The Hacker News
Software supply chain security has long focused on what ends up in an application: packages, dependencies, and the paths those components take into production. As AI coding tools become part of everyd...
7 Jul 20262 min read
Read article →Dark Reading
A newly identified flaw nicknamed GitLost may let an attacker access information from private GitHub repositories by abusing an organization’s public issue workflow. According to the report, the attac...
7 Jul 20261 min read
Read article →The Register - Security
A new survey from DigiCert suggests that many organizations are moving ahead with enterprise AI deployments faster than they are putting controls around them.According to the digital identity company,...
7 Jul 20262 min read
Read article →BleepingComputer
Cisco Talos says a China-linked threat group identified as UAT-7810 is continuing to grow its Operational Relay Box (ORB) infrastructure by compromising internet-facing networking gear, with unpatched...
7 Jul 20262 min read
Read article →The Hacker News
Security researchers say a suspected China-aligned threat cluster has been abusing flaws in Roundcube webmail to target physics and engineering departments at universities in the United States and Can...
7 Jul 20262 min read
Read article →BleepingComputer
Security researchers have identified a hidden authentication mechanism in several Tenda router firmware builds that could let a remote attacker reach the device’s web management interface with adminis...
7 Jul 20262 min read
Read article →The Register - Security
Security researchers say attackers are abusing Microsoft Teams to impersonate helpdesk personnel and convince employees to give them remote access, leading to malware installation on victim machines.A...
7 Jul 20262 min read
Read article →SecurityWeek
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly using Anthropic’s Mythos AI model to review government software for security weaknesses, according to a Reuters report ci...
7 Jul 20262 min read
Read article →SecurityWeek
Attackers are actively exploiting a critical Adobe ColdFusion vulnerability that was patched in late June, according to threat researchers and Canadian government warnings. The issue, tracked as CVE-2...
7 Jul 20262 min read
Read article →The Register - Security
Spanish police have arrested a man in Palencia whom investigators believe maintained ties to several pro-Russia hacktivist groups connected to attacks on critical infrastructure. The detention, which...
7 Jul 20262 min read
Read article →SecurityWeek
Researchers at Check Point say an Iran-linked advanced persistent threat group has been using a modular command-and-control framework in operations aimed at organizations in Israel. The activity has b...
7 Jul 20262 min read
Read article →The Hacker News
The CERT Coordination Center (CERT/CC) has issued an alert about a hidden authentication mechanism found in several Tenda router firmware releases. The flaw, tracked as CVE-2026-11405, can allow an at...
7 Jul 20261 min read
Read article →