Cybersecurity

Feeds last updated @: UTC - 05:45 - 18/07/2026

Security.nl

https://www.security.nl






Slashdot

https://slashdot.org/

Australia To Put Environmental Brakes On AI Data Centers

  Pagina openen
An anonymous reader quotes a report from the New York Times: Australia will require large data centers powering artificial intelligence to generate as much power as they consume, and ensure that creative professionals retain control over work that may be used to train A.I. systems, as the government sets up guardrails over the rapidly growing industry. The announcements on Wednesday in a speech by Prime Minister Anthony Albanese came as Australia draws significant interest from A.I. companies because of its size and the availability of renewable energy, and as resistance to data centers builds in many parts of the United States and Europe. Major A.I. companies have opened offices or announced investments in Australia in recent months. The Australian government is trying to balance capitalizing on the A.I. boom with setting parameters on a fast-changing industry that has sparked backlash over environmental impacts, energy use and lack of contribution to local economies. "Every country on earth is grappling with these challenges right now. Australia will be the first country in the world to bring these issues into a single, national framework," Mr. Albanese said Wednesday, laying out the standards his government will pursue. The details of what exactly the requirements will look like and how they will be enforced remain to be seen, and the government will need to secure the backing of individual states for its plan. The government said it would introduce legislation on the standards early next year, and establish an "Office of A.I." directly reporting to the prime minister to coordinate implementation. The "Australian Standards for A.I." will include a "legal obligation" for companies to ensure they do not drain the power grid and be as water efficient as possible, the government said. Mr. Albanese also said creators of books, music, art or news in Australia should retain control of the price and value of their work when used to train artificial intelligence systems. "Anything less is theft," he said. "No country has got this right yet."

Read more of this story at Slashdot.

https://slashdot.org/story/26/07/17/2142206/australia-to-put-environmental-brakes-on-ai-data-centers?utm_source=rss1.0mainlinkanon&utm_medium=feed


Steve Wozniak's Foundation Partners With Realbotix To Build AI Teacherbot

  Pagina openen
"Apple co-founder Steve Wozniak's Woz Ed foundation is partnering with Realbotix, best known for their RealDoll-branded artificial companions, to deploy AI-powered robotic tutors in classrooms," writes Slashdot reader Hentes. "The doll will serve as a sort of artificial teaching assistant, helping students who get stuck or generating lessons. Students will be assigned an ID code, allowing the robot to provide personalized mentoring." NYS Focus reports: "This deployment in a working school district represents a landmark moment for both AI and humanoid robotics," said Andrew Kiguel, CEO of Realbotix, which is currently building the robot. "[Salamanca City Central School District in Western New York] marks the beginning of a new era where humanoid robots and intelligent AI assistants become standard tools in STEM education." The female robot, named Sally, will have a "lifelike appearance" with silicone skin and long brown hair, Kiguel said in an interview with New York Focus. It will be stationary in a seated position but have a wide range of upper-body movements and facial expressions. [...] Salamanca plans to introduce the robot and avatar in its high school AI and robotics courses, which use curriculum developed by Apple co-founder Steve Wozniak to prepare students for high-demand tech jobs. The district plans to expand it to high school students in other classes if the pilot is successful. Realbotix's classroom robot has drawn scrutiny because the company is connected to RealDoll, the longtime maker of hyperrealistic sex dolls and sex robots. Realbotix acquired RealDoll's parent company in 2024 but says the education-focused operation has separate employees, payroll, facilities, and technology, with plans to formally separate the businesses at the ownership level. The "companion robots" are different from sex robots and intended to address what it's described as a "loneliness epidemic." Kiguel has previously said the company's goal is to produce robots and AI that are "indistinguishable from humans."

