phishing Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk A sophisticated phishing campaign mimicking legitimate job offers from companies like Netflix, OpenAI, and Adobe is targeting Google account users. Attackers are using realistic email addresses and LinkedIn research to i… Graham Cluley · Jul 9, 2026 High phishingrecruitmentgoogle
threat-intel EU takes member states to court over unimplemented cybersecurity law The European Commission has filed legal action against Ireland, Spain, France, and the Netherlands for failing to implement the NIS2 Directive, a cybersecurity law designed to improve security for critical infrastructure… The Record · Jul 9, 2026 Medium IEESFRcybersecurityeu lawcritical infrastructure
threat-intel AI Gateways Offer Attackers the Keys to the Kingdom A cryptomining incident highlighted how AI gateways, increasingly used to manage access to AI models and cloud infrastructure, are becoming attractive targets for attackers. The attacker gained initial access via brute-f… Dark Reading · Jul 9, 2026 High aigatewaycloud
threat-intel AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up AI-powered attacks are now executing significantly faster, requiring security teams to adapt their defenses. This article details a new attack methodology leveraging AI models like Mythos, highlighting the need for a shi… The Hacker News · Jul 9, 2026 High aiattackthreat
data-breach 12 Million Impacted by Data Breach at Japanese Telco KDDI A data breach at Japanese telecom KDDI has impacted over 12 million users due to a zero-day vulnerability exploited by hackers. The attackers gained access to email addresses and passwords, prompting a company-wide passw… SecurityWeek · Jul 9, 2026 High JPdata breachzero-daypassword reset
threat-intel Schneider Electric Easergy MiCOM Px40 Series Schneider Electric has issued a security advisory (SEVD-2026-104-03) regarding a critical vulnerability in its Easergy MiCOM Px40 Series protection relays. This vulnerability, a Use of Hard-coded Credentials (CWE-798), c… CISA Advisories · Jul 9, 2026 High CVE-2026-4832cwe-798snmpindustrial control systems
vulnerability OpenPLC v3 A critical vulnerability exists in OpenPLC v3, allowing authenticated attackers to write arbitrary files and escalate to arbitrary native code execution through the program upload process. This vulnerability affects crit… CISA Advisories · Jul 9, 2026 Critical CVE-2026-14480vulnerabilityindustrial control systemscwe-73
vulnerability Schneider Electric PowerChute Serial Shutdown Schneider Electric PowerChute Serial Shutdown versions 1.4 and earlier contain multiple vulnerabilities that could allow attackers to overwrite critical files, inject malicious data, gain unauthorized access, or trigger… CISA Advisories · Jul 9, 2026 High CVE-2026-2399CVE-2026-2404CVE-2026-2405vulnerabilitypatchsecurity advisory
vulnerability 15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google A 15-year-old Linux kernel vulnerability, dubbed ‘GhostLock,’ has been exploited to earn a security researcher $92,000. The flaw allows for local privilege escalation and container escapes, highlighting the long-term ris… SecurityWeek · Jul 9, 2026 High CVE-2026-43499linuxkernelvulnerability
threat-intel The Language of AI Could Change How Humans Speak A joint statement from the Five Eyes intelligence alliance warns of rapidly increasing cyber risks stemming from the accelerating development of AI models. The core concern is that AI, particularly open-source models, is… Schneier on Security · Jul 9, 2026 High aicybersecurityhacking
threat-intel Summer of Clearinghouses The article discusses the recent surge in ‘clearinghouses’ – collections of pre-disclosure vulnerabilities – and argues that these are largely a distraction from the real issue: the speed at which vulnerabilities are dis… The Hacker News · Jul 9, 2026 High vulnerabilityopen sourceclearinghouse
ransomware GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses The GodDamn ransomware family, a rebrand of Beast ransomware (originally based on Monster), is utilizing a newly discovered malicious driver called PoisonX to disable endpoint defenses and gain access to systems. Threat… The Hacker News · Jul 9, 2026 High ransomwarepoisonxbyovd
vulnerability Microsoft Patches Defender ‘RoguePlanet’ Vulnerability Microsoft has released a patch to address a Defender vulnerability, dubbed RoguePlanet, which could allow an attacker to escalate privileges. The vulnerability was initially identified by Nightmare Eclipse (Chaotic Eclip… SecurityWeek · Jul 9, 2026 High CVE-2026-50656CVE-2026-41091CVE-2026-45498vulnerabilitypatchdefender
ransomware Mount Royal University Confirms Data Stolen in Ransomware Attack Mount Royal University in Canada suffered a ransomware attack that resulted in the theft of employee and student data. The attackers, identified as CMD Organization, exfiltrated over 10 terabytes of information and are d… SecurityWeek · Jul 9, 2026 High CAransomwaredata breachtor
threat-intel 'GodDamn' Ransomware Uses BYOVD to Smite US Companies The ransomware group Hyadina, operating under the name "GodDamn," is leveraging a Microsoft-approved, malicious kernel driver – dubbed "PoisonX" – to infiltrate US organizations and deploy its ransomware. They utilize a… Dark Reading · Jul 9, 2026 High RUransomwaredriverbyovd
vulnerability AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique AI coding assistants like Claude Code, Amazon Q Developer, and Cursor are vulnerable to a decades-old technique called GhostApproval, where attackers can trick the tools into accessing and modifying sensitive system file… SecurityWeek · Jul 9, 2026 High symlinkaicoding
vulnerability Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges Microsoft has patched a critical vulnerability, RoguePlanet, within its Defender antivirus software that could allow attackers to gain SYSTEM-level privileges. This flaw, discovered by Chaotic Eclipse, allows for arbitra… The Hacker News · Jul 9, 2026 Critical CVE-2026-50656CVE-2026-33825CVE-2026-45498vulnerabilityprivilege escalationantivirus
threat-intel European Organizations Have a Collaboration Security Confidence Gap A recent survey by Wire reveals a significant gap between European organizations' confidence in their collaboration security and the actual practices surrounding sensitive data sharing. Despite high confidence levels, ma… Dark Reading · Jul 9, 2026 Medium shadow itdata governanceaccess control
vulnerability Chrome 150 Update Patches 27 Vulnerabilities Google released Chrome 150, addressing 27 security vulnerabilities, including two critical flaws related to use-after-free bugs. The update represents a significant effort to remediate a substantial number of memory safe… SecurityWeek · Jul 9, 2026 Medium memory-safetyvulnerabilitychrome
threat-intel Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images Meta has launched Muse Image, an AI tool that allows users to generate images using their public Instagram content. The feature is being rolled out gradually and users can opt-out of having their content used by the AI.… The Hacker News · Jul 9, 2026 Medium aiinstagrammeta