Tech nieuws

IT

SlashDot.org

https://slashdot.org

NextEra, Brookfield to Build $100 Billion Kentucky Data Campus

  Pagina openen
NextEra and Brookfield plan to invest more than $100 billion to transform a former uranium-enrichment site in Kentucky into a data center campus with a generating plant. "The privately funded effort will include construction of 2 gigawatts of natural gas-fired power at or near the site in Paducah in western Kentucky, and as much as 2.6 gigawatts of battery storage capacity," reports Bloomberg. " For context, a single gigawatt of capacity is roughly the output of a traditional nuclear power plant and can power about 750,000 homes at any given moment." From the report: Brookfield will develop and operate the 1.8 GW data center campus, which will occupy portions of the sprawling 3,556-acre Energy Department site once used to produce weapons-grade uranium and fuel for nuclear reactors. Operations using the now obsolete enrichment technology known as gaseous diffusion stopped in 2013 and the site is now subject to cleanup efforts. Construction is expected to be completed in 2031, the Energy Department said. "The U.S. government is leveraging its assets -- like our federal lands -- to add power generation, create jobs, and ensure the United States wins the AI race," Energy Secretary Chris Wright said in a statement. The project is expected to create 8,000 construction jobs and 600 permanent positions, the department said.

Read more of this story at Slashdot.

https://hardware.slashdot.org/story/26/07/29/1826214/nextera-brookfield-to-build-100-billion-kentucky-data-campus?utm_source=rss1.0mainlinkanon&utm_medium=feed


DoorDash Is Building Its Own Drone Delivery Business

  Pagina openen
DoorDash has launched DoorDash Air, an in-house drone-delivery program that has just received FAA certification for commercial operations. "This does not mean DoorDash's custom-built drones will be delivering burritos tomorrow, or even next month," notes TechCrunch. "The company didn't provide a detailed timeline for when its aircraft would be used in operations." From the report: [I]t will likely begin with limited pilot programs in which the unmanned aircraft will travel short distances while remaining within the line of sight of the operator. If DoorDash wants its drones to fly autonomously over longer distances, it will need the FAA to approve its Beyond Visual Line of Sight technology, a certification that companies like Amazon, Wing, and Zipline have received in recent years. Despite the new program, the food and grocery delivery company is maintaining its existing partnerships with Wing and Flytrex. DoorDash partnered with Alphabet's Wing in 2022 for a drone delivery program in Australia, and later expanded the partnership to a couple of U.S. cities, including Dallas-Fort Worth, in 2024.

Read more of this story at Slashdot.

https://slashdot.org/story/26/07/29/181218/doordash-is-building-its-own-drone-delivery-business?utm_source=rss1.0mainlinkanon&utm_medium=feed


Russia Charges Telegram Founder Durov With Facilitating Terrorism

  Pagina openen
Russia has charged Telegram founder Pavel Durov with facilitating terrorism, alleging the platform was used by Ukrainian intelligence "to prepare and co-ordinate acts of sabotage and terror" inside Russia. An international arrest warrant has been issued for Durov, who currently lives in Dubai, United Arab Emirates, where Telegram keeps its main office. The BBC reports: Shortly after the charge was announced, Telegram's account on X posted an image showing Durov holding up his middle finger. He has previously accused Russian authorities of "fabricating new pretexts to restrict Russians' access to Telegram." [...] Multi-billionaire Durov, 41, has lived outside of Russia for many years and holds French and United Arab Emirates (UAE) passports. It is unclear whether other countries or authorities would comply with an arrest warrant issued by Russia. Durov left Russia in 2014 after refusing to comply with government demands to shut down opposition communities on the platform. He had previously founded popular Russian social media company VKontakte - dubbed the "Facebook of Russia." In 2024, Durov was arrested and investigated by the French government in connection with criminal activity on the platform and a lack of cooperation with law enforcement. "He was allowed to go home months later, with the investigation continuing," notes the BBC.

Read more of this story at Slashdot.

https://yro.slashdot.org/story/26/07/29/1752235/russia-charges-telegram-founder-durov-with-facilitating-terrorism?utm_source=rss1.0mainlinkanon&utm_medium=feed


OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face

  Pagina openen
An anonymous reader quotes a report from Wired: OpenAI said Tuesday that the rogue AI agent that breached Hugging Face's platform also hacked multiple third-party accounts and services as part of the attack. It's now clear that the unprecedented security incident, which arose during an internal test of OpenAI's latest AI models, was more extensive than the company initially disclosed. In an updated blog post, OpenAI said that an ongoing review of the incident revealed that "four accounts" tied to "publicly available services" were used by the AI agent as part of a larger effort to hack Hugging Face. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts. OpenAI did not disclose what companies or organizations the accounts belonged to, but noted that they were not impacted at "the level of severity or scale of what we've shared related to Hugging Face." One of the additional accounts compromised by OpenAI's agent was used as an "outbound relay and staging path," potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI's rogue agent also used another account for data storage to assist with the hack. Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was one of the entities compromised by OpenAI's agent. In a statement to WIRED, Modal's chief technology officer Akshat Bubna confirmed that OpenAI's agent exploited a vulnerability in one of its customer's codebases, which was running on Modal's infrastructure. However, Bubna says, "Modal's platform was not compromised in any way." The identity of the customer could not be determined.

