date / Author
source
title
short description
attacks and breaches
7/20/2026 Sinisa Markovic
Paidwork breach exposes sensitive data of 23 million user
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets itself as a way to earn money through simple tasks like watching ads, testing apps, and completing surveys, with most jobs paying only a few cents at a time. For its users, many of whom are drawn to the platform for small, incremental earnings, the fallout from this … More →
The post Paidwork breach exposes sensitive data of 23 million user appeared first on Help Net Security.
attacks and breaches
7/20/2026 Sinisa Markovic
Italy fines WINDTRE €1.7 million over security flaws behind two data breaches
Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging to more than 365,000 customers. The regulator opened its investigation after WINDTRE, one of Italy’s major telecom operators, reported two separate data breaches in February 2025. The attackers relied on old-school social engineering instead of exploiting software vulnerabilities. Posing as support technicians, … More →
The post Italy fines WINDTRE €1.7 million over security flaws behind two data breaches appeared first on Help Net Security.
vulnerabilities and exploits
7/20/2026 Ionut Arghire
OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory.
The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek.
attacks and breaches
7/20/2026 Eduard Kovacs
New Index Tracks Material Breaches — And Refuses to Add Up the Losses
Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens.
The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek.
attacks and breaches
7/20/2026 Ionut Arghire
Ernst & Young Data Breach Affects Personal, Financial Information
Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform.
The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek.
technology and tools,vulnerabilities and exploits
7/20/2026 Mike Lennon
Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations.
The post Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool appeared first on SecurityWeek.
vulnerabilities and exploits
7/20/2026 Eduard Kovacs
WP2Shell WordPress Vulnerabilities Exploited in the Wild
Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure.
The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
technology and tools
7/20/2026 Divya
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier
Microsoft will stop delivering feature updates, bug fixes, and security patches for the OneDrive sync app on systems running Windows version 21H2 and earlier on August 15, 2026. This change was announced in the Microsoft 365 Message Center notification MC1426708 and leaves organizations with older Windows endpoints exposed to an increasingly unsupported file synchronization client, […]
The post Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
technology and tools
7/20/2026 Divya
Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues
Microsoft has released KB5121767, an out-of-band (OOB) cumulative update for Windows 11 versions 22H2 and 21H2. This update addresses a system performance issue related to the Intel Innovation Platform Framework (Intel IPF) drivers. The update was made available on July 18, 2023, specifically for devices affected by this issue, which arose after installing recent Windows […]
The post Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
attacks and breaches
7/20/2026 Mayura Kathir
U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million
U.S. federal prosecutors have unsealed a sweeping indictment charging three Russian nationals and two St. Petersburg–based companies for operating a global “bulletproof hosting” infrastructure. That enabled widespread cyberattacks against critical sectors, causing losses exceeding $62 million across at least 21 U.S. states and multiple countries. The defendants Alexander Alexandrovich Volosovik, 43, Kirill Andreevich Zatolokin, 34, […]
The post U.S. Charges Three Russian Nationals Over International Cyberattacks Costing Victims More Than $62 Million appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
vulnerabilities and exploits
7/20/2026 Divya
Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover
Kimai users who are running the official Docker image are strongly urged to update their installations after a critical vulnerability, tracked as CVE-2026-52824 and GHSA-jr9p-4h4j-6c58, was discovered. This vulnerability exposes installations to the risk of account takeover due to a publicly known application secret. The flaw affects Kimai versions 2.57.0 and earlier, and it has […]
The post Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
vulnerabilities and exploits
7/20/2026 Mayura Kathir
North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images
A sophisticated North Korean threat campaign dubbed “Contagious Interview” has resurfaced with new delivery techniques, leveraging weaponized SVG image files to deploy the OTTERCOOKIE malware while coinciding with a separate supply chain intrusion targeting the Ruby ecosystem. Security researchers tracking DPRK-linked activity note that the campaign continues to impersonate recruiters and job interview workflows, luring […]
The post North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
laws, regulations and policies
7/20/2026 Anamarija Pogorelec
The Windows 10 hangover is becoming a security problem
Windows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered vulnerabilities unpatched. “There’s a temporary bridge that we need to consider when looking at these numbers. Microsoft’s consumer Extended Security Updates program keeps eligible Windows 10 devices patched for one extra year, until October 12, … More →
The post The Windows 10 hangover is becoming a security problem appeared first on Help Net Security.
