Latest Cybersecurity News and Articles
30 July 2026
Researchers warn that AI could turn dangling DNS takeovers into a nation-state weapon capable of disrupting governments, banks and global supply chains.
The post ‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale appeared first on SecurityWeek.
30 July 2026
Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft.
In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session.
Måløy's
30 July 2026
Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model: users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations. Firewalls
30 July 2026
Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.
The post Semiconductor Firm Analog Devices Discloses Data Breach appeared first on SecurityWeek.
30 July 2026
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.
A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or
30 July 2026
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent remote access.
"In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate
30 July 2026
Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container.
The post Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms appeared first on SecurityWeek.
30 July 2026
Claroty has analyzed 750,000 cyber-physical systems across some of the world’s largest data center facilities.
The post 1 in 5 Data Center Assets Are Within Easy Reach of Attackers appeared first on SecurityWeek.
30 July 2026
Five years after the initial release, the refresh introduces new elements, removes others, and updates terminology.
The post US and Allies Update SBOM Guidance appeared first on SecurityWeek.
30 July 2026
The major browser update resolves roughly 80 critical- and high-severity security defects.
The post Chrome 151 Patches 370 Vulnerabilities appeared first on SecurityWeek.
30 July 2026
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors.
The activity, which began on July 22, 2026, involves the
30 July 2026
The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the equipment authorization required for import, marketing, or sale in the US.
Previously authorized models can still be sold, and devices people already own are unaffected. Federal purchases and use
30 July 2026
The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices.
The post Cisco Secure FMC Zero-Day Exploited in the Wild appeared first on SecurityWeek.
30 July 2026
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages carrying more than 2 billion weekly downloads between them.
The original Aikido and Wiz reports did not attribute the
30 July 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation.
The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log
29 July 2026

Details of parents and staff, including email addresses and phone numbers, are among data taken by cybercriminalsThe Department for Education and a police database have been targeted by a cyber-attack, exposing more than 740,000 pieces of data.Details of government officials, senior school leaders, university staff, police officers and members of the public have been taken by hackers. Continue reading...
29 July 2026
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads.
Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,
29 July 2026
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution.
The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's
29 July 2026
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.
The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter.
"A malicious actor with network access to vCenter
29 July 2026
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response.
Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls.
Braham's water plant went offline, and the city asked residents to minimize