Latest Cybersecurity News and Articles


NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

24 July 2026
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators should be on 4.14.2. The simplest one takes a settings change. A

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

24 July 2026
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution. Redis 6.2.23, 7.2.15, and 7.4.10

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

24 July 2026
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed weaponizing security flaws in WinRAR software to

Data Breach Confirmed After Australian Energy Giant Origin Is Hacked

24 July 2026
A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it.  The post Data Breach Confirmed After Australian Energy Giant Origin Is Hacked appeared first on SecurityWeek.

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

23 July 2026
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it. The NSA, CISA and partner agencies published

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

23 July 2026
AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider appeared first on SecurityWeek.

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

23 July 2026
Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. The danger was

Is Patching Dead? Vulnerability Management in the Post-Mythos Era

23 July 2026
You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching Dead? Vulnerability Management in the Post-Mythos Era appeared first on SecurityWeek.

Chick-fil-A Accounts Get Fried in Credential Stuffing Attack

23 July 2026
Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts. The post Chick-fil-A Accounts Get Fried in Credential Stuffing Attack appeared first on SecurityWeek.

Abstract Raises $25 Million to Expand Composable Security Operations Platform

23 July 2026
The latest investment round brings the total raised by Abstract to nearly $50 million. The post Abstract Raises $25 Million to Expand Composable Security Operations Platform appeared first on SecurityWeek.

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

23 July 2026
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which shared details of the vulnerability with The Hacker News ahead of publication, said about 500,000 macOS users running

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

23 July 2026
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or Edge in headless mode and drives the browser

Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

23 July 2026
SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek.

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

23 July 2026
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region; it was offline by the time the report

UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations

23 July 2026
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign

How Synthetic Identity Fraud is Coming for Machine Identities

23 July 2026
Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points with fabricated ones to create a person who doesn't exist. Since no real victim monitors misuse, a

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

23 July 2026
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13,

Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses

23 July 2026
Hackers recently obtained non-sensitive customer information and other documents from the company. The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses appeared first on SecurityWeek.

Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

23 July 2026
Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone number. The idea is to use a video selfie as a way to regain access if a user ever gets locked out or doesn't have access

Personal and banking details among customer data stolen in Origin Energy hack

23 July 2026
Personal and banking details among customer data stolen in Origin Energy hack Hackers access Australian customers’ names, addresses, dates of birth, phone numbers and some bank account details, company saysFollow our Australia news live blog for latest updatesGet our breaking news email, free app or daily news podcastOrigin Energy customers’ addresses, phone numbers and partial bank account data have been accessed in a hack, the company has confirmed.The firm has 4.8m customer accounts in Australia, providing electricity, fossil gas, LPG and internet services to homes and businesses. Continue reading...