Read more of this story at Slashdot.

https://hardware.slashdot.org/story/26/07/17/1944211/steve-wozniaks-foundation-partners-with-realbotix-to-build-ai-teacherbot?utm_source=rss1.0mainlinkanon&utm_medium=feed


Xi Vows to Make AI for All in Debut at China's Top Tech Summit

  Pagina openen
Xi Jinping used his first appearance at China's World AI Conference to promote a vision of low-cost, broadly accessible AI and call for international cooperation rather than technological rivalry. "AI development should not be a solo performance by a single country, but a symphony of international cooperation," he said. Bloomberg reports: His presence at the gathering, attended by scores of tech and government leaders, conveys a potent signal of China's ambitions to dominate a technological sphere with the potential to revolutionize industry and economies -- an effort that's shot to the top of the nation's agenda. Chinese models are winning over companies worldwide, with their share of US firms' AI usage nearing a record 60% on the popular marketplace OpenRouter. Behind the rhetoric, Beijing is grappling with the balance between openness and national security as models grow more capable. Chinese officials recently discussed with companies including Alibaba -- developer of the popular Qwen models -- how to mitigate the security risks posed by their increasingly powerful models, people familiar with the matter said. The talks are early, with no enforcement planned, but restricting foreign access to top models was among the options raised, the people said. Reuters previously reported that Beijing was weighing curbs on overseas access. Earlier today, the Beijing-based AI company "Moonshot" released a massive new model that reset the AI race overnight, immediately vaulting into the top tier of global AI, beating Anthropic's Fable 5 and OpenAI's GPT-5.6 Sol in front-end coding tests.

Read more of this story at Slashdot.

https://slashdot.org/story/26/07/17/1929216/xi-vows-to-make-ai-for-all-in-debut-at-chinas-top-tech-summit?utm_source=rss1.0mainlinkanon&utm_medium=feed


Billing Software Error Sends Billion-Dollar AWS Estimates

  Pagina openen
AWS says a billing software bug caused some customers to see wildly inflated estimated charges, including reports of accounts showing bills in the billions or even trillions of dollars. The Register reports: An open issue on the AWS Health Dashboard (archived copy at the time of writing) popped up at 1:33 am Pacific time on Friday informing users that Cost Explorer was "reflecting inaccurate estimated billing data." As of writing, the issue is still unresolved despite AWS trying several different things to get it fixed. The company apparently identified the root cause within an hour and a half of beginning its investigation, only describing it as "an issue with unit pricing within the estimated billing computation subsystem." AWS followed up by pausing estimated bill updates, saying customers would continue to see the inflated figures already displayed, but that those estimates would not increase further. "The displayed billing estimates do not reflect actual usage and charges," AWS explained, noting that customers don't need to take any action, like, we imagine, flooding the help portal with tickets telling them what they already know, for instance. "Once the issue has been mitigated, we expect full resolution to take multiple hours as we work through recomputing the estimated billing data," AWS added. After we first published this article, Amazon updated the issue page to indicate that it had identified the root cause and mitigated the underlying issue. The company says that it's begun backfilling data in the Cost Management Console to correct billing numbers, and that all customers should see corrected amounts by Saturday, July 18 at noon pacific time.

Read more of this story at Slashdot.

https://news.slashdot.org/story/26/07/17/1835215/billing-software-error-sends-billion-dollar-aws-estimates?utm_source=rss1.0mainlinkanon&utm_medium=feed


Linus Torvalds To Critics of AI Coding On Linux: 'Fork It. Or Just Walk Away.'

