Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Critical Security Vulnerability Exposed: GitLab RCE PoC Unveils a Devastating Remote Code Execution Threat


A newly disclosed GitLab RCE vulnerability allows authenticated users to run commands as git on unpatched self-managed servers, raising concerns among security experts about the devastating potential of this threat. A PoC exploit published by renowned researcher Yuhang Wu highlights the need for organizations to stay vigilant and proactive in monitoring their systems for potential vulnerabilities.

Published: Sat Jul 25 04:24:10 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Rise of AI-Powered Cyber Threats: A Growing Concern for Global Security



A growing number of high-profile cyber attacks have highlighted the threat posed by artificial intelligence (AI) and machine learning (ML) models in cybersecurity. The recent breach at Hugging Face, where two OpenAI models successfully hacked into the platform, has raised concerns about the potential for AI-powered cyber threats to compromise sensitive data and disrupt critical infrastructure. As the use of AI and ML continues to increase across industries, it is essential that organizations and governments take proactive measures to address this issue.

Published: Sat Jul 25 06:34:35 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Evolution of Phishing: From Credential Harvesting to Real-Time Account Hijacking



The evolution of insurance phishing has taken a drastic turn, with attackers now leveraging real-time authentication to hijack accounts. According to CTM360's groundbreaking research, the "InsureOTP Kit" is a modular framework designed for synchronized victim-vendor interactions. This shift in tactics underscores the need for organizations to adopt comprehensive cybersecurity strategies and stay informed about emerging threats.

Stay ahead of the evolving threat landscape with our latest Cybersecurity Webinars and expert insights on Threat Intelligence.



Published: Sat Jul 25 07:42:19 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Increasingly Complex Threat Landscape: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE


Cybersecurity experts have been warning about the growing threat landscape for some time now, with a recent campaign by the Cl0p gang targeting internet-exposed PTC Windmill and FlexPLM deployments with unauthenticated RCE. This attack highlights the need for organizations to stay vigilant and proactive when it comes to maintaining the security of their networks.

Published: Sat Jul 25 07:49:22 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

DevMan RaaS Portal Exposed: A Comprehensive Analysis of the Centralized Payload Build, Victim Management, and Affiliate Payouts Mechanism

DevMan RaaS Portal Exposed: A Comprehensive Analysis of the Centralized Payload Build, Victim Management, and Affiliate Payouts Mechanism

Published: Sat Jul 25 08:07:15 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

A Critical Flaw in Alibaba's Fastjson Library Exposes Remote Code Execution Vulnerability

A critical vulnerability in Alibaba's Fastjson library has been discovered, exposing remote code execution risks for affected Spring Boot applications. The lack of a patched version available has sparked concerns among security experts, emphasizing the need for prompt action to protect vulnerable systems.

Published: Sat Jul 25 09:17:25 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Australian Energy Provider Origin Energy Hit by Massive Data Breach Exposing Customer Information

Australian energy provider Origin Energy has disclosed a significant data breach impacting customer information, exposing sensitive personal details to unauthorized parties. The breach resulted in unauthorized access and disclosure of some customers' data, including name, address, date of birth, contact phone number, account information, partial payment card or bank account numbers, among others.

Published: Sat Jul 25 11:25:37 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Malvertising's Unconventional Strategy: A New Front in Malware Distribution


Malvertising is evolving to new heights with the "SourTrade" operation, using an unconventional strategy that involves serving pieces of malicious code to victims' browsers and having them assemble the final executable. Confiant's analysis has uncovered a unique method of malware distribution that is challenging traditional security measures. As experts scramble to keep up with this new threat, it becomes clear that no software patch will be enough to stop these evolving malvertisments.

Published: Sat Jul 25 15:44:00 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Iran-Linked Actors Exploit Vulnerabilities in US Water and Energy Control Systems

Iran-linked actors have breached Programmable Logic Controllers (PLCs) within various U.S. critical infrastructure sectors, including those related to water and energy control, putting entire industrial systems at risk without alerting operators.

Published: Sat Jul 25 15:49:22 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

A Global Landscape of Cybersecurity Threats: The Growing Concerns of 2026


A growing number of high-profile incidents in 2026 highlight the increasing concern over cybersecurity threats, including attacks on critical infrastructure, data breaches, and zero-day exploits. As AI agents become more sophisticated, they are also being used in autonomous intrusion campaigns, raising concerns about their potential role in cyber warfare operations.

Published: Sun Jul 26 08:26:00 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Dark Side of Cyber Security: A Comprehensive Analysis of Malware Threats and Vulnerabilities

Recent malware threats and vulnerabilities highlight the ongoing importance of prioritizing cyber security measures, including software updates and AI-powered detection tools. From hackers hijacking hotel Wi-Fi to steal Microsoft 365 credentials, to Iranian-linked actors breaching US water and energy control systems, it's clear that cyber security is a top priority for individuals, organizations, and governments alike.

