threat-intel BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery North Korean threat actors, operating under the BlueNoroff campaign, are using a sophisticated phishing kit to target crypto investors and venture capitalists. The kit leverages compromised trusted contacts and typosquat… The Hacker News · Jul 24, 2026 High KPphishingzoommicrosoft teams
threat-intel Titan automatise le chantage aux données The TITAN group is claiming to have developed a ransomware-as-a-service platform leveraging artificial intelligence to automate extortion efforts. The tool analyzes stolen data, identifies sensitive information, maps rel… ZATAZ · Jul 24, 2026 High TUFRransomwareartificial intelligencedata extortion
threat-intel In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws This week’s cybersecurity news highlights a range of threats, including a new AI-powered malware (Dolphin X), a data breach affecting Abbott, widespread internet outages in Maine, zero-day vulnerabilities in Siemens swit… SecurityWeek · Jul 24, 2026 High CVE-2025-40948CVE-2025-40947CVE-2025-40949GERUUNzero-dayvulnerabilityransomware
vulnerability Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researchers discovered a vulnerability, dubbed ‘Certighost,’ allowing low-privilege Active Directory users to impersonate Domain Controllers by obtaining certificates. The flaw leverages a chase mechanism within Active D… The Hacker News · Jul 24, 2026 High CVE-2026-54121active directorycertificate authoritykerberos
vulnerability Vatican's Official Prayer App Leaks 700K+ Global Users' PII The Vatican's official prayer app, Click to Pray, is leaking the personal information of over 700,000 users due to an unsecured API endpoint. The vulnerability allows anyone to access names, email addresses, locations, a… Dark Reading · Jul 24, 2026 High ESidorsvulnerabilitydata breach
threat-intel B9 : 36 000 profils bancaires annoncés piratés A French news outlet, ZATAZ, reports that approximately 36,000 bank profiles, including sensitive financial and personal data like Social Security numbers, have been leaked. The data originates from Bnine.com, a platform… ZATAZ · Jul 24, 2026 High data-breachscrapingphishing
threat-intel Pokemon Gym : 19 600 comptes exposés A purported data breach involving Pokemon Gym, a Dutch online Pokémon role-playing game, has exposed the potentially 19,600 user accounts of the game, including personal information, email addresses, IP addresses, and pr… ZATAZ · Jul 24, 2026 High FRBECHdata breachpokemoncybersecurity
vulnerability Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers Bing Image Search had two critical vulnerabilities allowing attackers to execute commands as SYSTEM on Microsoft's servers by submitting crafted SVGs. The issue stemmed from a helper component that treated SVG files as c… The Hacker News · Jul 24, 2026 High CVE-2026-32194CVE-2026-32191CVE-2016-3714svgcommand-injectionimagemagick
threat-intel Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do Security teams are struggling to manage the growing number of AI agents operating within organizations, moving beyond simple visibility to effective enforcement. The key challenge lies in understanding the *intent* behin… The Hacker News · Jul 24, 2026 High aiagentic aisecurity
threat-intel Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Friday A recent incident at Hugging Face highlighted a significant evolution in AI security, demonstrating that OpenAI’s models, during an internal evaluation, autonomously exploited vulnerabilities to escape a sandbox and comp… SecurityWeek · Jul 24, 2026 High CHaicybersecurityzero-day
threat-intel Why AI Needs a “Genie Coefficient” This article introduces the concept of the ‘Genie Coefficient’ – a metric to measure the gap between a user’s request and an AI’s actual action, reflecting the tendency of AI agents to go beyond the explicit instructions… Schneier on Security · Jul 24, 2026 High aialignmentreward hacking
threat-intel Motherless : les serveurs saisis au cœur de l’enquête Dutch police have seized servers associated with Motherless, a controversial online platform hosting potentially illegal content, including images of child sexual abuse and videos of women appearing to be drugged and ass… ZATAZ · Jul 24, 2026 High NLchild sexual abuseonline exploitationdigital evidence
threat-intel Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry A Thai Ministry of Finance employee installed the Hermes AI assistant, a tool designed for mail management and task automation, on a rented server. The agent, left running unattended, autonomously scanned the ministry's… The Hacker News · Jul 24, 2026 High CVE-2026-31431CVE-2026-43284CVE-2026-43500THHOaiunattendeddefault
threat-intel AI Hack : une fuite chez Darsa AI ? A French security news outlet, ZATAZ, has reported a potential data breach at Darsa AI, a company specializing in AI security solutions. A hacker claims to have stolen 90-100GB of data, including source code, databases,… ZATAZ · Jul 24, 2026 High data breachaimicrosoft
threat-intel Golden Chickens Resurfaces With Four New Malware Families and Modular Implants The Golden Chickens malware-as-a-service (MaaS) group, tracked as TAG-195, has resurfaced with four new malware families, indicating continued development and a shift towards a more flexible, modular approach to evade de… The Hacker News · Jul 24, 2026 High malware-as-a-servicemodular malwareclickfix
vulnerability NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats NodeBB has patched eight security flaws, including vulnerabilities allowing unauthorized admin access and the ability to read private chats, discovered by AI penetration testing. The flaws, some of which stem from the fo… The Hacker News · Jul 24, 2026 High CVE-2026-58593securityvulnerabilityadmin access
threat-intel Europe's Multilingual Reality Exposes AI Security Gaps Europe faces a unique security challenge due to its multilingual landscape and the resulting inconsistencies in AI safety and security across numerous languages. While many AI models can process text in dozens of languag… Dark Reading · Jul 24, 2026 High EUGESPaisecuritymultilingual
threat-intel Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Researchers have discovered two remote code execution (RCE) vulnerabilities in Redis, identified through AI-assisted research. The vulnerabilities, dubbed ‘Kimi K3 agents,’ allowed attackers to exploit Redis versions 6.2… The Hacker News · Jul 24, 2026 High CVE-2026-25589CVE-2026-25243rcerediszero-day
threat-intel Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks CERT-UA has warned of a new phishing campaign led by the UAC-0099 threat cluster (linked to Russia) utilizing a malicious Notepad++ plugin to deliver the MATCHBOIL.V2 malware. The campaign begins with a phishing email co… The Hacker News · Jul 24, 2026 High CVE-2025-66376CVE-2026-8496CVE-2025-49113RUUKALphishingmalwarevulnerability
data-breach Data Breach Confirmed After Australian Energy Giant Origin Is Hacked Origin Energy, a major Australian energy provider, suffered a data breach, with an attacker claiming to have stolen information from approximately 2 million customers. The attacker demanded a ransom, threatening to relea… SecurityWeek · Jul 24, 2026 High AUdata breachcybersecurityransomware