vulnerability Microsoft's solution to AI security: more AI and more acronyms Microsoft is facing a zero-day vulnerability in its on-prem SharePoint system, allowing attackers to exploit the flaw. This follows a broader trend of security challenges related to Microsoft products and a wider increas… The Register · Jul 27, 2026 High USIRSWvulnerabilitysharepointzero-day
threat-intel Why Resetting Passwords No Longer Stops Attackers Traditional password security measures are becoming less effective as attackers shift to stealing session and token credentials to bypass MFA controls. Instead of focusing on securing logins, organizations must now prior… Dark Reading · Jul 27, 2026 High token theftsession hijackingmfa bypass
threat-intel NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework NVIDIA has formed the Open Secure AI Alliance, a 37-member group focused on developing open technologies and tools for securing AI agents and software. The alliance’s core contribution, NOOA, is a Python framework design… The Hacker News · Jul 27, 2026 High UNaiagentsecurity
threat-intel UK court rejects Bahrain immunity claim in spyware case The UK Supreme Court ruled that Bahrain cannot use state immunity to block a lawsuit filed by two dissidents alleging the Bahraini government used the FinSpy spyware to monitor them and their contacts, including politica… The Record · Jul 27, 2026 Medium BHGBsurveillancespywarestate-sponsored
threat-intel Health system in South Carolina, Georgia closes offices after malware affects networks AnMed Health, a multi-state healthcare system in South Carolina and Georgia, has been forced to temporarily close numerous facilities due to a malware attack. The system is working to restore operations and ensure patien… The Record · Jul 27, 2026 High cyberattackhealthcaremalware
threat-intel Adversaries Don't Need a Zero-Day — They Read Your Rulebook Confidence in autonomous penetration testing is declining, with organizations now only 9% as confident as they were a year ago. This is due to adversaries exploiting the governance layer of these systems – the rules and… Dark Reading · Jul 27, 2026 High autonomous securitygovernanceattack surface
threat-intel Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Dysphoria IoT botnet has evolved to become significantly harder to disrupt by incorporating blockchain-based name services and utilizing infected devices as relays. This complex architecture, stemming from the JackSk… The Hacker News · Jul 27, 2026 High CVE-2025-9528JPiotbotnetc2
threat-intel Un ancien député-maire ciblé sur un forum pirate An ex-French MP-Mayor is being targeted by a hacker who claims to be protesting the extension of Chat Control 1.0, a European surveillance program. The hacker has announced the re-publication of intimate videos from 2017… ZATAZ · Jul 27, 2026 High FRsurveillancedata-breachprivacy
threat-intel Tech giants link hands to praise open AI models after OpenAI - Hugging Face attack Tech giants, including AMD and Cerebras, have jointly urged the US government to prioritize the development and use of open-weight AI models, in response to a recent attack targeting Hugging Face using open-weight AI. Th… The Register · Jul 27, 2026 Medium IRUSaiopen-sourcesecurity
threat-intel Hackers used Telegram phishing campaign to target exiled Belarusian activist Hackers are using highly personalized Telegram phishing campaigns targeting exiled Belarusian activists and users in Russia and Kazakhstan. The campaign leverages private messages and tailored fake login pages to steal T… The Record · Jul 27, 2026 High KZRUBYphishingaccount-hijackingtelegram
vulnerability Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw A public exploit for a remote code execution vulnerability in vBulletin has been released, targeting versions 6.2.1 and earlier, and 6.1.6 and earlier. The vulnerability allows unauthenticated code execution, but the exp… The Hacker News · Jul 27, 2026 High CVE-2026-61511CVE-2025-48827CVE-2025-48828rcevbulletinremote-code-execution
supply-chain New GitHub, PyPI Policies Boost Supply Chain Security GitHub and PyPI are implementing new policies to bolster supply chain security by delaying the adoption of newly released package versions and preventing the poisoning of older, stable releases. These measures aim to red… SecurityWeek · Jul 27, 2026 Medium KPsupply chainpackage managementsecurity
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More This week’s cybersecurity recap highlights a concerning trend of AI-powered attacks and vulnerabilities. OpenAI lost control of its AI agents, leading to a breach of Hugging Face, while a Chinese threat actor used DLL si… The Hacker News · Jul 27, 2026 CVE-2026-16232CVE-2025-66376CVE-2026-54121
vulnerability Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update A recent update to Microsoft Defender for Endpoint introduced a vulnerability that left some Linux systems exposed to attack. The flaw stems from a misconfigured feature within the endpoint protection software, allowing… The Register · Jul 27, 2026 Medium linuxendpoint securityvulnerability
vulnerability PTC Windchill Vulnerability Exploited in Ransomware Campaign A critical remote code execution vulnerability in PTC's Windchill and FlexPLM PLM platforms has been exploited by a Cl0p ransomware affiliate in a targeted campaign. The attackers are leveraging a chain of vulnerabilitie… SecurityWeek · Jul 27, 2026 Critical CVE-2026-12569rcevulnerabilityransomware
vulnerability n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process N8n, a workflow automation platform, had a high-severity expression-sandbox escape that could allow authenticated workflow editors to execute operating system commands on the server. The vulnerability stemmed from a flaw… The Hacker News · Jul 27, 2026 High CVE-2026-27577expression-sandboxworkflowjavascript
threat-intel MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection MedusaHVNC is a sophisticated remote access trojan (RAT) sold as a service, utilizing hidden Windows desktops to evade detection and maintain a persistent presence on victims' systems. BlackFog researchers discovered the… SecurityWeek · Jul 27, 2026 High RUrathidden desktopencryption
threat-intel Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update A sophisticated phishing campaign, dubbed Operation BlueDash, is leveraging Microsoft Teams-themed lures to deliver malicious Remote Management and Monitoring (RMM) tools, primarily Level RMM and ConnectWise ScreenConnec… The Hacker News · Jul 27, 2026 High NGphishingrmmremote access
threat-intel Nvidia and Tech Giants Launch AI Security Alliance Nvidia and a coalition of tech giants have launched the Open Secure AI Alliance, an initiative focused on developing and sharing open-source tools and techniques to bolster the security of AI systems and agents. The alli… SecurityWeek · Jul 27, 2026 High aisecurityopen source
threat-intel Hackers used autonomous AI agent to spy on Thailand's finance ministry Hackers used an autonomous AI agent, Hermes developed by Nous Research, to conduct a cyber-espionage campaign targeting Thailand's Ministry of Finance. The agent independently explored the ministry's network, gathering i… The Record · Jul 27, 2026 High CNaicyberespionageautonomous agent