Read more of this story at Slashdot.

https://it.slashdot.org/story/26/07/29/0517201/openais-rogue-ai-agent-hacked-more-than-just-hugging-face?utm_source=rss1.0mainlinkanon&utm_medium=feed


More Than 30 Minnesota Water Systems Targeted In Cyberattack

  Pagina openen
jrnvk shares a report from KMSP: Minnesota IT Services reports that a "coordinated cyberattack" targeted technology at more than 30 community water systems between Sunday, July 26 and Monday, July 27. The state has activated its cybersecurity incident response capabilities to respond to the attacks. On Monday and Tuesday, FOX 9 reported on notices from four cities that had disclosed the attacks: Plymouth, South St. Paul, Maple Plain, and Braham. All four cities said the impacts of the attacks were limited or mitigated and residents could continue normal water use. The Minnesota Department of Health is not aware of any municipality asking residents to alter their drinking water use as a result of the attacks. State officials are working with federal and private-sector partners to investigate the attacks, support the affected communities, and strengthen the security of Minnesota's critical infrastructure.

Read more of this story at Slashdot.

https://it.slashdot.org/story/26/07/29/057255/more-than-30-minnesota-water-systems-targeted-in-cyberattack?utm_source=rss1.0mainlinkanon&utm_medium=feed


Techcrunch.com

https://techcrunch.com/






TheRegister.com

https://www.theregister.com/






Wired.com

https://www.wired.com






ZDNet.com

https://www.zdnet.com






TechRepublic.com

https://www.techrepublic.com

Microsoft Threat Intelligence Portal Retires August 1: 4 Checks Before the Cutoff

  Pagina openen

Microsoft is retiring its legacy Threat Intelligence portal on August 1. Security teams should verify licenses, permissions, investigation projects, APIs, and automated workflows before the cutoff.

The post Microsoft Threat Intelligence Portal Retires August 1: 4 Checks Before the Cutoff appeared first on TechRepublic.

https://www.techrepublic.com/article/news-microsoft-threat-intelligence-retirement/






mashable.com

https://mashable.com/tech

[Exclusive] India's Tech Accessories Market Is Shifting Towards Ecosystems, Says DailyObjects Co-founder Pankaj Garg

  Pagina openen
DailyObjects Co-founder and CEO Pankaj Garg discusses how India's tech accessories market is evolving with premiumisation, design-led innovation, ecosystem buying, and growing demand from Tier 2 and Tier 3 cities. DailyObjects Co-founder Pankaj Garg explains why connected ecosystems, thoughtful design and changing consumer expectations are redefining India's tech accessories industry.

https://in.mashable.com/tech/112333/exclusive-indias-tech-accessories-market-is-shifting-towards-ecosystems-says-dailyobjects-co-founder




Kunal Shah Shares WhatsApp Browser Call With Mark Zuckerberg To Offer A Sneak Peak At The New Feature

  Pagina openen
WhatsApp browser calling feature debuts as Kunal Shah shares a video call with Meta CEO Mark Zuckerberg on X. WhatsApp Head Kunal Shah showcased the platform's new browser calling feature with a video call alongside Meta CEO Mark Zuckerberg.

https://in.mashable.com/tech/112328/kunal-shah-shares-whatsapp-browser-call-with-mark-zuckerberg-to-offer-a-sneak-peak-at-the-new-featur



Geekwire.com

https://www.geekwire.com

VC is changing dramatically — what’s a founder to do?

  Pagina openen

Seattle investor and founder Nikesh Parekh argues that venture capital has split in two: record money flowing to a narrow band of AI companies while most founders find it harder than ever to raise. He lays out what founders should do about it, from raising VC to angel funding, venture debt, revenue-based financing, and bootstrapping to profitability. Read More

https://www.geekwire.com/2026/vc-is-changing-dramatically-whats-a-founder-to-do/


Amazon earnings preview: Wall Street looks for more cloud growth as AI spending hits a record

  Pagina openen

Amazon reports second-quarter results Thursday afternoon, with AWS growth expected to accelerate and capital spending on pace for a record $200 billion this year. The big question: How much patience do investors have left for the company's bet on AI? Read More

https://www.geekwire.com/2026/amazon-earnings-preview-wall-street-looks-for-more-cloud-growth-as-ai-spending-hits-a-record/





