<?xml version="1.0" encoding="UTF-8" standalone="no"?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:gd="http://schemas.google.com/g/2005" xmlns:georss="http://www.georss.org/georss" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:thr="http://purl.org/syndication/thread/1.0"><id>tag:blogger.com,1999:blog-4802841478634147276</id><updated>2026-07-30T15:19:07.717+05:30</updated><title type="text">The Hacker News</title><subtitle type="html">The Hacker News has been internationally recognized as a leading news source dedicated to promoting awareness for security experts and hackers</subtitle><link href="https://thehackernews.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml"/><link href="https://thehackernews.com/feeds/posts/default?redirect=false" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/" rel="alternate" type="text/html"/><link href="http://pubsubhubbub.appspot.com/" rel="hub"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default?start-index=26&amp;max-results=25&amp;redirect=false" rel="next" type="application/atom+xml"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><generator uri="http://www.blogger.com" version="7.00">Blogger</generator><openSearch:totalResults>16908</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-3098078847994139837</id><published>2026-07-30T15:01:21.460+05:30</published><updated>2026-07-30T15:03:04.235+05:30</updated><title type="text">Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts</title><summary type="html">
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.

A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3098078847994139837" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3098078847994139837" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html" rel="alternate" title="Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGU7u7ESWcaN4Xy7bCwiH5yVHsr1vMjqCu05UKJ7c4tsJ4gSRsQXwg-WOe69VD1dLiRuf9FC3HTcjp1ia1NZPPg85MUmHz2TCOplJKSC002w7OMu0X9KWtXTN0MljVt88tQlfABhP7p4pnndpOJoplI5fnqheI8LZwBp623A6gx1HyurT4ZBHRSSils1g/s260-e100/south-korea.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-4732347486136030150</id><published>2026-07-30T13:10:48.390+05:30</published><updated>2026-07-30T13:10:48.390+05:30</updated><title type="text">Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation</title><summary type="html">
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors.

The activity, which began on July 22, 2026, involves the </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4732347486136030150" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4732347486136030150" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html" rel="alternate" title="Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAHLuK9rcrkKZxWdmWf50USFH75iYP3nViQrL7sP_6gBJUipIQfUTU0XmA2xnOTR57ZCQWd83Y2joLatEV3XVV10ph4uQV7LrrYLzDCfW4dBiDyvVtpyhD3fgrGY7J2hFbNtCzzp4CGU7DxDYCxnuzJtgCJKCMFuRxloks-iW4dXJlZADetaMQK5rZiUKF/s260-e100/outlook.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-230456856184194822</id><published>2026-07-30T12:58:43.796+05:30</published><updated>2026-07-30T12:58:43.797+05:30</updated><title type="text">FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks</title><summary type="html">
The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the equipment authorization required for import, marketing, or sale in the US.

Previously authorized models can still be sold, and devices people already own are unaffected. Federal purchases and use </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/230456856184194822" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/230456856184194822" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html" rel="alternate" title="FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipannhqI3vkI628-oBoMbtwDDVE4F2PpVmxVM9d10AE06EVVwZzrBde5sTZTddm_89YUCUkfopYwqVzuk2Y8I4g84Ete1SQLvrQ2gA8FVxyCt952gNJpTmXpReLiZZ6EIv33zLjDTFI-_KLydIHDGoIDkbv1ptGTXLdVf6NyeaKeWEEWX4yNsxx46-zyY/s260-e100/robots.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-3978545785477261529</id><published>2026-07-30T11:35:17.893+05:30</published><updated>2026-07-30T13:28:40.662+05:30</updated><title type="text">Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet</title><summary type="html">
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages carrying more than 2 billion weekly downloads between them.

The original Aikido and Wiz reports did not attribute the </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3978545785477261529" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3978545785477261529" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/amazon-links-debug-and-chalk-npm-hijack.html" rel="alternate" title="Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgWsCKCTbRf4kZF1zcu1cmfHaf-pPPKTo2q21iPUibGu2jsDaxT92LByZdMAi0d_luVH-yt263qlWE5uDFAh4Ue21dIUk_eu08YXHqwgHI_R9bziAK9nBUiht_lMbaL9bqBH800A0HtxNSYNISi1sZ4SKv1DanwxXBPj4rd6OFBk3ogNn9iTUmsiISve0/s260-e100/northkorean-npm.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-5703622199882049761</id><published>2026-07-30T10:38:39.165+05:30</published><updated>2026-07-30T10:38:39.165+05:30</updated><title type="text">Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data</title><summary type="html">
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation.

