Skip to content

News

World Cybersecurity News

RSS The Hacker News
  • World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent July 20, 2026
    In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. "We identified unauthorized access to a limited set of internal datasets […]
  • SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines July 20, 2026
    Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4) […]
  • Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution July 19, 2026
    F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade. Triggering it […]
  • UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware July 19, 2026
    Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's
  • SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access July 19, 2026
    A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this
  • New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code July 17, 2026
    Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install […]
  • OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests July 17, 2026
    Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. […]
  • Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT July 17, 2026
    Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron,
  • New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens July 17, 2026
    A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast […]
  • GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft July 17, 2026
    Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors […]
RSS Cybercrime Magazine
  • Sophos Fusion: A Complete AI-Native Cyber Defense System July 17, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 17, 2026 – Read the full story from Sophos With around 359 million businesses in the world, fewer than 35,000 have a CISO or security leader in place, according to the 2026 The post Sophos Fusion: A Complete AI-Native Cyber Defense System […]
    Taylor Fox
  • The Best Of Kevin Mitnick On The Cybercrime Magazine YouTube Channel July 16, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 16, 2026 – Watch the YouTube videos Kevin Mitnick, the world’s most famous hacker, passed away three years ago on Jul. 16, 2023. Mitnick visited the Cybersecurity Ventures HQ and Cybercrime Magazine studios in Northport, The post The Best Of Kevin Mitnick On The Cybercrime […]
    Taylor Fox
  • Daemon Fairless, Host Of “Hunting Warhead”, On The Cybercrime Magazine Podcast July 15, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 15, 2026 – Listen to the podcast Hunting Warhead is an award-winning investigative true-crime podcast from CBC Podcasts and the Norwegian newspaper VG. Hosted by Daemon Fairless, the show follows journalists, white-hat hackers, The post Daemon Fairless, Host Of “Hunting Warhead”, On The […]
    Taylor Fox
  • Human Risk Intelligence Is Part Of The Modern Cybersecurity Stack July 14, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 14, 2026 – Watch the YouTube video “When high-trust individuals are compromised, the blast radius reaches well beyond them to their companies, partners, and networks,” said Raman Khanna, Managing Director, Dell The post Human Risk Intelligence Is Part Of The Modern […]
    Taylor Fox
  • Cyber Risk Oversight in the AI Era: How Resilient is Your Enterprise? July 13, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 13, 2026 – Listen to the podcast Larry Clinton is the President and CEO of the Internet Security Alliance. Since 2001, ISA strives to promote the recognition of cybersecurity as an The post Cyber Risk Oversight in the AI Era: How […]
    Taylor Fox
  • Step Into The Business Hall At Black Hat USA 2026 July 10, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 10, 2026 – Watch the video The Cybercrime Magazine media team will step into the Business Hall at Black Hat USA in Las Vegas Aug. 2-4 and experience the future of cybersecurity. Where The post Step Into The Business Hall At Black Hat […]
    Taylor Fox
  • When “Secure” Cameras Become Peep Shows: 1M+ Baby Monitors Left Families Exposed July 9, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 9, 2026 – Listen to the podcast Strangers were watching your children sleep. For months, anyone with basic technical knowledge could access 1.1 million baby monitors and security cameras worldwide—no hacking The post When “Secure” Cameras Become Peep Shows: 1M+ Baby […]
    Taylor Fox
  • Silvia Semenzin: The Internet is Not a Safe Place for Women July 8, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 8, 2026 – Listen to the podcast The Internet is often portrayed as a neutral space, open and even democratic, a place full of possibilities. But for many women, the web is The post Silvia Semenzin: The Internet is Not a Safe […]
    Taylor Fox
  • The Hidden SecOps Bottleneck: Getting the Right Data In and the Right Actions Out July 7, 2026
    Because scaling security isn’t just about better detection—it’s about removing the friction around it – Mayuresh Ektare, Senior Vice President, Product Management San Jose, Calif. – Jul. 7, 2026 Every security team wants better outcomes. Faster detection. Faster triage. Faster investigation. Faster response. But many The post The Hidden SecOps Bottleneck: Getting the Right Data […]
    Taylor Fox
  • The Canvas Hack: Who, What, Where, When, and Why July 7, 2026
    This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Jul. 7, 2026 – Listen to the podcast EdTech company Instructure confirmed a massive data breach this past spring. The ShinyHunters group claimed responsibility, alleging that data of 275 million individuals was stolen, The post The Canvas Hack: Who, What, Where, When, and […]
    Taylor Fox

Cyberthreat Real Time Map

For more detailed map and information click here