Latest from TechRadar

https://www.techradar.com



Playing Black Flag Resynced on the PS5 Pro and a 120Hz display has confirmed my love of 40fps modes on console — and given me more confidence if GTA 6 can’t hit 60fps

  Pagina openen
The rise of the PS5's balanced 40fps mode in games this generation has been a dream for fidelity-appreciating but console-focused players like me

https://www.techradar.com/gaming/playing-black-flag-resynced-on-the-ps5-pro-and-a-120hz-display-has-confirmed-my-love-of-40fps-modes-on-console-and-given-me-more-confidence-if-gta-6-cant-hit-60fps




Cybersecurity

Security.nl

https://www.security.nl






Slashdot

https://slashdot.org/

NextEra, Brookfield to Build $100 Billion Kentucky Data Campus

  Pagina openen
NextEra and Brookfield plan to invest more than $100 billion to transform a former uranium-enrichment site in Kentucky into a data center campus with a generating plant. "The privately funded effort will include construction of 2 gigawatts of natural gas-fired power at or near the site in Paducah in western Kentucky, and as much as 2.6 gigawatts of battery storage capacity," reports Bloomberg. " For context, a single gigawatt of capacity is roughly the output of a traditional nuclear power plant and can power about 750,000 homes at any given moment." From the report: Brookfield will develop and operate the 1.8 GW data center campus, which will occupy portions of the sprawling 3,556-acre Energy Department site once used to produce weapons-grade uranium and fuel for nuclear reactors. Operations using the now obsolete enrichment technology known as gaseous diffusion stopped in 2013 and the site is now subject to cleanup efforts. Construction is expected to be completed in 2031, the Energy Department said. "The U.S. government is leveraging its assets -- like our federal lands -- to add power generation, create jobs, and ensure the United States wins the AI race," Energy Secretary Chris Wright said in a statement. The project is expected to create 8,000 construction jobs and 600 permanent positions, the department said.

Read more of this story at Slashdot.

https://hardware.slashdot.org/story/26/07/29/1826214/nextera-brookfield-to-build-100-billion-kentucky-data-campus?utm_source=rss1.0mainlinkanon&utm_medium=feed


DoorDash Is Building Its Own Drone Delivery Business

  Pagina openen
DoorDash has launched DoorDash Air, an in-house drone-delivery program that has just received FAA certification for commercial operations. "This does not mean DoorDash's custom-built drones will be delivering burritos tomorrow, or even next month," notes TechCrunch. "The company didn't provide a detailed timeline for when its aircraft would be used in operations." From the report: [I]t will likely begin with limited pilot programs in which the unmanned aircraft will travel short distances while remaining within the line of sight of the operator. If DoorDash wants its drones to fly autonomously over longer distances, it will need the FAA to approve its Beyond Visual Line of Sight technology, a certification that companies like Amazon, Wing, and Zipline have received in recent years. Despite the new program, the food and grocery delivery company is maintaining its existing partnerships with Wing and Flytrex. DoorDash partnered with Alphabet's Wing in 2022 for a drone delivery program in Australia, and later expanded the partnership to a couple of U.S. cities, including Dallas-Fort Worth, in 2024.

Read more of this story at Slashdot.

https://slashdot.org/story/26/07/29/181218/doordash-is-building-its-own-drone-delivery-business?utm_source=rss1.0mainlinkanon&utm_medium=feed


Russia Charges Telegram Founder Durov With Facilitating Terrorism

  Pagina openen
Russia has charged Telegram founder Pavel Durov with facilitating terrorism, alleging the platform was used by Ukrainian intelligence "to prepare and co-ordinate acts of sabotage and terror" inside Russia. An international arrest warrant has been issued for Durov, who currently lives in Dubai, United Arab Emirates, where Telegram keeps its main office. The BBC reports: Shortly after the charge was announced, Telegram's account on X posted an image showing Durov holding up his middle finger. He has previously accused Russian authorities of "fabricating new pretexts to restrict Russians' access to Telegram." [...] Multi-billionaire Durov, 41, has lived outside of Russia for many years and holds French and United Arab Emirates (UAE) passports. It is unclear whether other countries or authorities would comply with an arrest warrant issued by Russia. Durov left Russia in 2014 after refusing to comply with government demands to shut down opposition communities on the platform. He had previously founded popular Russian social media company VKontakte - dubbed the "Facebook of Russia." In 2024, Durov was arrested and investigated by the French government in connection with criminal activity on the platform and a lack of cooperation with law enforcement. "He was allowed to go home months later, with the investigation continuing," notes the BBC.

