ICYMI: 2026-07-10
Latest Headlines
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
Laser Attack Resets Tangem Wallet Passwords on Cards That Can’t Be Patched
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
Attackers Exploit ‘Ill Bloom’ Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops
Third US Security Expert Sentenced to Prison for Helping Ransomware Gang
China, India-Linked Hackers Both Targeted Same Pakistani Police Force
Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
GigaWiper Combines Multiple Malware for System-Level Sabotage
‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism
Network of 200 GitHub Repositories Used for Malware Infection
Progress Urges ShareFile Admins to Shut Down Servers Over Credible Security Threat
One WhatsApp Message Turns OpenClaw Into a Remote Access Tool for Hackers
Top 10 Best Unified Threat Management (UTM) Solutions in 2026
Hackers Can Go From CitrixBleed 2 Exploitation to Ransomware in Under an Hour
Malicious Windows Shortcuts Use PowerShell and Node.js to Enable Remote Code Execution
GNU Guix Vulnerabilities Allow Remote Privilege Escalation via Malicious Binary Substitutes
Linux Kernel FUSE Vulnerability Lets Attackers Gain Root Privileges
Hackers are Turning AI Gateways as Attack Surfaces to Compromise Enterprise Networks
New Windows Process Injection Technique Bypasses Four Leading EDR Solutions
FastNetMon Launches Netomics, a Self-Hosted Routing Intelligence Platform
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
Progress urges ShareFile admins to shut down servers over “credible” threat
Money launderer accused of stealing seized crypto while in prison
The Replicant in Your Directory: AI Agents and the Identity Security Gap
Zimbra urges customers to patch critical web client XSS flaw
Former ransomware negotiator gets 4 years for BlackCat attacks
– MTZ