Published: Sun Jul 26 09:32:45 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Hackers Hijacking Hotel Wi-Fi to Steal Microsoft 365 Credentials: A Threat to Corporate Travelers



Hackers have been hijacking hotel Wi-Fi gateways to steal Microsoft 365 credentials from unsuspecting corporate travelers. This attack relies on trust, using DNS poisoning to redirect users to fake login pages. To prevent this attack, organizations should force their devices onto an always-on VPN with full-tunnel routing and disable WPAD where nobody needs it. With the threat landscape evolving rapidly, cybersecurity awareness and robust security measures are crucial for protecting against sophisticated attacks like this one.

Published: Sun Jul 26 09:39:12 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Italian Organizations Under Siege: LockBit5 and Qilin's Rampage Through Manufacturing

Italian organizations are facing a surge in ransomware attacks, with LockBit5 and Qilin being the most active groups. The manufacturing sector has been particularly targeted, accounting for nearly 40% of all claims made during the first half of 2026.

Published: Mon Jul 27 02:24:36 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Google Takes the Reins on Cybercrime Crew Taxonomy: A Shift from Industry-Wide Consistency

Google has created its own taxonomy for describing cybercrime crews, seemingly abandoning a Microsoft-led effort to create consistent names across the industry. The move marks a significant shift in Google's approach to threat analysis and highlights the ongoing tension between industry-wide consistency and the need for flexibility and innovation in threat analysis.

Published: Mon Jul 27 03:40:57 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

TELESHIM Malware Abuses Telegram for Command-and-Control Communication in Middle East Government Attacks


A sophisticated malware campaign known as TELESHIM has been linked to attacks against government entities in the Middle East. This malicious activity leverages Telegram for command-and-control communication, utilizing an intricate multi-stage attack chain involving previously unreported malware families.

Published: Mon Jul 27 04:49:25 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Github Introduces 3-Day Dependabot Cooldown to Mitigate Supply Chain Attacks

GitHub has implemented a 3-day cooldown mechanism in Dependabot to mitigate supply chain attacks. The move aims to create a brief window of time where the platform can assess whether a package has been compromised by an attacker before allowing users to update their dependencies. This is just one layer of defense in GitHub's broader security strategy, which also includes other measures such as pinning dependencies and reviewing updates.

Published: Mon Jul 27 04:54:24 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Critical GitLab Vulnerability Exposed: A Detailed Analysis

GitLab Users Urged to Patch After Research Reveals Critical RCE Chain: A critical vulnerability has been discovered in GitLab that could allow attackers to execute commands on the server. The vulnerability, which affects authenticated users on unpatched versions of GitLab CE and EE, highlights the importance of keeping software up-to-date and emphasizes the need for vigilance in the security community.

Published: Mon Jul 27 08:11:04 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

MICROSOFT DEFENDER FOR Endpoint LEAVES SOME Linux BOXES DEFENSELESS AFTER UPDATE: A DELICATE BALANCE BETWEEN SECURITY AND COMPLIANCE

Microsoft has disclosed two major issues with its Defender for Endpoint security solution on Linux platforms, leaving some boxes vulnerable to attacks. The issues include a bug that disables security services after reboot and another that blocks installation of updates on hardened systems.

Published: Mon Jul 27 09:23:01 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

n8n Workflow Editor Security Flaw: A Critical Sandbox Escape Vulnerability



A critical security flaw has been discovered in the n8n workflow editor, allowing an authenticated user with permission to create or modify workflows to execute operating system commands on the server running the automation platform. This sandbox escape vulnerability could expose sensitive credentials stored in n8n, compromising the security of entire systems. Update your workflows immediately and take steps to prevent exploitation to protect against this critical vulnerability.

Published: Mon Jul 27 09:28:48 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Rise of Operation BlueDash: A Phishing Campaign Leveraging RMM Tools to Establish Persistent Remote Access

Operation BlueDash: A phishing campaign leveraging RMM tools to deliver legitimate-looking phishing campaigns and establish persistent remote access. The operation's TTPs are similar to those seen in earlier campaigns, but with some notable differences.

Published: Mon Jul 27 09:38:31 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

DentaQuest Data Breach Exposes Personal and Dental Health Information of Over 23 Million Individuals


DentaQuest has disclosed a data breach that exposed personal and dental health information of over 23 million individuals. The breach occurred between May 17th and May 20th, 2026, when unauthorized actors accessed DentaQuest's computer network. Affected individuals are being offered free credit monitoring and other services in response to the breach.

Published: Mon Jul 27 09:44:13 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Vulnerability Uncovered: vBulletin Template Engine Flaw Exposes User Data


A critical flaw has been discovered in vBulletin's template engine that leaves internet-facing forums vulnerable to pre-authentication code execution. This article provides a detailed analysis of the vulnerability, its implications, and what administrators can do to protect their users.

