Cyber Security News
Be Cyber Aware. Subscribe. Our chat: t.me/cybersecuritynewschat Our vacancies channel: @CyberSecurityJobs LinkedIn: https://www.linkedin.com/company/securitynews/ 📩 Collab: cybersecnewsinfo@gmail.com Paid Ads: @cybersecadmin
显示更多📈 Telegram 频道 Cyber Security News 的分析概览
频道 Cyber Security News (@cyber_security_channel) 英语 语言赛道中的 是活跃参与者。目前社区聚集了 56 199 名订阅者,在 技术与应用 类别中位列第 2 322,并在 美国 地区排名第 503 位。
📊 受众指标与增长动态
自 невідомо 创建以来,项目保持高速增长,吸引了 56 199 名订阅者。
根据 29 七月, 2026 的最新数据,频道保持稳定运转。过去 30 天订阅人数变化为 621,过去 24 小时变化为 17,整体触达仍然可观。
- 认证状态: 未认证
- 互动率 (ER): 平均受众互动率为 8.59%。内容发布后 24 小时内通常能获得 2.67% 的反应,占订阅者总量。
- 帖子覆盖: 每篇帖子平均可获得 4 825 次浏览,首日通常累积 1 499 次浏览。
- 互动与反馈: 受众积极参与,单帖平均反应数为 5。
- 主题关注点: 内容集中在 cybersecurity, attack, threat, cyber, ----- 等核心主题上。
📝 描述与内容策略
作者将该频道定位为表达主观观点的平台:
“Be Cyber Aware. Subscribe.
Our chat: t.me/cybersecuritynewschat
Our vacancies channel: @CyberSecurityJobs
LinkedIn: https://www.linkedin.com/company/securitynews/
📩 Collab: cybersecnewsinfo@gmail.com
Paid Ads: @cybersecadmin”
凭借高频更新(最新数据采集于 30 七月, 2026),频道始终保持新鲜度与高覆盖。分析显示受众积极互动,使其成为 技术与应用 类别中的关键影响点。
数据加载中...
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 29 七月 | +21 | |||
| 28 七月 | +37 | |||
| 27 七月 | +39 | |||
| 26 七月 | +30 | |||
| 25 七月 | +35 | |||
| 24 七月 | +48 | |||
| 23 七月 | +30 | |||
| 22 七月 | +24 | |||
| 21 七月 | +15 | |||
| 20 七月 | +6 | |||
| 19 七月 | +10 | |||
| 18 七月 | +38 | |||
| 17 七月 | +19 | |||
| 16 七月 | +23 | |||
| 15 七月 | +39 | |||
| 14 七月 | +19 | |||
| 13 七月 | +17 | |||
| 12 七月 | +27 | |||
| 11 七月 | +19 | |||
| 10 七月 | +27 | |||
| 09 七月 | +23 | |||
| 08 七月 | +25 | |||
| 07 七月 | +30 | |||
| 06 七月 | +28 | |||
| 05 七月 | +10 | |||
| 04 七月 | +15 | |||
| 03 七月 | +17 | |||
| 02 七月 | +32 | |||
| 01 七月 | +5 |
| 2 | AgentBaiting: 800 Fake AI skills and MCP Servers Seed SmartLoader Malware
Island researchers uncovered ~7,600 malicious repos from ~6,600 fake profiles, 800+ posing as AI skills or MCP servers.
ZIP archives disguised as installers deliver SmartLoader, which injects StealC — pulling browser sessions, tokens, API creds, and screenshots.
Around 200 campaign repos accounted for over 14 million downloads before takedown.
@Cyber_Security_Channel | 2 672 |
| 3 | ClickLock macOS Malware Hostage-takes Users Until They Type Their Password
Group-IB documented ClickLock, a macOS stealer delivered via a ClickFix «Cloudflare human verification» lure that runs a malicious Terminal command.
It shows a fake password dialog with the victims real username; if refused, it kills Finder and Terminal every 210 ms for up to 83 hours until the password is entered.
After that it grabs credentials, browser data, crypto wallet extensions, FileZilla configs and shell history, then self-deletes — ~100 infections across 33 countries since May.
@Cyber_Security_Channel | 2 907 |
| 4 | 1Password Partners with Anthropic to Give Claude Access to Your Credentials
1Password and Anthropic unveiled a «zero-exposure» framework that lets Claude AI agents retrieve credentials from a 1Password vault without the assistant ever seeing the raw values.
Authentication happens through a scoped broker; the model receives an authenticated session, not the secret itself.