The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5703622199882049761" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5703622199882049761" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/cisco-fmc-zero-day-actively-exploited.html" rel="alternate" title="Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFSDmsE6q7010reBwpOwS1ESkJSxlBlgRBbtjEVAdeClQFAkRfpriRQWUpL0Br8xnFdF1mctv4Ttj1Nv77MMIKm9qlNehPtTLYzOQwcZAWR4Vw1HzjAvItevYjwQkUo_2JNRluc2_OeJ3vOZ-P8meai9NLLWBvothfh7GDqoOpMPmKpOO-hjAeY-Pxa-BV/s260-e100/cisco.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-4769253413210293736</id><published>2026-07-29T23:40:00.590+05:30</published><updated>2026-07-30T09:09:41.137+05:30</updated><title type="text">Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads</title><summary type="html">
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads.

Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4769253413210293736" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4769253413210293736" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html" rel="alternate" title="Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjswJ2Clfk448ySFwyQiVVviqzKzT4B9iwnvVio4_dzvA1TXPnNuDJUI8MozBddPvdWmL2JH3jVvzTxg8A2Z6X9qNPYtxjuVx7RKQkMW8vNVBIEs0sgcrLfywQVufYMEKpxa0vgo2k24bNa_EJaudCFTsvlqQKqbT3jsuzRJdI26GR4pRJrkNKAFx_xiKk/s260-e100/rubyrails.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-2162095004970693012</id><published>2026-07-29T21:09:30.222+05:30</published><updated>2026-07-29T21:09:30.222+05:30</updated><title type="text">Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory</title><summary type="html">
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution.

The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2162095004970693012" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2162095004970693012" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html" rel="alternate" title="Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCgiIKxPiETcU1yIlU2RFsHgjXg2uLgbzaJ-98y7sPuujYarFbc0FdMqSRLIKJ1hYrsGLCZTCf5k40RtQ2PgwmA2L6tLAidOymHNIduXN3vtU0u0BsI37PLgWK8gwla3oTYkdD8ggssjMfF_5PuC9-exVYpBcqjg9tvscJ7XNAaHJxeUmCj-WP8VttRSgy/s260-e100/mcp.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6617702381499274436</id><published>2026-07-29T21:01:15.061+05:30</published><updated>2026-07-30T10:22:17.756+05:30</updated><title type="text">Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape</title><summary type="html">
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.

The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter.

"A malicious actor with network access to vCenter </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6617702381499274436" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6617702381499274436" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html" rel="alternate" title="Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLKz0u1mJIVvPAxiFFqsvkMVXxyXqS_paYhbtTRFLoIWyl5Q_FwIrJjruxEYH0LAdzJm38P48m_T_24ycKfjPs2bg6FUoy2IWVUxH7SpNtiSJuExOy3dDEAWprGwkvhY5005OPyFUzl2qJzAztAckgZNLVzqlp34s9HtQ3wrvq6lDCcXgYwfOXKF08wtdp/s260-e100/vmware.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-3477480866774737754</id><published>2026-07-29T19:18:36.578+05:30</published><updated>2026-07-29T20:34:10.683+05:30</updated><title type="text">Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline</title><summary type="html">

A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response.

Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls.

Braham's water plant went offline, and the city asked residents to minimize </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3477480866774737754" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3477480866774737754" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/coordinated-cyberattack-targets-30.html" rel="alternate" title="Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2Bq6dazLT-P0v4T1DEwFJ86iFFR6sRJnNqjoFBKPVc0FuCvvys-WCkQjT86mHuwxs_DuEpBBb1_y8sOyqqFu7Smth-4YGfw7tTawHxUD9RxGs2Dzau_QCJXc4GtRCnUsNMwbgrx2jh8ozwPpo3udCn4t63ntw6B25phrH1meZil0zODzpvhXViz7Z8-k/s260-e100/water-plant-attack.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-7986604276101025978</id><published>2026-07-29T19:12:57.911+05:30</published><updated>2026-07-29T20:32:46.482+05:30</updated><title type="text">Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments</title><summary type="html">
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years.

