ru
Feedback
TECHZONE™

TECHZONE™

Открыть в Telegram

TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news

Больше
592
Подписчики
Нет данных24 часа
-27 дней
-730 день
Архив постов
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots https://thehackernews.com/2026/07/thinking-fast-and-slow-in-soc-case-for.html A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as we mapped out the broader architecture, something kept nagging at me. The design they were building

Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory https://thehackernews.com/2026/07/attacker-uses-suspected-ai-generated.html Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. "The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating AD_Report.html to measure the success of the

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history. From that one lapse, French security firm Lexfo lifted the operator's entire toolkit and pivoted through it to two more

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days https://thehackernews.com/2026/07/icagenda-and-balbooa-forms-joomla-flaws.html The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below - CVE-2026-48939 - A vulnerability in the

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html Version 8.14.0 of the jscrambler npm package shipped with a malicious preinstall hook that silently drops and runs a native infostealer during installation, one build each for Windows, macOS, and Linux. Published on July 11, 2026, it needs no import and no CLI call. Installing 8.14.0 is enough to run it. Socket flagged the release six minutes after it was

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns https://thehackernews.com/2026/07/hackers-weaponize-balochistan-police.html Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026. "At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to execute malicious scripts in a user's session. It has yet to be assigned a CVE identifier. "The

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages https://thehackernews.com/2026/07/injective-labs-github-compromise-pushes.html Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot https://thehackernews.com/2026/07/six-new-u-boot-flaws-could-let.html Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs can crash a device. The other two could let an attacker who slips a malicious image in front of the bootloader run their own code, before the device

Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched https://thehackernews.com/2026/07/laser-attack-resets-tangem-wallet.html Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to anything the attacker picks. No old password. No backup card. Once it is reset, whoever did it controls the wallet and can move the coins out. This is not an emergency for most owners. The attack needs

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws https://thehackernews.com/2026/07/researcher-details-whatsapp-to-host.html Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vulnerabilities is as follows - GHSA-hjr6-g723-hmfm (CVSS score: 8.8) - An operating system

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic https://thehackernews.com/2026/07/new-modbeacon-rat-uses-grpc-streaming.html The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that propagates malware via counterfeit installers using SEO poisoning techniques, it belies their true organizational

Attackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets https://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness, an attacker can work it out and take everything it controls. Coinspect has confirmed one coordinated sweep on May

Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks https://thehackernews.com/2026/07/ransomware-negotiator-gets-70-months-in.html A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple victims and working with two other cybersecurity professionals to target additional victims in 2023. In a sentencing memorandum, federal prosecutors described Martino as a "

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs https://thehackernews.com/2026/07/dormant-github-accounts-help-attackers.html Datadog Security Labs is warning of "several overlapping campaigns" that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. "Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub 'ghost' accounts that are often years old, or compromised OAuth tokens and personal

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware https://thehackernews.com/2026/07/new-gigawiper-windows-backdoor-bundles.html Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from. Each is a different way to break a machine: wipe the whole disk, overwrite the Windows drive, or run fake "ransomware" that scrambles files with a key it never saves

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk https://thehackernews.com/2026/07/npm-12-disables-install-scripts-by.html GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The Microsoft-owned subsidiary noted that the following npm install behaviors that used to run automatically before have been made opt-in - allowScripts defaults to off, meaning

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories https://thehackernews.com/2026/07/threatsday-cloud-bucket-hijacking.html Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it all looks until the bill arrives. The full ThreatsDay list is below. Global

AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up https://thehackernews.com/2026/07/ai-attacks-move-in-minutes-join-this.html AI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the next host before your team clears the first alert. That is the gap, and it is not your fault. The tools and runbooks most teams run on were built for attackers who work at human speed. AI-driven

Summer of Clearinghouses https://thehackernews.com/2026/07/summer-of-clearinghouses.html Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quietly months earlier, heads down, taking findings and shipping fixes, because customers kept asking us to. We only announced it now because everyone else started announcing theirs,