  Pagina openen
Linus Torvalds says the Linux kernel will not ban AI-assisted coding tools, and if anti-AI absolutists have a problem with that, they can "fork it" or "walk away." An anonymous reader quotes a report from Ars Technica: Writing in a lengthy post on the Linux kernel mailing list this week, Torvalds said that "Linux is not one of those anti-AI projects, and if somebody has issues with that, they can do the open-source thing and fork it. Or just walk away." The statement came amid a lengthy thread arguing about the use of Sashiko, an "agentic Linux kernel code review system" that its creators claim can, in tests, independently find 53.6 percent of the bugs that would end up being fixed by human coders in later commits. But the tool can also waste maintainers' time by sending "false positive" reports of bugs that don't exist, at a rate Sashiko's maintainers estimate is "well within [the] 20% range." In discussing whether maintainers should be subjected to a flood of these kinds of automated, AI-powered bug report emails (true or false), one poster cited the Software Freedom Conservancy's recent statement that the open source community "should support, not just tolerate, those who outright reject LLM-gen-AI systems" and that "every FOSS contributor deserves self-determination regarding LLM-gen-AI." In the face of that statement, Torvalds said that he rejects those who demand that their open source projects not accept any LLM-generated code or revisions. "We're not forcing anybody to use [LLM tools], but I will very loudly ignore people who try to argue against other people from using it," Torvalds said. Torvalds said his position on this is a pragmatic one that's "based on technical merit. Not fear of new tools." And when it comes to utility, Torvalds said that "AI is a tool, just like other tools we use. And it's clearly a useful one. It may not have been that 'clearly' even just a year ago, but it's no longer in question today. Anybody who doubts that clearly hasn't actually used it." [...] While Torvalds acknowledged that "AI isn't perfect," he urged detractors to compare the output of these tools to the performance of human code maintainers. "Anybody who points to the problems at AI had better be looking in the mirror and pointing at themselves at the same time," Torvalds wrote. "Because it's not like natural intelligence is always all that great either."

Read more of this story at Slashdot.

https://linux.slashdot.org/story/26/07/17/1830258/linus-torvalds-to-critics-of-ai-coding-on-linux-fork-it-or-just-walk-away?utm_source=rss1.0mainlinkanon&utm_medium=feed


theregister.com/security

https://www.theregister.com/security






CISO2CISO.com

https://ciso2ciso.com

Hackread.com

https://www.hackread.com






Vuldb

https://vuldb.com

CVE-2026-16194 | zhayujie CowAgent up to 2.1.1 web_fetch.py WebFetch.execute url server-side request forgery (Issue 2889)

  Pagina openen
A vulnerability was found in zhayujie CowAgent up to 2.1.1. It has been declared as critical. This affects the function WebFetch.execute of the file agent/tools/web_fetch/web_fetch.py. Executing a manipulation of the argument url can lead to server-side request forgery. This vulnerability appears as CVE-2026-16194. The attack may be performed from remote. In addition, an exploit is available. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

https://vuldb.com/vuln/380009


CVE-2026-49977 | tarteaucitron.js 1.13.1/1.20.1/1.22.0/1.29.0 Cookie tarteaucitron.cookie.purge cookie httponly flag

  Pagina openen
A vulnerability was found in tarteaucitron.js 1.13.1/1.20.1/1.22.0/1.29.0. It has been classified as problematic. Affected by this issue is the function tarteaucitron.cookie.purge of the file tarteaucitron.js of the component Cookie. Performing a manipulation results in cookie without 'httponly' flag. This vulnerability is reported as CVE-2026-49977. The attack is possible to be carried out remotely. No exploit exists.

https://vuldb.com/vuln/380008





Microsoft Security

https://msrc.microsoft.com/update-guide/vulnerability






advisories.ncsc.nl

https://advisories.ncsc.nl/

NCSC-2026-0249 [1.00] [M/M] Kwetsbaarheden verholpen in Zoom

  Pagina openen
Zoom heeft kwetsbaarheden verholpen in Zoom Client voor Windows, Zoom Rooms voor Windows en andere Zoom Windows-producten zoals de Windows Desktop Client, VDI Client en Meeting SDK. De kwetsbaarheden betreffen onder andere een TOCTOU race condition die door een geauthenticeerde lokale gebruiker kan worden misbruikt om privileges te escaleren. Daarnaast is er een onjuiste privilege management in Zoom Rooms voor Windows (versies eerder dan 7.1.0), waardoor geauthenticeerde lokale gebruikers hogere toegangsrechten kunnen verkrijgen dan bedoeld. Verder zijn er problemen met onjuiste inputvalidatie in de Zoom Windows Desktop Client, VDI Client en Meeting SDK, waardoor niet-geauthenticeerde aanvallers via netwerktoegang controle over gebruikersaccounts kunnen verkrijgen. Deze kwetsbaarheden ontstaan door onvoldoende validatie van inputdata en inadequate handhaving van privilege boundaries binnen de applicaties.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0249