According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7986604276101025978" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7986604276101025978" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/nine-year-fraud-campaign.html" rel="alternate" title="Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhD9hThKkBhl022O0TklhaF1JKxLj1RKJjnUgfHzzyuxctFOR0UIyUS0FH1No7KlXJHHmQwUKafQf0UYDm0g6v5RU0m1VS-7v-NtgBCW0OXsPhVeX-IAnluUD-FpMoyTc-wrN55GFssISEWcfJNhBPywn7Pp35cww_lLDZdrWxEqpGWgC15vSK_N4Qo1eM/s260-e100/russian-hacking.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1057942879431004184</id><published>2026-07-29T17:45:00.000+05:30</published><updated>2026-07-29T17:45:00.111+05:30</updated><title type="text">Mythos Asks the Right Question. It Doesn't Answer It.</title><summary type="html">
AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along.

The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change?

The honest answer is</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1057942879431004184" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1057942879431004184" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/mythos-asks-right-question-it-doesnt.html" rel="alternate" title="Mythos Asks the Right Question. It Doesn't Answer It." type="text/html"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0mieQQ57yqCRvM0amMKsszEvpX9AK9C4fSA6fyD6rx9VpNdjgYpiFk2D_AfSYT386yNTNuL1-ki2llA_LR-LXYw9r0p0nb2FZCnnP-u33sN2McktovTGN13k_n_i7HExGQdX6GcRSG0uKJAawc_6wusYkt37jY5sTvjz7k8kLa8RTIZM_NABBL64mbnY/s260-e100/meshs.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-5992639043967605003</id><published>2026-07-29T17:27:00.839+05:30</published><updated>2026-07-29T17:27:00.839+05:30</updated><title type="text">Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser</title><summary type="html">
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.

Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update.

"No settings or additional user interaction are required," Eten Zou, </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5992639043967605003" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5992639043967605003" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/researchers-show-single-malicious.html" rel="alternate" title="Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOwFIxqT8kRBNj9LdZBZhO1g2RPJwUttxQosrS_mPoNXkIR-JB-yM87HPzuPZ1tazourGhRg9Sco6YQEGZkC77DSqXBYjp0DkNDAUHOaAOnIisRYNPAQfNWwqnmoILXOgR0wwyGVNlU3kSVRU6TcfyAx5ztaAWZfbKnCDJYgUeIVsM7n7O2zq7fGc-xnI/s260-e100/tor-exploit.gif" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6444576934131187001</id><published>2026-07-29T16:43:10.461+05:30</published><updated>2026-07-29T16:59:48.561+05:30</updated><title type="text">73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack</title><summary type="html">
Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack.

According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by Vanson Bourne in January </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6444576934131187001" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6444576934131187001" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html" rel="alternate" title="73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack" type="text/html"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixbolkSzPCa__qy94Mm27YfEsvVeyY94SOG5BrCQCGtAe-QenE0qDM5Tkbb7eOy0PwSCECFGMrZ7IG7lVePoMWjqMn8s_7-5_r8JUSQ7WVHsHAo-zZIhyphenhyphenyNW5aGTbFkpgtu99ucSeEgcJK75UdxkAsWKjXf_x8zEGpcDURPf9UJjcDz8JSHFD0uahDcOI5/s260-e100/ss.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1713223709251703554</id><published>2026-07-29T16:30:00.666+05:30</published><updated>2026-07-29T16:30:00.666+05:30</updated><title type="text">Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity</title><summary type="html">


The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law.

The principal security agency said the instant messaging platform "failed to remove numerous channels, chats, and bots on the platform that are </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1713223709251703554" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1713223709251703554" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/russia-charges-telegram-founder-pavel.html" rel="alternate" title="Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMUnFYtFjTBTc4gylDAEu-XkRP-crArKjOPCGhPhdX7S3Of7UKlVyAbHVb9CyAStiVaXJkXjUgXssYTKSJNnQvJvxdn_diL69NGa-2lhE_6GJCBFp0qMshbqCPnCksje_5yYMqhqh43Np9-CEkjJDa_gs6Axq0lxbi12SlPKqPWf-s6_Roin-zR0DIBjvy/s260-e100/x-post-telegram.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-5993941950359417930</id><published>2026-07-29T14:28:27.032+05:30</published><updated>2026-07-29T14:29:22.499+05:30</updated><title type="text">Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass</title><summary type="html">
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5993941950359417930" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5993941950359417930" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html" rel="alternate" title="Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIxq_zUC231fexQTfY9VPvqP7FWVRurT9fbUUS3YMpMX2SRmJu9eXIlH7v6fnvqJGtirQwXJVjs1h-hbUM7j-R6DlfpW7M4kt28q9EoxMt7jJFjUjaAoVsuTWSsBZOFcDj99U8ApvFR4B4sDQ37QHYeWXjJsowFBP3n8-TBfzcKB2Rl-de-OluIkzbJIYb/s260-e100/cp-poc.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-4165882855520812036</id><published>2026-07-29T13:21:00.379+05:30</published><updated>2026-07-29T14:02:46.056+05:30</updated><title type="text">OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach</title><summary type="html">
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment also hacked multiple third-party accounts and services as part of the attack.