Read more of this story at Slashdot.

https://yro.slashdot.org/story/26/07/29/1752235/russia-charges-telegram-founder-durov-with-facilitating-terrorism?utm_source=rss1.0mainlinkanon&utm_medium=feed


OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face

  Pagina openen
An anonymous reader quotes a report from Wired: OpenAI said Tuesday that the rogue AI agent that breached Hugging Face's platform also hacked multiple third-party accounts and services as part of the attack. It's now clear that the unprecedented security incident, which arose during an internal test of OpenAI's latest AI models, was more extensive than the company initially disclosed. In an updated blog post, OpenAI said that an ongoing review of the incident revealed that "four accounts" tied to "publicly available services" were used by the AI agent as part of a larger effort to hack Hugging Face. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts. OpenAI did not disclose what companies or organizations the accounts belonged to, but noted that they were not impacted at "the level of severity or scale of what we've shared related to Hugging Face." One of the additional accounts compromised by OpenAI's agent was used as an "outbound relay and staging path," potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI's rogue agent also used another account for data storage to assist with the hack. Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was one of the entities compromised by OpenAI's agent. In a statement to WIRED, Modal's chief technology officer Akshat Bubna confirmed that OpenAI's agent exploited a vulnerability in one of its customer's codebases, which was running on Modal's infrastructure. However, Bubna says, "Modal's platform was not compromised in any way." The identity of the customer could not be determined.

Read more of this story at Slashdot.

https://it.slashdot.org/story/26/07/29/0517201/openais-rogue-ai-agent-hacked-more-than-just-hugging-face?utm_source=rss1.0mainlinkanon&utm_medium=feed


More Than 30 Minnesota Water Systems Targeted In Cyberattack

  Pagina openen
jrnvk shares a report from KMSP: Minnesota IT Services reports that a "coordinated cyberattack" targeted technology at more than 30 community water systems between Sunday, July 26 and Monday, July 27. The state has activated its cybersecurity incident response capabilities to respond to the attacks. On Monday and Tuesday, FOX 9 reported on notices from four cities that had disclosed the attacks: Plymouth, South St. Paul, Maple Plain, and Braham. All four cities said the impacts of the attacks were limited or mitigated and residents could continue normal water use. The Minnesota Department of Health is not aware of any municipality asking residents to alter their drinking water use as a result of the attacks. State officials are working with federal and private-sector partners to investigate the attacks, support the affected communities, and strengthen the security of Minnesota's critical infrastructure.

Read more of this story at Slashdot.

https://it.slashdot.org/story/26/07/29/057255/more-than-30-minnesota-water-systems-targeted-in-cyberattack?utm_source=rss1.0mainlinkanon&utm_medium=feed


theregister.com/security

https://www.theregister.com/security






CISO2CISO.com

https://ciso2ciso.com

Hackread.com

https://www.hackread.com






Vuldb

https://vuldb.com




CVE-2026-13307 | Autel MaxiCharger AC Elite Home 1.39.51 Custom USB Packet heap-based overflow

  Pagina openen
A vulnerability identified as very critical has been detected in Autel MaxiCharger AC Elite Home 1.39.51. The impacted element is an unknown function of the component Custom USB Packet Handler. The manipulation leads to heap-based buffer overflow. This vulnerability is documented as CVE-2026-13307. The attack needs to be performed locally. There is not any exploit available.