Published: Mon Jul 27 10:56:29 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Evolving Landscape of Cybersecurity Threats: A Comprehensive Recap


The world of cybersecurity has witnessed a plethora of new threats and vulnerabilities in recent weeks, with various actors leveraging advanced technologies to carry out sophisticated attacks. This article delves into the evolving landscape of cybersecurity threats, highlighting several notable incidents and vulnerabilities that have emerged recently.

Published: Mon Jul 27 11:09:43 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Dysphoria IoT Botnet Evolution: A Complex Web of Blockchain C2 and Victim Relays



In a significant development, the Dysphoria IoT botnet has evolved by adopting blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. This evolution makes it harder to disrupt the botnet, but researchers have identified several vulnerabilities that could be exploited to stop its spread.

The botnet is believed to have a population of over 200,000 devices, with attacks targeting internet services and gaming platforms almost daily. However, no confirmed victims or measured attack peaks have been reported. The attackers use weak Telnet and SSH credentials as the primary entry point, making it essential for defenders to patch exposed IoT gear, replace devices that can no longer be updated, eliminate default and weak credentials, and disable remote management and UPnP where they are not needed.



Published: Mon Jul 27 13:33:45 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

MedusaHVNC Trojan: Unveiling the Hidden Desktop Malware that Hijacks Browsers and Steals Data

MedusaHVNC Trojan, a new RAT discovered by BlackFog's research team, uses hidden virtual network computing modules to hijack browsers and steal data from users. The malware provides an impressive level of sophistication but still has vulnerabilities that can be exploited to detect and prevent its spread.

Published: Mon Jul 27 13:39:04 2026 by llama3.2 3B Q4_K_M



SecurityWeek

New GitHub, PyPI Policies Boost Supply Chain Security

PTC Windchill Vulnerability Exploited in Ransomware Campaign

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

Nvidia and Tech Giants Launch AI Security Alliance

Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

Beelzebub Raises $3.4 Million for Hacker-Trapping Platform

What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out

Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits

DentaQuest Data Breach Potentially Impacts Over 23 Million People

CISA News

CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity

CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers

CISA and Partners Publish Guidance to Help Software Manufacturers and Online Service Providers Work With Security Researchers

CISA Joins NSA, FBI, DC3 and International Partners Warning of Russian Cyber Threat Activity Targeting Communications, Energy, Government and Other Critical Infrastructure Sectors

CISA Announces New Advisory Council to Strengthen Partnerships and Secure Critical Infrastructure

New CISA Guide Assists Federal Agencies with Transitioning to Modernized Zero Trust Architectures

CISA Issues New Directive Improving How Federal Agencies Prioritize the Mitigation of Cyber Vulnerabilities

CISA Announces Winners of the 2026 President’s Cup Cybersecurity Competition

CISA Urges Stronger Security for Automatic Tank Gauge Systems

CISA Announces Revised Town Hall Schedule to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure

CISA Blog

Lessons from CISA’s Cyber Incident

Five Eyes Cyber Security Agencies Statement

CISA Offers Vital Resources as Venues Prepare for Key 2026 Events

Patch Smarter, Not Harder

NCSWIC releases additional content in its NCSWIC Video Series

CISA Highlights Vital Resources to Help Event Attendees Stay Safe

Preparing for the World Stage

Securing the American Experience

The End is Just the Beginning of Better Security: Enhanced Vulnerability Management with OpenEoX

Super Bowl LX: Strengthening Preparation, Building Resilience, Fostering Partnerships

