ICYMI: 2026-07-09
Latest Headlines
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
Meta’s New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
QIZ Security Raises $17 Million for Cryptographic Governance Platform
UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge
15-Year-Old Linux Vulnerability ‘GhostLock’ Earns Researchers $92k From Google
Mount Royal University Confirms Data Stolen in Ransomware Attack
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique
GodDamn Ransomware Rebrands From Beast and Uses PoisonX Driver to Disable Defenses
ACSC Warns of Large-Scale CMS Exploitation Campaign Deploys Webshells on Vulnerable Websites
RedHook Android RAT Abuses ADB Wireless Debugging to Gain Shell-Level Access
Microsoft Adopts AI-Powered Scanning to Find Vulnerabilities Before Attackers
A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours
RoundCube 0-Click Vulnerability Enables Stored XSS Attack via MIME Type Attachment
Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts
HP Linux Printing Software Vulnerability Allows Remote Attackers to Execute Arbitrary Code
Hackers Use Fake Paysafe, Skrill, and Neteller Packages to Harvest API Keys and Tokens
Linux Kernel Vulnerability Enables Passwordless Root Through DRM Render Nodes
OpenMandriva Linux says contributor tried to sabotage the project
Injective SDK on npm infected with cryptocurrency wallet stealer
New Helix vishing group emerges in SharePoint data theft attacks
Microsoft expects more Windows security updates from AI-discovered flaws
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
Police arrests 5,800 suspects in global anti-fraud crackdown
AssuranceAmerica data breach exposes records of 6.9 million drivers
Microsoft patches RoguePlanet Defender zero-day vulnerability
– MTZ