Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
When Trusted Gov Infrastructure Becomes an Attack Channel: PhantomEnigma Puts Banks at RiskÂ
8+ hour, 10+ min ago (321+ words) A recent attack investigated by ANY.RUN experts revealed how attackers used more than 20 hijacked Brazilian government websites to support a campaign targeting banking organizations. Credential theft is one of the most dangerous parts of the PhantomEnigma campaign because it…...
Hackers Exploit ServiceNow Sandbox Escape Flaw for Pre-Auth Remote Code Execution
12+ hour, 13+ min ago (282+ words) Threat actors have begun actively exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform that allows unauthenticated remote code execution through a script sandbox escape. Threat intelligence firm Defused confirmed the first exploitation attempts surfaced on Friday, with…...
Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content
10+ hour, 9+ min ago (352+ words) Microsoft has confirmed that the Podcasts feature within its Copilot app will be officially discontinued starting August 18, 2026, cutting off access for users to create new podcasts or retrieve previously generated ones. The move affects the entire Copilot consumer user base,…...
Agentic Hacker Exploits Langflow RCE to Encrypt AI and Machine-Learning Infrastructure
13+ hour, 6+ min ago (446+ words) The operator exploited the Langflow remote code execution flaw tracked as CVE-2025-3248 and deployed a purpose-built ransomware tool called ENCFORGE to encrypt model checkpoints, vector databases, training data, and AI deployment artifacts. It allows unauthenticated attackers to execute arbitrary Python…...
PENTDEM AI Pentesting Daemon Uses 34 Security Tools to Automate Attack Chains
1+ day, 14+ hour ago (305+ words) A newly surfaced open-source project called PENTDEM is drawing attention for packaging 34 real-world penetration testing tools into an autonomous, LLM-guided daemon that can run full attack chains with minimal human input. According to Gabson, the tool arrives amid a broader…...
Critical Kimai Docker Flaw Lets Hackers Forge Cookies and Hijack Admin Accounts
1+ day, 15+ hour ago (394+ words) A critical vulnerability in the official Kimai Docker image has been disclosed, allowing unauthenticated attackers to forge authentication tokens and take over any user account, including super_admin, on affected deployments. Tracked as CVE-2026-52824, the flaw stems from a hardcoded default secret…...
Linux Furtex Toolkit Enables Stealthy Process Injection and Data Exfiltration
1+ day, 14+ hour ago (476+ words) A newly disclosed toolkit called Furtex is drawing attention for packaging a wide range of post-exploitation, evasion, and telemetry-blinding techniques into a single project built around raw io_uring and eBPF operations. The toolkit was publicly announced by MatheuZSecurity on July 19 as…...
DigiCert Security Breach Linked to GoldenEyeDog Certificate Hijacking Campaign
1+ day, 15+ hour ago (368+ words) DigiCert’s April 2026 security incident has been linked to a GoldenEyeDog subgroup tracked as CylindricalCanine, which allegedly used malware to compromise a support employee’s device and intercept code-signing certificate activation data. The attackers then used stolen certificates to sign malware, giving…...
Hugging Face Breach Driven End-to-End by Autonomous AI Agents
1+ day, 16+ hour ago (538+ words) Hugging Face disclosed this week that it detected and contained a security breach in its production infrastructure, marking what the company describes as the first incident in its history to be driven end-to-end by an autonomous AI agent system. The…...
OpenSSL DoS Flaw Lets Unauthenticated Attackers Trigger Massive Memory Allocation
3+ day, 16+ hour ago (349+ words) A newly disclosed critical weakness in OpenSSL lets an attacker crash a server without ever completing a handshake or proving their identity. Documented by the Okta Red Team, named “HollowByte,” the flaw takes advantage of how OpenSSL reserves memory during…...