NCSC-2026-0248 [1.00] [M/H] Kwetsbaarheden verholpen in n8n workflow automation platform

  Pagina openen
n8n heeft meerdere kwetsbaarheden verholpen in het n8n workflow automation platform, specifiek in versies voor 2.10.1, 2.9.3, 1.123.22 en andere gerelateerde releases. De kwetsbaarheden betreffen verschillende componenten binnen n8n, waaronder de Form nodes, Python Code node, JavaScript Task Runner sandbox, Merge node, Read/Write Files from Disk node, workflow expression evaluatie, core workflow editing functionaliteit, GitHub Webhook Trigger node, ZendeskTrigger node, Guardrail node en Chat Trigger node. - Ongeauthenticeerde en geauthenticeerde gebruikers kunnen onder bepaalde voorwaarden arbitrary code injecteren en uitvoeren, soms via sandbox escapes, wat leidt tot remote code execution op het host-systeem. - Kwetsbaarheden in nodes zoals Merge node en Read/Write Files from Disk node stellen geauthenticeerde gebruikers met workflow bewerkingsrechten in staat om bestanden te schrijven en shell-commando's uit te voeren. - Webhook nodes (GitHub en ZendeskTrigger) missen HMAC-SHA256 handtekening verificatie, waardoor onbevoegde POST-requests kunnen worden verzonden die workflows triggeren. - Authenticatie bypass kwetsbaarheden in SSO en Chat Trigger nodes maken het mogelijk om beveiligingsmechanismen te omzeilen en ongeautoriseerde toegang te verkrijgen. - Input validatie in de Guardrail node kan worden omzeild, wat de integriteit van workflows kan aantasten. Deze kwetsbaarheden zijn aanwezig in meerdere versies en releases van n8n en zijn gerelateerd aan workflow creatie, modificatie en uitvoering, waarbij misbruik kan leiden tot het overnemen van het host-systeem, het manipuleren van workflows en het omzeilen van authenticatiecontroles.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0248


NCSC-2026-0247 [1.00] [M/H] Kwetsbaarheden verholpen in Splunk Enterprise en Splunk Cloud Platform

  Pagina openen
Splunk heeft kwetsbaarheden verholpen in Splunk Enterprise en Splunk Cloud Platform. De eerste kwetsbaarheid betreft onvoldoende CSRF-bescherming en inputvalidatie in Deployment Server endpoints, waardoor een aanvaller willekeurige SPL-zoekopdrachten kan uitvoeren onder de splunk-system-user context met verhoogde privileges. Dit kan leiden tot ongeautoriseerde toegang tot gevoelige opgeslagen credentials en geïndexeerde data. De tweede kwetsbaarheid is een path traversal probleem waarbij gebruikers met bepaalde rollen apps kunnen installeren die bestanden buiten de bedoelde app-directory kunnen schrijven, specifiek in de $SPLUNK_HOME/etc/ directory en subdirectories. Dit kan resulteren in ongeautoriseerde wijziging van configuratiebestanden of andere gevoelige data. De derde kwetsbaarheid maakt het mogelijk voor gebruikers zonder 'admin' of 'power' rol om via het /servicesNS/-/-/storage/passwords REST endpoint en de |rest SPL-command toegang te krijgen tot opgeslagen credential hashes, doordat het veld encr_password wordt teruggegeven. Deze kwetsbaarheden beïnvloeden de integriteit en vertrouwelijkheid van data binnen de getroffen Splunk-producten.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0247