Expect similar patterns from other agent-first stacks as autonomous workflows meet enterprise credential policies.
@Cyber_Security_Channel | 3 621 |
| 5 | 🔍 What if the Phishing Page that Steals Access Never Appears in the Security Scan you Trust?
Ghost Phishing can keep real lure hidden until the victim’s browser decrypts and renders it.
Static analysis may return a clean result while the user is already interacting with a fully active phishing page.
This risk can be reduced with browser-level visibility.
ANY.RUN helps security teams see what actually happens in the browser, including:
👻 Decrypted phishing content as it appears
🧩 Runtime DOM changes and hidden page elements
🌐 Requests and redirects behind the attack
⚡ Clear evidence for faster triage and response
Don’t let hidden phishing activity go unseen.
Get full visibility with ANY.RUN → click here to enhance security now.
-----
#ad #paidpromotion #sponsored
@Cyber_Security_Channel | 4 019 |
| 6 | ClickLock macOS Malware Hostage-takes Users Until They Type Their Password
Group-IB documented ClickLock, a macOS stealer delivered via a ClickFix «Cloudflare human verification» lure that runs a malicious Terminal command.
It shows a fake password dialog with the victims real username; if refused, it kills Finder and Terminal every 210 ms for up to 83 hours until the password is entered.
After that it grabs credentials, browser data, crypto wallet extensions, FileZilla configs and shell history, then self-deletes — ~100 infections across 33 countries since May.
@Cyber_Security_Channel | 1 |
| 7 | Hugging Face breach: rogue AI agent burned through sandboxes to steal internal creds
Hugging Face confirmed a malicious dataset exploited a vulnerability to execute code on its servers, escalating access to internal datasets and service credentials.
The company blamed «an external AI agent, which executed many thousands of individual actions across a swarm of short-lived sandboxes» — detected by its own anomaly system.
Credentials have been rotated and the flaw patched; users are urged to rotate their access tokens.
@Cyber_Security_Channel | 3 910 |
| 8 | ⚡️Hugging Face Hacked in Autonomous AI Attack
Hugging Face says it responded to the attack largely with its own AI, addressed the dataset code-execution paths exploited for initial access, evicted the attackers from its infrastructure, rebuilt the affected nodes, and revoked and rotated all affected credentials.
Cyber_Security_Channel | 3 496 |
| 9 | 1Password Partners with Anthropic to Give Claude Access to Your Credentials
1Password and Anthropic unveiled a «zero-exposure» framework that lets Claude AI agents retrieve credentials from a 1Password vault without the assistant ever seeing the raw values.
Authentication happens through a scoped broker; the model receives an authenticated session, not the secret itself.
Expect similar patterns from other agent-first stacks as autonomous workflows meet enterprise credential policies.
@Cyber_Security_Channel | 1 |
| 10 | FortiBleed campaign traced to INC and Lynx ransomware operations
“The Nextcloud issue appears to have been used as part of the attackers’ broader operational workflow, likely for expansion or infrastructure access after initial compromise,” Ensar Seker, CISO at SOCRadar, told Cybersecurity Dive.
Cyber_Security_Channel | 4 753 |
| 11 | Join the Webinar: Vulnerability Detection with AI, explore how AI is transforming the industry, understand the latest application security challenges, earn CPE credits, and gain practical insights from cybersecurity experts.
⚡ Key Insights:
✔ New threats from vibe coding
✔ Risks of AI to automate coding
✔ OWASP Top 10 for LLMs brief overview of
✔ Frequent application security pitfalls
✔ Implementation of risk-based application security program
✔ Automation of mobile & web security scanning with CI/CD pipeline
✔ Mobile application security scanning with Neuron Mobile
✔ Mastering web application & API security scanning with Neuron
✔ AI for automation of application security testing
📅 Date & Time: July 23, 2026
• Session 1 – Geneva 10am | Dubai 12pm | Singapore 4pm
• Session 2 – Geneva 5pm | New York 11am | California 8am
🎤 Host: Dr. Ilia Kolochenko, Founder, Chief Architect & CEO at ImmuniWeb.
✅ Register: click here for sign up access.
-----
#ad #paidpromotion #sponsored
@Cyber_Security_Channel | 5 005 |
| 12 | Pegasus Infected Phone of EU Lawmaker Investigating Spyware Abuse
Citizen Lab confirmed with high confidence that Stelios Kouloglou — a Greek MEP and substitute member of the European Parliament's PEGA Committee, which was set up to probe NSO Group's Pegasus abuses — was infected with the spyware twice, in October 2022 and March 2023.
