uz
Feedback
Cyber Security News

Cyber Security News

Kanalga Telegram’da oā€˜tish

Be Cyber Aware. Subscribe. Our chat: t.me/cybersecuritynewschat Our vacancies channel: @CyberSecurityJobs LinkedIn: https://www.linkedin.com/company/securitynews/ šŸ“© Collab: cybersecnewsinfo@gmail.com Paid Ads: @cybersecadmin

Ko'proq ko'rsatish

šŸ“ˆ Telegram kanali Cyber Security News analitikasi

Cyber Security News (@cyber_security_channel) Ingliz til segmentidagi kanali faol ishtirokchi. Hozirda hamjamiyat 56 204 obunachidan iborat bo'lib, Texnologiyalar & Aralashmalar toifasida 2 322-o'rinni va AQSH mintaqasida 503-o'rinni egallagan.

šŸ“Š Auditoriya koā€˜rsatkichlari va dinamika

невіГомо sanasidan buyon loyiha tez oā€˜sib, 56 204 obunachiga ega boā€˜ldi.

29 Iyul, 2026 dagi oxirgi ma’lumotlarga koā€˜ra kanal barqaror faollikka ega. Oxirgi 30 kunda obunachilar soni 621 ga, soā€˜nggi 24 soatda esa 17 ga oā€˜zgardi va umumiy qamrov yuqori darajada qolmoqda.

  • Tasdiqlash holati: Tasdiqlanmagan
  • Jalb etish (ER): Auditoriya oā€˜rtacha 8.59% darajada jalb etiladi. Nashrdan keyingi dastlabki 24 soatda kontent odatda umumiy obunachilar sonining 2.67% ini tashkil etuvchi reaksiyalarni toā€˜playdi.
  • Post qamrovi: Har bir post oā€˜rtacha 4 825 marta koā€˜riladi; birinchi sutkada odatda 1 499 ta koā€˜rish yigā€˜iladi.
  • Reaksiyalar va oā€˜zaro ta’sir: Auditoriya faol: har bir postga oā€˜rtacha 5 ta reaksiya keladi.
  • Tematik yoā€˜nalishlar: Kontent cybersecurity, attack, threat, cyber, ----- kabi asosiy mavzularga jamlangan.

šŸ“ Tavsif va kontent siyosati

Muallif resursni shaxsiy fikrni ifoda etish maydoni sifatida ta’riflaydi:
ā€œBe Cyber Aware. Subscribe. Our chat: t.me/cybersecuritynewschat Our vacancies channel: @CyberSecurityJobs LinkedIn: https://www.linkedin.com/company/securitynews/ šŸ“© Collab: cybersecnewsinfo@gmail.com Paid Ads: @cybersecadminā€

Yuqori yangilanish chastotasi (oxirgi ma’lumot 30 Iyul, 2026 da olingan) sababli kanal doimo dolzarb va katta qamrovli boā€˜lib qoladi. Analitika auditoriya kontent bilan faol hamkorlik qilishini, uni Texnologiyalar & Aralashmalar toifasidagi muhim ta’sir nuqtasiga aylantirishini koā€˜rsatadi.

56 204
Obunachilar
+1724 soatlar
+2237 kunlar
+62130 kunlar
Postlar arxiv
Microsoft Patch Tuesday: 622 CVEs, Ā«the mother of allĀ» Releases Microsoft disclosed 622 vulnerabilities in July — triple Junes previous record of 206 — including 63 critical and two exploited zero-days (CVE-2026-56155 in AD FS, CVE-2026-56164 in SharePoint Server). Breakdown: 416 in Windows, 82 in Office, 46 in Edge; Trend Micros Dustin Childs called it Ā«the mother of all releasesĀ». Analysts credit AI-powered bug discovery — 2026 could top 2,000-3,000 CVEs, blowing past the 1,245 full-year record from 2020. @Cyber_Security_Channel

šŸ¤ Cyber Security News is looking for ADVERTISERS Our community is continuously growing and we are searching for exciting com
šŸ¤ Cyber Security News is looking for ADVERTISERS Our community is continuously growing and we are searching for exciting companies & products to share with our audience. Requirements to Qualify • Relevant to channels niche / industry • Long-term approach and collaboration mindset • $2,000+ monthly ad spend budget to invest in campaigns What We Offer • Exposure to 80,000+ community members • Personal success manager to scale your campaigns • Brand awareness, leads, sign-ups, customers, followers, etc. šŸ“© Contact for Partnership If you are serious about promoting your business, send us an introduction Email → cybersecnewsinfo@gmail.com Important Note Spots to become a sponsor are limited. Reach out before they fill up. (we only have 6 left) - - - - - @Cyber_Security_Channel