The latest disclosure shows that the security incident, which stemmed from an internal security test, was more extensive in scope than previously </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4165882855520812036" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4165882855520812036" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html" rel="alternate" title="OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqsDw-FCPzIqH_GCkBZgDD96kt0ZtwQzjSe3SOunA8WWGUTXqCB2FG_28DY0JgdD6zh07gHisKrTi2Wh5VVNAcoUMyJ9tZ_VGzPM73iid2PPg15oqKMbnRhk9CcTJlevxRQJL5Sq2MbJjYCIgQ_zOEsgyu_Jy72ubSLAvy_YK499pDr48Rp9Plh322h8_P/s260-e100/openai-breach.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-2606675054778197253</id><published>2026-07-29T13:17:19.059+05:30</published><updated>2026-07-29T13:18:02.474+05:30</updated><title type="text">New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands</title><summary type="html">
Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account.

Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2606675054778197253" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2606675054778197253" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html" rel="alternate" title="New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjm9I3aoAsUS5yCtKTvSX6LYxjKfJu-RShA1QmcUiBLu760VFfeqd6D4NfH3ttKHoQkfWT57oL0_4KJBovY7nshgiGQ4R5wimWh-2k48f9qjdlJtjKqK0oM5vxquJFPuguLbBkbqzA7xc4NgjQaxkcU7tVSQ0a3GyXreEyvdvR4NmERWPbkiR6Um2thKfY/s260-e100/Gitea-rce.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-7639311314998742127</id><published>2026-07-29T12:37:23.972+05:30</published><updated>2026-07-29T12:37:23.972+05:30</updated><title type="text">Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates</title><summary type="html">
Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers.

They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7639311314998742127" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7639311314998742127" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html" rel="alternate" title="Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOpdosdOAoAjpR73DY5i_8YN9dHOY7KsBws53ivjlY3iVg0-EZAO6CliWbdg61_hT6eI9_Im9aiH_c312ttIHamIl4IIxe2omPSWjC4OaCfbNKZC7Gr85jXs12NObtpiSAK1PNljccRdmzvITRijNNh16c2IDK3kWmL5Ce3lbzQNCJaMy4wgKwWyB2oiI/s260-e100/android-rat.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1300350832796448715</id><published>2026-07-29T09:50:57.127+05:30</published><updated>2026-07-29T09:51:17.302+05:30</updated><title type="text">Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js</title><summary type="html">
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family.

The list of affected packages is as follows -


  @joyfill/layouts@0.1.2-2773.beta.0
  @joyfill/components@4.0.0-rc24-2773-beta.4

The two packages "contain an import-time JavaScript implant that resolves encrypted code </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1300350832796448715" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1300350832796448715" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html" rel="alternate" title="Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjbnnos_l5g9tfmBH7efqHHPJs-C6Ti9zjG9iifZXs0QLLoUn7L1BwkunpqbD55rRvqSiJx0R_DTAl12TBnL9MN0DkDtzhwnm8Xgbsbu8LZuKyRDnVtq3cbeMlEmNJEmZgXy3BeOILj2kM24GojxXfDJDr93XsEiORhP9q1sYo814jzq4UsQCS0RRZmhp5k/s260-e100/npm-hack.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-4519052299194501946</id><published>2026-07-29T00:29:07.348+05:30</published><updated>2026-07-29T22:48:41.034+05:30</updated><title type="text">Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack</title><summary type="html">
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128.

