vulnerability Microsoft Reins in RoguePlanet Zero-Day Threat A disgruntled security researcher, known as "Nightmare-Eclipse," published a proof-of-concept exploit (RoguePlanet) for a Windows Defender vulnerability, leading Microsoft to issue an out-of-band patch. The vulnerability… Dark Reading · Jul 9, 2026 High CVE-2026-50656CVE-2026-33825zero-dayprivilege-escalationmicrosoft
threat-intel AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready This article discusses the growing risk posed by AI agents in software development environments and highlights that most organizations are unprepared to manage this new type of identity. Unlike traditional service accoun… Dark Reading · Jul 9, 2026 High aiidentitygovernance
threat-intel New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware Microsoft has uncovered a sophisticated Windows backdoor, dubbed GigaWiper, that combines destructive capabilities with remote control functionality. GigaWiper operates by bundling three separate tools – a disk wiper, a… The Hacker News · Jul 9, 2026 High IRISUKransomwarebackdoordata destruction
threat-intel Winning 54% of the time Cisco Talos Intelligence has identified a China-nexus threat actor, UAT-7810, expanding its Operational Relay Box (ORB) network. The group exploits unpatched vulnerabilities in Ruckus and ASUS routers to deploy custom ma… Cisco Talos · Jul 9, 2026 High CHorbproxyrouter
threat-intel ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories This week's ThreatsDay highlights a diverse range of cyber threats, from global fraud operations and ransomware tool overlaps to sophisticated social engineering attacks and vulnerabilities in popular software. Key event… The Hacker News · Jul 9, 2026 High CVE-2026-9181CVE-2025-49760CVE-2025-59200CHTAESsocial engineeringphishingransomware
threat-intel As Global Conflicts Go Digital, Businesses Need Wartime Gameplans As global conflicts become increasingly digital, businesses across various sectors are becoming increasingly vulnerable targets for nation-states engaged in warfare. The case of Intellect Services, a Ukrainian tax softwa… Dark Reading · Jul 9, 2026 High UKIRUNcyberwarfarenation-stategeopolitics
threat-intel Latvian forestry company still restoring systems weeks after ransomware attack A Latvian state-owned forestry company, LVM, is still recovering from a ransomware attack that disrupted its systems for weeks. The attack, attributed to a foreign, financially motivated ransomware group, led to the leak… The Record · Jul 9, 2026 High LVransomwarecyberattackdata breach
threat-intel UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge The UK government is launching a multi-faceted cybersecurity initiative, Cyber Shield, focused on leveraging agentic AI to bolster national cyber defenses against increasingly rapid AI-powered attacks. Simultaneously, th… SecurityWeek · Jul 9, 2026 High UKaicybersecuritynational security
vulnerability Palo Alto Networks Patches 13 Vulnerabilities Palo Alto Networks has released advisories detailing 13 vulnerabilities across its products, including a critical buffer overflow that could lead to arbitrary code execution. While the company reports no active exploitat… SecurityWeek · Jul 9, 2026 High CVE-2026-0288vulnerabilitypatchbuffer overflow
threat-intel NSA revives 'Tailored Access Operations' name for elite hacking unit The National Security Agency (NSA) has revived its elite hacking unit, formerly known as TAO (Tailored Access Operations), as part of a reorganization aimed at bolstering its capabilities against evolving cyber threats f… The Record · Jul 9, 2026 High IRCHNOhackingcyber espionagenational security
phishing Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk A sophisticated phishing campaign mimicking legitimate job offers from companies like Netflix, OpenAI, and Adobe is targeting Google account users. Attackers are using realistic email addresses and LinkedIn research to i… Graham Cluley · Jul 9, 2026 High phishingrecruitmentgoogle
threat-intel AI Gateways Offer Attackers the Keys to the Kingdom A cryptomining incident highlighted how AI gateways, increasingly used to manage access to AI models and cloud infrastructure, are becoming attractive targets for attackers. The attacker gained initial access via brute-f… Dark Reading · Jul 9, 2026 High aigatewaycloud
threat-intel AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up AI-powered attacks are now executing significantly faster, requiring security teams to adapt their defenses. This article details a new attack methodology leveraging AI models like Mythos, highlighting the need for a shi… The Hacker News · Jul 9, 2026 High aiattackthreat
data-breach 12 Million Impacted by Data Breach at Japanese Telco KDDI A data breach at Japanese telecom KDDI has impacted over 12 million users due to a zero-day vulnerability exploited by hackers. The attackers gained access to email addresses and passwords, prompting a company-wide passw… SecurityWeek · Jul 9, 2026 High JPdata breachzero-daypassword reset
threat-intel Schneider Electric Easergy MiCOM Px40 Series Schneider Electric has issued a security advisory (SEVD-2026-104-03) regarding a critical vulnerability in its Easergy MiCOM Px40 Series protection relays. This vulnerability, a Use of Hard-coded Credentials (CWE-798), c… CISA Advisories · Jul 9, 2026 High CVE-2026-4832cwe-798snmpindustrial control systems
vulnerability Schneider Electric PowerChute Serial Shutdown Schneider Electric PowerChute Serial Shutdown versions 1.4 and earlier contain multiple vulnerabilities that could allow attackers to overwrite critical files, inject malicious data, gain unauthorized access, or trigger… CISA Advisories · Jul 9, 2026 High CVE-2026-2399CVE-2026-2404CVE-2026-2405vulnerabilitypatchsecurity advisory
vulnerability 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google A 15-year-old Linux kernel vulnerability, dubbed ‘GhostLock,’ has been exploited to earn a security researcher $92,000. The flaw allows for local privilege escalation and container escapes, highlighting the long-term ris… SecurityWeek · Jul 9, 2026 High CVE-2026-43499linuxkernelvulnerability
threat-intel The Language of AI Could Change How Humans Speak A joint statement from the Five Eyes intelligence alliance warns of rapidly increasing cyber risks stemming from the accelerating development of AI models. The core concern is that AI, particularly open-source models, is… Schneier on Security · Jul 9, 2026 High aicybersecurityhacking
threat-intel Summer of Clearinghouses The article discusses the recent surge in ‘clearinghouses’ – collections of pre-disclosure vulnerabilities – and argues that these are largely a distraction from the real issue: the speed at which vulnerabilities are dis… The Hacker News · Jul 9, 2026 High vulnerabilityopen sourceclearinghouse
ransomware GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses The GodDamn ransomware family, a rebrand of Beast ransomware (originally based on Monster), is utilizing a newly discovered malicious driver called PoisonX to disable endpoint defenses and gain access to systems. Threat… The Hacker News · Jul 9, 2026 High ransomwarepoisonxbyovd