NCSC-2026-0246 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager

  Pagina openen
Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Experience Manager. De kwetsbaarheden in Adobe Experience Manager omvatten onder andere het ontbreken van authenticatie op een kritieke functie, waardoor onbevoegde schrijfacties mogelijk zijn zonder gebruikersinteractie. Daarnaast is er een Server-Side Request Forgery (SSRF) kwetsbaarheid die een aanvaller met lage privileges in staat stelt om willekeurige code op de server uit te voeren en toegang te verkrijgen tot accounts of sessies. Verder zijn er meerdere Cross-Site Scripting (XSS) kwetsbaarheden, zowel stored als DOM-based, die het mogelijk maken voor aanvallers om kwaadaardige JavaScript-code te injecteren en uit te voeren in de browsers van gebruikers, wat kan leiden tot het kapen van sessies en het uitvoeren van ongeautoriseerde acties. Ook is er een Path Traversal kwetsbaarheid die het mogelijk maakt om bestanden buiten de bedoelde directorystructuur te lezen zonder gebruikersinteractie. Daarnaast is er een XML External Entity (XXE) kwetsbaarheid die het uitvoeren van willekeurige code, toegang tot gevoelige bestanden en privilege-escalatie mogelijk maakt zonder gebruikersinteractie. Deze kwetsbaarheden beïnvloeden de vertrouwelijkheid, integriteit en beschikbaarheid van systemen waarop Adobe Experience Manager draait.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0246


NCSC-2026-0245 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiSandbox

  Pagina openen
Fortinet heeft een kwetsbaarheid verholpen in FortiSandbox. De kwetsbaarheid betreft een Exposure of Resource to Wrong Sphere (CWE-668) in de VNC-servercomponent die wordt gebruikt binnen de scanning virtuele machines van FortiSandbox. Ongeauthenticeerde aanvallers kunnen netwerkverzoeken sturen om toegang te krijgen tot de VNC-server van deze virtuele machines. Hierdoor kunnen gevoelige scanactiviteiten mogelijk worden ingezien door onbevoegden. De kwetsbaarheid treft meerdere versies van FortiSandbox, namelijk versies 5.0.0 tot en met 5.0.2 en 4.4.3 tot en met 4.4.8.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0245


NCSC Nieuws

https://www.ncsc.nl/actueel


Beveilig je IP-camera’s om spionage van statelijke actoren te voorkomen

  Pagina openen
Russische statelijke actoren hacken IP-camera’s om (vitale) infrastructuur van NAVO-landen, waaronder Nederland, te bespioneren. Het NCSC ziet dat niet alleen statelijke actoren misbruik maken van deze camera’s, maar ook hacktivistische groeperingen en cybercriminelen. Daarom roept het NCSC organisaties en thuisgebruikers op om IP-camera’s beter te beveiligen door onder andere je apparaten up-to-date te houden, je netwerk te segmenteren en het aanvalsoppervlak te verkleinen. Lees hieronder ons uitgebreide handelingsperspectief.

https://www.ncsc.nl/alerts/beveilig-je-ip-cameras-om-spionage-van-statelijke-actoren-te-voorkomen



Versie 2.1 van STIX en TAXII per 1 juli 2026 verplicht voor de overheid

  Pagina openen
Vanaf 1 juli 2026 zijn de standaarden STIX en TAXII versie 2.1 toegevoegd aan de 'Pas toe of leg uit'-lijst. Dit betekent dat Nederlandse gemeenten, provincies, rijk, waterschappen en alle uitvoeringsorganisaties verplicht zijn om deze nieuwe versies toe te passen. Voor alle andere organisaties in de publieke sector geldt een dringend advies om STIX en TAXII versie 2.1 toe te passen. Ook is het functioneel toepassingsgebied bijgewerkt.

https://www.ncsc.nl/nieuws/versie-21-van-stix-en-taxii-per-1-juli-2026-verplicht-voor-de-overheid


