JadePuffer returns with ransomware built to target AI models and infrastructureHelp Net Security·Jul 21, 00:00 UTC · Jul 21, 2026RansomwareCVE-2025-3248160
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050The Hacker News·Jul 20, 14:33 UTC · Jul 20, 2026Malware42
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 FilesThe Hacker News·Jul 17, 08:56 UTC · Jul 17, 2026Malware130
Phishing Campaign Hides Lua Loader as TrueType Font FileInfosecurity Magazine·Jul 16, 15:00 UTC · Jul 16, 2026Malware30
A single malware file can outweigh an entire AI datasetHelp Net Security·Jul 16, 03:52 UTC · Jul 16, 2026Malware30
VS Code agent host runs Copilot, Claude, and Codex in a dedicated processHelp Net Security·Jul 16, 00:00 UTC · Jul 16, 2026AI tools & infra30
Reading between the lines of a cyber insurance policyHelp Net Security·Jul 16, 00:00 UTC · Jul 16, 2026Phishing & fraud30
Ransom demands are down, email is the top way attackers get inHelp Net Security·Jul 16, 00:00 UTC · Jul 16, 2026Ransomware57
Yemeni War Emphasizes Importance of Internet Control in Statecraft and Conflict/yemen-internetRecorded Future·Jul 16, 00:00 UTC · Jul 16, 2026Data breach57
Phishing Campaign Abuses eCards to Deploy RMM ToolsInfosecurity Magazine·Jul 15, 15:00 UTC · Jul 15, 2026Threat actor45
Microsoft Patches Record 622 Flaws, Including Two ZeroThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Vulnerability in the wildCVE-2026-56164CVE-2026-56155CVE-2026-50661+6 CVEs60
Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters ActivityThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Ransomware45
Week in review: Accenture data breach, great open-source cybersecurity toolsHelp Net Security·Jul 12, 00:00 UTC · Jul 12, 2026Data breach in the wildCVE-2026-48282CVE-2026-55255CVE-2026-50656160
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress SitesThe Hacker News·Jul 10, 11:30 UTC · Jul 10, 2026Malware in the wildCVE-2026-3844CVE-2021-29441CVE-2026-3300+10 CVEs60
AWS gives its ERP agent deny-by-default rules and a separate identityHelp Net Security·Jul 10, 00:00 UTC · Jul 10, 2026Advisory30
Friday Squid Blogging: The Chinese Control the Majority of Argentina's Squid FleetSchneier on Security·Jul 9, 16:08 UTC · Jul 9, 2026Vulnerability142
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running ItThe Hacker News·Jul 9, 05:17 UTC · Jul 9, 2026Exploit / PoCCVE-2026-3986150
Messaging fraud trends point to smarter attacks, stronger blockingHelp Net Security·Jul 9, 00:00 UTC · Jul 9, 2026Phishing & fraud42
Malicious AI agent skills can slip past the scanners built to stop themHelp Net Security·Jul 9, 00:00 UTC · Jul 9, 2026Malware42
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet MalwareThe Hacker News·Jul 8, 15:19 UTC · Jul 8, 2026Malware30
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking UsersThe Hacker News·Jul 8, 12:52 UTC · Jul 8, 2026Malware30
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking SignaturesThe Hacker News·Jul 8, 11:51 UTC · Jul 8, 2026Advisory130
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in CodeThe Hacker News·Jul 8, 11:21 UTC · Jul 8, 2026AI safety & security130
Omnigent: Open-source AI agent framework and meta-harnessHelp Net Security·Jul 8, 07:16 UTC · Jul 8, 2026AI safety & security130
macOS is becoming a proving ground for AI agentsHelp Net Security·Jul 8, 00:00 UTC · Jul 8, 2026AI research30
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo DataThe Hacker News·Jul 7, 14:07 UTC · Jul 7, 2026Exploit / PoC145
A privacy-first take on local malware analysisHelp Net Security·Jul 7, 05:45 UTC · Jul 7, 2026Malware30
Scoring AI hackers when there is no answer keyHelp Net Security·Jul 7, 05:44 UTC · Jul 7, 2026Vulnerability30
Researchers Claim First Fully Agentic Ransomware: JadePufferInfosecurity Magazine·Jul 6, 08:30 UTC · Jul 6, 2026RansomwareCVE-2025-3248CVE-2021-2944160
Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attackHelp Net Security·Jul 5, 00:00 UTC · Jul 5, 2026Vulnerability in the wildCVE-2026-12569CVE-2026-48558CVE-2026-4681760
U.S. Government Entity Paid Kairos $1 Million in DataThe Hacker News·Jul 4, 13:06 UTC · Jul 4, 2026Ransomware57
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits AndroidThe Hacker News·Jul 3, 19:41 UTC · Jul 3, 2026Exploit / PoC in the wildCVE-2026-46242CVE-2026-43074CVE-2026-31431+2 CVEs160
Catching ransomware on the wire before it locks the file serverHelp Net Security·Jul 2, 00:00 UTC · Jul 2, 2026Ransomware157
DHS to unveil replacement council for critical infrastructure cybersecurityCyberScoop·Jul 1, 20:29 UTC · Jul 1, 2026Exploit / PoC in the wild60
Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF LuresThe Hacker News·Jul 1, 15:26 UTC · Jul 1, 2026Malware30
Brazilian Banking Trojan Ousaban Targets Spain and PortugalInfosecurity Magazine·Jul 1, 13:45 UTC · Jul 1, 2026Malware30
RustDuck: The Botnet That's Still Small but Engineering Like It Plans to GrowSecurity Affairs·Jul 1, 10:25 UTC · Jul 1, 2026Malware in the wildCVE-2025-29635CVE-2017-17215CVE-2024-1781+1 CVEs160
Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing APIThe Hacker News·Jul 1, 05:32 UTC · Jul 1, 2026Malware30
Most teams will ship AI-written infrastructure code with little reviewHelp Net Security·Jul 1, 03:10 UTC · Jul 1, 2026Industry130
Telegram-Based Millenium RAT Campaign Infects 60,000 DevicesInfosecurity Magazine·Jun 29, 14:30 UTC · Jun 29, 2026Malware42