AgentBaiting: 800 Fake AI skills and MCP Servers Seed SmartLoader Malware Island researchers uncovered ~7,600 malicious repos from ~6,600 fake profiles, 800+ posing as AI skills or MCP servers. ZIP archives disguised as installers deliver SmartLoader, which injects StealC — pulling browser sessions, tokens, API creds, and screenshots. Around 200 campaign repos accounted for over 14 million downloads before takedown. @Cyber_Security_Channel

ClickLock macOS Malware Hostage-takes Users Until They Type Their Password Group-IB documented ClickLock, a macOS stealer delivered via a ClickFix Ā«Cloudflare human verificationĀ» lure that runs a malicious Terminal command. It shows a fake password dialog with the victims real username; if refused, it kills Finder and Terminal every 210 ms for up to 83 hours until the password is entered. After that it grabs credentials, browser data, crypto wallet extensions, FileZilla configs and shell history, then self-deletes — ~100 infections across 33 countries since May. @Cyber_Security_Channel

1Password Partners with Anthropic to Give Claude Access to Your Credentials 1Password and Anthropic unveiled a «zero-exposure» framework that lets Claude AI agents retrieve credentials from a 1Password vault without the assistant ever seeing the raw values. Authentication happens through a scoped broker; the model receives an authenticated session, not the secret itself. Expect similar patterns from other agent-first stacks as autonomous workflows meet enterprise credential policies. @Cyber_Security_Channel

šŸ” What if the Phishing Page that Steals Access Never Appears in the Security Scan you Trust? Ghost Phishing can keep real lu
šŸ” What if the Phishing Page that Steals Access Never Appears in the Security Scan you Trust? Ghost Phishing can keep real lure hidden until the victim’s browser decrypts and renders it. Static analysis may return a clean result while the user is already interacting with a fully active phishing page. This risk can be reduced with browser-level visibility. ANY.RUN helps security teams see what actually happens in the browser, including: šŸ‘» Decrypted phishing content as it appears 🧩 Runtime DOM changes and hidden page elements 🌐 Requests and redirects behind the attack ⚔ Clear evidence for faster triage and response Don’t let hidden phishing activity go unseen. Get full visibility with ANY.RUN → click here to enhance security now. ----- #ad #paidpromotion #sponsored @Cyber_Security_Channel

ClickLock macOS Malware Hostage-takes Users Until They Type Their Password Group-IB documented ClickLock, a macOS stealer delivered via a ClickFix Ā«Cloudflare human verificationĀ» lure that runs a malicious Terminal command. It shows a fake password dialog with the victims real username; if refused, it kills Finder and Terminal every 210 ms for up to 83 hours until the password is entered. After that it grabs credentials, browser data, crypto wallet extensions, FileZilla configs and shell history, then self-deletes — ~100 infections across 33 countries since May. @Cyber_Security_Channel

Hugging Face breach: rogue AI agent burned through sandboxes to steal internal creds Hugging Face confirmed a malicious dataset exploited a vulnerability to execute code on its servers, escalating access to internal datasets and service credentials. The company blamed Ā«an external AI agent, which executed many thousands of individual actions across a swarm of short-lived sandboxesĀ» — detected by its own anomaly system. Credentials have been rotated and the flaw patched; users are urged to rotate their access tokens. @Cyber_Security_Channel

āš”ļøHugging Face Hacked in Autonomous AI Attack Hugging Face says it responded to the attack largely with its own AI, addressed the dataset code-execution paths exploited for initial access, evicted the attackers from its infrastructure, rebuilt the affected nodes, and revoked and rotated all affected credentials. Cyber_Security_Channel

1Password Partners with Anthropic to Give Claude Access to Your Credentials 1Password and Anthropic unveiled a «zero-exposure» framework that lets Claude AI agents retrieve credentials from a 1Password vault without the assistant ever seeing the raw values. Authentication happens through a scoped broker; the model receives an authenticated session, not the secret itself. Expect similar patterns from other agent-first stacks as autonomous workflows meet enterprise credential policies. @Cyber_Security_Channel

FortiBleed campaign traced to INC and Lynx ransomware operations ā€œThe Nextcloud issue appears to have been used as part of the attackers’ broader operational workflow, likely for expansion or infrastructure access after initial compromise,ā€ Ensar Seker, CISO at SOCRadar, told Cybersecurity Dive. Cyber_Security_Channel

Join the Webinar: Vulnerability Detection with AI, explore how AI is transforming the industry, understand the latest applica
Join the Webinar: Vulnerability Detection with AI, explore how AI is transforming the industry, understand the latest application security challenges, earn CPE credits, and gain practical insights from cybersecurity experts. ⚔ Key Insights: āœ” New threats from vibe coding āœ” Risks of AI to automate coding āœ” OWASP Top 10 for LLMs brief overview of āœ” Frequent application security pitfalls āœ” Implementation of risk-based application security program āœ” Automation of mobile & web security scanning with CI/CD pipeline āœ” Mobile application security scanning with Neuron Mobile āœ” Mastering web application & API security scanning with Neuron āœ” AI for automation of application security testing šŸ“… Date & Time: July 23, 2026 • Session 1 – Geneva 10am | Dubai 12pm | Singapore 4pm • Session 2 – Geneva 5pm | New York 11am | California 8am šŸŽ¤ Host: Dr. Ilia Kolochenko, Founder, Chief Architect & CEO at ImmuniWeb. āœ… Register: click here for sign up access. ----- #ad #paidpromotion #sponsored @Cyber_Security_Channel