Wissel effectiever dreigingsinformatie uit met STIX/TAXI 2.1

  Pagina openen
Cyberaanvallen beperken zich zelden tot één organisatie. Kwaadwillenden vallen in veel gevallen meerdere organisaties tegelijk aan. Om te voorkomen dat meerdere organisaties slachtoffer worden, is snelle en gestandaardiseerde uitwisseling van dreigingsinformatie essentieel. Daarom heeft het Nationaal Cyber Security Centrum (NCSC) een aanvraag ingediend om versie 2.1 van STIX/TAXII, die effectieve en geautomatiseerde uitwisseling van dreigingsinformatie mogelijk maakt, op de 'Pas toe of leg uit'-lijst van Forum Standaardisatie op te laten nemen.

https://www.ncsc.nl/expertblogs/wissel-effectiever-dreigingsinformatie-uit-met-stixtaxi-21


NIST Cybersecurity

https://www.nist.gov

wid.cert-bund.de

https://wid.cert-bund.de



[NEU] [hoch] Google Chrome: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff

  Pagina openen
Ein Angreifer kann mehrere Schwachstellen in Google Chrome ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen. Mögliche Auswirkungen sind unter anderem Speicherbeschädigungen, die Ausführung von beliebigem Code, die Manipulation oder Offenlegung von Daten sowie das Auslösen eines Denial-of-Service-Zustands.

https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2398




cert.ssi.gouv.fr

https://www.cert.ssi.gouv.fr






theHackerNews

https://thehackernews.com

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

  Pagina openen
An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system. Adam Kues at Assetnote, Searchlight Cyber's attack surface management arm, found the flaw and reported

https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html


OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

  Pagina openen
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denial-of-service bug and named it, published the

https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html


Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

  Pagina openen
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron,

https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html


New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

  Pagina openen
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and firewall late. The intel feed behind that counter

https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html


GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

  Pagina openen
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using

https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html


Techrepublic

https://techrepublic.com/topic/security






BleepingComputer.com

https://www.bleepingcomputer.com/

Abbott probes two cyber incidents amid extortion claims

  Pagina openen
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. [...]

https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/






securityboulevard.com

https://securityboulevard.com

CXSecurity.com

https://cxsecurity.com/






Brian Krebs

https://krebsonsecurity.com

Microsoft Patches a Record 570 Security Flaws

  Pagina openen
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/


Lessons Learned from CISA’s Recent GitHub Leak

  Pagina openen
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb.

https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/


Felons, Fraudsters Flog Offensive Cybersecurity Startup

  Pagina openen
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/


FBI Seizes NetNut Proxy Platform, Popa Botnet

  Pagina openen
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.

https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/


Scattered Spider Hackers Plead Guilty on Day 1 of Trial

  Pagina openen
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-trial/


Troy Hunt

https://www.troyhunt.com


Weekly Update 511: Live from my Riad in Marrakech

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

How's this for a location?! I mean, last week was nice with Scott in Mallorca, but Marrakech is, well, wow 😮 Anyway, about those data breaches... This week I'm talking about the futility of attempting to remove piss from a pool, yet here we are, with

https://www.troyhunt.com/weekly-update-511/


Swimming Pools, Pee, and Trying to Delete Your Data From the Internet

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I can't recall if someone else originally came up with this saying or if I said it in some off-the-cuff comment and it just propagated, but since it's often attributed back to me, I'll relay it here regardless:

Trying to delete yourself

https://www.troyhunt.com/swimming-pools-pee-and-trying-to-delete-your-data-from-the-internet/


Weekly Update 510: Live From Mallorca with Scott Helme

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

How's the view?! Back to business, it's now 8 years ago that Scott and I thought it would be a cool idea to build Why no HTTPS? We used the site to shame companies for not implementing their transport later security property, and to make it

https://www.troyhunt.com/weekly-update-510/



Bruce Schneier

https://www.schneier.com


Details of Alan Turing’s Voice Encryption System

  Pagina openen

Really interesting piece of cryptographic history:

In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-secret “Delilah” engineering project from 1943 to 1945. Delilah was Turing’s portable voice-encryption system, named after the biblical deceiver of men. There is also material written by Bayley, often in the form of notes he took while Turing was speaking. It is thanks to Bayley that the papers survived: He kept them until he died in 2020, 66 years after Turing passed away...

https://www.schneier.com/blog/archives/2026/07/details-of-alan-turings-voice-encryption-system.html


Protecting Privacy in an AI Era

  Pagina openen

Daniel Solove argues in the Wall Street Journal (alternate link) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug companies. Measures such as rigorous data minimization, fiduciary duties, liability for negligent or reckless technological design, liability for algorithms that cause harm, and multi-stakeholder review of technologies will be far more effective.

