Cyber Security News
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit.
"FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP
Published: Mon, 20 Jul 2026 23:53:03 +0530, Author: info@thehackernews.com (The Hacker News)
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.
What makes it more than a
Published: Mon, 20 Jul 2026 22:59:50 +0530, Author: info@thehackernews.com (The Hacker News)
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.
Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks
Published: Mon, 20 Jul 2026 20:03:43 +0530, Author: info@thehackernews.com (The Hacker News)
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.
Here is the full
Published: Mon, 20 Jul 2026 19:02:26 +0530, Author: info@thehackernews.com (The Hacker News)
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops.
That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence
Published: Mon, 20 Jul 2026 17:43:39 +0530, Author: info@thehackernews.com (The Hacker News)
Mythos Didn't Break Your Security Program. Your Exposure Window Could.
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of
Published: Mon, 20 Jul 2026 17:00:00 +0530, Author: info@thehackernews.com (The Hacker News)
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02.
The overflow lets an attacker "execute code in the context of the current process," per the
Published: Mon, 20 Jul 2026 14:40:56 +0530, Author: info@thehackernews.com (The Hacker News)
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.
The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential
Published: Mon, 20 Jul 2026 14:37:11 +0530, Author: info@thehackernews.com (The Hacker News)
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.
The company said it detected and responded to the incident targeting its production infrastructure earlier last week.
"We identified unauthorized access to a limited set of internal datasets and to several credentials used by
Published: Mon, 20 Jul 2026 10:57:26 +0530, Author: info@thehackernews.com (The Hacker News)
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
The rogue gems are listed below -
git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026
Dendreo (versions 1.1.3, 1.1.4) -
Published: Mon, 20 Jul 2026 10:45:39 +0530, Author: info@thehackernews.com (The Hacker News)
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade.
Triggering it can crash or restart the worker, causing a denial of
Published: Mon, 20 Jul 2026 02:12:49 +0530, Author: info@thehackernews.com (The Hacker News)
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.
According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's
Published: Sun, 19 Jul 2026 19:00:55 +0530, Author: info@thehackernews.com (The Hacker News)
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.
Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this
Published: Sun, 19 Jul 2026 18:48:56 +0530, Author: info@thehackernews.com (The Hacker News)
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it.
An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until
Published: Sat, 18 Jul 2026 02:50:10 +0530, Author: info@thehackernews.com (The Hacker News)
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts.
OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denial-of-service bug and named it, published the
Published: Sat, 18 Jul 2026 01:50:53 +0530, Author: info@thehackernews.com (The Hacker News)
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.
The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron,
Published: Sat, 18 Jul 2026 00:24:51 +0530, Author: info@thehackernews.com (The Hacker News)
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.
A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and firewall late.
The intel feed behind that counter
Published: Fri, 17 Jul 2026 22:42:23 +0530, Author: info@thehackernews.com (The Hacker News)
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine.
Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using
Published: Fri, 17 Jul 2026 22:09:16 +0530, Author: info@thehackernews.com (The Hacker News)
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges.
"Any user who ran the project ended up with a four-stage payload aligned with OtterCookie: a browser credential and crypto wallet stealer, a file stealer, a
Published: Fri, 17 Jul 2026 19:18:56 +0530, Author: info@thehackernews.com (The Hacker News)
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a wake word that fires with the display off, and the ability to drive other apps in the background by imitating taps and typing.
Google has to ship it in the next major release, Android 18, and by 1 August 2027 at
Published: Fri, 17 Jul 2026 17:14:41 +0530, Author: info@thehackernews.com (The Hacker News)