Latest stories — Page 73

Two Critical NGINX Open Source Bugs Open the Door to Remote Code Execution
F5 patches a use-after-free in the HTTP/3 module and a second critical flaw. QUIC-enabled deployments are the immediate concern.

The Popa Botnet: When Your $40 Streaming Box Moonlights as a Residential Proxy
Researchers tie a four-year-old Android TV box botnet to NetNut, the residential proxy arm of NASDAQ-listed Alarum Technologies. The company disputes the framing.

Browser Add-Ons, AI Chat Links and In-Memory macOS Attacks: A Week the Internet Worked As Designed
Shady extensions, weaponised Claude conversations, fileless macOS intrusions and cloud agents turned into shells dominated the criminal feeds this week.

INC Ransomware Fills the LockBit Vacuum, Racks Up 830+ Victims
Two years after a quiet debut, INC has graduated from boutique RaaS to one of 2026's busiest extortion brands — riding the affiliate exodus from LockBit and BlackCat.

Windows Clipper Worm Phones Home Over Tor, Swaps Crypto Wallets via ActiveX
Microsoft says the campaign, active since February, uses USB-borne LNK files and Windows Script Host to drop a bundled Tor proxy that talks to a .onion C2.

DragonForce Crew Tunnels RAT Traffic Through Microsoft Teams Relays
A Go-based backdoor dubbed Backdoor.Turn piggybacks on Teams' own relay infrastructure to hide C2 calls inside a U.S. services firm's network.

Mastra npm Namespace Hit: 145 Packages Tampered After Contributor Account Hijack
Researchers tracking the 'easy-day-js' supply chain incident say a single compromised maintainer account was sufficient to push malicious versions across the @mastra/* registry footprint.

Accenture Moves to Acquire Dragos, runZero, and NetRise in $4.1 Billion OT Security Consolidation
The deal values Dragos alone at $3.25 billion. runZero and NetRise would fold under the Dragos umbrella post-close.

The Agents Nobody Owns: AI Identities Are Quietly Becoming Your Worst Insider Risk
Orphaned AI agents and standing privileges are accumulating across enterprise environments. Most security teams can't tell you who authorized them — or revoke them quickly when they go wrong.

India Tells Court Telegram Couldn't Detect Exam-Leak Channels Before Block
Government says it warned Telegram two weeks before pulling the plug. Telegram says the ban is unlawful and that it cooperated.

ClickFix Campaign Turns Google Ads, GitLab, and Claude Into a Six-Wave Trust Machine
Attackers chained legitimate infrastructure across seven weeks to push malicious PowerShell commands to developers. Session tokens, SSH keys, and cloud credentials were the prize.

PCI DSS 4.0.1 Drags Checkout Scripts Into Scope, and Most Merchants Aren't Ready
Independent QSA assessment puts Reflectiz against the new client-side rules. The verdict: the script soup running on your payment page is now an auditable surface.

Fortibleed: How 75,000 FortiGate Firewalls Ended Up on an Attacker's Credential List
Configuration files. Legacy SHA-256 hashes. Automation at scale. The Fortibleed campaign is a slow-burn credential harvest that perimeter defenders are still catching up to.

Six Security Leaders Who Changed Jobs in Early 2026
From Air Force intelligence to frontier AI, the CISO hiring market is moving. Here is who landed where — and what the patterns suggest.

AI Breaks the Assumption Cybersecurity Was Built On
Modern security programs were engineered around deterministic systems. Agentic AI isn't one.

The AI-SOC Is Maturing Fast. Here Are the Human Roles It Actually Creates.
Autonomous triage agents are already displacing Tier 1 analyst work. But the agentic SOC depends on a new class of human specialists — and those roles are filling now.

SailPoint to Buy Entro Security for a Reported $200 Million
The acquisition adds non-human identity and secrets management to SailPoint's governance platform — a gap that's become increasingly hard to ignore.

Google to Harvest UK and EU IP Addresses for Ad Targeting Starting August 2026
The same signal Google once branded a privacy red flag becomes a measurement tool, just as the ICO sharpens its consent rules.

Clipper Crew Buys Sponsored Posts on News Sites to Push Trojanized Crypto Tools
An untracked actor is laundering credibility through paid press placements, a phishing-grade WordPress hub, and seeded GitHub and SourceForge repos to deliver clipboard hijackers.

Microsoft Acknowledges 'RoguePlanet' Defender Zero-Day, Patch Still in the Works
CVE-2026-50656 is a privilege escalation bug in the Malware Protection Engine — the component sitting at the heart of every Defender install.

Tailscale and OpenSSH Became a Junior Operator's Back Door After His Havoc C2 Went Dark
An intrusion at a small French auto-sector firm shows how commodity remote-access tooling defeats the assumption that killing the C2 ends the incident.