> TODAY'S SUMMARY (10 articles)
Today's cyber news highlights a range of emerging threats and vulnerabilities. Notably, two unpatched zero-day vulnerabilities in Citrix NetScaler appliances are actively exploited, posing significant risks. Additionally, Microsoft SharePoint's CVE-2026-65660 has been flagged by CISA, indicating ongoing exploitation, with a patching deadline recently issued. The recent Gyazo breach has compromised 23.6 million user records, further emphasizing the growing risk of data exposure. In malware news, a notable report discusses the proliferation of cybercrime marketplaces, exemplified by Ardit Kutleshi's guilty plea for selling stolen data. On the positive side, Cloudflare has addressed a serious cross-tenant flaw that exposed customer data. Overall, the landscape remains dynamic, with AI integration in cybersecurity and malware research continuing to evolve.
|
// AI-powered summary generated at 16:00
Keyloggers, audio-visual surveillance, and token theft on CaptivePortal's agenda as hospitality sector put on alert
The payments giant says BioCatch’s behavioral and device intelligence will help financial institutions combat account takeovers, scams and other forms of digital fraud.
The post Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion appeared first on SecurityWeek.
The list of people behind companies, foundations and trusteeships is part of efforts to combat money laundering and terror financing.
The post Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations appeared first on SecurityWeek.
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. [...]
Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure
It's time. Time for tinkerers, security researchers, hackers, and fellow nerds to gather together in signature black hoodies and utilikilts to beat the heat in Las Vegas for the summer security conferences: BSidesLV, Black Hat USA, and DEF CON.
EFF's lawyers, activists, and technologists are excited...
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]
River Bank says hackers deleted data stolen in its June ransomware attack, though the investigation into the incident is still ongoing. River Financial Corporation, the parent company of River Bank & Trust, says hackers deleted data stolen during a ransomware attack that hit parts of its server...
Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered “On July 31, 2026, N‑able saw an increase...
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended.
Some of it was clever. Most of it was just access left lying aroun...
We break down CrashStealer — a new macOS infostealer: how it spreads, what data it steals, how it bypasses Apple’s built-in defenses, and what you can do to protect your Mac.
Mimecast has unveiled Agent Risk Center, a beta capability for discovering, monitoring, and governing AI agents, alongside Managed Threat Response, a redesigned 24/7 service that combines AI-assisted triage with analyst-confirmed remediation. According to Mimecast’s analysis, 98% of organizations al...
A Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention. Researchers at Palo Alto Networks’ Unit 42 uncovered the operation after the threat actor’s AI agent misconfigured a...
Trump rejects Tehran theory, blames 'grossly incompetent' governor of Minnesota instead
SentinelOne has today announced governed, closed-loop response across the Singularity Platform, delivering trustworthy automation for security operations. Purple AI and Singularity Hyperautomation now autonomously investigate alerts, reach verdicts, and execute responses. Security teams set the boun...
Horizon3.ai has announced a $250 million Series E at a valuation of more than $2 billion, tripling its valuation from $650 million at Series D in just over a year. The oversubscribed round was co-led by existing investors NightDragon and NEA, with participation from seven new investors and five retu...
See how Targeted Mobile Extraction and Collect Files in ADF Pro help investigators stay within warrant or consent scope while acquiring only the mobile data that matters.
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly dis...
The bank holding company was hacked in June, but the investigation into the incident continues.
The post River Bank Says Hackers Deleted Data Stolen in Ransomware Attack appeared first on SecurityWeek.