handala and Ababil of Minab, are increasingly targeting a broader range of organizations beyond critical infrastructure. These groups, often described as h… Dark Reading · Jul 9, 2026 Medium CVE-2021-22681IRhacktivismcyber espionagevulnerability exploitation
vulnerability WolfSSL, GeoVision, VTK vulnerabilities Cisco Talos has disclosed a significant number of vulnerabilities across WolfSSL, GeoVision, and VTK-DICOM. These vulnerabilities range from buffer overflows and command injection to session cookie issues and heap overfl… Cisco Talos · Jul 9, 2026 Medium CVE-2026-28739CVE-2026-25106CVE-2026-33091buffer_overflowcommand_injectioncve
threat-intel Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs Datadog Security Labs has discovered a campaign where attackers are systematically mapping corporate GitHub organizations by leveraging dormant accounts and stolen credentials to gather extensive information about a comp… The Hacker News · Jul 9, 2026 Medium githubenumerationapi
supply-chain npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk GitHub has released npm 12, significantly bolstering supply chain security by disabling install scripts and deprecating granular access tokens (GATs). These changes restrict automated script execution and limit the abili… The Hacker News · Jul 9, 2026 Medium npmsupply chainsecurity
threat-intel QIZ Security Raises $17 Million for Cryptographic Governance Platform Israeli cybersecurity startup QIZ Security secured $17 million in seed funding to bolster its cryptographic governance platform, addressing the growing threat of quantum computing and the need for continuous cryptographi… SecurityWeek · Jul 9, 2026 Medium IScryptographypost-quantumquantum computing
threat-intel EU takes member states to court over unimplemented cybersecurity law The European Commission has filed legal action against Ireland, Spain, France, and the Netherlands for failing to implement the NIS2 Directive, a cybersecurity law designed to improve security for critical infrastructure… The Record · Jul 9, 2026 Medium IEESFRcybersecurityeu lawcritical infrastructure
threat-intel European Organizations Have a Collaboration Security Confidence Gap A recent survey by Wire reveals a significant gap between European organizations' confidence in their collaboration security and the actual practices surrounding sensitive data sharing. Despite high confidence levels, ma… Dark Reading · Jul 9, 2026 Medium shadow itdata governanceaccess control
vulnerability Chrome 150 Update Patches 27 Vulnerabilities Google released Chrome 150, addressing 27 security vulnerabilities, including two critical flaws related to use-after-free bugs. The update represents a significant effort to remediate a substantial number of memory safe… SecurityWeek · Jul 9, 2026 Medium memory-safetyvulnerabilitychrome
threat-intel Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images Meta has launched Muse Image, an AI tool that allows users to generate images using their public Instagram content. The feature is being rolled out gradually and users can opt-out of having their content used by the AI.… The Hacker News · Jul 9, 2026 Medium aiinstagrammeta
threat-intel _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary], (Tue, Jul 7th) A self-propagating bot, originating from Belarus (as claimed by its creator), has been scanning for open ports and attempting brute-force login attempts on various servers worldwide. The bot’s purpose is to raise awarene… SANS Internet Storm Center · Jul 9, 2026 Medium BYscanbrute-forcessh
vulnerability Multiples vulnérabilités dans Traefik (09 juillet 2026) Multiple vulnerabilities have been discovered in Traefik, allowing an attacker to bypass security policies. These vulnerabilities affect older versions of the popular reverse proxy and load balancer, requiring immediate… CERT-FR · Jul 9, 2026 Medium CVE-2026-65601CVE-2026-65602traefikvulnerabilitysecurity
threat-intel Cash App owner to pay $45 million to settle allegations of lax security Block, Inc. (Cash App's parent company) will pay $45 million to settle allegations of misleading users about Cash App's security and failing to adequately protect them from fraud. The settlement stems from a lack of prop… The Record · Jul 8, 2026 Medium securityfraudmisleading
threat-intel AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers Sophos researchers discovered that AI coding assistants like Claude Code, Cursor, and OpenAI Codex are triggering traditional endpoint security rules designed to detect malicious activity. These agents, while harmless in… The Hacker News · Jul 8, 2026 Medium aicoding assistantendpoint security
threat-intel Accenture Confirms Data Breach After Hacker Claims Source Code Theft Accenture has confirmed a data breach following claims from a hacker that 35 gigabytes of data, including sensitive credentials and source code, was stolen. The incident involved a threat actor attempting to sell the all… SecurityWeek · Jul 8, 2026 Medium data breachcredential theftsource code
threat-intel New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware Researchers at Tel Aviv University have identified a new attack method called ‘HalluSquatting’ that leverages AI coding assistants’ tendency to fabricate names. Attackers register fake software package names that AIs com… The Hacker News · Jul 8, 2026 Medium ISaihallucinationprompt injection
threat-intel Former UK privacy chief preparing legal action against woman who reported him, minister says The former UK Information Commissioner, John Edwards, is preparing to sue a female employee at the Information Commissioner’s Office (ICO) who reported concerns about his behavior. This follows an independent investigati… The Record · Jul 8, 2026 Medium GBsexual_harassmentdata_protectiongovernance
threat-intel Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip Spanish authorities, with assistance from the FBI, arrested a man suspected of aiding pro-Russian hacktivist groups, specifically in facilitating the escape of a Ukrainian hacker linked to CARR. The investigation uncover… The Record · Jul 8, 2026 Medium SPPOBErussianhacktivismddos
phishing Webinar Today: Why Email Security Keeps Failing The article highlights a persistent and evolving phishing campaign that continues to successfully target organizations despite existing email security measures. The campaign demonstrates a significant gap in current defe… SecurityWeek · Jul 8, 2026 Medium email securityphishingcybersecurity