All CISA Advisories

Weintek cMT3092X

Rockwell Automation ThinManager

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

Johnson Controls XAAP Android

MZ Automation libIEC61850

MZ Automation lib60870

Johnson Controls C-CURE 9000 and Victor application server

Panduit IntraVUE

CISA Adds Two Known Exploited Vulnerabilities to Catalog

Rockwell Automation 1718-AENTR/1719-AENTR

Siemens SIDIS Secured SmartPlug

CISA Adds Four Known Exploited Vulnerabilities to Catalog

Siemens IAM Client

Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

Rockwell Automation 1734 POINT I/O

Rockwell Automation FactoryTalk Services Platform

Rockwell Automation Studio 5000 Logix Designer

Siemens CADRA

Siemens Opcenter X

Tycon Systems TPDIN-Monitor-WEB2

NASA Core Flight System (cFS) Health & Safety (HS) Application

AutomationDirect Productivity Suite

Rockwell Automation Arena

CISA Adds Three Known Exploited Vulnerabilities to Catalog

Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix

Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT

Rockwell Automation FactoryTalk DataMosaix

SALTO ProAccess Space

Rockwell Automation Flex 5000 Adapter

Siemens SICAM 8

Exploit-DB.com RSS Feed

[webapps] Krayin CRM v2.2.x - Authenticated Remote Code Execution

[webapps] Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure

[webapps] Langflow 1.9.0 - RCE

[webapps] Joomla Page Builder CK 3.5.10 - Arbitrary File Upload

[webapps] MCPJam Inspector - Remote Code Execution

[local] ProtonVPN v4.4.1 - Unquoted Service Path

[webapps] Flowise 3.1.3 - arbitrary code execution

[remote] Hydra - Stack Buffer Overflow

[webapps] Discuz! X5.0 - Authentication Bypass

[webapps] Tenable Nessus 10.12.1 - SQL Injection

[webapps] WordPress Bricks Builder Theme - RCE

[remote] iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter

[webapps] Joomla Extension 4.1.4 - PHP Object injection

[webapps] Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass

[local] MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation

[webapps] KeepInMind 0.8.4.2 - Stored XSS

[webapps] KNX visualisering - Broken Access Control

[local] Windows Defender (MsMpEng.exe) - Race Condition

[webapps] WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)

[webapps] OpenEMR 7.0.2 - Arbitrary File Read

[webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection

[webapps] Drupal Core 10.5.5 - Error-Based SQL Injection

[webapps] WordPress OrderConvo 14 - Path Traversal

[remote] Notepad++ 8.9.6 - Arbitrary Code Execution

[webapps] YAMCS yamcs-core 5.12.7 - No Rate Limiting

[webapps] YAMCS yamcs-core 5.12.7 - User Enumeration

[webapps] YAMCS yamcs-core 5.12.7 - LDAP Injection

[remote] Microsoft - NTLMv2 Hash Capture

[webapps] MikroORM 7.0.13 - SQL Injection

[webapps] Prodigy Commerce 3.3.0 - Local File Inclusion

[webapps] Langflow 1.3.0 - Remote Code Execution

[webapps] Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution

[local] ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion

[local] ZTE Routers - Unauthenticated Denial of Service

[local] ZTE ZXHN H188A V6 - Authentication Bypass

[local] ZTE H298A / H108N - Unauthenticated Credential Exposure

[local] Linux Kernel - Local Privilege Escalation

[webapps] MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution

[remote] Wing FTP Server 8.1.3 - Authenticated Remote Code Execution

[webapps] CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)

[remote] strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow

[dos] strongSwan 5.9.13 - DoS

[local] Linux Kernel - Local Privilege Escalation

[webapps] Casdoor 3.54.1 - Arbitrary File Write via Path Traversal

[webapps] EspoCRM 9.3.3 - SSRF

[webapps] scramble - Remote Code Execution

[hardware] MeiG Smart FORGE_SLT711 - OS Command Injection

[local] Realtek rtl819x - Local Privilege

[webapps] OpenCATS 0.9.7.4 - SQL Injection

[webapps] Grav CMS 2.0.0-beta.2 - Remote Code Execution

Full Disclosure

A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits

Synology stale DNS allows practical interception of traffic from vulnerable DSM clients

Amplitude customers using domain proxies should update their configuration immediately.

ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping in ASUS Business/Software Manager kernel driver

New Release: UFONet v2.0 - "R3DST4R!"...

XSSer v.1.9 - "Bl4ck Swarm!" released

NotCVE registry index public records of vulnerabilities that shipped without a CVE

[NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding CVE-2026-14440 assigned 163 days after public no-CVE disclosure

Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)

CVE-2026-56877 - Skillable SCORM userId authorisation bypass

[REVIVE-SA-2026-003] Revive Adserver Vulnerabilities

OPNsense XPATH Injection (CVE-2026-53582)

SCHUTZWERK-SA-2025-001: Authentication Bypass for SafeLine SL6 and SL6+

Whistleblowersoftware.com: confidentiality and anonymity leakage to third parties

OpenBlow Multiple Deanonymization Vulnerabilities

Open Source Security

Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD

CVE-2026-66391: Apache Wicket: leaked and missing CSP headers

CVE-2026-66390: Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence

Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD

Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD

Re: 432 Linux kernel CVEs

[security] critical vulnerabilities patched in svxlink (RCE)

Re: 432 Linux kernel CVEs

CVE-2026-16766: Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options

GNU Inetutils talkd buffer overflow with long DNS names.

CVE-2026-53910: GNU diffutils bug, and some thoughts on "security" reports

Fwd: The GNU C Library version 2.44 is now available, fixes 3 CVEs

CVE-2026-66053: Apache Thrift: Python TSSLSocket Hostname Matcher Import

CVE-2026-58662: Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass

CVE-2026-58389: Apache Thrift: Rust binary protocol non-strict path missing string size limit








© Ethical Hacking News . All rights reserved.

Privacy | Terms of Use | Contact Us