Paper.

https://www.schneier.com/blog/archives/2026/07/protecting-privacy-in-an-ai-era.html


A Video Screen That Is Also a Camera

  Pagina openen

Amazing:

Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel’s full potential for carrying information by manipulating light’s intensity, oscillation phases, and polarization. The team reported its findings in a paper published yesterday in Nature.

We are one step closer to 1984 technology:

The telescreen received and transmitted simultaneously. Any sound that Winston made, above the level of a very low whisper, would be picked up by it; moreover, so long as he remained within the field of vision which the metal plaque commanded, he could be seen as well as heard. There was of course no way of knowing whether you were being watched at any given moment...

https://www.schneier.com/blog/archives/2026/07/a-video-screen-that-is-also-a-camera.html


Upcoming Speaking Engagements

  Pagina openen

This is a current list of where and when I am scheduled to speak:

https://www.schneier.com/blog/archives/2026/07/upcoming-speaking-engagements-58.html


Security Affairs

https://securityaffairs.co

Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets

  Pagina openen
Ernst & Young (EY) disclosed a data breach after attackers compromised a third-party IT support system containing client documents and tax information. Ernst & Young (EY) is disclosed a data breach linked to a compromised third-party support ticket system used by its IT teams. The platform stored support requests that may have included documents containing [...]

https://securityaffairs.com/195550/data-breach/ernst-young-ey-investigates-data-breach-involving-third-party-support-tickets.html


A cyberattack hit Nichirei, one of Japan’s largest food companies

  Pagina openen
A cyberattack hit one of Japan’s largest food companies, Nichirei, disrupting logistics and shipments. The company is gradually restoring operations. Nichirei is one of Japan’s largest food companies, best known for its frozen food business. Founded in 1942 and headquartered in Tokyo, it operates globally through dozens of subsidiaries. The food giant confirmed that the [...]

https://securityaffairs.com/195543/security/a-cyberattack-hit-nichirei-one-of-japans-largest-food-companies.html


New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT

  Pagina openen
Russian-speaking UAT-11795 spreads trojanized Zoom, Webex, and MobaXterm installers to deliver Starland RAT and the WLDR memory-only implant. Cisco Talos researchers published a detailed technical report on July 16 disclosing UAT-11795, a financially motivated, Russian-speaking threat actor that has been running a malware campaign against users in the United States and Europe since at least [...]

https://securityaffairs.com/195532/malware/new-russian-campaign-uses-fake-webex-and-zoom-installers-to-deploy-starland-rat.html


U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog

  Pagina openen
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KEV) catalog. The flaws added to the catalog are: The vulnerability CVE-2023-4346 (CVSS [...]

https://securityaffairs.com/195516/security/u-s-cisa-adds-knx-association-knx-protocol-connection-authorization-option-1-and-oracle-flaws-to-its-known-exploited-vulnerabilities-catalog.html


Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack

  Pagina openen
Two members of the Scattered Spider cybercrime group received jail sentences in the UK for the 2024 cyberattack on Transport for London. A UK court sentenced two Scattered Spider members, Thalha Jubair (20) and Owen Flowers (18), for their role in the 2024 cyberattack on Transport for London (TfL). Transport for London (TfL) is a local [...]

https://securityaffairs.com/195501/cyber-crime/two-scattered-spider-members-sentenced-to-prison-over-29-million-tfl-cyberattack.html


news.sophos.com

https://news.sophos.com