The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4519052299194501946" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/4519052299194501946" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html" rel="alternate" title="Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPhJ6dzEL23Ak57nA_XsbXtGaxl5wNrcGBPMQBVz1jddDuX_oTndpQjl3omqMxhRnQ1P4cSF7Ut18tccLFT2BxngpYTqTP8Kg6f4clFWRQ2GvxetR-uAGjMS2SsZwsiPcq5vyxCmP_AN3rCPvO5WMQeLNEit0q14i0iY9wuIUDAHMXkyvO3KjIC6c6Ozg/s260-e100/Claude.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6199638610285022515</id><published>2026-07-28T20:31:33.764+05:30</published><updated>2026-07-28T20:31:33.764+05:30</updated><title type="text">Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process</title><summary type="html">
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process.

If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force.

Tengu supports 25 distributed denial-of-service (</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6199638610285022515" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6199638610285022515" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html" rel="alternate" title="Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0zv7PihU6xAba7-fb5OY-Xv5YIEPM1HhmCu2ET65l5TSKYrPh6q4pYVQRNJtHb9RkvO1oNsBBrsxs50Hm_GRnPKCu4XoG1hhtPOoeGILfRHN99ICGSO72NOGQ6AdUc_haCrQvHRUn4YiyFmCy99WgH1v4-4GRLirZzsV1b5MmCjfTX3a2yWmg1tWOr38/s260-e100/tengu-botnet.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-3764777437851830957</id><published>2026-07-28T20:11:36.191+05:30</published><updated>2026-07-28T20:11:36.191+05:30</updated><title type="text">24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login</title><summary type="html">
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet.

Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose password-derived authentication hashes before login due to</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3764777437851830957" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3764777437851830957" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html" rel="alternate" title="24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIZDJmL5vHIaEgakZEwVC-O1KGBidMz7xrUS6MQmj0Nfqx4_WzGlwmz4amGxIwYa2PEJTKr5UsFwkh8lEOoFkjAVwTm38bgmbc_gDW2-__9MBpP5Z6cWQrIjFTe3tKTMEhD2lX3XyTrIe0T4mQDruecN3nCWqHUpkU5NpW5OIzZFy5la9RQnMCsmGkt-n8/s260-e100/bmcs.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-2157486306697680267</id><published>2026-07-28T19:03:47.123+05:30</published><updated>2026-07-30T09:24:28.575+05:30</updated><title type="text">JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach</title><summary type="html">
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment.

Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2157486306697680267" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2157486306697680267" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html" rel="alternate" title="JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVRTEATuhKwW2BlflaNjqHVV9mJlq6m3_rFzsUHv3RXATsLWdyJvG-XoWDftscxMF9r_-551JELumQMj7Jhp_iY-GTj79r3RxYKEEJkPo8B7Zd5SuiBnPRWjM1MBygMvV0Za1ZLItcoSjsCY4gDwbV-ZOkXLEzi2vohrqrlYSJL4Ut0GmmDvhEhiGti1U/s260-e100/openai-0day.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-5845377395110852048</id><published>2026-07-28T18:26:14.464+05:30</published><updated>2026-07-28T18:40:44.795+05:30</updated><title type="text">Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root</title><summary type="html">
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default.

The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6 </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5845377395110852048" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5845377395110852048" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html" rel="alternate" title="Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDmz4Rv-IWcHYP4Y_-WINLECGsPviBOTJXEPhvz2mO671_s8c1Rao7iErkNghWYtomczRf82scnXyzrBTAIc4urvwSlv3j4AK1XaEw75WVsIfXLfNDQd1JGUoVRWW50H48KA3VxzAbL1KTuf3sKCgzmSE3toXbqcIA-N5vwN4A_wcmRdwDLBSJbBpmmME/s260-e100/OpenWrt.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-1908561438884884460</id><published>2026-07-28T17:25:20.341+05:30</published><updated>2026-07-28T17:25:20.341+05:30</updated><title type="text">Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays</title><summary type="html">


The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.

The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers, </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1908561438884884460" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/1908561438884884460" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html" rel="alternate" title="Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-Whbx97t7xBrrpM26fYSbwg29hdKR8zskNLIwlrWC0Jd3Rrf4INhiCTI3WMw8NzmJ1iETQlt-CKdUxBzL2hef4pgQBOoI1rrrtRbU96hJRUXtTGy5dT40mP2B1AshyphenhyphenM4mc1K1-IISWwY6PSPyGXNBHplHM8kuxX9e5Di6RmMybyO2Q7Guu__CK8jOOkja/s260-e100/proxy.jpg" width="72"/></entry></feed>