technology and tools
7/20/2026 Sinisa Markovic
A forensic tool for backdoored code completions in AI assistants
Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some of that code can be tampered with before training starts. A poisoned example teaches a model to write insecure code when it sees a certain cue, and the flaw sits quietly until the right prompt … More →
The post A forensic tool for backdoored code completions in AI assistants appeared first on Help Net Security.
mobile security,protection
7/20/2026 Anamarija Pogorelec
Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security
ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs through the App Store. Getting started The onboarding process begins with a request for notification permissions, followed by instructions for enabling the Safari extension. Once enabled, the extension checks websites before they load to help protect browsing … More →
The post Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security appeared first on Help Net Security.
technology and tools
7/20/2026 Anamarija Pogorelec
Nearly half of open-source AI projects never reach production
Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as model capability improves. Open source AI in 2026, in four numbers. (Source: Mozilla) “Without investment in the infrastructure, tooling, and governance around open models, we risk locking in a system where only restrictive, closed AI … More →
The post Nearly half of open-source AI projects never reach production appeared first on Help Net Security.
vulnerabilities and exploits
7/18/2026 Help Net Security
Two new high severity WordPress vulnerabilities, patch immediately!
The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137 – A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber Which versions of WordPress are vulnerable? WordPress 6.9 is affected by … More →
The post Two new high severity WordPress vulnerabilities, patch immediately! appeared first on Help Net Security.
mobile security,technology and tools
7/17/2026 Graham Cluley
Google’s Gemini lets strangers send messages from your locked Android phone
Gemini, Google's AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone.
Read more in my article on the Hot for Security blog.
attacks and breaches
7/17/2026 SecurityWeek News
In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
Noteworthy stories that might have slipped under the radar: OpenClaw AI agents exploited via WhatsApp, ransomware hits naval defense firm TKMS, Lidl discloses data breach.
The post In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint appeared first on SecurityWeek.
vulnerabilities and exploits
7/17/2026 Sinisa Markovic
Spirals ransomware locks down victim systems in under 24 hours
A previously unknown ransomware strain called Spirals was used last month in an attack against an IT services company in South Asia, where attackers went from initial access to data theft and encrypting the network in less than 24 hours, according to Symantec’s Threat Hunter Team. Spirals encrypts files quickly after gaining a foothold Spirals is written in Rust and encrypts files using a separate AES-128 key per file, each wrapped with an attacker-controlled ECDH … More →
The post Spirals ransomware locks down victim systems in under 24 hours appeared first on Help Net Security.
laws, regulations and policies
7/17/2026 SecurityWeek News
Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday
Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI.
The post Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday appeared first on SecurityWeek.
attacks and breaches
7/17/2026 Ionut Arghire
Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei
The company disconnected its systems on July 13 and is starting to gradually restore operations.
The post Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei appeared first on SecurityWeek.
attacks and breaches
7/17/2026 Sinisa Markovic
Scammers weaponize FaceTime to drain bank accounts
Apple is warning iPhone and iPad users that scammers are using FaceTime calls to trick them into handing over money and account details. According to Apple, scammers pose as trusted organizations and use social engineering to convince people to hand over account credentials, security codes, and financial information. Apple says a caller can fake its number entirely, a trick known as spoofing, so the incoming call looks like it comes from Apple or a bank … More →
The post Scammers weaponize FaceTime to drain bank accounts appeared first on Help Net Security.
vulnerabilities and exploits,attacks and breaches
7/17/2026 Sinisa Markovic
Ransomware attack halts Coca-Cola’s Fairlife US milk production
A ransomware attack has stopped milk production at Fairlife, the Coca-Cola dairy brand known for its high-protein milk, protein shakes, and nutrition drinks. Coca-Cola disclosed the incident on July 16, 2026, in a Form 8-K filed with the U.S. Securities and Exchange Commission (SEC). “Product quality and safety have not been impacted. However, as a result of the incident, production operations at fairlife in the United States are temporarily suspended. fairlife’s Canada production operations are … More →
The post Ransomware attack halts Coca-Cola’s Fairlife US milk production appeared first on Help Net Security.
vulnerabilities and exploits
7/17/2026 Ionut Arghire
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server.
The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek.
vulnerabilities and exploits
7/17/2026 Ionut Arghire
Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack
The company says the incident has not affected product quality and safety, nor Fairlife’s Canada production.
The post Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack appeared first on SecurityWeek.
vulnerabilities and exploits,technology and tools
7/17/2026 Anamarija Pogorelec
Prompt injection is becoming the XSS of the web agent era
Autonomous web agents read whatever a page displays, and much of that content comes from strangers. Product reviews, seller listings, and advertisements sit beside trusted site menus on a single page. An agent that reads all of that text as instructions can be steered by any of it. A group at UC Berkeley describe Cross-Site Prompting, or XSP, as the agent-era version of Cross-Site Scripting. Their system, Prismata, sits between a web agent and the … More →
The post Prompt injection is becoming the XSS of the web agent era appeared first on Help Net Security.
attacks and breaches
7/17/2026 Sinisa Markovic
The script, not the voice, is what makes AI voice phishing work
The call comes in at 4:40 on a Friday. The voice belongs to a senior manager, or sounds close enough, and she needs a password reset before a flight. She is polite, she is in a hurry, and she has the last four of the badge number. Researchers at Harvard Kennedy School, Meta and elsewhere ran a version of that moment past 4,100 US adults, using six commercial voice systems and human callers as a … More →
The post The script, not the voice, is what makes AI voice phishing work appeared first on Help Net Security.
technology and tools,vulnerabilities and exploits
7/16/2026 Kevin Townsend
AI Data Centers Are Being Built Faster Than They Can Be Secured
AI infrastructure introduces new security risks that traditional data center designs were never built to handle.
The post AI Data Centers Are Being Built Faster Than They Can Be Secured appeared first on SecurityWeek.
vulnerabilities and exploits
7/16/2026 Eduard Kovacs
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency.
The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek.
laws, regulations and policies
7/16/2026 Sinisa Markovic
Scattered Spider members jailed over Transport for London hack that cost £29 million
Two members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters and cost the transport authority an estimated £29 million. Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall, pleaded guilty last month, on the day their trial was set to start. The National Crime Agency (NCA) … More →
The post Scattered Spider members jailed over Transport for London hack that cost £29 million appeared first on Help Net Security.
vulnerabilities and exploits,technology and tools
7/16/2026 Sinisa Markovic
Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes
A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI) In more than 200 sessions between March 19 and April 21, 2026, the threat actor worked with Gemini to deploy and operate infrastructure that controlled eight computers inside a dental clinic and gain access to the clinic’s OpenDental database. Posing as an … More →
The post Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes appeared first on Help Net Security.
technology and tools,vulnerabilities and exploits
7/16/2026 Waqas
OkoBot Malware Uses ClickFix, Hidden Browser Extensions to Steal Crypto Data
Kaspersky says OkoBot targets crypto users through fake software, stealing wallet files, seed phrases and passwords while recording activity inside wallet apps.
attacks and breaches,technology and tools
7/16/2026 Graham Cluley
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed.
Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them at their own game...
All this and more in this episode of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White.
vulnerabilities and exploits
7/16/2026 Ionut Arghire
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
Attackers could exploit the bugs to modify configurations, terminate or restart processes, cross security boundaries, leak memory, and execute code.
The post F5 Patches Multiple NGINX, BIG-IP Vulnerabilities appeared first on SecurityWeek.
laws, regulations and policies
7/16/2026 Eduard Kovacs
China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans
Chinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures.
The post China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans appeared first on SecurityWeek.
attacks and breaches,laws, regulations and policies
7/16/2026 Zeljka Zorz
Romania’s land registry hit by cyber attack, data allegedly for sale
Romania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical incident” has now been confirmed as a cyber attack. While the circumstances are still being investigated by the competent state institutions, ANCPI stated that the data administered through its IT systems has not been compromised as a … More →
The post Romania’s land registry hit by cyber attack, data allegedly for sale appeared first on Help Net Security.
laws, regulations and policies,technology and tools
7/16/2026 Anamarija Pogorelec
Microsoft makes Windows SSO prompts easier to manage
Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed environments will continue to receive SSO permission prompts. Admin control for SSO prompts in Windows (Source: Microsoft) Why Microsoft introduced it In the European Economic Area (EEA), Microsoft changed the Windows sign-in experience so users can choose … More →
The post Microsoft makes Windows SSO prompts easier to manage appeared first on Help Net Security.
laws, regulations and policies,attacks and breaches
7/16/2026 Sinisa Markovic
Police take down investment fraud network that stole €100 million a month
Dutch police, working alongside Belgian authorities and Europol, have dismantled a major criminal network accused of operating a global investment fraud scheme through dozens of fraudulent call centers. Investigators estimate the organization generated more than €100 million a month by targeting victims in multiple countries. The group operated around 20 call centers staffed by more than 700 people posing as financial advisers. The main suspect, a 46-year-old man with Israeli and Polish citizenship, was arrested … More →
The post Police take down investment fraud network that stole €100 million a month appeared first on Help Net Security.