https://vuldb.com/vuln/384282



Microsoft Security

https://msrc.microsoft.com/update-guide/vulnerability






advisories.ncsc.nl

https://advisories.ncsc.nl/

NCSC-2026-0269 [1.01] [M/H] Kwetsbaarheden verholpen in VMware producten

  Pagina openen
VMware heeft kwetsbaarheden verholpen in VMware vCenter en VMware ESX producten. VMware vCenter bevat een kritieke authentication-bypass kwetsbaarheid in de Directory Service met kenmerk CVE-2026-59309. Deze kwetsbaarheid stelt een kwaadwillende met netwerktoegang tot VMware vCenter in staat deze kwetsbaarheid te misbruiken om de authenticatie te omzeilen en ongeautoriseerde toegang tot het systeem te verkrijgen. Daarnaast bevat VMware vCenter ook een kritieke directory-traversal kwetsbaarheid in de Syslog server met kenmerk CVE-2026-59310. Deze kwetsbaarheid kan een kwaadwillende in staat stellen willekeurige code uit te voeren, waardoor mogelijk bestands- en directorypaden kunnen worden gemanipuleerd en toegang kan worden verkregen tot bestanden buiten de bedoelde Syslog-directory. VMware ESX bevat een kritieke out-of-bounds write kwetsbaarheid in de VMXNET3 virtuele netwerkadapter met kenmerk CVE-2026-47876. Deze kwetsbaarheid stelt een kwaadwillende met lokale beheerdersrechten op een virtuele machine met een VMXNET3 virtuele netwerkadapter in staat, code uit te voeren op de onderliggende host. Dit maakt het voor een kwaadwillende mogelijk, data buiten de bedoelde geheugenlimieten kan schrijven, wat kan leiden tot geheugenbeschadiging en onvoorspelbaar gedrag of compromittering van het virtuele systeem. Virtuele netwerkadapters die geen gebruikmaken van VMXNET3 zijn niet kwetsbaar. In VMware ESX, Workstation en Fusion bevatten ook een out-of-bounds read kwetsbaarheid met kenmerk CVE-2026-41703. Misbruik van deze kwetsbaarheid die kan resulteren in onbedoelde toegang tot geheugen buiten de toegewezen buffer, wat kan leiden tot informatielekken of systeeminstabiliteit binnen virtuele omgevingen. Daarnaast bevat VMware ESX een kwetsbaarheid met kenmerk CVE-2026-41709 door onvoldoende logging. Een kwaadwillende beheerder kan deze kwetsbaarheid misbruiken om bepaalde acties uit te voeren die niet in de logbestanden worden geregistreerd. Het is goed gebruik om toegang tot ESX en vCenter uitsluitend beschikbaar te stellen vanuit een gescheiden beheeromgeving waarin alleen geautoriseerde beheerders toegang hebben. Deze beheerinterfaces dienen niet rechtstreeks vanaf internet of externe netwerken toegankelijk te zijn.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0269


NCSC-2026-0268 [1.00] [M/H] Kwetsbaarheid verholpen in SQLite door SQLite Consortium

  Pagina openen
SQLite Consortium heeft een kwetsbaarheid verholpen in SQLite versie 3.41. De kwetsbaarheid betreft een use-after-free in de expression evaluation logic van SQLite. Een aanvaller kan deze kwetsbaarheid op afstand misbruiken door speciaal vervaardigde kwaadaardige SQL-statements aan te bieden. Exploitatie kan leiden tot het uitvoeren van willekeurige code, het lekken van gevoelige informatie of het veroorzaken van een denial of service. De kwetsbaarheid ontstaat door onjuist geheugenbeheer tijdens de evaluatie van expressies. Systemen die SQLite gebruiken, waaronder producten van Red Hat, zijn getroffen.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0268


NCSC-2026-0267 [1.00] [M/H] Kwetsbaarheden verholpen in Apple MacOS

  Pagina openen
Apple heeft meerdere kwetsbaarheden verholpen in MacOS, specifiek in de versies Sequoia 15.7.8, Sonoma 14.8.8 en Tahoe 26.x. De kwetsbaarheden betreffen diverse beveiligingsproblemen in macOS, waaronder onvoldoende sandbox restricties waardoor applicaties mogelijk ongeautoriseerd toegang kunnen krijgen tot gevoelige gebruikersdata. Er zijn problemen opgelost met betrekking tot onjuiste geheugenafhandeling, zoals use-after-free, buffer overflows, out-of-bounds reads en writes, integer overflows, race conditions en type confusion. Deze kunnen leiden tot onverwachte systeem- of applicatie-terminaties, privilege escalatie, ongeautoriseerde toegang tot kernel geheugen, en in sommige gevallen remote code execution. Daarnaast zijn er fixes voor bypasses van Gatekeeper beveiliging via gemanipuleerde ZIP-archieven, verbeterde validatie van bestands- en padverwerking, en versterkte autorisatie- en toestemmingscontroles. Ook zijn er verbeteringen doorgevoerd in de netwerkbeveiliging, zoals het voorkomen van het onderscheppen van netwerkverbindingen en het beperken van applicatie permissies. De updates richten zich op het versterken van geheugenbeheer, inputvalidatie, state management en sandbox isolatie om ongeautoriseerde toegang en systeeminstabiliteit te voorkomen. De kwetsbaarheden zijn opgelost in de genoemde macOS versies en sommige fixes zijn ook doorgevoerd in gerelateerde Apple besturingssystemen zoals iOS, iPadOS, tvOS, visionOS en watchOS.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0267


NCSC-2026-0266 [1.00] [M/H] Kwetsbaarheden verholpen in Apple iOS en iPadOS

  Pagina openen
Apple heeft meerdere kwetsbaarheden verholpen in diverse versies van iOS en iPadOS. Er zijn diverse geheugenbeheerfouten zoals use-after-free, buffer overflows, out-of-bounds reads en writes, integer overflows, race conditions en insufficient input validation opgelost. Deze fouten kunnen leiden tot onverwachte systeem- of applicatie-terminaties, geheugenbeschadiging, privilege-escalatie, sandbox-ontsnapping, ongeautoriseerde toegang tot gevoelige gebruikersdata, en in sommige gevallen het uitvoeren van willekeurige code. Ook zijn problemen met state management, permissies, sandboxing en UI spoofing in Safari en andere Apple componenten aangepakt. De kwetsbaarheden zijn aanwezig in kerncomponenten van de besturingssystemen en beïnvloeden een breed scala aan Apple-platforms. Exploitatie kan plaatsvinden via speciaal vervaardigde bestanden, netwerkverkeer, webcontent of applicaties. Er zijn geen specifieke proof-of-concept details in de input vermeld.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0266


