vulnerability 'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure Two significant ‘confused deputy’ vulnerabilities persist in Google Cloud Platform (GCP) and Microsoft Azure, allowing attackers to escalate privileges and bypass security controls. Despite reporting these flaws to both… Dark Reading · Jul 27, 2026 High cloud securityidentity managementaccess control
threat-intel Outdated VPNs should be purged from federal agencies, senator says Senator Ron Wyden is urging federal agencies to remove outdated and insecure VPNs from their systems, citing a growing threat of foreign adversaries exploiting these vulnerabilities to gain access to sensitive U.S. gover… The Record · Jul 27, 2026 High RUCHvpnzero-trustremote access
threat-intel FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown The FBI, in collaboration with international law enforcement agencies, successfully dismantled LockBit, one of the most prolific ransomware-as-a-service (RaaS) groups, through Operation Cronos. The operation focused on b… Dark Reading · Jul 27, 2026 High UNRUransomwareraasoperation cronos
vulnerability Microsoft's solution to AI security: more AI and more acronyms Microsoft is facing a zero-day vulnerability in its on-prem SharePoint system, allowing attackers to exploit the flaw. This follows a broader trend of security challenges related to Microsoft products and a wider increas… The Register · Jul 27, 2026 High USIRSWvulnerabilitysharepointzero-day
threat-intel Why Resetting Passwords No Longer Stops Attackers Traditional password security measures are becoming less effective as attackers shift to stealing session and token credentials to bypass MFA controls. Instead of focusing on securing logins, organizations must now prior… Dark Reading · Jul 27, 2026 High token theftsession hijackingmfa bypass
threat-intel NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework NVIDIA has formed the Open Secure AI Alliance, a 37-member group focused on developing open technologies and tools for securing AI agents and software. The alliance’s core contribution, NOOA, is a Python framework design… The Hacker News · Jul 27, 2026 High UNaiagentsecurity
threat-intel Health system in South Carolina, Georgia closes offices after malware affects networks AnMed Health, a multi-state healthcare system in South Carolina and Georgia, has been forced to temporarily close numerous facilities due to a malware attack. The system is working to restore operations and ensure patien… The Record · Jul 27, 2026 High cyberattackhealthcaremalware
threat-intel Adversaries Don't Need a Zero-Day — They Read Your Rulebook Confidence in autonomous penetration testing is declining, with organizations now only 9% as confident as they were a year ago. This is due to adversaries exploiting the governance layer of these systems – the rules and… Dark Reading · Jul 27, 2026 High autonomous securitygovernanceattack surface
threat-intel Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Dysphoria IoT botnet has evolved to become significantly harder to disrupt by incorporating blockchain-based name services and utilizing infected devices as relays. This complex architecture, stemming from the JackSk… The Hacker News · Jul 27, 2026 High CVE-2025-9528JPiotbotnetc2
threat-intel Un ancien député-maire ciblé sur un forum pirate An ex-French MP-Mayor is being targeted by a hacker who claims to be protesting the extension of Chat Control 1.0, a European surveillance program. The hacker has announced the re-publication of intimate videos from 2017… ZATAZ · Jul 27, 2026 High FRsurveillancedata-breachprivacy
threat-intel Hackers used Telegram phishing campaign to target exiled Belarusian activist Hackers are using highly personalized Telegram phishing campaigns targeting exiled Belarusian activists and users in Russia and Kazakhstan. The campaign leverages private messages and tailored fake login pages to steal T… The Record · Jul 27, 2026 High KZRUBYphishingaccount-hijackingtelegram
vulnerability Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw A public exploit for a remote code execution vulnerability in vBulletin has been released, targeting versions 6.2.1 and earlier, and 6.1.6 and earlier. The vulnerability allows unauthenticated code execution, but the exp… The Hacker News · Jul 27, 2026 High CVE-2026-61511CVE-2025-48827CVE-2025-48828rcevbulletinremote-code-execution
vulnerability n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process N8n, a workflow automation platform, had a high-severity expression-sandbox escape that could allow authenticated workflow editors to execute operating system commands on the server. The vulnerability stemmed from a flaw… The Hacker News · Jul 27, 2026 High CVE-2026-27577expression-sandboxworkflowjavascript
threat-intel MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection MedusaHVNC is a sophisticated remote access trojan (RAT) sold as a service, utilizing hidden Windows desktops to evade detection and maintain a persistent presence on victims' systems. BlackFog researchers discovered the… SecurityWeek · Jul 27, 2026 High RUrathidden desktopencryption
threat-intel Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update A sophisticated phishing campaign, dubbed Operation BlueDash, is leveraging Microsoft Teams-themed lures to deliver malicious Remote Management and Monitoring (RMM) tools, primarily Level RMM and ConnectWise ScreenConnec… The Hacker News · Jul 27, 2026 High NGphishingrmmremote access
threat-intel Nvidia and Tech Giants Launch AI Security Alliance Nvidia and a coalition of tech giants have launched the Open Secure AI Alliance, an initiative focused on developing and sharing open-source tools and techniques to bolster the security of AI systems and agents. The alli… SecurityWeek · Jul 27, 2026 High aisecurityopen source
threat-intel Hackers used autonomous AI agent to spy on Thailand's finance ministry Hackers used an autonomous AI agent, Hermes developed by Nous Research, to conduct a cyber-espionage campaign targeting Thailand's Ministry of Finance. The agent independently explored the ministry's network, gathering i… The Record · Jul 27, 2026 High CNaicyberespionageautonomous agent
ransomware Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack Coca-Cola’s Fairlife subsidiary suffered a ransomware attack from the Anubis group, resulting in a data breach and the potential release of 1TB of stolen data. Production has largely resumed, but the group is threatening… SecurityWeek · Jul 27, 2026 High ransomwaredata breachdouble extortion
threat-intel Cognyte Sells a Mobile Cell Surveillance Van Cognyte, an Israeli surveillance firm, has sold a mobile cell surveillance van called FalcoNet, mimicking a cell tower to track nearby phones. This technology, similar to Stingrays, allows law enforcement to monitor comm… Schneier on Security · Jul 27, 2026 High ISsurveillanceprivacycell-site
threat-intel What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out Lookout has launched a new Mobile Security Exposure Center (MSEC) designed to provide organizations with a deeper understanding of the vulnerabilities hidden within their mobile apps. MSEC creates a ‘software bill of mat… SecurityWeek · Jul 27, 2026 High CHmobile-securitysbomvulnerability