The first infection came while he was hospitalized; the second during the committee's final drafting phase.
Attribution remains open, NSO did not respond, and Kouloglou announced plans to sue.
@Cyber_Security_Channel | 5 069 |
| 13 | FortiBleed Credential-Harvesting Op Tied to INC and Lynx Ransomware Groups
Researchers linked FortiBleed, a Golang-based tool that intercepts authentication traffic on Fortinet devices, to INC and Lynx ransomware operations — an operator was found logged into negotiation panels for both.
Traffic-sniffing was observed on ~19,000 Fortinet devices; attackers gained admin access on 409 targets, fully compromised 354, and deployed ransomware on 12 — encrypting hundreds of endpoints.
Some intrusions also leveraged a suspected zero-day in Nextcloud; no CVE has been assigned yet.
@Cyber_Security_Channel | 5 456 |
| 14 | Medtronic Data Breach Hits 3.8 Million People — ShinyHunters Suspected of Ransom Payment
Medtronic confirmed that ShinyHunters accessed its corporate IT systems in April 2026 and stole personal and medical data on 3,834,294 people — including names, dates of birth, Social Security numbers and health details.
The group listed Medtronic on its leak site on April 17 claiming 9 million records, then removed it, suggesting a possible ransom payment.
Affected individuals are being offered 24 months of credit and dark-web monitoring plus identity theft restoration.
@Cyber_Security_Channel | 5 281 |
| 15 | 🔍 What if the Most Dangerous part of a Phishing Page Never Appears in Your URL Scanner?
That's exactly how EvilTokens works.
Its AES-GCM encrypted "ghost" code stays invisible until the browser decrypts and renders it, leaving static URL analysis with only part of the story.
Meanwhile, attackers abuse Microsoft's legitimate Device Code flow to take over Microsoft 365 accounts without stealing passwords.
ANY.RUN's latest research shows how browser-level inspection uncovers:
👻 Hidden decrypted HTML and DOM changes
🌐 The requests powering the phishing flow
🎯 IOCs and detection opportunities for threat hunting
⚡ Evidence that speeds up SOC triage and response
If your investigation stops at the initial HTTP response, you may be missing the attack.
Read the full analysis: tap here to access the article.
-----
#ad #paidpromotion #sponsored
@Cyber_Security_Channel | 5 632 |
| 16 | «Bad Epoll» 0-Day in Linux Kernel Grants Root on Linux Servers and Android Devices
Researchers disclosed CVE-2026-46242, a use-after-free race condition in the Linux kernel's epoll subsystem that lets a local unprivileged user escalate to root.
The exploit reportedly achieves ~99% reliability and is reachable from the Chrome renderer sandbox, opening a browser-to-kernel escalation chain.
Epoll cannot be disabled, so patching is the only mitigation — a fix landed roughly two months after initial disclosure.
@Cyber_Security_Channel | 5 775 |
| 17 | US Offers $10M for Info on Russia-Linked Hackers Behind Signal and WhatsApp Attacks
The State Department announced a $10 million reward for information on UNC5792 and UNC4221, two Russia-linked groups accused of hijacking the Signal and WhatsApp accounts of government officials.
The operations abused legitimate «linked device» features via phishing pages.
Officials working on Ukraine-related policy were among the primary targets.
@Cyber_Security_Channel | 5 899 |
| 18 | ‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access
At a high level, the vulnerabilities exist because the kernel does not separate the page cache used for executables and files from packet data processed via zero-copy paths, and in-place transformations such as encryption/decryption that write back to the same buffer.
Cyber_Security_Channel | 6 154 |
| 19 | From Last Week: Klue Breach Cascades Into Multiple Cybersecurity Firms
Attackers breached market-intelligence platform Klue and pivoted into the Salesforce environments of several of its cybersecurity-firm customers.
Disclosed downstream victims include HackerOne, Huntress, Recorded Future, Snyk, and Tanium.
The incident underscores how SaaS supply-chain access can turn one vendor compromise into a sector-wide breach.
@Cyber_Security_Channel | 6 129 |
| 20 | Microsoft Ties Mastra AI npm Supply Chain Attack to North Korea
Microsoft attributed a supply chain attack on the Mastra AI ecosystem to Sapphire Sleet, a North Korean group also known as BlueNoroff.
Attackers compromised more than 140 npm packages to plant malicious dependencies in downstream developer projects.
The campaign extends a pattern of DPRK targeting of Web3 and AI developer pipelines.
@Cyber_Security_Channel | 5 946 |