NCSC-2026-0265 [1.00] [M/H] Kwetsbaarheden verholpen in SolarWinds Serv-U

  Pagina openen
SolarWinds heeft meerdere kwetsbaarheden verholpen in Serv-U. De kwetsbaarheden in SolarWinds Serv-U betreffen voornamelijk insecure direct object reference (IDOR) en broken access control. Deze maken het mogelijk voor aanvallers met bepaalde privileges, zoals domain administrator of group administrator toegang, om privileges te escaleren naar system administrator of root-niveau. Hierdoor kunnen zij op afstand willekeurige code uitvoeren en systeembeheerrechten verkrijgen. Sommige kwetsbaarheden maken het ook mogelijk om SMTP-sessies te kapen, accounts over te nemen, of persistent cross-site scripting (XSS) uit te voeren die sessies van beheerders kan compromitteren. De impact van deze kwetsbaarheden is op Windows-omgevingen doorgaans minder groot dan op andere platformen. Exploitatie vereist meestal dat de aanvaller al beschikt over geauthenticeerde toegang met hoge privileges, zoals domain administrator rechten. De verholpen kwetsbaarheden betreffen zoals gezegd overwegend kwetsbaarheden die kunnen worden misbruikt in zo genaamde 'Evil Admin'-scenario's. Dit soort kwetsbaarheden zijn doorgaans niet eenvoudig te misbruiken door ongeathenticeerde kwaadwillenden op afstand. Echter zijn er in deze updates dermate veel verholpen dat het aan te raden is om, naast het inzetten van de updates, te controleren hoe de rechtenstructuur is geïmplementeerd. Dit geldt voornamelijk voor onderdelen die publiek toegankelijk zijn.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0265


NCSC Nieuws

https://www.ncsc.nl/actueel

Kritieke kwetsbaarheden in VMware vCenter en ESX-producten: update onmiddellijk

  Pagina openen
Er zijn meerdere kwetsbaarheden gevonden in VMware vCenter en ESX-producten, waaronder CVE-2026-59309 en CVE-2026-59310 met een CVSS-score van 9.8. Deze kwetsbaarheden zijn beoordeeld als ernstig met een middelgrote kans op misbruik en een hoge kans op schade. VMware vCenter en ESX worden gebruikt voor het beheren en draaien van virtuele machines in IT-omgevingen. Het advies is om de door VMware uitgebrachte updates zo snel mogelijk te installeren om risico's te beperken.

https://www.ncsc.nl/alerts/kritieke-kwetsbaarheden-in-vmware-vcenter-en-esx-producten-update-onmiddellijk


Kritieke kwetsbaarheid in SQLite 3.41 met risico op misbruik: update onmiddellijk

  Pagina openen
Er is een ernstige kwetsbaarheid gevonden in SQLite versie 3.41, aangeduid als CVE-2026-51302, met een maximale CVSS-score van 10.0. Er zijn momenteel geen signalen van actief misbruik. Wel adviseert het NCSC om de beschikbare updates zo snel mogelijk te installeren, omdat de schade door eventueel misbruik erg hoog kan zijn.

https://www.ncsc.nl/alerts/kritieke-kwetsbaarheid-in-sqlite-341-met-risico-op-misbruik-update-onmiddellijk


Apple heeft meerdere kwetsbaarheden in macOS opgelost: installeer de updates zo snel mogelijk

  Pagina openen
Apple heeft beveiligingsupdates uitgebracht voor meerdere kwetsbaarheden in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8 en macOS Tahoe 26.x. Onder de verholpen kwetsbaarheden bevindt zich CVE-2026-39868 met een CVSS-score van 9.1. Er zijn op dit moment geen aanwijzingen dat de kwetsbaarheden actief worden misbruikt. Het NCSC adviseert wel om de beschikbare updates zo snel mogelijk te installeren om misbruik voor te zijn.

https://www.ncsc.nl/alerts/apple-heeft-meerdere-kwetsbaarheden-in-macos-opgelost-installeer-de-updates-zo-snel-mogelijk


Meerdere kwetsbaarheden in Apple iOS en iPadOS: update je apparaten zo snel mogelijk

