TECHZONE™
Открыть в Telegram
TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news
Больше592
Подписчики
Нет данных24 часа
-27 дней
-730 день
Архив постов
592
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots
https://thehackernews.com/2026/07/thinking-fast-and-slow-in-soc-case-for.html
A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as we mapped out the broader architecture, something kept nagging at me. The design they were building
592
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
https://thehackernews.com/2026/07/attacker-uses-suspected-ai-generated.html
Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration.
"The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD_Report.html to measure the success of the
592
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history.
From that one lapse, French security firm Lexfo lifted the operator's entire toolkit and pivoted through it to two more
592
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
https://thehackernews.com/2026/07/icagenda-and-balbooa-forms-joomla-flaws.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild.
The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below -
CVE-2026-48939 - A vulnerability in the
592
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html
Version 8.14.0 of the jscrambler npm package shipped with a malicious preinstall hook that silently drops and runs a native infostealer during installation, one build each for Windows, macOS, and Linux.
Published on July 11, 2026, it needs no import and no CLI call. Installing 8.14.0 is enough to run it.
Socket flagged the release six minutes after it was
592
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
https://thehackernews.com/2026/07/hackers-weaponize-balochistan-police.html
Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026.
"At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and
592
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html
Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution.
The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to execute malicious scripts in a user's session. It has yet to be assigned a CVE identifier.
"The
592
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
https://thehackernews.com/2026/07/injective-labs-github-compromise-pushes.html
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases.
The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was
592
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
https://thehackernews.com/2026/07/six-new-u-boot-flaws-could-let.html
Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers.
Four of the bugs can crash a device. The other two could let an attacker who slips a malicious image in front of the bootloader run their own code, before the device
592
Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched
https://thehackernews.com/2026/07/laser-attack-resets-tangem-wallet.html
Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to anything the attacker picks.
No old password. No backup card. Once it is reset, whoever did it controls the wallet and can move the coins out.
This is not an emergency for most owners. The attack needs
592
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.html
Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host.
A brief description of the high-severity vulnerabilities is as follows -
GHSA-hjr6-g723-hmfm (CVSS score: 8.8) - An operating system
592
New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic
https://thehackernews.com/2026/07/new-modbeacon-rat-uses-grpc-streaming.html
The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON.
Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that propagates malware via counterfeit installers using SEO poisoning techniques, it belies their true organizational
592
Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets
https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html
Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness, an attacker can work it out and take everything it controls.
Coinspect has confirmed one coordinated sweep on May
592
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
https://thehackernews.com/2026/07/ransomware-negotiator-gets-70-months-in.html
A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple victims and working with two other cybersecurity professionals to target additional victims in 2023.
In a sentencing memorandum, federal prosecutors described Martino as a "
592
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
https://thehackernews.com/2026/07/dormant-github-accounts-help-attackers.html
Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API.
"Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub 'ghost' accounts that are often years old, or compromised OAuth tokens and personal
592
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
https://thehackernews.com/2026/07/new-gigawiper-windows-backdoor-bundles.html
Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from.
Each is a different way to break a machine: wipe the whole disk, overwrite the Windows drive, or run fake "ransomware" that scrambles files with a key it never saves
592
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
https://thehackernews.com/2026/07/npm-12-disables-install-scripts-by.html
GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA).
The Microsoft-owned subsidiary noted that the following npm install behaviors that used to run automatically before have been made opt-in -
allowScripts defaults to off, meaning
592
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
https://thehackernews.com/2026/07/threatsday-cloud-bucket-hijacking.html
Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it.
This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it all looks until the bill arrives.
The full ThreatsDay list is below.
Global
592
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
https://thehackernews.com/2026/07/ai-attacks-move-in-minutes-join-this.html
AI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the next host before your team clears the first alert.
That is the gap, and it is not your fault. The tools and runbooks most teams run on were built for attackers who work at human speed. AI-driven
592
Summer of Clearinghouses
https://thehackernews.com/2026/07/summer-of-clearinghouses.html
Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quietly months earlier, heads down, taking findings and shipping fixes, because customers kept asking us to. We only announced it now because everyone else started announcing theirs,
