CISA Orders Emergency Patching For Cisco FMC Zero-Day Exploited Through Static Credentials post, juli 30, 2026juli 31, 2026 A newly disclosed vulnerability in Cisco Secure Firewall Management Center is being actively exploited in attacks, prompting the US Cybersecurity and Infrastructure Security Agency to order federal agencies to apply emergency fixes within days. Tracked as CVE-2026-20316, the vulnerability allows an unauthenticated remote attacker to sign in to an affected… Continue Reading
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack post, juli 29, 2026juli 31, 2026 The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in “a coordinated cyberattack.” The attacks occurred on Sunday and Monday, July 26 and 27, and targeted operational technology (OT) systems at local water utilities. Continue Reading
Critical GitLab Flaw Enables Remote Code Execution post, juli 26, 2026juli 27, 2026 Security researchers have published proof-of-concept exploit code for a remote code execution vulnerability affecting multiple versions of self-managed GitLab, sharply increasing the urgency for organizations that have not installed patches released in June 2026. The exploit chain allows an authenticated GitLab user with permission to commit changes to a project… Continue Reading
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks post, juli 23, 2026juli 27, 2026 An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it… Continue Reading
Check Point Patches Actively Exploited SmartConsole Flaw Allowing Full Administrative Access post, juli 23, 2026juli 27, 2026 Check Point has released urgent security updates for three vulnerabilities affecting its firewall and security-management platforms, including a critical SmartConsole authentication bypass that attackers have already exploited against a small number of customers. The most serious vulnerability, tracked as CVE-2026-16232, could allow an unauthenticated remote attacker to obtain a valid… Continue Reading
OpenAI hackt ander AI-bedrijf, maar van ‘op hol geslagen AI’ is geen sprake post, juli 23, 2026juli 31, 2026 OpenAI heeft per ongeluk een ander AI-bedrijf gehackt. Dat gebeurde tijdens een test waarmee OpenAI wilde kijken hoe goed zijn AI-programma’s presteren op het gebied van cybersecurity. Nadat OpenAI zijn AI-programma’s veel vrijheid had gegeven om de test te voltooien, gebeurde iets wat niet de bedoeling was: ze verlieten de… Continue Reading
Google Unveils Gemini 3.5 Flash Cyber AI To Find, Validate & Patch Software Vulnerabilities post, juli 21, 2026juli 22, 2026 Google DeepMind has introduced Gemini 3.5 Flash Cyber, a specialised artificial intelligence model designed to discover, validate and help remediate security vulnerabilities across large software codebases. Built on Gemini 3.5 Flash and fine-tuned specifically for cybersecurity work, the lightweight model is intended to give defensive teams a faster and more… Continue Reading
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang post, juli 21, 2026juli 22, 2026 The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecurity company Arctic Wolf. Palo Alto Networks addressed the vulnerability (CVE-2026-0257) on May 13 and warned that attackers had begun abusing it to breach corporate networks after Rapid7 reported observing it being exploited… Continue Reading
New Malware Turns Microsoft 365 Calendars Into Covert Command-and-Control Channel post, juli 21, 2026juli 22, 2026 A newly uncovered Windows malware implant is abusing Microsoft 365 calendar events to receive instructions and exfiltrate stolen files, allowing its operators to conceal espionage activity inside legitimate Microsoft cloud traffic. The malware, named HOLLOWGRAPH by Group-IB, transforms a compromised Microsoft 365 mailbox calendar into a two-way command-and-control channel. Attackers… Continue Reading
Autonomous AI Agent Breaches Hugging Face In High-Speed Infrastructure Attack post, juli 20, 2026juli 22, 2026 Hugging Face has disclosed a significant security breach in which an autonomous artificial intelligence agent compromised part of its production infrastructure, stole service credentials and moved laterally across several internal computing clusters. The incident represents one of the clearest publicly documented examples of an AI agent independently conducting a multi-stage… Continue Reading