Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Google Unveils Gemini 3.5 Flash Cyber AI To Find, Validate & Patch Software Vulnerabilities

post, juli 21, 2026juli 22, 2026

Google DeepMind has introduced Gemini 3.5 Flash Cyber, a specialised artificial intelligence model designed to discover, validate and help remediate security vulnerabilities across large software codebases. Built on Gemini 3.5 Flash and fine-tuned specifically for cybersecurity work, the lightweight model is intended to give defensive teams a faster and more…

Continue Reading

N-day is Becoming N-Hour. Patching Faster Won’t Save You.

post, juli 21, 2026juli 22, 2026

Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn’t updated yet….

Continue Reading

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

post, juli 21, 2026juli 22, 2026

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecurity company Arctic Wolf. Palo Alto Networks addressed the vulnerability (CVE-2026-0257) on May 13 and warned that attackers had begun abusing it to breach corporate networks after Rapid7 reported observing it being exploited…

Continue Reading

New Malware Turns Microsoft 365 Calendars Into Covert Command-and-Control Channel

post, juli 21, 2026juli 22, 2026

A newly uncovered Windows malware implant is abusing Microsoft 365 calendar events to receive instructions and exfiltrate stolen files, allowing its operators to conceal espionage activity inside legitimate Microsoft cloud traffic. The malware, named HOLLOWGRAPH by Group-IB, transforms a compromised Microsoft 365 mailbox calendar into a two-way command-and-control channel. Attackers…

Continue Reading

Autonomous AI Agent Breaches Hugging Face In High-Speed Infrastructure Attack

post, juli 20, 2026juli 22, 2026

Hugging Face has disclosed a significant security breach in which an autonomous artificial intelligence agent compromised part of its production infrastructure, stole service credentials and moved laterally across several internal computing clusters. The incident represents one of the clearest publicly documented examples of an AI agent independently conducting a multi-stage…

Continue Reading

Claude For Chrome Flaw Allows Malicious Extensions To Abuse AI Privileges

post, juli 18, 2026juli 20, 2026

A security weakness in Anthropic’s Claude for Chrome extension could allow another malicious browser extension to activate predefined AI workflows without a genuine user click, potentially exposing information held in Gmail, Google Docs and Google Calendar or initiating actions in services such as Salesforce. The issue was discovered by Manifold…

Continue Reading

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

post, juli 17, 2026juli 20, 2026

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. “Any user who ran the project ended up with a four-stage payload aligned with OtterCookie: a browser…

Continue Reading

Professional Services Giant Ernst & Young (EY) Hacked

post, juli 17, 2026juli 20, 2026

Ernst & Young has begun notifying clients of a data breach after an attacker compromised a third-party support platform and downloaded documents containing personal and financial information used in preparing tax returns. The incident affected an external IT service-management system used by EY employees supporting the firm’s client tax services….

Continue Reading

Zoom Patches Critical Flaw Allowing Remote Account Takeover

post, juli 16, 2026juli 17, 2026

Zoom has released emergency security updates to address a critical vulnerability in several of its Windows products that could allow an unauthenticated attacker to take control of a user’s account over a network. The vulnerability, tracked as CVE-2026-53412, affects the Zoom Workplace desktop application, the company’s Virtual Desktop Infrastructure client…

Continue Reading

Coca-Cola says Fairlife ransomware attack halts US dairy production

post, juli 16, 2026juli 17, 2026

The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. In a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), Coca-Cola said Fairlife detected unauthorized access to some of its…

Continue Reading
  • Previous
  • 1
  • …
  • 8
  • 9
  • 10
  • …
  • 47
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes