<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.techradar.com/feeds/tag/cyber-security" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from TechRadar in Cyber-security ]]></title>
                <link>https://www.techradar.com/computing/computing-security/cyber-security</link>
        <description><![CDATA[ All the latest cyber-security content from the TechRadar team ]]></description>
                                    <lastBuildDate>Wed, 29 Jul 2026 06:00:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ They might have grown up online — but Gen Z are apparently far less likely to use antivirus, study finds ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/they-might-have-grown-up-online-but-gen-z-are-apparently-far-less-likely-to-use-antivirus-study-finds</link>
                                                                            <description>
                            <![CDATA[ A new survey from cybersecurity specialists Kaspersky has revealed a worrying trend among Gen Z: they’re ignorant of online threats. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2dHF3Z3PkeSKnULDdFqtgA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/okt5myc3MwKUsdMaigYsi8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Jul 2026 06:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/okt5myc3MwKUsdMaigYsi8-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone frustrated]]></media:description>                                                            <media:text><![CDATA[Phone frustrated]]></media:text>
                                <media:title type="plain"><![CDATA[Phone frustrated]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/okt5myc3MwKUsdMaigYsi8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Just 27% of Gen Z respondents use antivirus software for mobile devices, and are less likely to regularly change passwords</strong></li><li><strong>57% of Gen Z spend more time online than offline, Kaspersky finds</strong></li><li><strong>And only 28% regularly backup important personal data stored on their phones</strong></li></ul><p>Gen Z has no awareness of cybersecurity, online safety principles, or the risks of not changing your password. With just over half (52%) of respondents admitting they have had devices, data, or online accounts attacked, only 27% actually employ standard countermeasures like mobile antivirus tools.</p><p>In a study of 7200 respondents from 18 countries, the company also found only 28% regularly backup important personal data stored on their phones. </p><p>An average Gen Z-er appears to rely almost completely on their smartphone, which is where they store the information they value most, apparently without cloud backups or syncing in place. The survey has shown that social media accounts have been hacked (17%) and gaming accounts lost (12%), but smartphones have further risks to personal privacy if the correct precautions are not taken.</p><h2 id="gen-z-needs-to-appreciate-the-risks">Gen Z needs to appreciate the risks</h2><p>Access to personal photographs, identity documents, email, financial details, and of course social media profiles can be acquired via a compromised smartphone, opening the victim to a host of targeted attacks. Direct financial attacks can be made, identity theft, and more, depending on how successful the attacker is. Keeping the device out of an attackers reach, rather than inadvertently sharing its contents, is the safer course of action.</p><p>Irina Ermilova, Vice President for Consumer Product Management at Kaspersky, looked to address the apparent disconnect between a generation that has grown up with internet access and portable digital tech, and its lack of cybersecurity nous.</p><p>“Gen Z has grown up online, so digital services often feel intuitive and familiar to them. However, familiarity should not be confused with security expertise," she noted. "Being able to navigate apps, platforms and devices confidently does not necessarily mean being able to identify scams, manage passwords securely or protect personal data.”</p><p>“The findings show that cybersecurity tools and habits need to become as natural part of everyday digital life as messaging, gaming or using social media.”</p><h2 id="training-gen-z-to-find-digital-threats">Training Gen Z to find digital threats</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1280px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FuW8LNMkpnWpR5Loire6pR" name="tr-kaspersky-case404" alt="Screenshot from Kaspersky browser game Case 404" src="https://cdn.mos.cms.futurecdn.net/FuW8LNMkpnWpR5Loire6pR.png" mos="" align="middle" fullscreen="" width="1280" height="720" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Kaspersky)</span></figcaption></figure><p>Looking for a solution to this lack of cyber-risk awareness, Kaspersky has launched an interactive online game aimed at Gen Z users. <a href="https://case404.kaspersky.com/" target="_blank">Case 404</a> is a "cyber-detective adventure" in the point-and-click mold, set in the future with fictional cases that have been inspired by actual digital threats.</p><p>In playing the game, Kaspersky hopes that Gen Z users will spot the scams and phishing attempts, and take that knowledge with them into the real world and stay safe and secure online.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ It's not just OpenAI models escaping and running riot — experts show how Claude Cowork can break its bonds and access Mac files ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/its-not-just-openai-models-escaping-and-running-riot-experts-show-how-claude-cowork-can-break-its-bonds-and-access-mac-files</link>
                                                                            <description>
                            <![CDATA[ Anthropic partially mitigated the issue, and there are things users can do to defend themselves, too. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4ePtwBtUWhGdeVjtV2gT6k</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kQgz8fSBJp3j2YakUJFn4N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 26 Jul 2026 13:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kQgz8fSBJp3j2YakUJFn4N-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/ gguy]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Claude AI]]></media:description>                                                            <media:text><![CDATA[Claude AI]]></media:text>
                                <media:title type="plain"><![CDATA[Claude AI]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kQgz8fSBJp3j2YakUJFn4N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Accomplish AI showed Claude Cowork could escape a VM sandbox via Linux zero‑day CVE‑2026‑46331</strong></li><li><strong>Agent accessed host Mac files, risking exfiltration of SSH keys, cloud credentials, and more</strong></li><li><strong>Anthropic shifted Cowork to default cloud execution; local users must harden configs to mitigate exposure</strong></li></ul><p>Recent news of <a href="https://www.techradar.com/pro/security/this-one-was-different-from-anything-we-had-handled-before-hugging-face-confirms-it-was-hit-by-cyberattack-powered-by-an-ai-agent">a ChatGPT agent escaping the sandbox and attacking services on the internet</a> raised quite a few eyebrows, but it seems it’s not the only one capable of running wild. Security researchers Accomplish AI are saying they achieved similar results with Anthropic’s Claude Cowork.</p><p>In a new report, the researchers said they ran a local session in a Mac-hosted <a href="https://www.techradar.com/best/best-virtual-machine-software" target="_blank">virtual Linux machine</a> and then observed as the agent broke free of the VM and started reading and writing files on the underlying system.</p><p>“We connected a folder to a fresh Claude Cowork session, sent one short message, and watched the agent escape the sandbox,” Oren Yomtov, principal security researcher at Accomplish AI, told<em> </em><a href="https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html" target="_blank"><em>The Hacker News</em></a>. “From inside the VM, it reached the host Mac and read and wrote files all over it, far outside the folder we'd connected, with no permission prompt anywhere.”</p><h2 id="defaulting-to-cloud-execution">Defaulting to cloud execution</h2><p>This means that, in theory, the agent can be used to access or exfiltrate anything that’s stored on the Mac’s user account, including SSH keys, cloud credentials, and more. To break out of the sandbox, the agent exploited CVE-2026-46331 ("pedit COW"), a Linux kernel privilege-escalation vulnerability. This flaw, fixed in mid-June this year, was given a severity score of 7.8/10 (high).</p><p>Accomplish AI disclosed these findings with Anthropic, which allegedly acknowledged them but did not issue a direct fix. However, the version of Claude Cowork that was released afterwards defaults to cloud execution which, the publication claims, addresses the issue. Still, users who opt to run the agent locally rather than in the <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud</a> will remain exposed. </p><p>Mitigations are possible, though. Users should disable unprivileged user namespaces, grant/revoke seccopm permissions, stop modules autoloading, and restrict sharing of the whole host into the VM. </p><p>"Scope it to the folders that were actually connected instead of all of /, or at least mount it read-only, and run coworkd with ProtectSystem=strict in its own mount namespace so it isn't re-execing binaries a session user can poison," Accomplish AI explained. "Then even a full guest-root has nothing to land on, the last two steps of the chain have nowhere to go."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This Russian cybercrime campaign can infect a user just by viewing an email ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-russian-cybercrime-campaign-can-infect-a-user-just-by-viewing-an-email</link>
                                                                            <description>
                            <![CDATA[ A high-severity flaw in Zimbra allowed Russian criminals easy access, where they stole important secrets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TURduCNGpenh8p9SH4Vx9Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 26 Jul 2026 11:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[russian flag]]></media:description>                                                            <media:text><![CDATA[russian flag]]></media:text>
                                <media:title type="plain"><![CDATA[russian flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Proofpoint reports Russian TA488 exploited Zimbra zero‑day CVE‑2025‑66376 in espionage campaigns</strong></li><li><strong>“Half‑click exploit” let attackers compromise systems when victims merely viewed malicious emails</strong></li><li><strong>Targets included NATO, Ukrainian government, and defense entities; group vanished after Feb 2026 exposure</strong></li></ul><p>Russian state-sponsored cybercriminals have been abusing a zero-day vulnerability in the Zimbra <a href="https://www.techradar.com/best/best-secure-email-providers" target="_blank">email and collaboration</a> platform to conduct espionage against western targets - primarily military and government agencies, experts have warned.</p><p>Cybersecurity researchers <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits" target="_blank">Proofpoint</a> claim the campaign has been ongoing for at least a year, possibly longer, describing it as a “half-click exploit”, because the victims don’t even need to do anything specific in order to get infected. </p><p>Usually, when an attack is done via email, the victim is required to at least download a file or click a link. In this case, a cross-site scripting (XSS) vulnerability in the Zimbra web-based email service allowed the Russians to infiltrate the computers as soon as the victim views the email, nothing more.</p><h2 id="targeting-nato-and-ukraine">Targeting NATO and Ukraine</h2><p>The vulnerability in question is now tracked as CVE-2025-66376. It was assigned a severity score of 7.2/10 (high), and was patched in November 2025. However, the threat actors have been leveraging it long before Zimbra patched it up.</p><p>Proofpoint says numerous groups were observed, throughout the years, abusing this flaw. This time around, though, the group in question is tracked as TA488, also known as Laundry Bear or Void Blizzard.</p><p>“After successful exploitation, TA488 established persistent access to the systems and exfiltrated emails from the targeted users,” Proofpoint’s report reads. Besides emails, the crooks hunted for passwords, email directories, two-factor authentication tokens, and more. The group has been “consistently” targeting NATO and Ukrainian government organizations, alongside entities in the defense industrial base, </p><p>The group seems to be defunct now, since the researchers could not find any activity post February 2026. At that time, security researchers Seqrite disclosed a detailed breakdown of the group’s infrastructure and modus operandi, resulting in TA488 burning down months-old setups and vanishing.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts claim to have found more weaknesses in Apple's Gatekeeper tool — but it doesn't seem too bothered ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-claim-to-have-found-more-weaknesses-in-apples-gatekeeper-tool-but-it-doesnt-seem-too-bothered</link>
                                                                            <description>
                            <![CDATA[ Gatekeeper doesn't blink when you archive a legitimate app and replace it with an evil doppelganger. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cigoAwt4EPwNFgf9LCcsXa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 25 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg">
                                                            <media:credit><![CDATA[Apple]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:description>                                                            <media:text><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:text>
                                <media:title type="plain"><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers show Gatekeeper can be bypassed by replacing a previously run legitimate macOS app with malware</strong></li><li><strong>Attack requires prior user‑level code execution, then swaps in a malicious app that Gatekeeper won’t re‑verify</strong></li><li><strong>Apple dismissed the issue, saying locally rebuilt bundles fall outside Gatekeeper’s scope, leaving risk to social engineering</strong></li></ul><p>A pair of researchers claims to have found a way around Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. However Apple doesn’t really see it that way and has seemingly decided not to pursue the issue further.</p><p>Gatekeeper’s modus operandi is rather simple - when a user downloads an app from outside the App Store, it verifies the product comes from an identified developer and is notarized by Apple. If it can’t verify it - it won’t allow it to run on the machine. </p><p>Now, security researchers Talal Haj Barky and Tommy Mysk claim that, as long as a legitimate app was run at least once on a macOS device, it can be replaced with a malicious version, and Gatekeeper won’t even blink its virtual eye.</p><h2 id="locally-built">Locally built</h2><p>That also means the attack is not that straightforward to pull off. The threat actor needs to have a way to execute user-level code (for example, a malicious app, a compromised software package installed through a package manager, or a prompt injection attack that tricks an AI agent).</p><p>Once that is obtained, they can archive a legitimate app, remove the original, then replace it with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and Gatekeeper will not try to re-authorize it. That malicious version can then trick the victim into compromising the device even further, since a certain level of trust was already established. </p><p>After reporting the issue to Apple, the company apparently just closed it. </p><p>"Apple doesn't consider this attack to be 'modifying' the signed executable," Mysk said. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope."</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/07/24/researchers-replace-downloaded-macos-apps-with-evil-twins-apple-shrugs/5277858" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Iran-linked group caught hiding surveillance tools in fake apps ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-privacy-security/iran-linked-group-caught-hiding-surveillance-tools-in-fake-apps</link>
                                                                            <description>
                            <![CDATA[ Researchers at Recorded Future found evidence that an Iran-linked group is spreading MarkiRAT spyware through fake VPN and media player apps promoted on social media, targeting Farsi speakers worldwide. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rcr4Mct7ErHSY84Lpy5fvW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 25 Jul 2026 06:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Malware kan ställa till med oreda]]></media:description>                                                            <media:text><![CDATA[A hand with a mobile phone and VPN application in front of the Iran flag]]></media:text>
                                <media:title type="plain"><![CDATA[A hand with a mobile phone and VPN application in front of the Iran flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Recorded Future found an Iran-linked group spreading spyware</strong></li><li><strong>The malware is delivered through fake VPN and media player apps</strong></li><li><strong>Researchers assess that most targets are Iranian users</strong></li></ul><p>A new report from <a href="https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat" target="_blank" rel="nofollow">Recorded Future's Insikt Group</a> describes a campaign that inverts the whole point of a privacy tool: fake VPN apps built specifically to spy on the people who install them.</p><p>Researchers have linked fresh infrastructure to an Iran-nexus threat cluster they track as TAG-182, which is using fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. The group is "highly likely" to be targeting Iranians living inside and outside the country, <a href="https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ir-2026-0701.pdf" target="_blank" rel="nofollow">the report says</a>.</p><p>It's a blunt reminder that choosing one of the <a href="https://www.techradar.com/vpn/best-vpn" target="_blank" rel="nofollow">best VPN</a> services is a lot more secure than downloading free, unvetted tools.</p><h2 id="fake-apps-real-surveillance">Fake apps, real surveillance</h2><p>Insikt Group identified a cluster of attacker-controlled domains allegedly used to stage downloads of applications that appear nowhere on Google Play or Apple's App Store. </p><p>Two names stand out: Pis2ray VPN and a media player branded YESHICA, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original.</p><p>According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In plain terms, that is software that hands control of your device to somebody else. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">A fake VPN app. A fake media player. Both delivering Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT:https://t.co/G7p9JO6peT#ThreatIntelligence #Cybersecurity pic.twitter.com/GwDyvGC99r<a href="https://twitter.com/cantworkitout/status/2072720755884695924">July 2, 2026</a></p></blockquote><div class="see-more__filter"></div></div><p>Analysts have documented it capturing screenshots and uploading them to attacker-run servers, while disguising itself under believable process names.</p><p>It also abuses BITS, the background service Windows uses to fetch updates, to pull down further files. Because that activity looks like ordinary system housekeeping rather than an attack, it tends to slip past routine cleanup.</p><p>MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group <a href="https://securelist.com/ferocious-kitten-6-years-of-covert-surveillance-in-iran/102806/" target="_blank" rel="nofollow">Kaspersky</a> documented conducting years of covert surveillance against activists inside Iran. </p><p>Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned surveillance groups.</p><h2 id="why-a-fake-vpn-makes-such-an-effective-lure">Why a fake VPN makes such an effective lure</h2><p>Distribution runs largely through social media. Insikt Group found Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around the <a href="https://www.techradar.com/vpn/vpn-privacy-security/the-internet-is-not-connected-irans-88-day-blackout-begins-to-lift-but-traffic-remains-under-50-percent">country's prolonged internet shutdown</a>, which ended with partial restoration of access on 26 May 2026.</p><p>The people most desperate for a <a href="https://www.techradar.com/vpn/virtual-private-networks">virtual private network (VPN)</a> in a censored country are exactly the people most likely to install one from a social media link, because the official stores are often the very thing they cannot reach. </p><p>Recorded Future considers it almost certain that most targets are located in Iran or tied to anti-government movements in Europe and North America. TechRadar has covered <a href="https://www.techradar.com/vpn/vpn-privacy-security/beware-iran-linked-fake-vpn-apps-found-to-spy-on-android-users" target="_blank" rel="nofollow">previous Iran-linked fake VPN campaigns</a>, and this one seems to follow the same pattern with better infrastructure.</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>Most readers will never be targeted by a state actor, but the underlying lesson travels. </p><p>Install VPN apps only from official stores, and check that the provider has a real, verifiable presence outside the app listing. </p><p>Treat any VPN promoted through an Instagram post, a Telegram channel, or a direct message as suspect, however polished it looks. </p><p>Star ratings are a weak signal, since fake reviews are cheap.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers hid dangerous malware on a page hidden in Anthopic's Claude.ai domain ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-hid-dangerous-malware-on-a-page-hidden-in-anthopics-claude-ai-domain</link>
                                                                            <description>
                            <![CDATA[ Claude Artifacts have been used as phishing lures, once again, this time to deliver a dangerous RAT. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QdvwhGRfCMpSAUVqaeF54X</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg">
                                                            <media:credit><![CDATA[Anthropic]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mobile phone displaying a Claude login screen.]]></media:description>                                                            <media:text><![CDATA[Mobile phone displaying a Claude login screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Mobile phone displaying a Claude login screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress spots malicious Claude Artifact spoofing Claude Desktop, spreading SectopRAT malware</strong></li><li><strong>Victims were redirected via Bing ads, infecting at least 29 organizations between July 21–22, 2026</strong></li><li><strong>Claude removed the artifact after 7,000+ views; malvertising risks persist despite disclaimers on artifacts</strong></li></ul><p>At least 29 organizations have been infected with a Remote Access Trojan (RAT) after mistaking a public Claude Artifact for a legitimate Claude page. </p><p>A Claude Artifact is an interactive document, or piece of code, that the AI generates and then hosts on the Claude platform. It can then be shared with other people as an example, or proof of concept, for different solutions. The link to an artifact usually looks something like this:</p><p>claude[.]ai/public/artifacts/ca466f1f-21c0-42af-b329-8f1c7534a891</p><p>Claude Artifacts are often used for phishing and other forms of scams, and we’ve seen it in <a href="https://www.techradar.com/pro/security/infostealers-are-being-disguised-as-claude-code-openclaw-and-other-ai-developer-tools" target="_blank">ClickFix attacks</a> in the past. Claude responded by adding a disclaimer to every artifact, stating that the content is user-generated and thus unverified.</p><p>In this particular case, a malicious artifact was created to spoof the download page for Claude Desktop. Victims would get redirected to an attacker-controlled domain, where instead of the Claude app, they’d download SectopRAT, a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">remote access trojan</a> capable of stealing credit card data, personal information, files, passwords, and more.</p><h2 id="promoting-the-scam">Promoting the scam </h2><p>The artifact was then promoted on Bing, showing up at the very top of search results to people searching for “Claude Desktop App”. </p><p>For years, the cybersecurity community has warned about malvertising, urging users to double-check the domain before clicking on any links, even promoted ones. However, the problem here is that the ad takes the victims to the legitimate Claude domain, making scrutiny that much harder.</p><p>The campaign was spotted by security researchers <a href="https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat" target="_blank">Huntress</a>, who said that between July 21 and July 22, 2026, their SOC “lit up with a swathe of unusual executable installs, Defender exclusions, and anomalous persistence across 29 organizations, all coming from ClaudeDesktop.exe.”</p><p>Claude has since removed the malicious artifact, but not before it raked up more than 7,000 views. It is possible that other organizations, outside Huntress’ field of view, also fell victim to this scam.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn ChatGPT's Workspace Agent Builder can be hijacked to create malicious AI workers ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-chatgpts-workspace-agent-builder-can-be-hijacked-to-create-malicious-ai-workers</link>
                                                                            <description>
                            <![CDATA[ A single phishing link could have spelled disaster, thanks to a flaw in ChatGPT's Agent Builder. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pSVUHumwJu8iaWxQ7btdxc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TzcYH2Dk7mqJFU7QJPad8Y-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TzcYH2Dk7mqJFU7QJPad8Y-1280-80.jpg">
                                                            <media:credit><![CDATA[NurPhoto / Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT app on an iPhone]]></media:description>                                                            <media:text><![CDATA[ChatGPT app on an iPhone]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT app on an iPhone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TzcYH2Dk7mqJFU7QJPad8Y-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zenity Labs found AgentForger, a flaw in OpenAI’s ChatGPT Agent Builder</strong></li><li><strong>Malicious links could instantly deploy rogue agents that exfiltrate sensitive data without user prompts</strong></li><li><strong>OpenAI patched the issue by removing the risky URL parameter; no abuse detected</strong></li></ul><p>AI agents are handy for answering customer emails, or tracking reports for newly released security vulnerabilities. But what if they go rogue and turn on the very enterprise they’re supposed to support?</p><p>Security researchers from Zenity Labs have found a way for cybercriminals to trick people into deploying such agents into their own tech stack. Since all it takes is a single click, the disruptive potential of these attacks is arguably significantly bigger than anything else a phishing attack could do.</p><p>The flaw was discovered in OpenAI’s ChatGPT Agent Builder, a feature that lets users create custom AI agents. The researchers dubbed it “AgentForger", explaining that the issue stems from an overly permissive parameter in the tool, which allowed anyone to create ChatGPT links that include virtually any instructions. </p><h2 id="agent-trust-failure">Agent trust failure</h2><p>As soon as the victim clicks on the link, they send the instructions to Agent Builder which acts on them immediately - without prompting or otherwise notifying the victim.</p><p>In theory, a single phishing email could trick a person into deploying a malicious agent that exfiltrates sensitive data or does anything else that company’s AI agents are permitted to do. To make matters worse, the AI agent would persist on the infrastructure indefinitely, doing the attackers’ bidding until caught. </p><p>“This is an agent trust failure, and existing security controls were never built to see it,” commented Michael Bargury, co-founder and CTO of Zenity.</p><p>The researchers disclosed their findings with OpenAI in early June 2026, and the company came back with a fix a few days later. </p><p>The bug was solved by removing the URL parameter that originally enabled the attack, it was explained. There is no evidence that it was previously discovered, or abused, by malicious actors.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bad news — paying a ransomware demand might cause hackers to come back and ask for more ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/bad-news-paying-a-ransomware-demand-might-cause-hackers-to-come-back-and-ask-for-more</link>
                                                                            <description>
                            <![CDATA[ Hackers really have no incentive to walk away from a victim - so why should they? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oEjKtvAMaWbcGwRn87mZvh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 05:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Proofpoint 2026 AI‑Era Ransomware Report found 54% of victims paid attackers despite warnings</strong></li><li><strong>37% faced repeat extortion after paying; 2% paid but never regained access to files</strong></li><li><strong>Experts urge prevention: phishing awareness, offline backups, and AI‑powered endpoint protection</strong></li></ul><p>Security researchers Proofpoint have seemingly proved once again that paying <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> actors does not guarantee they’ll walk away for good - in fact, they’ve proven that in many cases, they’ll simply come back for more because they know they can get paid.</p><p>The company's “2026 AI-Era Ransomware Report”, based on a survey of almost 1,000 security professionals across 12 markets, found globally, more than half (54%) of affected organizations paid their attackers to regain access to locked files and prevent them from sharing stolen documents on the dark web.</p><p>This is despite repeated pleas by law enforcement and the cybersecurity industry not to engage with the attackers and not to, under any circumstances, pay the ransom demand. Proofpoint argues that the real-world pressure organizations suffer when faced with disruptions is, in many instances, simply too big to tolerate.</p><h2 id="asking-for-a-second-payment">Asking for a second payment</h2><p>The logic behind the “don’t pay” argument is simple - by paying, the victims are motivating the attackers to do more damage, and are funding future attacks. At the same time, there is no guarantee that the decryption keys will work, that the attackers will really delete the files they had stolen, and that they won’t strike again in a few weeks.</p><p>This final argument has now been proven. While around half (56%) of victims paid one ransom and regained access, more than a third (37%) faced a second extortion demand soon after paying. Another 2% paid and never regained access at all. </p><p>Instead of paying the ransom demand, the industry suggests businesses protect their premises by educating their employees on the dangers of phishing, keeping updated backups in offline storage, and running (if possible, AI-powered) endpoint detection and protection services across the entire tech stack.</p><p><em>Via </em><a href="https://techcrunch.com/2026/07/22/if-you-pay-a-hackers-ransom-chances-are-that-theyll-come-back-for-more/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts have found a trojan able to rig online live betting platforms ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-have-found-a-trojan-able-to-rig-online-live-betting-platforms</link>
                                                                            <description>
                            <![CDATA[ A company building betting software was targeted with a rather sneaky trojan. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UbpcBTvNkV6nbqLzBq2xw4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LjsHPauSLhKbcYzTG2rmEX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LjsHPauSLhKbcYzTG2rmEX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Online games]]></media:description>                                                            <media:text><![CDATA[Online games]]></media:text>
                                <media:title type="plain"><![CDATA[Online games]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LjsHPauSLhKbcYzTG2rmEX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>JFrog found Newtonsoftt.Json.Net, a trojan NuGet package mimicking the popular Newtonsoft.Json library</strong></li><li><strong>Malware specifically targeted Digitain’s crash‑game backend, rigging outcomes with insider knowledge of its codebase</strong></li><li><strong>Issue was quickly fixed but attackers remain unidentified</strong></li></ul><p>Security researchers JFrog have <a href="https://jfrog.com/blog/nuget-typosquat-targets-betting-platform/" target="_blank">discovered</a> a unique trojan targeting one specific company, while letting everyone else who’s infected walk away unharmed.</p><p>Named Newtonsoftt.Json.Net, the trojan is a typosquatted NuGet package variant of the hugely popular JSON library called Newtonsoft.Json. The legitimate package is one of the most-used code libraries in the .NET programming world, needed by almost every project in existence. It is a small piece of software that helps .NET applications read, understand, and exchange data between different systems.</p><p>According to JFrog, someone published an almost identical package, copied the real author’s name, license, and made it work as intended. For almost anyone who installed it, it worked entirely normal. However, for developers working on Digitain’s crash-game backend, it’s a whole different story. </p><h2 id="rigging-the-games">Rigging the games</h2><p>Digitain is an Armenian software company providing online sports betting and gaming software platforms to gambling companies around the world.</p><p>On the infected machine running Digitain’s real crash-game code, the malware swaps in a rigged number instead of a fair one, using a formula based on the date and time. </p><p>What this means is that the results of the gambling game are rigged, allowing the attackers to know, in advance, which rounds are manipulated and place their bets accordingly. </p><p>The malware also sets up a private confirmation channel to report back for every rigged round, allowing the attackers to know if the cheat code still works or not. </p><p>JFrog did not identify the attackers, but they did stress that it was most likely an insider. </p><p>Apparently, only someone with inside knowledge of Digitain’s codebase (for example a current or former employee, or a contractor) could have built such an exploit, since it required knowledge of the exact internal function name inside Digitain’s game engine that decides the crash-game outcome. </p><p>The researchers reached out to Digitain on July 7 2026 and were notified, two days later, that the issue had already been escalated to the team and, in the meantime, fixed.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This devious malware scans over 300 apps to build an AI profile telling hackers which victims to target ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-devious-malware-scans-over-300-apps-to-build-an-ai-profile-telling-hackers-which-victims-to-target</link>
                                                                            <description>
                            <![CDATA[ Malware started talking to their bosses, telling them where to strike next. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dD6tYK5jkxNm5YaX69LWLQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eVgzzXmQMEyvzfYvAaAMrX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 13:40:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eVgzzXmQMEyvzfYvAaAMrX-1280-80.jpg">
                                                            <media:credit><![CDATA[wk1003mike / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Trojan]]></media:description>                                                            <media:text><![CDATA[Trojan]]></media:text>
                                <media:title type="plain"><![CDATA[Trojan]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eVgzzXmQMEyvzfYvAaAMrX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Varonis Threat Labs uncovered Dolphin X, a powerful RAT with 329 features across 10 categories</strong></li><li><strong>Its standout “AI Profiler” ranks victims by usage and sends summaries to attackers daily</strong></li><li><strong>Malware is sold on the dark web via subscription tiers, starting at $80 per month</strong></li></ul><p>What if malware could talk to its operator and tell it which of the infected victims is worth paying attention to, and which not? A few years ago, this might have been science fiction but today, thanks to breakthroughs in Artificial Intelligence (AI), not only is it possible, it’s also already available on the black market.</p><p>Security researchers Varonis Threat Labs recently <a href="https://www.varonis.com/blog/dolphin-x-stealer" target="_blank">disclosed</a> finding a rather revolutionary remote access trojan (RAT) called Dolphin X. </p><p>Even without advanced AI capabilities, the RAT is quite potent, acting as an infostealer, a Hidden Virtual Network Computing (HVNC), a DDoS botnet, or a loader. Just its infostealer capabilities are nothing short of impressive - it can target more than 300 applications to steal browser passwords, enterprise credentials, cryptocurrency wallet data, DevOps secrets, and different sensitive files, and it comes with 329 features split into 10 categories.</p><h2 id="ai-profiler">AI Profiler</h2><p>However, the AI capability is the one that stunned the researchers. Called “AI Profiler”, the feature ranks victims by app usage, browsing history, and more, sending a daily summary to the attackers. </p><p>The malware is now being offered on the dark web, where other criminals can subscribe to one of three tiers. The basic tier costs $80 per month, while the top tier is around $230 per month. Lifetime subscription costs $1,140 for basic access, and goes up to $3,420 for the top tier. </p><p>"Dolphin X’s collection scope reaches well beyond browser passwords to SSH keys, cloud tokens, and DevOps credentials," Varonis said in its write-up. "On the wrong machine, a single infection could expose access to an entire production environment."</p><p>"Its use of AI is also interesting because it shows us how AI is being integrated into more cybercrime tooling."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A malicious Chrome extension for Adobe Acrobat could let hackers access private WhatsApp chats ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-malicious-chrome-extension-for-adobe-acrobat-could-let-hackers-access-private-whatsapp-chats</link>
                                                                            <description>
                            <![CDATA[ Researchers find a universal cross-site scripting-class cross-origin data disclosure vulnerability in a popular Chrome extension. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5ZGuvAuVv7kLKhivJo4DFK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3hRUaAPv8gwJBWYX8h3HqT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3hRUaAPv8gwJBWYX8h3HqT-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Chrome logo on a mobile phone&#039;s screen]]></media:description>                                                            <media:text><![CDATA[Google Chrome logo on a mobile phone&#039;s screen]]></media:text>
                                <media:title type="plain"><![CDATA[Google Chrome logo on a mobile phone&#039;s screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3hRUaAPv8gwJBWYX8h3HqT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Guardio Labs found CVE‑2026‑48294 in Adobe Acrobat Chrome extension, enabling cross‑site data disclosure</strong></li><li><strong>Attackers could steal WhatsApp Web chats if victims opened malicious landing pages with extension active</strong></li><li><strong>Adobe patched the flaw in version 26.7.2.0; update recommended for 314M extension users</strong></li></ul><p>If you have Adobe Acrobat’s extension for Chrome, and you like chatting through WhatsApp Web, there is a potential security vulnerability you might want to address.</p><p>Security researchers from Guardio Labs discovered a “universal cross-site scripting (UXSS)-class cross-origin data disclosure vulnerability”, which is another way of saying that a website could use the flaw to read the contents of a different website, loaded in a separate tab. </p><p>The vulnerability was found in the Adobe Acrobat <a href="https://www.techradar.com/computing/chrome/these-are-the-10-best-chrome-extensions-of-2025-according-to-google-and-theres-one-i-definitely-recommend" target="_blank">Chrome extension</a> and is now tracked as CVE-2026-48294. It was given a severity score of 7.4/10 (high), and affects versions 26.5.2.2 and earlier. Guardio Labs dubbed it “HermeticReader” because of what it exploits. </p><h2 id="insultingly-ordinary-setup">"Insultingly ordinary" setup</h2><p>The extension comes with different integrations, such as Google Drive or, in this case - WhatsApp Web. The WhatsApp integration component, internally known as "Hermes" is where the bug was found. </p><p>In theory, an attacker could create a new landing page and share it with the victim via email, instant messaging, SEO poisoning, or other methods. If the victim 1) has the vulnerable version of the Adobe Acrobat Chrome extension installed; 2) has WhatsApp loaded in a separate tab; and 3) opens the malicious landing page, it could trigger the extension’s vulnerable code path and allow the attackers to access everything the victim has on their WhatsApp. </p><p>Some sources argue that threat actors could use this vulnerability to pull one-time passcodes delivered via WhatsApp.</p><p>"The setup is almost insultingly ordinary: an attacker-controlled page, dressed to look like the kind of page you land on via search results, marketing emails, etc.," Guardio Labs wrote in its analysis. </p><p>"The visitor, who already has the Adobe Acrobat extension installed, opens that page. The page wakes up a dormant engine inside the extension, reaches directly into WhatsApp Web. Seconds later, the rendered WhatsApp Web view - the chat list, contact names, messages, the profile name, the text of whatever conversation is open - the whole WhatsApp in the attacker's hands."</p><p>Adobe has since publicly acknowledged the issue and thanked Guardio Labs’ researchers for their help. It has also fixed the problem in version 26.7.2.0 that’s currently available for download. The extension has more than 314 million users.</p><p><em>Via </em><a href="https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ South Korea warns diplomats they could be at risk following hack on education system ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/south-korea-warns-diplomats-they-could-be-at-risk-following-hack-on-education-system</link>
                                                                            <description>
                            <![CDATA[ Initial reports are saying up to 6,000 people might have been affected. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aQk9gutRc62bND2wEnduQK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/T886YqTSDTnduW95C5KxgU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 11:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/T886YqTSDTnduW95C5KxgU-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[South Korea&#039;s flag]]></media:description>                                                            <media:text><![CDATA[South Korea&#039;s flag]]></media:text>
                                <media:title type="plain"><![CDATA[South Korea&#039;s flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/T886YqTSDTnduW95C5KxgU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>South Korean government discloses ten‑month cyberattack on the National Diplomatic Academy’s online education system</strong></li><li><strong>Data stolen included user IDs, names, emails, and encrypted passwords of at least 6,000 individuals</strong></li><li><strong>MFA shut down IT systems, deployed enhanced security, and delayed disclosure due to diplomatic sensitivity</strong></li></ul><p>Current and former employees of the South Korean Ministry of Foreign Affairs (MFA), as well as other government personnel, may have had their data siphoned out by cybercriminals in an attack that lasted for ten months.</p><p>The South Korean government has disclosed an attack against the online education system of its National Diplomatic Academy. The system, set up in 2022 by the country’s premier institution for educating and training diplomats, apparently contained a security vulnerability that unnamed threat actors managed to exploit.</p><p>In an announcement published on the official website of the South Korean government, both the details about the flaw, as well as about the attackers, were not disclosed.</p><h2 id="thousands-are-affected">Thousands are affected</h2><p>However, it did note that the attack took place between April 2025 and February 2026. During these ten months, cybercriminals were able to steal user IDs, names, emails, as well as <a href="https://www.techradar.com/best/password-manager" target="_blank">encrypted passwords</a> of trainees in the National Diplomatic Academy Online Education System.</p><p>Unique identification information, sensitive information, mobile phone numbers, home addresses, and photos were not compromised, it said.</p><p>In response to the attack, MFA shut down its entire IT infrastructure and deployed “enhanced security measures”, without elaborating what these measures were. It urged all employees to remain vigilant of incoming emails, and to reach out if they receive anything “suspicious”. </p><p>While the official announcement lacks details, <em>BleepingComputer</em> reported that the attack impacted “at least 6,000 individuals, 350 of them being current government attachés dispatched abroad.” Citing an MFA spokesperson, the publication said the Ministry decided to disclose the incident with a five-month delay due to the “sensitive nature” of the attack, and the need to thoroughly analyze it before going public. </p><p>"We recognized this issue in February, but we announced it five months later because of the sensitivity of the matter regarding our diplomatic and security affairs, and the need for careful review and analysis," said South Korea Foreign Ministry's spokesperson Park Il.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A bizarre new malware campaign hacks your printer and forces it to print out ransomware demands ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-bizarre-new-malware-campaign-hacks-your-printer-and-forces-it-to-print-out-ransomware-demands</link>
                                                                            <description>
                            <![CDATA[ Researchers detail two incidents in Latin America in which system misconfigurations resulted in ransomware attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zcXHEpjACADHj5DbgFB367</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:description>                                                            <media:text><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kaspersky detailed ransomware cases in Colombia and Mexico where attackers exploited misconfigured systems</strong></li><li><strong>Victims’ drives were locked with BitLocker, ransom notes printed via office printers</strong></li><li><strong>New group “XEntry Team” claimed responsibility; misconfigurations remain a major breach risk</strong></li></ul><p>Cybercriminals have, in true Hollywood fashion, started using office printers to notify victims they were struck by <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>.</p><p>Security researchers at Kaspersky have <a href="https://securelist.com/new-extortion-scheme-printers-bitlocker/120718/" target="_blank">detailed</a> two incidents which recently took place, one in Colombia, and one in Mexico, where cybercriminals took advantage of misconfigured systems. </p><p>However both had the same outcome - the attackers used BitLocker to lock down key drives, and then used office printers to print out their ransom notes.</p><h2 id="xentry-team-claims-the-attacks">XEntry Team claims the attacks</h2><p>In Colombia, a machine containing eight terabytes of mission-critical data had its Endpoint Protection Platform (EPP) disabled due to compatibility issues. It also had an internet-exposed Remote Desktop Protocol (RDP) running, which enabled relatively easy access for the attackers.</p><p>The Mexico attack was somewhat different. Three months before springing to action, the attackers discovered misconfigurations in the MSSQL service which granted them privileged access to the target environment. They spent the next couple of months lowering the server’s security settings, dropping web shells, and even though some triggered EPP alarms, the victims never investigated thoroughly.</p><p>In the Colombia case, the attackers asked for only $3,000, an offer the victims quickly accepted. Therefore, there was not enough forensic evidence left behind to conduct a thorough investigation. Kaspersky did not say how much money the attackers asked for in the Mexico case, or if the victims ended up paying or not.</p><p>In both cases, the attackers did not exploit a vulnerability, or even target an oblivious employee with social engineering. Instead, they exploited misconfigurations, which continue to be one of the biggest causes of breaches and data leaks. </p><p>“We strongly recommend configuring the RDP in strict accordance with cybersecurity best practices to prevent unauthorized access,” Kaspersky warned. “This is especially critical: according to our Global Report: Anatomy of a Cyber World, more than 13% of incidents are related to policy violations and configuration errors, confirming that misconfigurations continue to pose a significant risk.”</p><p>The attacks were done by a group calling itself “XEntry Team”. There are no prior reports of this group, and it is either a previously unknown threat actor, or a simple rebrand.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple finally patches Hide My Email security flaw — a year after it was first discovered ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/apple-finally-patches-hide-my-email-security-flaw-a-year-after-it-was-first-discovered</link>
                                                                            <description>
                            <![CDATA[ A bug that was first discovered in June 2025 was finally fixed in early July 2026. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vbZdWUd8W3EzMmZrpT3jhj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SNA6BvwnpUaBPrrGGoBTkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SNA6BvwnpUaBPrrGGoBTkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[User holding an iPhone 8]]></media:description>                                                            <media:text><![CDATA[User holding an iPhone 8]]></media:text>
                                <media:title type="plain"><![CDATA[User holding an iPhone 8]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SNA6BvwnpUaBPrrGGoBTkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Apple fixes Hide My Email flaw which exposed anonymous addresses through bounced spam logs</strong></li><li><strong>Hidden emails created before July 7, 2026 may still be exposed in third‑party logs</strong></li><li><strong>Users should update and consider regenerating hidden addresses to reduce lingering exposure risk</strong></li></ul><p>A year after first being discovered, a vulnerability in Apple’s Hide My Email feature has finally been fixed - however some users will probably remain at risk until they make changes on their end, as well.</p><p>The Hide My Email feature is part of the paid iCloud+ offering and allows users to quickly create a new, anonymous email address - very handy for people who don’t want to share their email with different products across the web. It is also important since some companies tend to sell this information to third parties who then, unsolicited, start sending spam <a href="https://www.techradar.com/news/best-email-provider" target="_blank">emails</a> and various offers.</p><p>In June 2025, security researcher Tyler Murphy found a way to link these anonymous emails to the “real” addresses, making the entire service useless. He disclosed his findings to Apple, who responded with a fix. However, the issue remained, and Murphy went back-and-forth with Apple, until finally deciding to go public.</p><h2 id="was-it-finally-patched">Was it finally patched?</h2><p>Now, he says the issue had finally been resolved, but there are caveats:</p><p>“We don't know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can’t review your spam folder to learn whether you were affected,” he said.</p><p>Even though the bug is now fixed, he thinks the risk to Hide My Email users remains. “Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs.”</p><p>Apple released a working fix on July 3 2026, with users urged to update immediately.</p><p><em>Via </em><a href="https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/" target="_blank"><em>404 Media</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Chick-fil-A reveals data breach — customers warned hackers may have accessed their account info ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/chick-fil-a-reveals-data-breach-customers-warned-hackers-may-have-accessed-their-account-info</link>
                                                                            <description>
                            <![CDATA[ Thousands of users in Texas alone had their data compromised and the company is now sending out notifications. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QeESsoRnBK729szx6hUpbb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/syziJW6VhRCZRbcKNiKnRJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 14:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/syziJW6VhRCZRbcKNiKnRJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Javidestock/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Businessman staring at laptop with frightened face in the dark]]></media:description>                                                            <media:text><![CDATA[Businessman staring at laptop with frightened face in the dark]]></media:text>
                                <media:title type="plain"><![CDATA[Businessman staring at laptop with frightened face in the dark]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/syziJW6VhRCZRbcKNiKnRJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Chick‑fil‑A confirmed a credential stuffing attack between June 17–19, breaching thousands of accounts</strong></li><li><strong>Exposed data includes names, emails, membership numbers, payment details, birthdays, and addresses</strong></li><li><strong>Company logged out users, removed payment methods, restored balances, and notified multiple US states</strong></li></ul><p>Chick-fil-A is notifying its customers of a worrying cyber incident involving their sensitive information being leaked.</p><p>In a data breach notification letter being sent to affected customers, the fast food giant said it recently identified “suspicious login activity”, which prompted it to investigate further. </p><p>That investigation determined that unidentified threat actors ran a credential stuffing attack between June 17 and June 19 2026, successfully breaching an unknown number of accounts.</p><h2 id="logging-everyone-out">Logging everyone out</h2><p>A credential stuffing attack is when threat actors use automated systems to try thousands of username/password combinations against a service to see which ones work. The login credentials are usually obtained on the black market, in advance. </p><p>Since the attackers broke into people’s accounts, the data found inside was exposed. According to the notification letter, that data includes names, <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email addresses</a>, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, last four digits of payment cards, and the amount of Chick-fil-A credit.  </p><p>“The information may have included the month and day of your birthday, phone number, and address,” the company added.</p><p>After it discovered the intrusion, Chick-fil-A logged everyone out of their accounts and removed any stored payment methods. It also restored impacted customers’ account balances and, in some cases, added rewards to victim accounts, too. </p><p>We don’t know exactly how many people are affected by the breach, but it is definitely in the thousands. </p><p><em></em><a href="https://www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/" target="_blank"><em>BleepingComputer</em></a> found that the company notified the Texas Attorney General that the breach impacted 2182 of its citizens. Similar notifications went out to Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.</p><p>Chick-fil-A is one of the largest fast-food restaurant chains in the US, operating more than 3,000 restaurants across the United States, Canada and Puerto Rico. It employs over 200,000 people and generated about $10.3 billion in annual revenue in 2025.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Rental giant Carla leaks user names, emails, and phone numbers ahead of summer holiday break ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/rental-giant-carla-leaks-user-names-emails-and-phone-numbers-ahead-of-summer-holiday-break</link>
                                                                            <description>
                            <![CDATA[ Another day, another misconfigured database discovered online. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WYtKD67awS2SDZ94euaHag</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GcQXTy4NBXKeoop4V5WQnQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GcQXTy4NBXKeoop4V5WQnQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data leak]]></media:description>                                                            <media:text><![CDATA[Data leak]]></media:text>
                                <media:title type="plain"><![CDATA[Data leak]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GcQXTy4NBXKeoop4V5WQnQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cybernews found Carla’s exposed AWS bucket with 48,000 PDFs containing customer rental data</strong></li><li><strong>Files included names, emails, phone numbers, rental details, and travel patterns useful for phishing</strong></li><li><strong>Carla secured the database after disclosure; no evidence of malicious access, but risk remains</strong></li></ul><p>Car rental comparison and booking platform Carla kept a database with sensitive customer information unlocked on the open internet, freely available to anyone who knew where to look.</p><p>Cybersecurity researchers from<em> </em><a href="https://cybernews.com/security/carla-car-rental-data-leak/" target="_blank"><em>Cybernews</em></a>reported finding an exposed Amazon Web Services (AWS) bucket with approximately 48,000 PDF files. These files, which was later determined belonged to Carla, contained car rental details and drivers’ personal information. </p><p>Among other things, these files held vouchers and confirmation numbers, drivers’ names, email addresses, and phone numbers, rent periods, costs, pick-up and drop-off locations, as well as general vehicle information. </p><h2 id="carla-reacts">Carla reacts</h2><p>Cybernews says the data could have been used in convincing phishing attacks. Not only would malicious actors get contact information, but they could also deduce individuals’ travel patterns, which could be used to establish trust with the victims - a crucial step in social engineering attacks.</p><p>After disclosing the findings with Carla, the company locked the <a href="https://www.techradar.com/best/best-database-software" target="_blank">database</a> down. Currently, there is no evidence that it was accessed by malicious actors in the past, but Cybernews says “if our team uncovered it, so too may have threat actors that have automated tools searching specifically for unprotected corporate data.”</p><p>The service does not own a feel of its own. Instead, it works like a travel booking site, aggregating offers from hundreds of rental providers and offering users to compare prices and reserve cars online.</p><p>Misconfigured databases continue to be one of the key causes of major data spills. Businesses often misunderstand the shared responsibility model of cloud providers, leaving systems with default settings, or setting up weak and easily guessed credentials. </p><p><em>Cybernews</em> recently also <a href="https://www.techradar.com/pro/security/nextcloud-leaks-367k-records-european-cloud-giant-exposes-staff-and-clients-in-major-breach" target="_blank">reported discovering an exposed ElasticSearch cluster</a> belonging to Nextcloud and containing 367,000 records of employee data, client company data, contracts, and various scripts.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI says its models escaped a sandbox and breached Hugging Face ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/openai-says-its-models-escaped-a-sandbox-and-breached-hugging-face</link>
                                                                            <description>
                            <![CDATA[ New OpenAI models did whatever it took to achieve their goal - including exploiting zero-days. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QCjTgLYoCepWr3NrjNJs8E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 10:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI researchers confirm an AI agent escaped sandbox, exploited zero‑days, and attacked Hugging Face</strong></li><li><strong>Controlled experiment with GPT‑5.6 Sol showed autonomous chaining of vulnerabilities and credential theft</strong></li><li><strong>Security experts call it unprecedented, urging stronger AI governance, accountability, and protection models</strong></li></ul><p>OpenAI has confirmed one of its AI agents broke out of a sandbox, found and exploited zero-day vulnerabilities to gain access to the open internet, and then attacked a platform.</p><p>Not just any platform too - <a href="https://www.techradar.com/pro/security/this-one-was-different-from-anything-we-had-handled-before-hugging-face-confirms-it-was-hit-by-cyberattack-powered-by-an-ai-agent" target="_blank">the agent was able to breach Hugging Face</a>, one of the biggest AI and machine learning companies on the Internet today.</p><p>The good news is that this was a controlled experiment done by white hat researchers. The bad news is that if it could be done by researchers - it could probably be done by malicious actors, too.</p><h2 id="whatever-it-takes">Whatever it takes</h2><p>In a <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="nofollow">blog post</a> explaining the incident, OpenAI revealed the experiment was part of its testing of GPT‑5.6 Sol and an “even more capable pre-release model” to see how well they would perform on the ExploitGym benchmark.</p><p>ExploitGym is a cybersecurity benchmark that measures if an AI agent can turn a known software vulnerability into a real, working exploit. OpenAI ran it in a “highly isolated environment, with network access constrained to the ability to install packages through an internally hosted third-party software that acts as a proxy and cache for package registries.”</p><p>But the models found a way through. They identified and chained vulnerabilities in the package registry cache proxy to obtain open internet access and then attacked Hugging Face, reasoning that the solutions for the ExploitGym benchmark might be found there. </p><p>“In one example, the model chained together multiple attack vectors, including using stolen credentials and <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">zero-day vulnerabilities</a> to find a remote code execution path on the Hugging Face servers,” OpenAI said.</p><p>The security community is up in arms over what OpenAI called, "an unprecedented cyber incident,” while Ansgar Dodt, VP Product Management, Software Monetization at Thales said this “demands a fundamental rethink of software protection.”</p><p>Bill Conner, president and CEO of AI integration and automation expert Jitterbit, said that while investing in AI is “critically important,” “overly aggressive policy cannot compromise AI accountability, transparency and data privacy.” </p><p>“To lead in AI, governments and organizations must lead with principles. Responsible AI governance isn’t a side note but the foundation of lasting global influence.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn hackers could shut down entire power grids by hijacking cloud accounts ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-hackers-could-shut-down-entire-power-grids-by-hijacking-cloud-accounts</link>
                                                                            <description>
                            <![CDATA[ AI training can create spikes in energy consumption, and these can cause all sorts of harm to a power grid. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qWzmUhTiFCkRQP6HRGFqFg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fvSuoQXyuYpY9Y7Tgk4e2a-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/fvSuoQXyuYpY9Y7Tgk4e2a-1280-80.png">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:description>                                                            <media:text><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:text>
                                <media:title type="plain"><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fvSuoQXyuYpY9Y7Tgk4e2a-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zhejiang University researchers warned GPU workloads could destabilize local grids and cause blackouts</strong></li><li><strong>Attackers could exploit ~1,000 GPUs to drain current and generate excess heat in systems</strong></li><li><strong>Theoretical attack dubbed Bit2Watt; mitigations include detecting malicious patterns and energy buffering systems</strong></li></ul><p>Whenever an AI data center thinks really, really hard, it can increase its power consumption so much to trigger disruptions and possibly even blackouts and gear malfunctions. So, is it possible for a malicious actor to trigger this scenario deliberately, in order to cause physical harm?</p><p>Multiple researchers from the Zhejiang University in Hangzhou, China, wrote a research paper titled “Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures.”</p><p>In it, they claim that a malicious cloud tenant is, in theory, capable of launching GPU workloads so intensive that they cause physical damage.</p><h2 id="suggesting-mitigations">Suggesting mitigations</h2><p>"Our results indicate that GPU loads can reach modulation frequencies exceeding 6,000 Hz, compared with only a few hertz observed in conventional household loads such as air conditioners," the team wrote in its research paper. </p><p>"Such high-frequency modulations can substantially induce voltage excursions, harmonic distortion, and damping degradation."</p><p>An attacker could use around 1,000 GPUs to target a one-megawatt local power grid consisting primarily of distributed energy sources (such as solar panels), making it lose almost half of the electrical current, while generating around 20% more heat than usual.</p><p>"This not only threatens the availability of the computing equipment but also produces a negative damping ratio of -0.27, introducing an unstable mode into the system," the paper adds. </p><p>"Once the protections are triggered and computing loads are shed, it can trigger cascading failures, potentially leading to blackouts exceeding 80 percent in large-scale power systems."</p><p>AI data centers creating huge energy consumption swings is no news, and it’s a challenge some of the brightest minds of today are trying to solve. </p><p>Luckily, the attack is (still) purely theoretical, and the researchers published the paper to warn about potential misuse. They also suggested mitigations - defenders could look for malicious computational patterns, while operators should create energy buffering systems for unusual spikes in demand.</p><p><em>Via </em><a href="https://www.theregister.com/ai-and-ml/2026/07/20/malicious-cloud-customers-can-bring-down-the-power-grid/5275193" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/watch-out-that-microsoft-calendar-invite-dated-2050-could-be-hiding-stolen-files-and-worse</link>
                                                                            <description>
                            <![CDATA[ Check your calendars for entries far into the future - especially if you're an Israeli entity. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LjgKxK7hkjXzxZoDby7Pxa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 16:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / Westend61]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:description>                                                            <media:text><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:text>
                                <media:title type="plain"><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB discovers HollowGraph malware targeting Israeli entities, exfiltrating files via Microsoft Graph API</strong></li><li><strong>Operators hide instructions in future calendar entries, then attach encrypted stolen data to events</strong></li><li><strong>At least 12 systems were compromised; overlaps with Lyceum noted but attribution remains low‑confidence</strong></li></ul><p>Cybercriminals have found a way to communicate with the malware installed on victim devices through compromised Microsoft Calendar apps, experts have warned.</p><p>Security researchers at Group-IB have <a href="https://www.group-ib.com/blog/hollowgraph-microsoft-365/" target="_blank" rel="nofollow">detailed</a> a newly discovered piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> called HollowGraph designed to exfiltrate sensitive files from compromised devices.</p><p>What makes the malware stand out is the way it communicates with its operators. The best way to spot hidden malware is to monitor the traffic flowing in and out of a device, which is why cybercriminals try their best to hide this traffic, or blend it with another, legitimate one. In that respect, HollowGraph is unique because it abuses Microsoft Graph API and a compromised Microsoft 365 mailbox calendar.</p><h2 id="a-dozen-victims">A dozen victims</h2><p>After landing on a device and compromising the Microsoft 365 account, HollowGraph uses that account’s permissions to access Microsoft Graph. Operators create calendar entries containing instructions and place them far into the future (in the year 2050) to avoid being spotted. After acting on the instructions and harvesting valuable information, the malware exfiltrates it through the same channel.</p><p>Instead of uploading files to a suspicious server, HollowGraph attaches encrypted stolen data to calendar events and sends it through Microsoft Graph. For defenders, all of this traffic seems legitimate and usually flies under their radars. </p><p>So far, all of the victims are Israeli entities, Group-IB said. The researchers identified at least 12 compromised systems, three of which were still actively communicating with the attackers’ infrastructure during the investigation.</p><p>The researchers did not attribute the attack to any known threat actor, but hinted at a potential. They identified technical similarities in command structures and plugin mechanisms between HollowGraph’s framework, Cavern, and a .NET backdoor used by Lyceum (an Iranian-nexus threat actor associated with OilRig). However, Group-IB explicitly emphasizes that these overlaps are not distinct enough, so they assess this link with low confidence.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake FBI social media scams are on the rise — here's what to look out for ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/fake-fbi-social-media-scams-are-on-the-rise-heres-what-to-look-out-for</link>
                                                                            <description>
                            <![CDATA[ Victims reporting crimes to the FBI are actually being caught and revictimized, leading to further financial losses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3zSRMcDm3LticiguF3F3Nh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 15:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Scammers are pretending to offer FBI support to victims</strong></li><li><strong>Victims are becoming double-victims after falling for this trap</strong></li><li><strong>FBI's IC3 warns never to pay for support – support will come from law enforcement</strong></li></ul><p>Scammers are increasingly impersonating FBI personnel and the FBI's Internet Crime Complaint Center (IC3) to defraud people who have already lost money to cybercrime, ultimately leading to them being exploited twice in quick succession by capitalizing on their weaknesses.</p><p>Attackers pose as support for recovering lost money and assisting with IC3 complaints, but the real objective is to defraud victims out of even more money or sensitive information.</p><p>But savvy victims should be able to identify these scams relatively easy, because despite a rising volume, the attack vector remains highly suspicious.</p><h2 id="victims-are-being-hit-twice-via-fake-fbi-scams">Victims are being hit twice via fake FBI scams</h2><p>Rather than targeting the FBI's website, scammers send direct messages to victims or attract them via posts or ads on social media. "Some individuals received an email or a phone call, while others were approached via social media or forums," the FBI <a href="https://www.ic3.gov/PSA/2025/PSA250418" target="_blank">explained</a>.</p><p>In the post, the FBI warns that attackers meet victims where they are, such as on Facebook, then quickly move them away to other, more secure channels like Telegram and connect them with other associates. </p><p>"The IC3 will not ask for payment to recover lost funds," the bureau warned, noting that victims should be weary of being contacted after reporting an attack. "If further information is needed, individuals will be contacted by FBI employees from local field offices or other law enforcement officers."</p><p>Victims who have either been attacked once, or attacked for a second time while trying to report the first attack, should report it via www.ic3.gov. The DOJ Elder Justice Hotline (1-833-FRAUD-11) also offers support for citizens aged 60+.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Estée Lauder says it was hit by data breach caused by Oracle E-Business issue ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/estee-lauder-says-it-was-hit-by-data-breach-caused-by-oracle-e-business-issue</link>
                                                                            <description>
                            <![CDATA[ The breach happened in August 2025, but was only spotted recently by Estée Lauder. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">695ZinBxapjgP7UfKHCgHW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 14:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Estée Lauder confirms Oracle E‑Business Suite breach from August 2025, only disclosed in June 2026</strong></li><li><strong>Attackers stole extensive personal, financial, health, and employment data from HR management platform</strong></li><li><strong>Breach tied to CVE‑2025‑61882, a critical Oracle EBS RCE flaw exploited across 100+ organizations</strong></li></ul><p>If you remember the Oracle E-Business Suite vulnerability that was exploited around October 2025 in numerous attacks, you can now add Estée Lauder to the list of victims.</p><p>The cosmetics giant has confirmed having been hit, despite the initial breach happening almost a year ago, following an investigation in mid-June 2026 uncovering the incident.</p><p>In a data breach notification letter that is now being sent out, the company said that “on June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.”</p><h2 id="major-remote-code-execution-flaw">Major remote code execution flaw</h2><p>Estée Lauder said the platform was used by the holding company “for HR management purposes.”</p><p>We don’t know exactly how many people are affected by this incident, but we do know that the attackers obtained full names, postal addresses, email addresses, dates of birth, Social Security numbers (SSN), passport numbers, financial account information (including bank account numbers), health information, and employment information.</p><p>This is more than enough data to run highly disruptive and damaging <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a> attacks, and Estée Lauder’s warning is of little help coming almost a year too late. </p><p>In early October 2025, cybercriminals started mailing executives at various American organizations, claiming to have stolen sensitive files from their <a href="https://www.techradar.com/pro/security/oracle-forced-to-rush-out-patch-for-zero-day-exploited-in-attacks" target="_blank">Oracle E-Business Suite systems</a>. At the time, both Oracle and the wider cybersecurity community were not certain if the breaches actually happened, or if this was just a bluff to get the victims to pay a ransom demand.</p><p>However, the claims were soon confirmed, since more than 100 organizations reported falling victim. In early October 2025, Oracle issued an emergency fix to patch CVE-2025-61882, a 9.8/10 (critical) pre-authentication remote code execution (RCE) vulnerability in Oracle EBS. </p><p>"This vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password," Oracle said in the advisory. "If successfully exploited, this vulnerability may result in remote code execution."</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-millions-of-wordpress-websites-could-be-at-risk-following-reveal-of-worrying-bugs</link>
                                                                            <description>
                            <![CDATA[ Hackers are chaining together two newly discovered flaws to achieve remote code execution. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">U7wqkXxvNQXgVKZKgfnjpJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WordPress patches two flaws: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch‑route confusion, critical severity)</strong></li><li><strong>When chained, the bugs enabled unauthenticated remote code execution, allowing full site takeover</strong></li><li><strong>Admins should urgently upgrade to WordPress 6.9.5 or newer to protect against widespread active attacks</strong></li></ul><p>Millions of WordPress websites could be at serious risk, researchers are warning, due to two recently patched vulnerabilities that are being actively exploited in the wild.</p><p>WordPress developers released a patch for two vulnerabilities - an SQL injection bug tracked as CVE-2026-60137, and a REST API batch-route confusion bug, tracked as CVE-2026-63030.</p><p>The former is a medium-severity, 5.9/10 vulnerability affecting WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2, while the latter is a critical-severity, 9.8/10 flaw affecting versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 of the world’s <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">most popular website builder</a>.</p><h2 id="exploitation-underway">Exploitation underway</h2><p>According to <a href="https://www.theregister.com/security/2026/07/20/attackers-pummel-critical-wordpress-vuln-to-create-all-sorts-of-mischief/5275265" target="_blank"><em>The Register</em></a>, these bugs are not that dangerous when looked at separately, since they are rather difficult to exploit. However, when chained together, they allow unauthenticated threat actors to execute malicious code remotely, which means full website takeover.</p><p>Security researchers at Knott say threat actors picked up on the scent rather quickly. </p><p>The patch was released on Friday, but “by the early hours of Saturday morning, successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public,” Knott said.</p><p>“From our vantage point across a global client base, we are seeing widespread impact of this vulnerability across organizations of every size and every vertical.”</p><p>It is worth mentioning that these vulnerabilities affect WordPress directly, instead of different plugins or themes. WordPress is by far the most popular website builder platform in the world, powering more than half of all websites in existence today. </p><p>To protect your assets, make sure to upgrade WordPress to version 6.9.5, since it contains fixes for both flaws. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top AI coding agents can be easy victims to sandbox escapes, showing they aren't as secure as they claim to be ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/top-ai-coding-agents-can-be-easy-victims-to-sandbox-escapes-showing-they-arent-as-secure-as-they-claim-to-be</link>
                                                                            <description>
                            <![CDATA[ What if a host component outside the sandbox reads AI coding agents' output?  And what if that output is manipulated? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kw8ZmedvEMwdBmxvXTp6AV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 11:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Pillar researchers demonstrated sandbox escapes in AI coding agents</strong></li><li><strong>Exploits let attacker‑written configs run with trusted host privileges</strong></li><li><strong>Agentic security needs its own threat model, researchers claim</strong></li></ul><p>AI coding agents can be tricked into turning on their operators and assisting attackers in compromising the underlying systems, experts have warned. </p><p>Cybersecurity researchers Pillar have <a href="https://www.pillar.security/blog/the-week-of-sandbox-escapes" target="_blank">examined</a> different methods of achieving the same results, finding that over the course of a couple of months, Cursor, Codex, Gemini CLI, and Antigravity were all able to reproduce sandbox escapes and boundary bypasses. </p><p>In theory, a threat actor could create a repository containing malicious content (for example, a README file, a dependency, or similar) and trick the developer into using it. The malicious instructions tell the agent to create or modify a project configuration file, but since everything happens inside the workspace, no alarms are triggered.</p><h2 id="fixing-the-problems">Fixing the problems</h2><p>Then, a host component outside the sandbox (Git integration, an IDE extension, or local daemon) reads that modified configuration, executing attacker-written commands. Consequently, the code now runs with the privileges of the trusted host component, rather than the restricted <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agent</a>. Voila - the original sandbox boundary is effectively bypassed. </p><p>Three of the four platforms mentioned in the report have fixed the disclosed issues, Pillar said. </p><p>Cursor patched multiple vulnerabilities in version 3.0.0, with one assigned CVE-2026-48124 and another tracked through a GitHub Security Advisory. Codex CLI fixed it in version 0.95.0 but stressed that it’s still awaiting a CVE. Gemini CLI was affected by the Docker daemon issue, which the report says has also been fixed through advisory GHSA-v4xv-rqh3-w9mc.</p><p>For Antigravity, Google acknowledged both reported sandbox bypasses as valid security findings but labeled them “Other valid security vulnerabilities” and downgraded their severity. Apparently - it considers exploitation rather difficult. </p><p>“When it comes to agents, the sandbox boundary that developers expect in coding tools -- one that keeps the agent inside the sandbox and the user outside -- breaks down,” Pillar concluded. “The boundary we kept finding was both messier and porous, because If an agent gets to write the future inputs of systems, it was never sandboxed in the first place.”</p><p>“This is why agentic security requires its own threat model.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'This one was different from anything we had handled before': Hugging Face confirms it was hit by cyberattack powered by an AI agent ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-one-was-different-from-anything-we-had-handled-before-hugging-face-confirms-it-was-hit-by-cyberattack-powered-by-an-ai-agent</link>
                                                                            <description>
                            <![CDATA[ There's a new twist to the old code injection attack, and this one comes with AI seasoning. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YGS9VwWfcoup7Aym62fv9a</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hugging Face discloses cyberattack where malicious code hidden in a dataset exploited flaws in its systems, enabling privilege escalation and credential theft</strong></li><li><strong>The incident was unique in being orchestrated end‑to‑end by an autonomous AI agent, which launched thousands of short‑lived sandboxes and migrated C2 infrastructure across public services</strong></li><li><strong>No customer data or public models were tampered with, but the attack highlights the emerging “agentic attacker” scenario long predicted by the industry</strong></li></ul><p>Hugging Face, one of the biggest platforms for artificial intelligence (AI) and machine learning (ML), disclosed recently suffering a cyberattack supercharged by an AI agent.</p><p>“This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own,” Hugging Face explained in its <a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank" rel="nofollow">announcement</a>, noting that the attackers hid malicious code inside a dataset, which they then uploaded to the platform. </p><p>When Hugging Face’s automated systems processed that dataset, they exploited two software flaws which allowed the attackers’ code to run on one of the company’s servers.</p><h2 id="orchestrated-by-an-autonomous-ai-agent">Orchestrated by an autonomous AI agent</h2><p>This twist to the classic code injection attack allowed the attackers to expand their privileges and gain more control over the system, steal authentication credentials to access Hugging Face’s cloud infrastructure, and pivot to other internal systems. </p><p>But carrying the attack out mostly with an AI agent is what made this incident unique, Hugging Face explained. </p><p>Instead of a human threat actor typing commands, Hugging Face believes the attack was orchestrated by an AI-powered autonomous agent which, entirely on its own, decided which systems to probe, which vulnerabilities to exploit, which credentials to steal, and how to move laterally throughout the compromised infrastructure. </p><p>“The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness - used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services,” Hugging Face explained. “This matches the "agentic attacker" scenario the industry has been forecasting.”</p><p>In other words, the agent kept launching thousands of temporary computing environments, making it extremely hard to stop the attack (since there isn’t a single machine to block). At the same time, the infrastructure controlling the malware kept moving, likely by using legitimate public cloud or online services. Therefore, when the defenders blocked one control server, the attacks would simply come from another. </p><p>Currently there is no evidence of tampering with customer data, public user-facing models, or Spaces.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Colombian energy giant Ecopetrol says thousands of user accounts hit in cyberattack ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/colombian-energy-giant-ecopetrol-says-thousands-of-user-accounts-hit-in-cyberattack</link>
                                                                            <description>
                            <![CDATA[ The Ecopetrol attackers demanded a ransom payment but did not deploy an encryptor. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tCkHsH74JScubYSNL54dfU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ecopetrol confirms ransomware attempt in which attackers stole data from 3,300 user accounts but failed to deploy the encryptor due to security controls</strong></li><li><strong>Stolen files were pseudonymous, with no user identities or credentials compromised; transactional systems and partner networks remained unaffected</strong></li><li><strong>The company ousted the attackers, launched an investigation, and notified Colombian authorities; no ransom demand details or data leaks have surfaced so far</strong></li></ul><p>Latin American energy producer Ecopetrol has revealed it was victim of a ransomware attack, and while the threat actors managed to get away with sensitive data from thousands of user accounts, they were unable to deploy the encryptor and thus disrupt the company’s day-to-day operations.</p><p>In a statement shared with the public, Ecopetrol explained how an unidentified threat actor accessed their IT infrastructure and pulled data from 3,300 user accounts. The attacker then proceeded to install an encryptor but was stopped by the company’s security controls. </p><p>Despite failing to deploy the encryptor, the threat actor still reached out to the company demanding payment. We don’t know how much money they asked for, in exchange for not sharing the stolen files. The database has not yet leaked, it seems, and no one claimed responsibility for the intrusion. At the same time, Ecopetrol says the stolen files are pseudonymous, suggesting that they might not be particularly useful to the attackers: </p><h2 id="notifying-the-authorities">Notifying the authorities</h2><p>“The identity of the users of the 3,300 accounts that were illegally infiltrated was not affected, nor were the respective user access credentials captured,” the machine-translated announcement reads. “Ecopetrol S.A. confirms that no compromises have been identified in the transactional technological solutions of its digital ecosystem, those of its subsidiaries, or those of its network of commercial allies, financiers, providers, and clients.”</p><p>Ecopetrol said that it managed to oust the attackers and stop further data exfiltration. It also launched an internal investigation and notified relevant authorities, including the Colombian Attorney General’s Office, the Joint Cyber Command of the Military Forces, and others. </p><p>The investigation remains ongoing.</p><p>Ecopetrol is Colombia's state-controlled oil and gas giant. It runs production, refining, transportation, and exploration operations, and is present in multiple countries, including Chile, Peru, and Bolivia. Its annual revenue is around $30 billion.</p><p><em>Via </em><a href="https://cybernews.com/news/ecopetrol-hack-colombia-ransom/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware attacks hit SMBs harder than ever as cybercrime gang rivalry heats up ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/ransomware-attacks-hit-smbs-harder-than-ever-as-cybercrime-gang-rivalry-heats-up</link>
                                                                            <description>
                            <![CDATA[ Qilin and The Gentlemen are going at it, at the expense of SMBs facing more attacks than ever. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KKX2w2hiPFkYjNm9d5Yc7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/H6MfM7T3bjECJuLWR6mD5a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 12:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/H6MfM7T3bjECJuLWR6mD5a-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/H6MfM7T3bjECJuLWR6mD5a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NordStellar reports 2,581 ransomware attacks in Q2 2026, with Qilin (299) and The Gentlemen (284) leading activity, far ahead of DragonForce (147)</strong></li><li><strong>US SMBs were hit hardest, suffering 769 incidents; Canada (97), Germany (83), and the UK (74) followed, while attacks on billion‑dollar enterprises surged 74%</strong></li><li><strong>Experts say rivalry between Qilin and The Gentlemen is driving the spike, with major corporate hits seen as reputation‑boosting trophies in the cybercriminal underground</strong></li></ul><p>Two ransomware gangs are battling for dominance, and US-based SMBs are the ones suffering most for it, experts have claimed.</p><p>Fresh data about the state of ransomware in 2026, compiled by security experts from NordStellar, shows two groups - Qilin and The Gentlemen - being by far the most active ones. </p><p>After analyzing more than 200 threat actor blogs, NordStellar concluded that there were 2,581 <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> attacks in the second quarter of the year - and of that number, 299 belong to Qilin, the most active threat actor out there. Close second are The Gentlemen, with 284 attacks. The third most active group - DragonForce - doesn’t even come close with “just” 147 attacks.</p><h2 id="smbs-and-enterprises-under-assault">SMBs and enterprises under assault</h2><p>While it seems like a close race, it’s actually The Gentlemen who have been doing the heavy lifting between April and June 2026. This group experienced a 39% increase in attacks, while Qilin’s activity actually declined somewhat, compared to Q1.</p><p>In this morbid race to the bottom, the biggest victims are US-based small and medium-sized businesses (SMB). These companies, with up to 200 employees and revenues under $25 million, experienced 769 attacks in Q2 2026, followed by Canada (97), Germany (83), and the UK (74). </p><p>NordStellar also mentioned US enterprises, who are now increasingly being targeted. Attacks against organizations with revenues north of $1 billion surged by 74%, going from 23 incidents in Q1, to 40 in Q2. </p><p>“Ransomware actors historically target SMBs because these organizations often lack comprehensive defenses, which can increase the likelihood of a successful attack,” commented Vakaris Noreika, cybersecurity expert at NordStellar. </p><p>“This recent spike in enterprise targeting is unusual and may be a temporary fluctuation. This shift likely stems from the rivalry between dominant threat actors — a successful hit on a major corporation is a badge of honor that boosts a group’s reputation within the cybercriminal underground."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ernst & Young reveals data breach following hack on support system ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/ernst-and-young-reveals-data-breach-following-hack-on-support-system</link>
                                                                            <description>
                            <![CDATA[ Someone pulled sensitive customer data from EY's servers, but the data is yet to surface anywhere. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cP6va4FhPF6yEA9zg8rxz4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 11:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Representational image of a cybercriminal]]></media:text>
                                <media:title type="plain"><![CDATA[Representational image of a cybercriminal]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ernst & Young confirms breach via a third‑party IT service management platform, exposing client tax data between March 28 and April 12, 2026</strong></li><li><strong>Attackers accessed documents tied to tax support tickets; exact scope and affected clients remain undisclosed, with no dark web leaks or group claims so far</strong></li><li><strong>EY activated incident response, secured systems, and is offering 24 months of Experian identity monitoring to impacted customers</strong></li></ul><p>Ernst & Young (EY) has confirmed suffering a cyberattack in which it lost sensitive customer information, including tax data.</p><p>In a data breach notification letter sent to affected individuals, the firm said that on April 23, 2026, it spotted “anomalous activity” within a third-party platform its IT team uses. This is an IT service management platform that helps EY staff support the teams that perform tax-related work for clients. Therefore, the tickets submitted through this platform sometimes also contain documents with client tax information which may have been exposed in the incident.</p><p>EY then activated its incident response protocols, bringing in third-party cybersecurity experts, as well as notifying relevant authorities and affected clients. </p><h2 id="free-identity-theft-protection">Free identity theft protection</h2><p>Further investigation determined that the unnamed threat actors broke in on March 28, 2026 and have, until April 12, been exfiltrating the files. EY did not say exactly which information was pulled, or how many clients were affected. We also don’t know if this only pertains to US clients, or overseas ones, as well. The attackers have, since then, been removed from EY’s virtual premises, and the systems have been secured, the company confirmed. </p><p>So far, no hacking groups claimed responsibility for this attack, and the data is yet to surface anywhere on the dark web. EY’s customers should be on the lookout for unsolicited emails, especially those claiming to be from the professional services giant. </p><p>To help them stay secure, EY is offering 24 months of <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">free identity monitoring</a> and restoration services through Experian. </p><p>Ernst & Young is one of the "Big Four" largest professional services and accounting networks in the world. It is headquartered in London, but operates as a global network of independent members spanning more than 150 countries and employing more than 400,000 people. The company’s core business includes assurance, tax, consulting, and M&A strategy.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'The bypass is still six lines of JavaScript': Security experts warn that Claude for Chrome browser extension could be hijacked, despite it alerting Anthropic several times that something was wrong ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/the-bypass-is-still-six-lines-of-javascript-security-experts-warn-that-claude-for-chrome-browser-extension-could-be-hijacked-despite-it-alerting-anthropic-several-times-that-something-was-wrong</link>
                                                                            <description>
                            <![CDATA[ Researchers found Claude’s Chrome extension still contains vulnerabilities allowing fake clicks and permission bypasses despite Anthropic releasing multiple updates. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MgcPS4oDejjXRzT9jygM9c</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sun, 19 Jul 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Claude]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1280-80.png">
                                                            <media:credit><![CDATA[Anthropic]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Claude Chrome]]></media:description>                                                            <media:text><![CDATA[Claude Chrome]]></media:text>
                                <media:title type="plain"><![CDATA[Claude Chrome]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Anthropic’s Claude extension flaws allow fake clicks to launch sensitive AI workflows</strong></li><li><strong>Researchers found vulnerable handlers unchanged across eight extension updates</strong></li><li><strong>Synthetic clicks bypassed checks designed to confirm real user actions</strong></li></ul><p>Security researchers at Manifold Security have claimed Anthropic's Claude for <a href="https://www.techradar.com/computing/chrome/these-are-the-10-best-chrome-extensions-of-2025-according-to-google-and-theres-one-i-definitely-recommend">Chrome browser extension</a> contains two unpatched vulnerabilities in version 1.0.80, released July 7, 2026.</p><p>According to <a href="https://www.manifold.security/blog/claude-for-chrome-extension-bypass">Manifold Security</a>, it first reported both vulnerabilities to Anthropic through the company's bug bounty program on May 21, 2026, and received acknowledgment the following day.</p><p>The first flaw lets any browser extension trigger nine predefined Claude workflows by simulating a synthetic user click on claude.ai.</p><h2 id="nine-workflows-and-one-missing-check">Nine workflows and one missing check</h2><p>Researcher Ax Sharma found that the extension never verified whether a click event carried the Event.isTrusted property before acting on it.</p><p>Under default settings, the vulnerability received a CVSS score of 7.7 High, increasing to 9.6 Critical when users enabled automatic execution because Claude could perform actions without approval.</p><p>The nine hardcoded tasks include reading Gmail, opening Google Docs, checking Google Calendar, and modifying Salesforce leads without asking.</p><p>Because the <a href="https://www.techradar.com/best/browser">browser</a> marks synthetic clicks as untrusted, the extension should have rejected them but instead executed the workflow anyway.</p><p>Manifold Security confirmed on July 7 2026 that both vulnerabilities still work against version 1.0.80, months after first reporting them to Anthropic.</p><p>Anthropic released eight separate versions between 1.0.73 and 1.0.80 without altering the specific handlers’ researchers had already flagged as vulnerable.</p><p>The company closed the synthetic-click report, saying an existing internal report already tracked the broader trust-boundary issue researchers had described in detail.</p><p>However, Sharma believes the fix required only one additional line of code to verify the click event's isTrusted property before allowing the workflow to continue.</p><h2 id="a-second-structural-weakness">A second, structural weakness</h2><p>A second flaw involves a side-panel URL parameter called skipPermissions, which can activate a privileged mode without any consent prompt.</p><p>When the parameter is set to true, the panel begins skipping permission checks entirely, allowing Claude to act without asking the user first.</p><p>Manifold notes that only Anthropic's own scheduled-task feature is supposed to construct this kind of privileged URL internally right now.</p><p>The panel, however, honours that parameter regardless of which script or page actually constructed the originating URL string in practice.</p><p>One example task lets Claude read a user's Gmail inbox, identify promotional messages, and automatically click the unsubscribe links inside them.</p><p>Manifold warns that "the bypass is still six lines of JavaScript," months after researchers first flagged the underlying issue to Anthropic.</p><p>Anthropic classified this second finding as informational, arguing that the parameter is only ever constructed by its own internal systems.</p><p>Manifold said the content-script and side-panel code linked to both vulnerabilities remained byte-identical across the eight subsequent extension releases examined after the original report.</p><p>The flaws were also reproduced across Claude's Opus, Sonnet, and Fable side-panel model selections, indicating that the issue affected the extension's security design rather than the underlying artificial intelligence models.</p><p>The report also connected the findings with OWASP concerns involving LLM01: Prompt Injection and LLM06: Excessive Agency risks in AI applications.</p><p>The researchers noted that abuse involving <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> may remain difficult to detect because normal browser activity and network connections can appear unchanged while unauthorized AI actions occur.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'macOS users may face real, sophisticated threats that require neither exploits nor any elevated access to succeed': ClickLock Stealer tries to trick Apple users into revealing their passwords ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/macos-users-may-face-real-sophisticated-threats-that-require-neither-exploits-nor-any-elevated-access-to-succeed-clicklock-stealer-tries-to-trick-apple-users-into-revealing-their-passwords</link>
                                                                            <description>
                            <![CDATA[ ClickLock bores its victims into complying and then steals all sorts of data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rTfuMcJQcWwgFKNJxEtbqi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB uncovers ClickLock, a new macOS‑focused infostealer using aggressive social engineering by spamming password prompts and terminating key apps every 210ms until victims comply</strong></li><li><strong>Once credentials are obtained, it exfiltrates browser data, crypto wallets, password manager entries, FTP configs, and device info via Telegram Bot API</strong></li><li><strong>Active since May 2026, spotted in 33 countries (mostly Europe), distributed via ClickFix campaigns, and initially undetected by security vendors until recently</strong></li></ul><p>Security researchers from Group-IB have uncovered a new infostealer targeting primarily macOS users in Europe.</p><p>Dubbed <a href="https://www.group-ib.com/blog/clicklock-stealer-macos-malware/" target="_blank">ClickLock</a>, it is more of an annoying social engineering mechanism rather than a full-blown malware variant, constantly popping up a login prompt on the victim’s device, until they finally comply and share the credentials. </p><p>Every 210 milliseconds it terminates key apps on the device (Finder, Dock, TErminal, etc.), essentially making it useless. At the same time, it keeps prompting a password dialog on the screen, making sure the victim can do nothing but provide the credentials.</p><h2 id="targeting-europeans">Targeting Europeans</h2><p>The loop is set to continue for more than three straight days, or until the victim folds. </p><p>After getting the keys to the kingdom, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> gets to work and starts exfiltrating valuable information.</p><p>This includes data from key <a href="https://www.techradar.com/best/browser" target="_blank">browsers</a> (Chrome, Firefox, Brave, and others), saved logins, cookies, autofill data, and other browser information, data linked to cryptocurrency wallets and extensions, encrypted wallet vault material that can be cracked off-site, data from <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, cached cryptocurrency addresses across EVM, Bitcoin, Solana, TRON, TON, and Stacks, shell histories, FileZilla FTP configuration and recent-server data, and basic device information.Everything is then packaged into a .ZIP archive and exfiltrated via a Telegram Bot API.</p><p>Group-IB says the campaign has been active since at least May 2026, so it’s been active for a few months now. A researcher submitted a variant to VirusTotal in early June, but it remained undetected by all security vendors until recently, Group-IB says.</p><p>So far, it has been spotted in 33 countries, more than half of which are in Europe, it was also added. The malware is most likely being distributed via a ClickFix social engineering campaign, and has not been tied to any particular threat actor. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous new GoSerpent malware is apparently on the hunt for government secrets ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/dangerous-new-goserpent-malware-is-apparently-on-the-hunt-for-government-secrets</link>
                                                                            <description>
                            <![CDATA[ The malware has been hiding in plain sight for half a decade, stealing all sorts of valuable secrets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vjht9Nb5f4HTL3RNE3U26G</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:description>                                                            <media:text><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:text>
                                <media:title type="plain"><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kaspersky uncovers GoSerpent, a long‑running campaign on Southeast Asian government systems using a backdoor, RAT (Stowaway), and exfiltration tool (TmcLoader)</strong></li><li><strong>Attackers showed extreme patience, waiting weeks before deploying secondary tools to evade detection and outlast log retention policies</strong></li><li><strong>Attribution remains uncertain, but overlaps with past TetrisPhantom operations; defenders are urged to review shared IoCs to detect compromise</strong></li></ul><p>Security researchers Kaspersky discovered a five-year-old piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that’s been hiding on government computers in the Southeast Asian region, harvesting secrets and other actionable intelligence.</p><p>The company analyzed a campaign called GoSerpent, which comprises of a backdoor of the same name, a Remote Access Trojan (RAT) called Stowaway, and a two-stage data exfiltration tool called TmcLoader.</p><p>The backdoor was first used in 2021, it was said, meaning it was successfully hiding for half a decade. This was achieved, among other things, with plenty of patience and careful planning.</p><h2 id="tetrisphantom">TetrisPhantom</h2><p>“What stands out about GoSerpent is the deliberate dwell time,” Noushin Shabab, Lead Security Researcher in Kaspersky GReAT, explained. </p><p>“Usually, attackers want to move quickly once they get a foothold, but this group drops the initial backdoor and waits. They let the dust settle for weeks before deploying their secondary exfiltration tools like TmcLoader. That kind of patience is a calculated move designed to outlast standard log retention policies and automated security sweeps, making it incredibly difficult for defenders to connect the initial infection to the eventual data theft." </p><p>The researchers could not conclusively attribute this campaign to any particular threat actor but did say that it has a lot in common with older campaigns conducted by the TetrisPhantom actor, including victimology, technical capabilities, and operational methods. </p><p>Kaspersky analyzed TetrisPhantom back in 2023, when it saw the group compromising <a href="https://www.techradar.com/pro/security/dangerous-new-malware-can-crack-encrypted-usb-drives" target="_blank">secure USB drives</a> used to provide encryption for safe data storage. This campaign also targeted government entities in the Asia-Pacific region (APAC) but, at the time, it was a newly discovered threat actor with no overlap with other known groups. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Europe’s tech reset gives the UK a chance to lead on security and sovereignty ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/europes-tech-reset-gives-the-uk-a-chance-to-lead-on-security-and-sovereignty</link>
                                                                            <description>
                            <![CDATA[ The UK has a profound opportunity to become a trusted partner for secure, resilient digital infrastructure. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">X4NFAykiUYZKgHPbDk2wQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 14:26:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Knibbs ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/TippaPatt]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:description>                                                            <media:text><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:text>
                                <media:title type="plain"><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Across Europe, “tech sovereignty” is rising up the agenda. For business leaders, however, the implications are practical rather than political. At its core, sovereignty is about control, resilience and trust in the systems that underpin modern operations.</p><p>The European Commission’s recently announced technology sovereignty package reflects this shift. With proposals including the Chips Act 2.0, the Cloud and AI Development Act, an EU Open-Source Strategy and a Strategic Roadmap for Digitalisation and AI in Energy, it is intended to strengthen Europe’s digital independence and resilience.</p><p>That matters because <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> is now vital infrastructure. Cloud platforms, connectivity, AI systems and cyber security capabilities are becoming as essential to economic growth and national stability as energy and transport networks.</p><p>For years, digital transformation was driven by globalization, scale and efficiency, with organizations prioritizing rapid innovation, cost optimization and access to global technology ecosystems. </p><p>But cyber-attacks, regulatory divergence and geopolitical uncertainty have exposed a fundamental reality: efficiency without resilience creates fragility.</p><h2 id="from-efficiency-to-resilience">From efficiency to resilience</h2><p>Today, organizations are focused not only on whether systems can withstand cyber-attacks, but whether they can keep operating if a provider, jurisdiction or supply chain becomes unavailable.</p><p>Protection and prevention remain essential. But resilience also depends on where systems are hosted, who controls critical infrastructure, how data moves across jurisdictions and whether essential services can be restored quickly during disruption.</p><p>Sovereignty is best understood as the ability to continue functioning with confidence when external conditions change. This is particularly relevant for organizations delivering critical services. </p><h2 id="why-this-matters-for-the-uk">Why this matters for the UK</h2><p>The UK faces many of the same pressures as Europe: rising cyber threats, tighter regulation and rapid AI adoption. But it also has real strengths, including a mature <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cyber security</a> sector, world-leading professional services expertise, and a strong reputation for governance and innovation.</p><p>Those strengths give the UK a significant opportunity to position itself as a trusted partner for secure, resilient digital infrastructure. Realizing it, however, will require continued investment in infrastructure, skills and technology ecosystems.</p><p>The UK already has strong foundations. Within Vodafone Business, for example, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> services for government and defense customers date back to 1989, underlining the long-term importance of trusted communications and secure operations.</p><h2 id="sovereignty-must-include-ai">Sovereignty must include AI</h2><p>The sovereignty conversation is no longer limited to networks, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud computing</a> infrastructure or cyber security; it now extends to AI itself.</p><p>The UK government’s recent £400 million commitment to next-generation AI chips reinforces that ambition and signals a more deliberate push to build sovereign capability in the technologies that will underpin future competitiveness and resilience. </p><p>Government investment in sovereign computing capability and broader AI infrastructure also signals recognition that access to advanced computing resources is becoming a strategic national asset.</p><p>This matters because AI is rapidly becoming foundational infrastructure. Organizations are embedding it into business operations, cyber security programs, customer engagement and decision-making.</p><p>For businesses, sovereignty is not about limiting innovation. It is about ensuring critical capabilities can be developed, governed and accessed in ways that support long-term economic resilience and trust.</p><h2 id="connectivity-as-critical-infrastructure">Connectivity as critical infrastructure</h2><p>One of the most important and often overlooked aspects of sovereignty is connectivity. As organizations rely more on AI services, IoT devices and real-time data exchange, networks become the foundation of operational resilience.</p><p>If connectivity fails, everything built on it is affected, from customer services and supply chains to communications and core business operations.</p><p>That is why investment in secure, resilient, high-capacity networks is central to the sovereignty debate. Without trusted connectivity, digital sovereignty remains theoretical rather than practical.</p><p>The formation of VodafoneThree is a significant step in strengthening the UK’s digital backbone. With a commitment to invest £11 billion in next-generation connectivity and an ambition to deliver 99.96% population coverage by 2034, the UK is building infrastructure to support future growth and resilience.</p><p>As AI workloads, edge computing, hybrid working and data-intensive applications expand, resilient connectivity becomes a strategic national asset.</p><p>This is particularly important for organizations delivering essential services. Today, 77% of UK Blue Light services already run on Vodafone Business networks, underlining the growing importance of trusted connectivity in critical operations.</p><h2 id="a-strategic-moment-for-the-uk">A strategic moment for the UK</h2><p>Europe’s emerging sovereignty agenda should not be mistaken for digital isolation. Rather, it reflects a growing recognition that interdependence must be understood, managed and secured.</p><p>For security leaders, that means broadening the conversation beyond traditional threat protection to include critical dependencies, digital supply chain resilience and operational continuity. Cyber security is increasingly part of a wider discipline of digital resilience, where security, connectivity, infrastructure and governance converge.</p><p>By combining cyber security expertise, growing sovereign AI capabilities, regulatory strengths and continued investment in connectivity, the UK has an opportunity to establish itself as Europe’s trusted security ally.</p><p>In the next phase of digital transformation, success will not belong only to those with the most advanced technology, but to those with the most trusted, resilient and transparent foundations.</p><p>The sovereignty economy is already taking shape. The question is whether the UK chooses simply to participate in it, or to help define it.</p><p><em></em><a href="https://www.techradar.com/best/best-business-cloud-storage-service"><em>We've reviewed and rated the best business cloud storage services</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Claude can now enter all your passwords for you - if you give it permission ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/claude-can-now-enter-all-your-passwords-for-you-if-you-give-it-permission</link>
                                                                            <description>
                            <![CDATA[ 1Password partnership will mean Claude will never see the secrets or load them into its own memory. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gESvv4V9PcQSPAyMJnfqm6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg">
                                                            <media:credit><![CDATA[Anthropic]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mobile phone displaying a Claude login screen.]]></media:description>                                                            <media:text><![CDATA[Mobile phone displaying a Claude login screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Mobile phone displaying a Claude login screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>1Password unveils Claude partnership, letting Anthropic’s AI authenticate on users’ behalf via zero‑exposure architecture</strong></li><li><strong>Users approve each login with biometrics</strong></li><li><strong>New Agentic Mode in the browser extension locks down the interface when AI agents take over</strong></li></ul><p>Top <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager</a> company 1Password has launched a new tool that allows artificial intelligence assistant Claude to authenticate on behalf of their user, and thus complete assignments that were previously impossible without major security tradeoffs.</p><p><a href="https://1password.com/blog/1password-for-claude" target="_blank" rel="nofollow">1Password for Claude</a> is built on “zero-exposure architecture” - so in practice, it means Claude can essentially ask 1Password to complete the sign-in process, but it will never see the credentials, and they will never be loaded into its memory. </p><p>In turn, 1Password will notify the user, and will request biometric approval before proceeding. Once granted, it will autofill the credentials and check to see if they were exposed on the page or not. If submission fails, it will clear the filled values and report back. </p><h2 id="agentic-mode">Agentic Mode</h2><p>"We need a new security model that is purpose-built for agents, not just humans,” said Nancy Wang, CTO of 1Password. “The answer isn't handing agents your secrets. It is to let a user give an agent permission to use a credential without letting the agent see it. Claude knows it used your login; it does not need the password or one-time code in its context. That distinction is where trust in agents starts and the foundation we're building with Anthropic."</p><p>To further strengthen its security posture, 1Password also announced Agentic Mode, a new feature in the browser extension that gives users visibility and control over browser-based <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>. When a compatible AI agent takes over, the 1Password extension automatically locks down and hides the interface. The agent can only use the logins and OTPs explicitly approved for the current task. </p><p>Even if the integration is not set up, and even if 1Password is not required for the current agentic task, Agentic Mode works, the company stressed. Other agents, besides Claude, are supported, as well. </p><p>Currently a major debate is ongoing, about how much permissions AI agents should receive, and under what rules. We’ve already seen horror stories of AI agents deleting people’s entire email inboxes, or otherwise ruining days of hard work. Whether or not this picks up or most people remain skeptical about giving AI access to certain services, remains to be seen. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Coca-Cola shuts down Fairlife dairy production lines following ransomware attack ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/coca-cola-shuts-down-fairlife-dairy-production-lines-following-ransomware-attack</link>
                                                                            <description>
                            <![CDATA[ Coca-Cola confirms ransomware attack on Fairlife in an 8-K form filed with the SEC. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">98MXZYAA7TvT8EPNELLnKY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SPwVn22r6XRNTeSZsKjoTB-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/SPwVn22r6XRNTeSZsKjoTB-1280-80.png">
                                                            <media:credit><![CDATA[Coca-Cola]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI squirrels look at Coca-Cola trucks]]></media:description>                                                            <media:text><![CDATA[AI squirrels look at Coca-Cola trucks]]></media:text>
                                <media:title type="plain"><![CDATA[AI squirrels look at Coca-Cola trucks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SPwVn22r6XRNTeSZsKjoTB-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Coca‑Cola confirmed a ransomware attack on its dairy subsidiary Fairlife, forcing suspension of US production operations while Canada sites remain unaffected</strong></li><li><strong>Incident response protocols were activated, with third‑party experts and authorities engaged; product quality and safety were not impacted</strong></li><li><strong>Analysts warn the financial impact could be significant given Fairlife’s importance, with losses compounding the longer production remains offline</strong></li></ul><p>Coca Cola was forced to shut down parts of its operations to tackle an ongoing ransomware infection.</p><p>In an 8-K form recently filed with the US Securities and Exchange Commission (SEC), the company said the attackers struck Fairlife, its dairy company.</p><p>“On July 16, 2026, The Coca-Cola Company announced that fairlife, a dairy company owned by the company, identified unauthorized access by a third party to a portion of its systems, including its production-related systems, in connection with a <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> event,” the filing reads.</p><h2 id="compounding-impact">Compounding impact</h2><p>Coca Cola then explained that it kicked off its incident response and business continuity protocols, bringing in third-party cybersecurity experts to help investigate the attack and assess the damages. It also notified relevant authorities.</p><p>However, the production in the US has been affected, since parts of the operation had to be suspended: “Product quality and safety have not been impacted. However, as a result of the incident, production operations at fairlife in the United States are temporarily suspended. fairlife’s Canada production operations are not currently impacted,” Coca Cola explained.</p><p>It said it was now working to bring the systems back up, and that it has “not yet determined whether the incident is reasonably likely to materially affect the company.”</p><p>In a statement shared with TechRadar Pro, Cybersecurity Researcher and Advanced Services Lead at Arcova, Joseph Perry, stressed that the material impact is likely to be great. How great - depends on how fast Coca Cola moves. </p><p>“Fairlife is not a minor business buried inside Coca-Cola’s portfolio. Coca-Cola generated nearly $48 billion in net revenue last year and made a $6.1 billion contingent payment tied to its acquisition of fairlife, which provides important context for the value of the operation now sitting idle,” Perry explains. </p><p>“With production suspended across fairlife’s US facilities, every hour can compound the financial impact through lost output, delayed shipments, recovery costs, inventory exposure and potential disruption for retailers. Coca-Cola has not yet quantified the loss, but the longer production remains offline, the more quickly a cyber incident becomes a material business event.”</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/coca-cola-says-fairlife-ransomware-attack-halts-us-dairy-production/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Teenage TfL hackers sentenced to years in prison following Scattered Spider attacks ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/teenage-tfl-hackers-sentenced-to-years-in-prison-following-scattered-spider-attacks</link>
                                                                            <description>
                            <![CDATA[ Two young men pleaded guilty to hacking into Transport for London in 2024 and were given long prison sentences. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SLBSG4pbDpZE9xtCXUuJpP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 11:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Two UK men sentenced to 5 years and 6 months for the 2024 cyberattack on Transport for London, linked to the Scattered Spider group</strong></li><li><strong>Police seized devices showing evidence of the TfL breach; Flowers was also mid‑attack on US healthcare firms SSM Health and Sutter Health at the time of arrest</strong></li><li><strong>TfL reported $39M in damages; the NCA says the sentencing effectively dismantled Scattered Spider, with Microsoft confirming the arrests degraded the group’s operations</strong></li></ul><p>Two young men, one aged 20 and the other 18, have been sentenced to five years and six months in prison for their involvement in the <a href="https://www.techradar.com/pro/security/tfl-admits-2024-cyberattack-may-have-affected-over-10-million-people-personal-customer-info-stolen-heres-what-we-know-so-far">cyberattack on Transport for London (TfL)</a> in 2024.</p><p>Thalha Jubair, from East London, and Owen Flowers, from Walsall, West Midlands were arrested in 2025 under the suspicion that they were the leading members of <a href="https://www.techradar.com/pro/security/fbi-cisa-warn-of-more-scattered-spider-attacks-to-come">Scattered Spider</a> - an infamous hacking collective known for breaching dozens of companies. Initial reports from different cybersecurity organizations claimed the group consisted mostly of teenagers whose native language was English. </p><p>During the arrest, the police seized different types of electronic equipment from the suspects, including laptops, PCs, smartphones, hard drives, removable storage, and more. On one of the computers, law enforcement found screenshots and videos showing the intrusion into TfL’s systems.</p><h2 id="millions-in-damages">Millions in damages</h2><p>To make matters even worse, Flowers was in the middle of breaking into US healthcare companies SSM Health Care Corporation and Sutter Health when he was arrested: According to the National Crime Agency (NCA), these two were already “infiltrated and damaged”.</p><p>The attack on TfL was one of the more disruptive incidents that year, and one which caused a lot of financial damage, too. According to a report TfL shared with the City of London Police (CoLP), it suffered around $39 million in loss and recovery costs.</p><p>Both Jubair and Flowers initially pleaded not guilty and changed their pleas to guilty on the day they were due to stand trial, it was said. Now, they are both sentenced to more than five years in jail. The NCA says these arrests and sentencing effectively dismantled the notorious hacking collective.</p><p>“Although other cybercriminals may continue to use the damaged Scattered Spider brand, the NCA’s action against Jubair and Flowers effectively halted the group’s criminal activity,” the NCA said in its <a href="https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case" target="_blank" rel="nofollow">report</a>. </p><p>“Independent assessment supports this, with Microsoft confirming that the arrests materially degraded the group's ability to continue conducting cybercriminal operations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft nemesis returns with another zero-day PoC — but is 'LegacyHive' as nasty as expected? ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/microsoft-nemesis-returns-with-another-zero-day-poc-but-is-legacyhive-as-nasty-as-expected</link>
                                                                            <description>
                            <![CDATA[ Chaotic Eclipse is back with a new Windows 11 zero-day called LegacyHive. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">437WE24R6f5RrojuCvuFfS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HCMx4u3U8KVpNCqssJps2J-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HCMx4u3U8KVpNCqssJps2J-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/Ham patipak]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A laptop with the Windows 11 desktop on screen, glowing, while on a work desk ]]></media:description>                                                            <media:text><![CDATA[A laptop with the Windows 11 desktop on screen, glowing, while on a work desk ]]></media:text>
                                <media:title type="plain"><![CDATA[A laptop with the Windows 11 desktop on screen, glowing, while on a work desk ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HCMx4u3U8KVpNCqssJps2J-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researcher “Chaotic Eclipse” releases new Windows 11 zero‑day dubbed </strong><em><strong>LegacyHive</strong></em><strong>, a local privilege escalation bug targeting user registry hives</strong></li><li><strong>Exploit could let attackers elevate low‑privileged accounts, but requires prior device access; no CVE or full PoC was published</strong></li><li><strong>Experts caution that skilled actors could weaponize it quickly, urging intelligence teams to prepare mitigations despite lower perceived impact than earlier releases</strong></li></ul><p>Chaotic Eclipse, the infamous security researcher with a Microsoft grudge, did as they previously promised and released yet another zero-day vulnerability for fully patched Windows 11 devices. </p><p>However, other researchers don’t see it as dangerous as some of their previous releases.</p><p>Chaotic Eclipse disclosed a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">zero-day</a> called LegacyHive, which is a local privilege escalation (LPE) bug targeting Windows’ user hives.</p><h2 id="escalating-privileges">Escalating privileges</h2><p>A few months ago, a hacker/researcher with the alias Chaotic Eclipse started publishing functioning exploits for fully patched Windows 11 systems, all with PoCs, claiming that Microsoft acted against them in ill faith and argued that the company does not treat researchers with the respect they deserve.</p><p>They released a total of <a href="https://www.techradar.com/pro/security/the-exact-same-issue-that-was-reported-to-microsoft-by-google-project-zero-is-actually-still-present-unpatched-chaotic-eclipse-strikes-again-with-another-worrying-windows-security-flaw" target="_blank">seven exploits</a>, some more damning than others, and promised to release a “bone-shattering” one on July 14 2026. In the meantime, Microsoft first criticized the researcher for not “responsibly” disclosing the flaws, and at one point even threatening possible legal action. However, it did not sue the researcher and later backed away from the threat entirely, partly as a result of strong public backlash.</p><p>In Windows, user hives are registry files that store configuration settings specific to an individual user account. These include desktop preferences, user-specific application settings, network drive mappings, user-specific security and privacy settings, and more. </p><p>With LegacyHive, threat actors could, in theory, gain privileged read-write access targeting other users’ hives. Or, in other words, they could turn low-privileged accounts into high-privileged ones. However, they would first need to have any access to the device, which is one of the reasons why some security researchers don’t see it as disastrous as Chaotic Eclipse’s previous work.</p><p>What also makes LegacyHive different from some other releases is that this one was not released with a CVE identifier or a fully functioning Proof of Concept (PoC). </p><p>Still, security experts are urging intelligence teams to work fast, because skilled threat actors can fill the gaps with relative ease, and turn LegacyHive into a potent weapon.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/07/15/microsofts-serial-tormentor-drops-legacyhive-0-day/5271723" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian hacker turns Gemini CLI into a hacking agent, creates small-scale botnet ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/russian-hacker-turns-gemini-cli-into-a-hacking-agent-creates-small-scale-botnet</link>
                                                                            <description>
                            <![CDATA[ The hacker told the AI he was an authorized pentester - and the AI believed him. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2aLD452X3VLZeF4n8MnsB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:description>                                                            <media:text><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:text>
                                <media:title type="plain"><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Russian hacker “bandcampro” used Google’s Gemini CLI to control an eight‑device botnet at a dental clinic</strong></li><li><strong>The attacker tricked the AI by posing as a pen tester, directing it to migrate C2 infrastructure, troubleshoot connectivity, and prepare payload bundles</strong></li><li><strong>The AI assisted with daily operations like password guessing and WordPress access, highlighting risks of misuse when threat actors co‑opt AI tools</strong></li></ul><p>A Russian hacker and his AI companion were able to successfully control a miniature, eight-system botnet, with the hacker giving instructions in conversational language, and the AI doing his bidding, experts have found.</p><p>Analyzing 200 session logs obtained from the Russian-speaking threat actor known as “bandcampro”, cybersecurity researchers Trend Micro saw the hacker use Google’s Gemini CLI, an open source AI command-line tool that lets developers interact with Google's <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">Gemini AI</a> models directly from a terminal. </p><p>Scouring through a month’s worth of session logs (between April 21 and May 19 2026), the researchers discovered that the attacker tricked the AI by telling it they were an “authorized pen tester”. While the AI mostly complied with their nefarious overlord, they refused the orders on at least one occasion.</p><h2 id="gone-in-six-minutes">Gone in six minutes</h2><p>Trend Micro found the hacker controlled eight devices belonging to a dental clinic and sought to access their access their OpenDental database.</p><p>Using the AI, bandcampro did a number of things, starting with migrating the botnet to a new C2 infrastructure. He gave the AI a skill file with the full architecture description, standard operating procedures, infection one-liner, persistence commands, and troubleshooting steps.</p><p>He then told it to “study the C2 migration”, which had the AI process the guide and prepare all the code and necessary steps. It took the tool around six minutes to get the job done. </p><p>"The AI read the migration guide, then prepared a migration bundle, a small archive of server code, payloads, and the skill file. It then unpacked the bundle, launched the C&C server on a VPS, and brought up the Cloudflare tunnel," Trend Micro says.</p><p>Bandcampro then used the AI to troubleshoot connectivity issues, as well as for various daily operations, such as guessing passwords, generating plausible variants of existing passwords for WordPress portals, and more.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-operator/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thousands of US military beneficiaries have data breached following TRICARE cyberattack — DoD Benefits Numbers and some Social Security numbers leaked ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/thousands-of-us-military-beneficiaries-have-data-breached-following-tricare-cyberattack-dod-benefits-numbers-and-some-social-security-numbers-leaked</link>
                                                                            <description>
                            <![CDATA[ TriWest suffers an attack and loses TRICARE data on some 12,000 people. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sKjC3VLGBvQgwi3mgFXgtj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:description>                                                            <media:text><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:text>
                                <media:title type="plain"><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>TriWest Healthcare confirmed an April 16 breach in which an attacker accessed and downloaded sensitive data tied to 12,000 TRICARE beneficiaries</strong></li><li><strong>Stolen information includes names, DoD Benefits numbers, ZIP codes, authorization request types, and in some cases SSNs, addresses, and dates of birth</strong></li><li><strong>TriWest says it acted immediately to contain the intrusion and notify affected individuals; no group has claimed responsibility and stolen data has not surfaced online</strong></li></ul><p>US healthcare services company TriWest Healthcare networks recently suffered a cyberattack in which it lost sensitive customer data belonging to thousands of its clients’ users.</p><p>TriWest is a private company that manages government healthcare programs, primarily on behalf of the US Department of Defense (DoD) and the Department of Veterans Affairs (VA). One of its clients is TRICARE, a DoD healthcare program for active-duty service members, National Guard and Reserve members, military retirees, and their families. </p><p>According to Cybernews, TriWest recently started notifying TRICARE customers that an “unauthorized person” accessed its network on April 16 and “downloaded some TriWest information.” Citing data provided to the California State Attorney General’s Office, the publication says 12,000 TRICARE beneficiaries were recently notified of the breach.</p><h2 id="sounding-the-alarm">Sounding the alarm</h2><p>In a statement shared with <a href="https://www.moaa.org/content/publications-and-media/news-articles/2026-news-articles/benefits/nearly-12,000-tricare-beneficiaries-warned-of-data-breach/" target="_blank"><u>Military Times</u></a>, TriWest explained what it did the moment it spotted the intrusion: “With regard to timing, as soon as the incident was discovered, TriWest took immediate action to prevent any further unauthorized activity and worked diligently with the government to notify affected individuals, consistent with applicable law and notification timelines,” TriWest officials said.</p><p>The details about the incident, the nature of the attack, or the identity of the attackers, were not disclosed. We do know that the miscreants walked away with people’s names, DoD Benefits numbers, ZIP codes, types of authorization requests and, in some cases, Social Security numbers (SSN), postal addresses, and dates of birth.</p><p>At press time, the TriWest website, as well as the company’s newsroom, were offline. It is unclear if there is any connection to the data breach. So far, no threat actors claimed responsibility for the attack, and the data is yet to surface on the dark web.</p><p>In the meantime, TRICARE beneficiaries are warned to be wary of incoming emails, especially those claiming to come from the program or the company.</p><p><em>Via </em><a href="https://cybernews.com/news/tricare-west-health-data-breach-military-beneficiaries/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zoom patches critical security flaw which could have let hackers hijack accounts ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/zoom-patches-critical-security-flaw-which-could-have-let-hackers-hijack-accounts</link>
                                                                            <description>
                            <![CDATA[ Zoom finds improper input validation bug, but fortunately sees no evidence of abuse. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">StnEZtLDbRcvUu2DBR5ea3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oQs6iUSDCYDEV6yP7Pj9Gh-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/oQs6iUSDCYDEV6yP7Pj9Gh-1280-80.png">
                                                            <media:credit><![CDATA[LinkedIn]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Zoom Verified on LinkedIn Example]]></media:description>                                                            <media:text><![CDATA[Zoom Verified on LinkedIn Example]]></media:text>
                                <media:title type="plain"><![CDATA[Zoom Verified on LinkedIn Example]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oQs6iUSDCYDEV6yP7Pj9Gh-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zoom patches critical improper input validation flaw in multiple Windows clients and SDKs that allowed remote account takeover</strong></li><li><strong>Additional high‑severity bugs fixed include CVE‑2026‑53410 (TOCTOU race condition), CVE‑2026‑53409 (privilege management flaw), and CVE‑2026‑53411 (input validation issue)</strong></li><li><strong>All vulnerabilities were found internally, with no evidence of exploitation; users are urged to update Zoom Workplace and related products to the latest versions</strong></li></ul><p>Zoom has patched a critical-level vulnerability in multiple products that allowed threat actors to take over people’s accounts remotely.</p><p>In a security advisory, Zoom said it fixed an Improper Input Validation bug plaguing Zoom Desktop Client for Windows (before version 7.0.0), Zoom VDI Client for Windows (before versions 7.0.10, 6.6.15, and 6.5.18), and Zoom Meeting SDK for Windows (before version 7.0.0). It did not go into more details on how the flaw works.</p><p>The bug is now tracked as CVE-2026-53412, and was given a severity score of 9.8/10 (critical). To fix it, users are advised to update their software to the newest version.</p><h2 id="more-vulnerabilities">More vulnerabilities</h2><p>While certainly the most dangerous one, this is not the only bug Zoom recently addressed. The company also fixed a handful of less severe vulnerabilities, including a time-of-check to time-of-use (TOCTOU) race condition bug affecting Zoom Workplace for Windows before 7.0.5, Zoom Workplace VDI Client and VDI Plugin before 6.5.17/6.6.14, Zoom Rooms for Windows before 7.0.5, and Remote Control for Zoom Contact Center before 7.0.0. This bug is tracked as CVE-2026-53410 and was given a “high” severity score of 7/10. </p><p>Other notable mentions include CVE-2026-53409 (a high-severity improper privilege management flaw in Zoom Rooms for Windows before version 7.1.0), and </p><p>CVE-2026-53411 (a high-severity improper input validation flaw affecting the Zoom Workplace VDI Plugin for Windows before version 6.6.14).</p><p>Zoom found all of these vulnerabilities in-house and says there is no evidence that any of these were abused in real-life attacks in the past. </p><p>Zoom Workplace (the company’s <a href="https://www.techradar.com/best/best-online-collaboration-tools" target="_blank">all-in-one collaboration platform</a>) offers video meetings, team chat, phone, email, calendar, scheduling, whiteboards, and other productivity tools. It is an evolution of the original Zoom Meetings app which now competes with platforms such as Microsoft 365 and Google Workspace.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ KFC may be forced to shut some stores following cyberattack at key supplier ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/kfc-may-be-forced-to-shut-some-stores-following-cyberattack-at-key-supplier</link>
                                                                            <description>
                            <![CDATA[ Nichirei Co confirmed shutting parts of its infrastructure offline to contain a cyberincident which could affect KFC Japan stores. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">N2u2mC7m4y6PqqGv8ZPdLY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 10:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Nichirei Co confirms cyberattack disrupting refrigerated warehouse and frozen food logistics, impacting customers including KFC Japan</strong></li><li><strong>KFC warned of delivery delays leading to possible menu restrictions, shortened hours, or temporary suspension of online orders</strong></li><li><strong>No data leaks or attacker claims have surfaced; disruptions suggest ransomware, but both companies expect operations to normalize by week’s end</strong></li></ul><p>Nichirei Co, a large Japanese company which produces frozen and processed foods, and operates cold-chain logistics to distribute them across the country, has confirmed it suffered a cyberattack which affected some of its customers, including KFC.</p><p>The company confirmed the news in a notice stating, “Today, Nichirei Co experienced a system failure caused by unauthorized access." </p><p>Nichirei said that it is currently investigating the incident, but that there is no evidence of personal or customer data leaking outside the company. However, due to the nature of the incident (which hasn’t been explained in detail), multiple operations have been affected, including refrigerated warehouse inbound/outbound operations, and frozen food shipping services.</p><h2 id="no-claims-yet">No claims yet</h2><p>These disruptions affected, among others, KFC - one of the largest fast food chains in the world. In a separate announcement, KFC said that a system failure at Nichirei Logistics Group, which happened on July 13, affected the company’s logistics and delivery sites. “From Tuesday, July 14, 2026, food delivery to KFC stores is expected to be affected,” it said.</p><p>“As a result, each store may suspend operations depending on some products going out of stock, menu restrictions, shortened business hours, or ingredient stock availability. Additionally, online orders from the official app and website have also been temporarily suspended.”</p><p>The nature of the attack, or the identity of the attackers, were not disclosed. Since Nichirei had to shut down some of its services, it could mean this was a <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> attack and that some company data was stolen after all. The Register reports that KFC Japan hasn’t posted information about store closures and continues to promote summer menu items.</p><p>At press time, no threat actors claimed responsibility for the attacks, and no Nichirei/KFC data surfaced on the dark web. The companies expect to resume normal operations by the end of the week.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/07/16/cyberattack-threatens-utterly-critical-infrastructure-in-japan-kfc/5272220" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘A candidate who was hostile from day one never produces that baseline’: Nation states spies applying for legit jobs are hard to spot ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-candidate-who-was-hostile-from-day-one-never-produces-that-baseline-nation-states-spies-applying-for-legit-jobs-are-hard-to-spot</link>
                                                                            <description>
                            <![CDATA[ Nation state spies are using AI to create fake identities and realistic job applications, infiltrating organizations to steal intelligence. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4Rtu5w3gmuokG2QJknZ7AQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 17:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ desire.athow@futurenet.com (Desire Athow) ]]></author>                    <dc:creator><![CDATA[ Desire Athow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/oEw3XiohQwun9z7gMxKzkB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Désiré has been musing and writing about technology during a career spanning four decades. He dabbled in &lt;a href=&quot;https://www.techradar.com/news/the-best-website-builder&quot;&gt;website builders&lt;/a&gt; and &lt;a href=&quot;https://www.techradar.com/web-hosting/best-web-hosting-service-websites&quot;&gt;web hosting&lt;/a&gt; when DHTML and frames were in vogue and started narrating about the impact of technology on society just before the start of the Y2K hysteria at the turn of the last millennium.&lt;/p&gt;&lt;p&gt;Then followed a weekly tech column in a local business magazine in Mauritius, a late night tech radio programme called &lt;a href=&quot;https://web.archive.org/web/20030414214749/http://www.clicplus.com/&quot;&gt;Clicplus&lt;/a&gt; and a freelancing gig at the now-defunct, Theinquirer, with the late Mike Magee as mentor. After an eight-year stint at ITProPortal.com, where he discovered the joys of global techfests and transformed the publication into one of the biggest tech B2B independent publishers, Désiré moved to TechRadar Pro where he has been the editor for nine years.&lt;/p&gt;&lt;p&gt;He has an affinity for anything hardware and staunchly refuses to stop writing reviews of obscure products or cover niche B2B software-as-a-service providers. He is an avid deal hunter and can be found lurking around on various deals forums.&lt;/p&gt; ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Craig Hale ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Geopolitical tensions are mounting, and nation states are employing new types of strategies to gain intelligence. A recent Five Eyes warning, for example, accused Chinese military intelligence officers of using professional networking sites and online job platforms to target individuals of interest.</p><p>In this specific case, the agents pose as recruiters advertising seemingly legitimate work to build relationships and, ultimately, get their hands on non-public information. Popular sites like LinkedIn, Indeed and Upwork have all seen this new type of attack take place.</p><p>At the same time, a parallel threat sees operatives applying for jobs within trusted organizations with access to intelligence, creating insider threats that experts warn AI might be mostly responsible for.</p><p>Generative AI, for example, can create documents, write applications and even supply live answers during real-time remote interviews, meaning that a small group of fake applicants can extend their reach much more quickly.</p><h2 id="rather-than-attacking-existing-workers-nation-states-are-creating-their-own-job-candidates">Rather than attacking existing workers, nation states are creating their own job candidates</h2><p>Once inside an organization and with access to company tools like PCs, emails and other internal systems, nation state spies can then move laterally to acquire the information they sought.</p><p>Security experts at Exabeam warn that, because this technique is still evolving, it might not always be so easy to spot. Additionally, motives can differ, with Chinese intelligence operations typically seeking military, political or economic information. North Korean agents, on the other hand, tend to be tied to stealing money, which could also come with the side effect of data and intelligence theft.</p><p>Exabeam even observed this type of attack first-hand, when a North Korean-affiliated applicant used a false identity to apply for a job at the company. After passing technical tests, a video interview and other standard checks, the suspect’s laptop was quickly flagged for unusual activity.</p><p>In the following Q&A with AI Strategy and Security Research VP Steve Povolny, I discuss these new types of attacks, who’s responsible for stamping them out and what we can do to prevent similar incidents from happening more commonly.</p><ul><li><strong>The Five Eyes alliance recently warned that foreign intelligence groups are using job platforms to recruit insiders. How significant is this threat, and what is driving its growth?</strong></li></ul><p>This is among the most serious access-driven threats facing cleared workers, and it keeps growing because the economics now favor the attacker. </p><p>Foreign intelligence services no longer need handlers and dead drops when they can post a job ad on LinkedIn or Upwork and let candidates self-select based on the access listed in their own resumes. Generative AI lets them run thousands of these conversations at once, drafting outreach and scoring which applicants sit closest to sensitive information without a trained officer. </p><p>The Five Eyes alert describes a scaled, automated funnel, and that scale is what makes it dangerous.</p><ul><li><strong>A parallel risk runs alongside that warning: adversaries who secure employment directly rather than recruiting an existing employee. Which scenario presents the greater defensive challenge, and why?</strong></li></ul><p>The infiltration model gives defenders less to work with, which makes it the harder problem. When an adversary recruits someone already on staff, most of the suspicious behavior happens outside the company on platforms the employer never sees, yet the insider remains a known person with a verified identity and a real history. </p><p>When the adversary becomes the employee, the company has onboarded a fabricated person and handed them a laptop and standing network access on day one. No behavioral baseline exists, since everything that account does counts as a first. The deception also clears the controls most organizations trust, so the failure lands before any security tool gets a vote.</p><ul><li><strong>Exabeam identified a North Korea-affiliated individual who gained employment at the company. How did the operative clear Exabeam's hiring process, and what first signaled that something was wrong?</strong></li></ul><p>He cleared it by performing well on the parts we test and forging the parts we verify. Applying under the alias Trevor Rothluebber, he aced the technical interview and take-home assessment, passed the video interview and cleared our standard pre-employment process including the background check and I-9 validation.</p><p>Our hiring team flagged a suspicion that he leaned on generative AI for live help during the video call, the first soft signal. The hard signal arrived the moment he logged into his corporate account. Our threat intelligence feed matched his username to activity previously associated with North Korean operatives and rated it high risk, and that single match reframed how the team read everything that followed.</p><p>Simultaneously, Exabeam’s platform detected a number of anomalies inconsistent with a brand new employee’s first day, and escalating in severity within hours. Incident response quietly isolated and reimaged his laptop before any real damage could be done.</p><ul><li><strong>The candidate completed applications, interviews and assigned work without raising alarm. In retrospect, what indicators were present, and why did standard screening miss them?</strong></li></ul><p>The indicators existed, but they lived in places our screening was never built to read. The driver's license he submitted was either AI-generated or very badly manually modified, and the tell was physical. The image had unique aberrations, such as the ears in the photo which had an unnatural and pixelated modification an artifact that image generators still produce, and a reviewer skims past.</p><p>The live AI assistance during the interview was another, since his answers carried a fluency that did not match the natural hesitation you expect when someone reasons through an unfamiliar problem. Standard screening missed all of it because background checks and identity validation confirm whether documents are internally consistent and whether a record exists, and they never ask whether the human attached to those documents is real.</p><p>Further fabrication of documents such as I-9 were missed by a 3rd party identity verification company, and validation of (fake) job references was not properly identified.</p><ul><li><strong>How did AI contribute to the deception? What did the fraudulent documentation involve, and what capabilities does AI introduce that traditional forgery methods lack?</strong></li></ul><p>AI showed up at nearly every stage. The fraudulent documentation centered on a forged driver's license we believe was generated rather than physically produced, paired with a stolen identity that gave the paperwork a real history to rest on.</p><p>During the interview the candidate  appeared to have run an AI copilot feeding him answers in real time, and many of these tools now stay invisible to everyone else on the call even while the candidate shares a screen. What AI adds over traditional forgery is volume and believability together. A skilled forger could always produce one convincing passport, but the craft capped how many operations could run at once.</p><p>Generative tools remove that ceiling, so a single actor can fabricate convincing documents and coach themselves through a live technical interview across dozens of applications at once, and the forgery stopped being the bottleneck it used to be.</p><ul><li><strong>The Five Eyes warning focused on China, while the Exabeam case involved North Korea. Do these actors share tactics and objectives, or do they represent distinct operational models that overlap on method?</strong></li></ul><p>They overlap heavily on method while running on different motives, which defenders should sit with. The Chinese operation the Five Eyes described aims at intelligence collection, pulling government and military insight out of people who already hold access. </p><p>The North Korean program that hit us and so many others in this industry is funded differently, since much of its purpose is revenue for a sanctioned regime, with intrusion and theft riding alongside the paycheck. The objectives diverge, yet the tradecraft has converged on one toolkit of fabricated identities, AI-assisted documents, manufactured professional histories and the patient relationship-building that lets an operative stay quiet.</p><p>When two adversaries with separate goals reach the same playbook, that tells you the playbook works and other actors are already watching.</p><ul><li><strong>Conventional insider threat programs are built to detect employees who become compromised over time. How should organizations identify a candidate who was an adversary from the point of hire?</strong></li></ul><p>Our mindset must shift toward treating the moment of hire as the start of the highest-risk window rather than the end of vetting. Traditional insider programs watch for drift, the employee who gradually turns after a financial shock or a grievance, so they depend on a baseline built over months.</p><p>A candidate who was hostile from day one never produces that baseline, which forces you to scrutinize the earliest behavior most closely. In our case, the catch came from putting new accounts under enhanced monitoring and letting an AI agent correlate scattered signals that no single alert would have justified escalating.</p><p>The working principle is to give hiring workflows and new-hire activity the same suspicion you already apply to production access.</p><ul><li><strong>Where should accountability for this threat reside within an organization? Is it a security function, an HR function, or a gap that persists because ownership is unclear?</strong></li></ul><p>Accountability most often lives in the gap right now, and that gap is exactly why the threat works. Hiring sits with HR and talent acquisition, who are measured on filling roles quickly and are not equipped to run identity verification at an intelligence-grade level.</p><p>Detection sits with security, which usually gains no visibility into a candidate until that person already holds a badge and a laptop, and the adversary exploits the seam between the two.</p><p>The workable answer is shared ownership with a clean handoff, where security sets the identity and behavioral standards hiring must meet and stays involved through the first weeks of employment rather than inheriting the problem once onboarding closes.</p><ul><li><strong>Many mid-sized companies lack dedicated threat intelligence resources. What practical measures can such organizations implement to reduce their exposure?</strong></li></ul><p>Useful defense does not require a dedicated threat intelligence team. The interview itself is the cheapest control available, and small changes make it far more revealing.</p><p>Underspecifying a problem on purpose shows whether a candidate asks clarifying questions like a real engineer or simply produces a confident answer and switching the problem partway through tests whether they adapt or whether something is feeding them responses.</p><p>Asking for an external webcam that shows the workspace instead of a shared screen removes one of the easiest hiding spots for an interview copilot. Beyond hiring, the highest-leverage move is placing every new employee on a watchlist for closer monitoring through their first weeks, which costs configuration time rather than budget.</p><p>Even a basic, low-cost threat intelligence feed would have surfaced the username match that broke our case open.</p><ul><li><strong>What is the most contested prediction on this issue, one that many security leaders would currently dispute?</strong></li></ul><p>My contested prediction is that within a couple of years the verified human interview, run live and in person for any role with meaningful access, returns as a security requirement. Many security leaders will fight that because it breaks the remote-first hiring model they spent years optimizing.</p><p>The objection I expect is that it does not scale and shrinks the talent pool, and those concerns are legitimate. My counter is that the economics have already flipped for high-access roles, since the cost of onboarding a single fabricated adversary now dwarfs the friction of one in-person verification step.</p><p>The deeper claim underneath it is that remote identity verification as we practice it today is no longer reliable for sensitive positions, and AI is what made it unreliable. Most security leaders are not ready to say that out loud yet.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts flag new scam targeting fans seeking tickets for Celine Dion concerts ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-flag-new-scam-targeting-fans-seeking-tickets-for-celine-dion-concerts</link>
                                                                            <description>
                            <![CDATA[ Multiple scams targeting Celine Dion fans have already surfaced - it looks like this scam will go on (and on). ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wubbooKqvDht9F8jtExLaa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kMQVGNaXFmvhNxH6wp5LUh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kMQVGNaXFmvhNxH6wp5LUh-1280-80.jpg">
                                                            <media:credit><![CDATA[ Say thanks! Give a shoutout to Jefferson Santos on social or copy the text below to attribute.  Photo by Jefferson Santos on Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[shady person sitting at a computer.]]></media:description>                                                            <media:text><![CDATA[shady person sitting at a computer.]]></media:text>
                                <media:title type="plain"><![CDATA[shady person sitting at a computer.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kMQVGNaXFmvhNxH6wp5LUh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB warns of scams exploiting Celine Dion’s concert comeback, with fraudsters selling duplicate Ticketmaster tickets and spoofing sites like AXS and Paris La Défense Arena</strong></li><li><strong>Scammers embed themselves in Facebook fan groups and marketplaces, even using voice messages to build trust and make fake offers seem legitimate</strong></li><li><strong>Fans are advised to only buy from official distributors, verify tickets in person if using resellers, and contact banks to dispute charges if scammed</strong></li></ul><p>Celine Dion is back, and hackers are already trying to exploit the fact for their own financial gain, experts have warned.</p><p>A <a href="https://www.group-ib.com/blog/fake-concert-ticket-scam-celine-dion/" target="_blank">report</a> from security researchers Group-IB has claimed there are numerous scam campaigns all across the internet and social media, looking to exploit gullible fans and steal their money.</p><p>Its aptly named “The Scam Will Go On” report said it saw scammers lurking in Facebook Groups, Facebook Marketplace, and other fan-centric spaces, offering concert tickets for sale. The tickets themselves, hosted on Ticketmaster, are valid. However, the scammers only have a few tickets which can be redeemed by the first person who reaches the venue. Everyone else will be denied entry, since their tickets will already have been used.</p><h2 id="how-to-avoid-getting-scammed">How to avoid getting scammed</h2><p>But that’s not the only scam. Some people don’t want to pay an unknown third person via wire, and would prefer to purchase the tickets directly from a service. </p><p>For those people, the scammers created entire websites, spoofing ticketing distributors such as AXS and Ticketmaster. Group-IB also saw fake websites spoofing Celine Dion and Paris La Défense Arena, the stadium where the concert will take place. </p><p>“We see that such an event generates excitement and provides scammers with another opportunity to make a fortune at the expense of unsuspecting fans,” Group-IB warned. </p><p>“Scammers are using increasingly sophisticated techniques, such as embedding themselves into social networking fan groups and speaking directly to their victims via voice messages to make the interaction more personal and gain their victims’ trust more easily. Furthermore, official ticketing platforms are being misused to make scams seem legitimate.”</p><p>The researchers recommend fans only visit official websites and those of official distributors, and if they absolutely must buy from a reseller, to make sure they’re purchasing a physical ticket, in person. Those that fell for the scam should call their bank and lodge an objection on their credit card. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New phishing campaign hits LastPass, Bitwarden users - password manager customers warned not to fall for this scam ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/new-phishing-campaign-hits-lastpass-bitwarden-users-password-manager-customers-warned-not-to-fall-for-this-scam</link>
                                                                            <description>
                            <![CDATA[ No, LastPass' security policies have not been updated, and neither have Bitwarden's - it's a scam. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sT8YuaYXwd29zBkL8LgEdf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ramk8kAMZnG58FVJidCvuF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ramk8kAMZnG58FVJidCvuF-1280-80.jpg">
                                                            <media:credit><![CDATA[ wk1003mike / Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Shutterstock]]></media:description>                                                            <media:text><![CDATA[Fraude en ligne phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Fraude en ligne phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ramk8kAMZnG58FVJidCvuF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers are spoofing LastPass and Bitwarden with phishing emails from fake newsletter domains, tricking users into signing bogus DocuSign documents</strong></li><li><strong>Victims are redirected to malicious “compliance” domains flagged by Microsoft Defender and Cloudflare, already taken offline</strong></li><li><strong>Neither password manager was breached; this is domain spoofing, and users are urged to verify sender addresses and domains before clicking links</strong></li></ul><p>Criminals have been found impersonating popular password managers LastPass and Bitwarden online in an attempt to trick users into sharing their login credentials, and thus access to a treasure trove of passwords and other secrets.</p><p>LastPass recently issued a warning to its customers, raising awareness of the ongoing phishing campaign. </p><p>However the scam also now seems to have spread to other password managers, with Bitwarden customers also apparently being targeted.</p><h2 id="passwords-are-safe">Passwords are safe</h2><p>In the campaign, LastPass users received emails from the address “hello@lastpassnewsletter.com”. </p><p>This address does not belong to LastPass, and is in no way affiliated with the <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager</a>. In the message, the victims are told that the company’s security policies have been updated, and that they should navigate to a specific landing page and sign a DocuSign document.</p><p>The email comes with a ‘Review & Access Terms’ button which, if clicked, redirects the victims to lastpasscompliance[dot]com, yet another domain unaffiliated with the password management platform. </p><p><em></em><a href="https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-targeted-with-fake-security-alerts/" target="_blank"><em>BleepingComputer</em></a> claims this domain has already been flagged as malicious by both Microsoft Defender for Office 365, and Cloudflare and is currently offline. </p><p>Digging deeper, the journalists uncovered another campaign, almost identical, but now targeting Bitwarden users. In this case, the victims were being mailed from the “hello@bitwardennewsletter.com” addresses and were being redirected to bitwardencompliance[dot]com. Identical methodology, just slightly personalized. </p><p>It is important to note that neither LastPass nor Bitwarden were compromised as part of this attack. </p><p>The companies’ infrastructure is intact, and the passwords are safe. This is a typical domain spoofing attack in which the crooks purchase a domain similar to the legitimate one, in hopes that the victims won’t spot the difference.</p><p>As usual, the best course of action is to always be skeptical of incoming emails, and to double-check the domains and email addresses from which they are sent. It is also good to cross-reference these emails with any older messages that are proven to be authentic, to see if the domains and addresses match.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hundreds of GitHub repos found posing as real software to push malware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hundreds-of-github-repos-found-posing-as-real-software-to-push-malware</link>
                                                                            <description>
                            <![CDATA[ Russian hackers are trying to sneak infostealers onto people's devices to grab passwords, crypto, and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dxoB3qPWwHz8vExitx7Zed</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone malware]]></media:description>                                                            <media:text><![CDATA[Phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ArcticWolf uncovered 292 malicious GitHub repositories spoofing legitimate tools and products, delivering a new BoryptGrab infostealer variant</strong></li><li><strong>Malware steals from 19 browsers, 32 crypto wallets, messaging apps, Steam, and Windows Credential Manager, and uniquely bypasses Chrome’s App‑Bound Encryption via code injection</strong></li><li><strong>Most repos have been removed, but some remain active; GitHub’s popularity makes it a prime target, underscoring the need to vet code before use</strong></li></ul><p>Russian actors have reportedly created hundreds of malicious GitHub repositories masquerading as legitimate software but acting as a dangerous infostealer. </p><p>Cybersecurity researchers ArcticWolf discovered the campaign after finding their own products spoofed as part of the attack.</p><p>In total, the researchers found 292 fake repositories, spoofing things like security products, developer tools, macOS utilities, games, and more. Each repository contained a README file with the download URL.</p><h2 id="obviously-malicious">Obviously malicious</h2><p>Victims who download the program get a variant of the BoryptGrab infostealer family that grabs data from 19 browsers (<a href="https://www.techradar.com/best/password-manager" target="_blank">passwords</a>, cookies, payment information), 32 cryptocurrency wallets, Telegram, Discord, and Steam sessions, credentials for Meta’s Max, data from Windows Credential Manager, and more. It can also exfiltrate files from Desktop and Documents, and grab screenshots.</p><p>While most of the features can be found in other BoryptGrab variants, this one is unique in a sense that it can bypass Chrome’s App-Bound Encryption through direct code injection into the browser process.</p><p>While it hasn’t been specifically said that the threat actors are Russian, the compressed data is later sent to a Russia-based command-and-control (C2) infrastructure.</p><p>What’s also worth mentioning is that the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> is not designed to last. It has no anti-analysis layer, and doesn’t even try to hide itself in any specific manner. It does not establish persistence and simply tries to grab as much sensitive data as it can on the first attempt.</p><p>The attack, which seems to have started in the final days of June, is almost thwarted now, since most of the malicious repositories have been removed from GitHub. Citing “researchers”, <a href="https://www.bleepingcomputer.com/news/security/nearly-300-github-repos-pose-as-legit-software-to-push-malware/" target="_blank"><em>BleepingComputer</em></a> reported that several dozen still remain active, though. </p><p>Because of its importance and popularity in the open-source community, GitHub is currently one of the most targeted platforms on the internet, which is why it’s important to double-check and vet every piece of code before it’s applied to a project.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'No new vulnerability is needed to bypass UEFI Secure Boot': Experts find attackers can exploit decades-old flaws to gain access to key systems ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/no-new-vulnerability-is-needed-to-bypass-uefi-secure-boot-experts-find-attackers-can-exploit-decades-old-flaws-to-gain-access-to-key-systems</link>
                                                                            <description>
                            <![CDATA[ Almost a dozen vulnerable UEFI shim bootloaders discovered and revoked. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ojLPBeQtFiLPyCDTQAMKFB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AsscCgZRnWXMPyCxtEfpkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AsscCgZRnWXMPyCxtEfpkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An email symbol inside a red square warning sign, surrounded by red triangles with exclamation marks inside them, superimposed on someone typing on a laptop]]></media:description>                                                            <media:text><![CDATA[An email symbol inside a red square warning sign, surrounded by red triangles with exclamation marks inside them, superimposed on someone typing on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[An email symbol inside a red square warning sign, surrounded by red triangles with exclamation marks inside them, superimposed on someone typing on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AsscCgZRnWXMPyCxtEfpkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ESET discovers 11 vulnerable UEFI shim bootloaders signed by Microsoft, allowing attackers to bypass Secure Boot and deploy malicious bootkits</strong></li><li><strong>Any UEFI system trusting Microsoft’s 2011 third‑party certificate could be exposed, potentially billions of devices; attackers can bring old trusted shims to new systems</strong></li><li><strong>Microsoft has revoked the vulnerable shims, and users should apply the latest UEFI revocations (Windows auto‑updates, Linux via LVFS) to block exploitation</strong></li></ul><p>Cybersecurity experts from <a href="https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/" target="_blank">ESET</a> have discovered 11 vulnerable UEFI shim bootloaders, all signed by Microsoft, which could allow threat actors to exploit ancient vulnerabilities and bypass UEFI Secure Boot, deploying all sorts of malicious bootkits.</p><p>A shim is a small, intermediary bootloader that works as a bridge between a computer's firmware (UEFI) and the operating system's bootloader. Its primary purpose is to allow operating systems to work with UEFI Secure Boot without having Microsoft sign every <a href="https://www.techradar.com/best/best-linux-distros" target="_blank">Linux</a> bootloader individually.</p><p>Any UEFI-based machine that trusts the Microsoft Corporation UEFI CA 2011 third-party UEFI certificate authority (CE) certificate, regardless of the operating system, was said to be vulnerable to the shims (versions 0.9 and older). That would put the number of potentially vulnerable devices in the billions, since almost all modern x86 PCs use UEFI firmware, and most of them trust the Microsoft Corporation UEFI CA 2011 certificate out of the box.</p><h2 id="revoking-the-shims">Revoking the shims</h2><p>However, ESET reported its findings to CERT/CC and the vulnerable UEFI applications were all revoked. </p><p>The shims come from different tools such as PC diagnostic software, Linux distribution, and other UEFI-based utilities, the researchers explained. They also added that, since the attackers can bring their own vulnerable shims to any UEFI system with the Microsoft third-party UEFI certificate enrolled, they can exploit systems that are, at first, not affected. </p><p>To block the vulnerable shims, users should apply the latest UEFI revocations from Microsoft, it was said. While Windows systems will most likely do it automatically, Linux systems users should do it through the Linux Vendor Firmware Service. </p><p>“What makes these old shims dangerous is not a novel vulnerability; it’s that no new vulnerability is needed to bypass UEFI Secure Boot,” says ESET researcher Martin Smolár, who discovered the vulnerable shims. </p><p>“An attacker needs no complicated exploitation primitives — only a copy of an old, still-trusted but unrevoked shim binary and a basic understanding of how UEFI shims work. That is enough to bypass such an essential security feature as UEFI Secure Boot."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft just released its biggest Patch Tuesday ever, with a mammoth 622 fixes including three dangerous zero-days ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/microsoft-just-released-its-biggest-patch-tuesday-ever-with-a-mammoth-622-fixes-including-three-dangerous-zero-days</link>
                                                                            <description>
                            <![CDATA[ Microsoft shipped three times more fixes than usual in its latest Patch Tuesday update. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a4QTENza3vCL4mPwKTvD4f</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft’s July 2026 Patch Tuesday fixed a record 622 vulnerabilities, including 58 critical, two exploited in the wild, and one publicly disclosed, plus 428 Chromium bugs</strong></li><li><strong>Actively abused flaws include CVE‑2026‑56155 (AD FS privilege escalation) and CVE‑2026‑56164 (SharePoint privilege escalation), alongside notable issues in BitLocker and Copilot</strong></li><li><strong>Surge in fixes is linked to Microsoft’s use of Anthropic’s Mythos AI, with patch volumes rising sharply since its adoption</strong></li></ul><p>Microsoft has released its July 2026 Patch Tuesday download, marking another record-breaking update, addressing hundreds of flaws across the ecosystem.</p><p>The release, which is currently rolling out to Microsoft users, fixes a staggering 622 vulnerabilities, including 58 critical-severity ones, two that were observed as being abused in the wild, and one which has already been publicly disclosed. </p><p>On top of that, Microsoft shipped fixes for another 428 Chromium bugs, as well. </p><h2 id="a-jump-in-numbers">A jump in numbers</h2><p>There are simply too many vulnerabilities to mention all of them, however two that are being exploited in the wild are CVE-2026-56155 and CVE-2026-56164. The former is described as an “Insufficient granularity of access control in Active Directory Federation Services (AD FS)” bug, which allows an authorized attacker to elevate privileges locally. It carries a severity score of 7.8/10 (high).</p><p>The latter is a “Missing authentication for critical function in Microsoft Office SharePoint” bug that allows an unauthorized attacker to elevate privileges over a network. Microsoft assigned it a medium severity score (5.3/10), but the National Vulnerability Database gave it a 9.8/10 (critical).</p><p>Other notable mentions include CVE-2026-50661, a protection mechanism failure in Windows BitLocker that allows unauthorized attackers to bypass a security feature with a physical attack, and CVE-2026-48561, an improper neutralization of special elements used in a command in Microsoft Copilot, that allows an unauthorized attacker to execute code over a network.</p><p>If you think fixing 622 vulnerabilities in a month is a lot, you’re absolutely right. It’s well above what Microsoft is used to do, and this is most likely due to the company now using the fabled Mythos - Anthropic’s cybersecurity-oriented AI. </p><p>In June 2026, roughly a month and a half after the release of Mythos, Microsoft fixed 206 flaws, which raised eyebrows because it was significantly above the company’s usual amount of bugs fixed.</p><p>In May it fixed 120 flaws, in April 167, and in March - 79.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ White House launches 'Gold Eagle' cybersecurity clearinghouse to share and patch AI-discovered software flaws ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/white-house-launches-gold-eagle-cybersecurity-clearinghouse-to-share-and-patch-ai-discovered-software-flaws</link>
                                                                            <description>
                            <![CDATA[ 'Gold Eagle' scheme looks to centralize vulnerability identification and remediation for maximum efficiency. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dQ8QDDVQDMX7ftBUuZpt6A</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DFBL65zBbMWH2hNHzTrEuk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 09:07:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DFBL65zBbMWH2hNHzTrEuk-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Donald Trump sings executive order]]></media:description>                                                            <media:text><![CDATA[Donald Trump sings executive order]]></media:text>
                                <media:title type="plain"><![CDATA[Donald Trump sings executive order]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DFBL65zBbMWH2hNHzTrEuk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>White House, Treasury, DHS and DoW come together to launch Gold Eagle scheme</strong></li><li><strong>The initiative will prevent duplicated work and prioritize vulnerability remediation</strong></li><li><strong>Gold Eagle will also help to identify which systems could be at risk</strong></li></ul><p>The US Government has <a href="https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/" target="_blank">launched</a> Gold Eagle, a new clearinghouse which looks to centralize vulnerability discovery and remediation against a backdrop of evolving AI-powered security threats.</p><p>Gold Eagle will serve as a central hub between federal agencies, AI developers, open-source software developers and critical infrastructure companies, in a bid to increase the speed of vulnerability discovery and prevent major incidents from occurring in the first place.</p><p>The scheme came about under President Trump's June 2 2026 executive order 'Promoting Advanced Artificial Intelligence Innovation and Security' and represents collaboration between the Treasury, the DHS' Cybersecurity and Infrastructure Security Agency (CISA) and the Department of War.</p><h2 id="us-gold-eagle-scheme-addresses-growing-vulnerability-exploitations">US Gold Eagle scheme addresses growing vulnerability exploitations</h2><p>Under the scheme, vulnerabilities scanning will happen centrally to ensure multiple organizations aren't independently repeating the same work. Gold Eagle will also identify which software, networks and critical infrastructure could be at risk, before coordinating fixes. The White House described the scheme as a "force multiplier."</p><p>Although AI is largely to blame for the increase in attacks, Gold Eagle is set to fight fire with fire by employing AI to identify bugs too, using models like Anthropic's Mythos.</p><p>"Through this strategic partnership, we will expand existing security measures to safeguard software and networks in the 21st century and continue to promote advancements in artificial intelligence," DHS Secretary Markwayne Mullin wrote.</p><p>The concept of a dedicated clearinghouse centralizes vulnerability management to ensure the right bugs are being prioritized and to cut through the noise of lower-quality reports. Its assistance will most likely be felt by the open-source community, which has limited resources and financial backing to identify and fix issues as effectively as enterprise software vendors.</p><p>"Under the leadership of President Trump, we are bringing a wartime footing to the cyber domain to relentlessly patch vulnerabilities," Secretary of War Pete Hegseth added.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts get Google, Microsoft to pull trusted ModHeader with 1.6 million installs after finding it could harvest all kinds of data ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-get-google-microsoft-to-pull-trusted-modheader-with-1-6-million-installs-after-finding-it-could-harvest-all-kinds-of-data</link>
                                                                            <description>
                            <![CDATA[ Visited domains were being exfiltrated to a third-party server, seemingly under a Chinese actor's control. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wBogsTgqZ6B4E5RonumGgf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:description>                                                            <media:text><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:text>
                                <media:title type="plain"><![CDATA[Chrome, Edge, Safari, and Firefox browser apps on a mobile phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/97XMVxvuGbBvxfxdd8VJqH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Stripe OLT found ModHeader v7.0.18 carried a hidden spyware SDK, exfiltrating visited domains daily to a Chinese‑owned server and acting as adware</strong></li><li><strong>The extension had 1.6M downloads across Chrome and Edge before being pulled but installed endpoints remain at risk</strong></li><li><strong>Researchers urge defenders to identify and remove existing installations, as removal from stores does not automatically remediate compromised devices</strong></li></ul><p>ModHeader, a trusted Chrome and Edge browser extension with more than 1.6 million downloads, was found to be malicious, apparently sending sensitive data to a Chinese-owned server, and has since been pulled on both repositories. </p><p>Security researchers Stripe OLT revealed the news in a new <a href="https://stripeolt.com/knowledge-hub/threat-research/chrome-extension-hidden-data-exfiltration-900k-users/" target="_blank">report</a>, outlining how a ModHeader build v7.0.18 carried a hidden <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">spyware</a> SDK. </p><p>As per Stripe OLT, the spyware collects domains users visit, encrypts the data with AES-GCP, and then sends it - once a day - to a remote server. The collector was found inactive by default, but the required code, encryption key, and upload schedule were all already embedded in the extension.</p><h2 id="links-to-chinese-actors">Links to Chinese actors</h2><p>Researchers found no command-and-control functionality, which means the server only receives the stolen data and cannot communicate back. The extension also worked as an adware, displaying ads and opening advertising tabs on updates, including on enterprise-managed devices.</p><p>The researchers attributed the attack, albeit with low confidence, to a Chinese-speaking threat actor. The exfiltration domain routes emails through Lark, which is a suite common with Chinese-speaking teams, it was said. They also found Chinese strings in the code, and said that the listing ships a Simplified Chinese locale. </p><p>ModHeader is a Chrome and Edge <a href="https://www.techradar.com/best/browser" target="_blank">browser</a> extension that allows users to modify HTTP request and response headers sent between their browser and websites. Developers and security researchers use it to test APIs, troubleshoot applications, and simulate different environments. It has around 900,000 users on Chrome, and another 700,000 on Edge. </p><p>According to <a href="https://thehackernews.com/2026/07/google-and-microsoft-pull-modheader.html" target="_blank"><em>The Hacker News</em></a>, Microsoft pulled the tool from its repository on June 3 2026, followed by Google a week later, on July 10. </p><p>“Following our disclosure, Google has removed the extension from the Chrome Web Store,” Stripe OLT concluded. “We welcome this action, but removal from the store does not automatically remediate endpoints where the extension was already installed, so defenders should continue to identify and remove existing installations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'A single entry point can rapidly expand to greater enterprise impacts': Microsoft introduces changes to tackle ShinyHunters ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-single-entry-point-can-rapidly-expand-to-greater-enterprise-impacts-microsoft-introduces-changes-to-tackle-shinyhunters</link>
                                                                            <description>
                            <![CDATA[ Greater visibility, better detection, and stronger governance over OAuth-connected applications should mitigate ShinyHunters attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TkKBJ5zNq7m8xK9Fpcnpvg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cAewSdXkrLEUsD8muVzGX9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cAewSdXkrLEUsD8muVzGX9-1280-80.jpg">
                                                            <media:credit><![CDATA[gguy / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo outside building]]></media:description>                                                            <media:text><![CDATA[Microsoft logo outside building]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo outside building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cAewSdXkrLEUsD8muVzGX9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ShinyHunters abused OAuth trust in Salesforce by tricking users and later compromising SaaS integrations, stealing tokens to access hundreds of customer environments</strong></li><li><strong>Reports suggested up to 700 victims; attackers exfiltrated data via legitimate APIs, making activity appear normal and persistent</strong></li><li><strong>Microsoft responded with Defender for Cloud Apps upgrades, adding richer telemetry, near‑real‑time detection, and stronger governance over OAuth‑connected applications</strong></li></ul><p>The ShinyHunters cybercrime group were so creative in breaking into corporate Salesforce environments that they forced Microsoft’s hand, making the company introduce new security upgrades just to address the attacks. </p><p>Microsoft has <a href="https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/" target="_blank">revealed</a> it is focusing on improving visibility into OAuth-connected applications and strengthening governance over third-party integrations in <a href="https://www.techradar.com/best/best-antivirus" target="_blank">Microsoft Defender</a> for Cloud Apps. The changes fall into two main categories: Improved detection and investigation, and new posture and governance capabilities.</p><p>It makes sense, given that some reports claimed as many as 700 victims of the year-long campaign.</p><h2 id="changes-and-improvements">Changes and improvements</h2><p>But first, a little context: In August 2025, it was reported that ShinyHunters operatives were calling their targets on the phone, claiming to be IT support, and convincing them to authorize a seemingly legitimate Salesforce Data Loader application. This app was, in fact, controlled by the attackers and requested OAuth permissions which allowed them to access Salesforce data through official APIs. </p><p>Since everything happened through legitimate authentication and API calls, the activity looked like normal user behavior.</p><p>In the following months, the campaign evolved. Instead of tricking individual employees, ShinyHunters compromised third-party SaaS providers that integrated with Salesforce, including <a href="https://www.techradar.com/pro/security/salesloft-breached-to-steal-oauth-tokens-for-salesforce-data-theft-attacks" target="_blank">Salesloft's Drift</a> integration, Gainsight, and later Klue. </p><p>By stealing OAuth tokens or integration secrets from these vendors, they accessed hundreds of downstream customer Salesforce environments without interacting with each customer individually. </p><p>At one point, Google told reporters it was aware of <a href="https://en.wikipedia.org/wiki/ShinyHunters" target="_blank">more than 700 potentially impacted organizations</a>.</p><p>“Microsoft consulted with Salesforce to improve granularity in telemetry for Defender for Cloud Apps with near-real-time detection, offering connected application attribution and expanded application permission insights,” the company said in a new report. “This activity was not the result of a vulnerability inherent to Salesforce. Rather, the threat actors abused trusted OAuth relationships for unauthorized access, data exfiltration, and persistence.”</p><p>In other words, Microsoft enabled greater visibility into OAuth-connected applications and their activity, allowed for better detection of suspicious API and OAuth behavior through richer telemetry and correlation, and now provides stronger governance of connected apps through permission analysis, risk scoring, and lifecycle management.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US and security allies warn Russian attacks on critical infrastructure are ramping up against 'poorly configured and vulnerable networking devices worldwide' ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/us-and-security-allies-warn-russian-attacks-on-critical-infrastructure-are-ramping-up-against-poorly-configured-and-vulnerable-networking-devices-worldwide</link>
                                                                            <description>
                            <![CDATA[ Russians are targeting misconfigured routers running in critical infrastructure firms. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wjQv5EkWkmzmzH5MBDmBmJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kqDd8hw4VtrskmqGDY5fKa-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/kqDd8hw4VtrskmqGDY5fKa-1280-80.png">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person plugging an Ethernet cable into a router]]></media:description>                                                            <media:text><![CDATA[A person plugging an Ethernet cable into a router]]></media:text>
                                <media:title type="plain"><![CDATA[A person plugging an Ethernet cable into a router]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kqDd8hw4VtrskmqGDY5fKa-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NSA, FBI, CISA, and 15 allied agencies warn Russia’s FSB Center 16 is exploiting weak/default credentials and old Cisco flaws to compromise critical infrastructure devices</strong></li><li><strong>Advisory highlights CVE‑2018‑0171 (Smart Install DoS/RCE) and CVE‑2008‑412813 (CSRF in Cisco IOS 12.4) as examples of vulnerabilities still being abused</strong></li><li><strong>TTPs overlap with Chinese groups but attribution points to Russian actors like Berserk Bear and Energetic Bear; full IoCs and mitigations were published in the joint advisory</strong></li></ul><p>Russian state-sponsored threat actors are continuously targeting broken and poorly configured networking devices belonging to critical infrastructure providers all around the world, a <a href="https://www.ic3.gov/CSA/2026/260713.pdf" target="_blank" rel="nofollow">joint security advisory</a> published by the US National Security Agency (NSA) and more than a dozen other agencies has warned.</p><p>As per the advisory, hackers working for the Russian Federal Security Service (FSB) Center 16 are constantly scanning for <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">routers</a> and other internet-connected devices that can be accessed with “common or default” login credentials. </p><p>Once found, these devices are instructed to copy device configuration files and later exfiltrate them via the Trivial File Transfer Protocol to servers under their control. </p><h2 id="berserk-bear-and-salt-typhoon">Berserk Bear and Salt Typhoon</h2><p>In cases where default or weak credentials don’t work, the threat actors also try to exploit vulnerabilities. In the advisory, the agencies specifically mentioned two flaws in Cisco devices - CVE-2018-0171 and CVE-2008-412813. The former is an eight-year-old bug in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software that allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition, or to execute arbitrary code.</p><p>The latter is an even older (18 years old) set of multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router that allows remote attackers to execute arbitrary commands.</p><p>Even though many of these tactics, techniques, and procedures (TTP) overlap with Chinese hackers Salt Typhoon, the agencies suggested they are primarily focusing on Russian hackers known as Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, or Static Tundra.</p><p>The joint advisory is co-authored by the NSA, FBI, and CISA, as well as 15 other agencies from Australia, the United Kingdom, Canada, New Zealand, Estonia, Finland, France, and Italy.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This new macOS infostealer poses as an Apple crash reporting tool to try and steal all your valuable data ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-new-macos-infostealer-poses-as-an-apple-crash-reporting-tool-to-try-and-steal-all-your-valuable-data</link>
                                                                            <description>
                            <![CDATA[ Researchers found a new piece of macOS malware grabbing passwords, crypto data, and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SbwjYKP7zxrLGTEJgE6gNe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 14:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg">
                                                            <media:credit><![CDATA[Herry Sucahya on Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The menu bar running in macOS.]]></media:description>                                                            <media:text><![CDATA[The menu bar running in macOS.]]></media:text>
                                <media:title type="plain"><![CDATA[The menu bar running in macOS.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ctJuqMRzZN6mdeA4UPgdTd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Jamf researchers uncover “CrashStealer,” a notarized macOS infostealer disguised as Apple’s CrashReporter</strong></li><li><strong>Distributed via a fake site called “Werkbit Setup”, it bypasses Gatekeeper, installs a LaunchAgent</strong></li><li><strong>It then uses a fake password prompt to unlock Keychain, exfiltrating credentials, cookies, files, and data from 80 crypto wallets and 14 password managers</strong></li></ul><p>A new macOS infostealer has been spotted in the wild, masquerading as an Apple crash reporting tool, experts have warned.</p><p>Called CrashStealer, this C++ infostealer was designed to nab login credentials, keychain information, as well as data related to more than 80 cryptocurrency wallets.</p><p>Cybersecurity researchers Jamf published an in-depth <a href="https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/" target="_blank">report</a> on the malware, noting CrashStealer is most likely distributed via a fake software site that was only registered recently.</p><h2 id="unlocking-keychain">Unlocking Keychain</h2><p>Victims who land on the site (either via a social media recommendation or search engine results) need to know the PIN code before initiating the download. This was most likely done to avoid analyst scrutiny, as well as to increase perceived credibility and a sense of exclusivity.</p><p>Usually, apps downloaded from third-party sources are scanned by Gatekeeper, Apple’s built-in security system. However, Jamf says that this payload is delivered via a signed and Apple-notarized installer and distributed as a disk image named “Werkbit Setup”, which allowed it to bypass Gatekeeper without any warnings.</p><p>Those that download and run the program will get a binary named ‘CrashReporter.app’, which will create a LaunchAgent (‘com.apple.crashreporter.helper’), and will see a fake macOS password prompt.</p><p>That prompt unlocks the user’s Keychain where most of their secrets are stored (passwords, private cryptographic keys, and more) and then exfiltrates all information to a third-party server. </p><p>Besides Keychain data, the CrashReporter <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> also pulls browser credentials and cookies from most browsers, data from 80 cryptocurrency wallet extensions, 14 <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, locally stored files, and more. </p><p>Jamf said CrashReporter overlaps, to some extent, with other known infostealers (AMOS, for example), but is still unique enough given its client-side encryption mechanism, as well as the native C++ implementation.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>