threat-intel Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found A popular Chrome and Edge header-editing extension, ModHeader, was found to contain a hidden browsing history collector, despite claims it didn't collect data. Researchers at Stripe OLT discovered the collector was dorma… The Hacker News · Jul 13, 2026 High CNextensiondata-collectionheader-editing
threat-intel Russian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breach Russian journalist Ksenia Sobchak's Telegram channels were briefly taken over by hackers who published alleged private correspondence. The hackers, operating under the group Black Mirror, claimed to have stolen over 350G… The Record · Jul 13, 2026 Medium RUUKtelegramdata breachrussian
threat-intel GigaWiper Lets Threat Actors Choose Their Own Destructive Attack GigaWiper is a novel, modular malware that combines backdoor and wiper capabilities, allowing attackers to choose how to destroy a targeted system while minimizing their operational footprint. Initially identified as a G… Dark Reading · Jul 13, 2026 High IRRUVEwiperbackdoormodular
ransomware ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More This week’s security news is dominated by a concerning trend: vulnerabilities are being exploited faster than patches can be applied, leading to a surge in attacks. Notable events include a ShareFile threat urging users… The Hacker News · Jul 13, 2026 High CVE-2026-50746CVE-2026-50747CVE-2026-50748
threat-intel Lessons Learned from CISA’s Recent GitHub Leak A CISA contractor inadvertently published a massive trove of sensitive credentials, including AWS GovCloud keys and plaintext passwords, in a public GitHub repository for nearly six months before CISA was notified. The a… Krebs on Security · Jul 13, 2026 High secretsgithubaws
threat-intel Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption Jesse McGraw, once a notorious blackhat hacker known as GhostExodus and leader of the Electronik Tribulation Army (ETA), has undergone a dramatic transformation. Driven by a complex mix of factors including neurodiversit… SecurityWeek · Jul 13, 2026 High neurodiversityred-hatosint
threat-intel New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Researchers have developed MemGhost, an automated tool that can plant false memories in AI assistants by sending a single, carefully crafted email. The tool bypasses existing security measures by exploiting the agents' a… The Hacker News · Jul 13, 2026 High CVE-2025-32711aimemory poisoningemail
threat-intel Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft Forg365, a new PhaaS operation, is targeting Microsoft 365 accounts using a sophisticated combination of device code phishing, AitM tactics, and AI-assisted lure creation. The platform allows even inexperienced operators… The Hacker News · Jul 13, 2026 High UNRUphishingaitmdevice code
threat-intel Cybersecurity M&A Roundup: 37 Deals Announced in June 2026 In June 2026, a significant number of cybersecurity M&A deals were announced, highlighting the industry's ongoing consolidation and investment in advanced security technologies. Several key acquisitions focused on areas… SecurityWeek · Jul 13, 2026 High ISBECAmergers and acquisitionscybersecurityidentity management
vulnerability RabbitMQ Vulnerability Threatens Enterprise Systems A vulnerability (CVE-2026-5721) in RabbitMQ allows attackers to steal the broker's confidential OAuth secret, potentially leading to complete control over an organization's message queues, users, and settings. This flaw,… SecurityWeek · Jul 13, 2026 High CVE-2026-5721CVE-2026-57221rabbitmqoauthvulnerability
threat-intel Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting Russian state-sponsored actors are exploiting poorly configured and vulnerable networking devices, primarily routers, across critical infrastructure sectors worldwide. This joint cybersecurity advisory, released by numer… CISA Advisories · Jul 13, 2026 High CVE-2018-0171CVE-2008-4128RUsnmpcverouter
threat-intel Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling Meta has filed a patent for an AI system that continuously monitors a user's voice, eye movements, and device usage to analyze their emotional state and provide personalized feedback. The system would track speech patter… The Hacker News · Jul 13, 2026 High aiprivacyemotion-analysis
threat-intel Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots This article argues that current approaches to AI in Security Operations Centers (SOCs) are fundamentally flawed. Instead of deploying AI to handle the entire alert queue (System 2 work), security teams are often forcing… The Hacker News · Jul 13, 2026 High aisoccognitive
threat-intel Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory A threat actor leveraged an AI-generated PowerShell script to aggressively map an Active Directory environment, culminating in data exfiltration and a detailed inventory report. The attack chain, utilizing tools like s5c… The Hacker News · Jul 13, 2026 High aipowershellactive directory
threat-intel AI Data Centers and the Concentration of Wealth This article argues that focusing solely on opposition to AI data centers in the US is a misguided approach, as it obscures the larger issue of corporate AI dominance and the concentration of wealth within the industry.… Schneier on Security · Jul 13, 2026 High CHUNaidata centerscorporate power
vulnerability Zimbra Patches Critical Code Execution Vulnerability A critical cross-site scripting (XSS) vulnerability in Zimbra’s Classic Web Client could allow attackers to execute code on a victim’s system simply by opening a specially crafted email. Zimbra has released version 10.1.… SecurityWeek · Jul 13, 2026 Critical xssvulnerabilityzimbra
threat-intel EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign The European Union has imposed sanctions on Russian intelligence officers and entities involved in a long-running cyber espionage campaign targeting European governments and critical infrastructure. This campaign, spanni… SecurityWeek · Jul 13, 2026 High FRDEPLcyber espionagecritical infrastructurerussian threat
vulnerability Organizations Warned of Exploited Joomla Extension Vulnerabilities Two critical vulnerabilities in Joomla extensions – Balbooa Forms and iCagenda – have been actively exploited by threat actors, allowing for remote code execution without authentication. Both vulnerabilities have been ad… SecurityWeek · Jul 13, 2026 Critical CVE-2026-56291CVE-2026-48939joomlavulnerabilityremote code execution
vulnerability Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns Progress Software has instructed ShareFile customers to immediately shut down their Storage Zone Controller servers due to a credible security threat. The company suspects that vulnerabilities, previously addressed in Ma… SecurityWeek · Jul 13, 2026 Critical CVE-2026-2699CVE-2026-2701vulnerabilityremote code executioncve
data-breach Centers Laboratory Data Breach Affects 540,000 Individuals Centers Laboratory, a healthcare diagnostics company, suffered a data breach in August 2025, exposing the personal and protected health information of over 540,000 individuals. The breach was carried out by the WorldLeak… SecurityWeek · Jul 13, 2026 High data breachcybercrimehealthcare