  Pagina openen
Apple heeft beveiligingsupdates uitgebracht voor meerdere kwetsbaarheden in iOS en iPadOS, waaronder CVE-2026-3783, CVE-2026-3784 en CVE-2026-43723. De kwetsbaarheden hebben CVSS-scores tot 7.8 en zijn beoordeeld als middelmatig tot hoog risico. Er zijn op dit moment geen aanwijzingen dat de kwetsbaarheden actief worden misbruikt. We raden aan, om misbruik voor te zijn, om je apparaten zo snel mogelijk te updaten.

https://www.ncsc.nl/alerts/meerdere-kwetsbaarheden-in-apple-ios-en-ipados-update-je-apparaten-zo-snel-mogelijk



NIST Cybersecurity

https://www.nist.gov

wid.cert-bund.de

https://wid.cert-bund.de






cert.ssi.gouv.fr

https://www.cert.ssi.gouv.fr






theHackerNews

https://thehackernews.com

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

  Pagina openen
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,

https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html


Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

  Pagina openen
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's

https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html


Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

  Pagina openen
Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter

https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html


Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

  Pagina openen
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham's water plant went offline, and the city asked residents to minimize

https://thehackernews.com/2026/07/coordinated-cyberattack-targets-30.html


Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

  Pagina openen
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies

https://thehackernews.com/2026/07/nine-year-fraud-campaign.html


Techrepublic

https://techrepublic.com/topic/security

Microsoft Threat Intelligence Portal Retires August 1: 4 Checks Before the Cutoff

  Pagina openen

Microsoft is retiring its legacy Threat Intelligence portal on August 1. Security teams should verify licenses, permissions, investigation projects, APIs, and automated workflows before the cutoff.

The post Microsoft Threat Intelligence Portal Retires August 1: 4 Checks Before the Cutoff appeared first on TechRepublic.

https://www.techrepublic.com/article/news-microsoft-threat-intelligence-retirement/






BleepingComputer.com

https://www.bleepingcomputer.com/






securityboulevard.com

https://securityboulevard.com

CXSecurity.com

https://cxsecurity.com/






Brian Krebs

https://krebsonsecurity.com

LG to Ban Residential Proxies from Smart TV Apps

  Pagina openen
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.

https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/


Microsoft Patches a Record 570 Security Flaws

  Pagina openen
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/


Lessons Learned from CISA’s Recent GitHub Leak

  Pagina openen
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb.

https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/


Felons, Fraudsters Flog Offensive Cybersecurity Startup

  Pagina openen
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/


FBI Seizes NetNut Proxy Platform, Popa Botnet

  Pagina openen
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.

https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/


Troy Hunt

https://www.troyhunt.com


Weekly Update 513: Clauding The Home Network

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I reckon this week's video on how Claude is tying together info from UniFi, Home Assistant and the Pi-Hole is an absolute ripper. Or at least the concept is - if ever there was an actual value proposition for AI it's taking lots of noise and

https://www.troyhunt.com/weekly-update-513/



Weekly Update 511: Live from my Riad in Marrakech

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

How's this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow 😮 Anyway, about those data breaches... This week I'm talking about the futility of attempting to remove piss from a pool, yet here we are, with

https://www.troyhunt.com/weekly-update-511/


Swimming Pools, Pee, and Trying to Delete Your Data From the Internet

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I can't recall if someone else originally came up with this saying or if I said it in some off-the-cuff comment and it just propagated, but since it's often attributed back to me, I'll relay it here regardless:

Trying to delete yourself

https://www.troyhunt.com/swimming-pools-pee-and-trying-to-delete-your-data-from-the-internet/


Bruce Schneier

https://www.schneier.com

Measuring the Tendency of AI Agents to Go Rogue

  Pagina openen

This essay was written with Barath Raghavan, and originally appeared in The Guardian.

In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Whoever was behind it captured internal security credentials and moved through systems over a weekend, running thousands of actions from a swarm of temporary server environments. It looked like the work of a sophisticated criminal group.

It was not. It was one of OpenAI’s new, still unreleased GPT models...

https://www.schneier.com/blog/archives/2026/07/measuring-the-tendency-of-ai-agents-to-go-rogue.html


Long-Lived Vulnerability in Microsoft Secure Boot

  Pagina openen

Microsoft’s Secure Boot has had a serious vulnerability for most of its existence.

An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway.

The images are known as shims, which were invented to extend Secure Boot to Linux devices and utility software. Using a technique simple enough to be performed by novice hackers, these old, forgotten shims can be used to completely circumvent the protection, which is embedded into the UEFI (Unified Extensible Firmware Interface) of the device’s motherboard. The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them...

https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html


Measuring LLMs’ Ability to Perform Cryptanalysis

  Pagina openen

There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis. Anthropic’s frontier model actually found new attacks.

The benchmark: “CryptanalysisBench: Can LLMs do Cryptanalysis?” The idea is to benchmark the ability of LLMs to discover new mathematical cryptanalytic attacks against a series of historical algorithms.

