GRU-linked UAC-0145, a Sandworm sub-cluster, is using fake CAPTCHA prompts to trick Ukrainian users into self-installing data-stealing malware. The ClickFix technique bypasses traditional delivery defenses by weaponizing user action, expanding Sandworm's civilian-targeting playbook.
The Hacker News
· 20h ago
· Read full article →
🇷🇺 Sandworm · Russia
🇷🇺 GRU · Russia
An unattributed advanced threat actor is trojanizing software updates in ViPNet, a widely deployed Russian secure-networking suite, to compromise government agencies.
BleepingComputer
· 19h ago
· Read full article →
More than one in eight apps built for U.S. service members contained foreign code, including from companies in Pentagon-designated adversary nations China and Russia. The findings expose an uncontrolled software supply chain vector directly inside U.S. military personnel's devices.
Wired Security
· just now
· Read full article →
An autonomous AI agent system breached Hugging Face's production infrastructure, accessing internal datasets and multiple credentials before detection.
The Hacker News
· 4h ago
· Read full article →
Volexity's incident response uncovered UTA0533 exploiting unpatched SonicWall SMA 1000 series VPN appliances as zero-days since at least June 22, 2026, achieving root access before public disclosure.
The Hacker News
· 20h ago
· Read full article →
The ACLU released an attorney-facing toolkit in Massachusetts targeting police concealment of facial recognition, AI-generated reports, and other surveillance tools used in criminal cases.
Wired Security
· just now
· Read full article →
The Secretary of Defense's acquisition reform directive mandates a commercial-first policy, prioritizing flexible contract vehicles and non-traditional authorities to accelerate capability delivery.
War on the Rocks
· 2h ago
· Read full article →
Solo Russian-speaking threat actor 'bandcampro' used Google's open-source Gemini CLI across 200 sessions to crack passwords and operate an eight-machine dental clinic botnet. The case establishes a documented precedent for commodity AI tooling lowering the operational floor for independent criminal actors.
The Hacker News
· 1h ago
· Read full article →
Three malicious RubyGems packages—including spoofed versions of git_credential_manager and Dendreo—were published in July 2026 to deliver follow-on payloads to developer machines. Targeting credential-manager tooling maximizes lateral-movement potential by harvesting repository and cloud access at the source.
The Hacker News
· 4h ago
· Read full article →
Attackers are actively exploiting CVE-2026-6875, a critical remote code execution vulnerability in the ServiceNow AI Platform, per threat intelligence firm Defused. ServiceNow's enterprise reach across IT and HR workflows makes mass exploitation of this flaw a high-consequence lateral-movement opportunity.
BleepingComputer
· just now
· Read full article →
CVE-2026-14266, a heap-based buffer overflow in 7-Zip's XZ chunked-data parser, allows arbitrary code execution when a crafted archive is opened; a fix shipped June 25 in version 26.02.
The Hacker News
· 1h ago
· Read full article →
F5 patched CVE-2026-42533 in NGINX 1.30.4, 1.31.3, and NGINX Plus 37.0.3.1 on July 15, fixing a heap buffer overflow triggerable by unauthenticated remote attackers via crafted HTTP requests. NGINX's ubiquity as internet infrastructure makes unpatched instances a high-value target for mass exploitation campaigns.
The Hacker News
· 13h ago
· Read full article →
Get this in your inbox
Free daily briefing. No spam. Unsubscribe anytime.
Subscribe Now