Pegasus Infected Phone of EU Lawmaker Investigating Spyware Abuse Citizen Lab confirmed with high confidence that Stelios Kouloglou — a Greek MEP and substitute member of the European Parliament's PEGA Committee, which was set up to probe NSO Group's Pegasus abuses — was infected with the spyware twice, in October 2022 and March 2023. The first infection came while he was hospitalized; the second during the committee's final drafting phase. Attribution remains open, NSO did not respond, and Kouloglou announced plans to sue. @Cyber_Security_Channel

FortiBleed Credential-Harvesting Op Tied to INC and Lynx Ransomware Groups Researchers linked FortiBleed, a Golang-based tool that intercepts authentication traffic on Fortinet devices, to INC and Lynx ransomware operations — an operator was found logged into negotiation panels for both. Traffic-sniffing was observed on ~19,000 Fortinet devices; attackers gained admin access on 409 targets, fully compromised 354, and deployed ransomware on 12 — encrypting hundreds of endpoints. Some intrusions also leveraged a suspected zero-day in Nextcloud; no CVE has been assigned yet. @Cyber_Security_Channel

Medtronic Data Breach Hits 3.8 Million People — ShinyHunters Suspected of Ransom Payment Medtronic confirmed that ShinyHunters accessed its corporate IT systems in April 2026 and stole personal and medical data on 3,834,294 people — including names, dates of birth, Social Security numbers and health details. The group listed Medtronic on its leak site on April 17 claiming 9 million records, then removed it, suggesting a possible ransom payment. Affected individuals are being offered 24 months of credit and dark-web monitoring plus identity theft restoration. @Cyber_Security_Channel

šŸ” What if the Most Dangerous part of a Phishing Page Never Appears in Your URL Scanner? That's exactly how EvilTokens works.
šŸ” What if the Most Dangerous part of a Phishing Page Never Appears in Your URL Scanner? That's exactly how EvilTokens works. Its AES-GCM encrypted "ghost" code stays invisible until the browser decrypts and renders it, leaving static URL analysis with only part of the story. Meanwhile, attackers abuse Microsoft's legitimate Device Code flow to take over Microsoft 365 accounts without stealing passwords. ANY.RUN's latest research shows how browser-level inspection uncovers: šŸ‘» Hidden decrypted HTML and DOM changes 🌐 The requests powering the phishing flow šŸŽÆ IOCs and detection opportunities for threat hunting ⚔ Evidence that speeds up SOC triage and response If your investigation stops at the initial HTTP response, you may be missing the attack. Read the full analysis: tap here to access the article. ----- #ad #paidpromotion #sponsored @Cyber_Security_Channel

Ā«Bad EpollĀ» 0-Day in Linux Kernel Grants Root on Linux Servers and Android Devices Researchers disclosed CVE-2026-46242, a use-after-free race condition in the Linux kernel's epoll subsystem that lets a local unprivileged user escalate to root. The exploit reportedly achieves ~99% reliability and is reachable from the Chrome renderer sandbox, opening a browser-to-kernel escalation chain. Epoll cannot be disabled, so patching is the only mitigation — a fix landed roughly two months after initial disclosure. @Cyber_Security_Channel

US Offers $10M for Info on Russia-Linked Hackers Behind Signal and WhatsApp Attacks The State Department announced a $10 million reward for information on UNC5792 and UNC4221, two Russia-linked groups accused of hijacking the Signal and WhatsApp accounts of government officials. The operations abused legitimate «linked device» features via phishing pages. Officials working on Ukraine-related policy were among the primary targets. @Cyber_Security_Channel

ā€˜DirtyClone’ Linux Kernel Vulnerability Leads to Root Access At a high level, the vulnerabilities exist because the kernel does not separate the page cache used for executables and files from packet data processed via zero-copy paths, and in-place transformations such as encryption/decryption that write back to the same buffer. Cyber_Security_Channel

From Last Week: Klue Breach Cascades Into Multiple Cybersecurity Firms Attackers breached market-intelligence platform Klue and pivoted into the Salesforce environments of several of its cybersecurity-firm customers. Disclosed downstream victims include HackerOne, Huntress, Recorded Future, Snyk, and Tanium. The incident underscores how SaaS supply-chain access can turn one vendor compromise into a sector-wide breach. @Cyber_Security_Channel