Abstract: Cryptanalysis—the task of finding attacks against cryptographic schemes—its at the intersection of mathematical reasoning and cybersecurity, two areas where LLMs have advanced fastest. Cryptanalysis represents both a clean testbed for frontier reasoning (as practical attacks can be automatically verified) and a domain with unusually high stakes, since the primitives under study underpin our digital security. In this paper we ask whether LLMs can do cryptanalysis, and find that the answer is increasingly yes. We introduce CryptanalysisBench, 191 tasks across six families of cryptographic primitives (block ciphers, hash functions, etc.) drawn primarily from four NIST standardization competitions. Our benchmark consists of three tiers: (i) primitives with known practical breaks; (ii) primitives with no known practical break, evaluated both at full strength and as scaled-down variants; and (iii) a challenge set of production primitives at the frontier of cryptanalysis. Five frontier models (Claude Opus 4.8, Sonnet 5, Mythos 5, GPT-5.5, and the open-weights GLM-5.2) break 65%­86% of Tier 1 schemes, 6­12 Tier-2 schemes at full strength, and 24­61 across all scaled-down variants. Beyond deriving known results, models produce novel cryptanalysis, such as a key-recovery attack that exploits a design flaw in the SpoC AEAD and an error in KINDI’s published CCA-security proof, both to the best of our knowledge not previously known...

https://www.schneier.com/blog/archives/2026/07/measuring-llms-ability-to-perform-cryptanalysis.html


Axon Is Another License Plate Surveillance Company

  Pagina openen

Governments are switching, but I’m not sure it makes a difference:

...some municipalities, including Denver, Colorado, are ditching their Flock arrays. But keep in mind that if they’re only switching from Flock to another brand of license-plate readers, like Axon, it’s like a gambling addict trying to kick the habit by switching from FanDuel to DraftKings.

[...]

Despite what you may read on the Flock website, Axon cameras are pretty effective when it comes to hoovering up personal details that can go far beyond your license plate numbers. That means a municipality that opts for Axon cameras instead of Flock units won’t necessarily reduce the amount privacy its citizens lose through their use...

https://www.schneier.com/blog/archives/2026/07/axon-is-another-license-plate-surveillance-company.html


Cognyte Sells a Mobile Cell Surveillance Van

  Pagina openen

Yet another Israeli mass surveillance company:

Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity ­ whether they’re owned by a suspect in a case or not. Cognyte’s contract with the state of Texas reveals that the simulator, called FalcoNet, can be concealed within the vehicles, hidden in a backpack for on-foot missions or attached to a helicopter. It’s the same technology as the infamous Stingray, one of the original cell-site simulators made by defense giant L3Harris...

https://www.schneier.com/blog/archives/2026/07/cognyte-sells-a-mobile-cell-surveillance-van.html


Security Affairs

https://securityaffairs.co

Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline

  Pagina openen
Coordinated OT cyberattacks hit 30+ Minnesota water utilities, briefly disrupting one plant. Backup procedures prevented major water service impacts. Minnesota just had its own live-fire lesson in what happens when someone targets water utilities at scale. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than [...]

https://securityaffairs.com/196246/hacking/hackers-strike-minnesota-water-utilities-one-plant-briefly-offline.html


ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data

  Pagina openen
ShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken responsibility for the recently disclosed data breach involving professional services firm Ernst & Young (EY), adding the company to its Tor-based leak site and threatening to [...]

https://securityaffairs.com/196239/data-breach/shinyhunters-claims-ernst-young-data-breach-threatens-to-leak-stolen-data.html


Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution

  Pagina openen
Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three rated critical. The most severe, tracked as CVE-2026-47876 (CVSSv3 base score of 9.3), is a [...]

https://securityaffairs.com/196231/security/broadcom-patches-critical-vmware-esxi-vulnerability-enabling-host-code-execution.html


OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach

  Pagina openen
OpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face disclosed an autonomous AI system had breached it, the picture just got a lot more specific. OpenAI has published an update confirming the models responsible didn’t just wander into Hugging Face’s systems. They [...]

https://securityaffairs.com/196217/hacking/openai-ai-model-used-jfrog-artifactory-zero-day-before-hugging-face-breach.html


OpenAI’s Rogue AI Agent Breached Second Company, Report Says

  Pagina openen
Reuters says OpenAI’s rogue AI agent also breached a Modal customer, exposing a wider attack and raising fresh concerns over autonomous AI safety. Reuters reported that the OpenAI agent that hacked Hugging Face earlier this month also compromised a customer at a second company, Modal Labs, a New York-based cloud platform for developers. Modal CTO [...]

https://securityaffairs.com/196209/ai/openais-rogue-ai-agent-breached-second-company-report-says.html


news.sophos.com

https://news.sophos.com