SignalSec: Trending Cyber News

Latest threats, advisories, and industry developments

Trending
CyberScoopJust now

A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.

The “philosophical shift” that the memo authorizes raises legal, practical and moral questions, experts say. The post A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo. appeared first on CyberScoop.

AI/ML
Trending
CyberScoop1h ago

Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack

Cameron Curry stole corporate data and employee information, which he used to threaten the company as his six-month contract gig came to a close. He ultimately extorted the company for $7,540.92. The post Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack appeare...

General
Trending
BleepingComputer2h ago

Ukraine shuts down 94 fraudulent call centers, seize millions in cash

Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]

AI/ML
Trending
BleepingComputer2h ago

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]

AI/MLRansomwareData Breach
Trending
BleepingComputer4h ago

Hackers breach govt webmail while running parallel crypto fraud

The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]

AI/MLCrypto
Trending
BleepingComputer5h ago

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]

Zero-DayMicrosoft
Trending
BleepingComputer5h ago

AI 'watermark removers' flood the web. Almost none can prove they work.

Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthrop...

AI/ML
Trending
CyberScoop6h ago

AI’s ‘middle class’ has gotten dramatically better at hacking

As frontier models and their sandbox escaping exploits dominate front-page news, researchers are increasingly worried about cheaper, more efficient AI models.  The post AI’s ‘middle class’ has gotten dramatically better at hacking appeared first on CyberScoop.

AI/ML
Trending
BleepingComputer6h ago

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]

AI/ML
Trending
BleepingComputer7h ago

Trezor discloses data breach affecting nearly 14,000 customers

Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping provider and logistics partner, got hacked. [...]

CryptoData BreachHardware/IoT
Trending
The Register Security8h ago

Trump wants to grant private cyber firms a license to hack back

Contractors could surveil and disrupt foreign criminal networks, provided they follow strict rules and put up $1M

General
Trending
The Register Security8h ago

The backup Microsoft never promised you

SPONSORED FEATURE: Your M365 and Azure data might not be as safe as you think from ransomware; time for a reality check

RansomwareCloud SecurityMicrosoft
Trending
SecurityWeek8h ago

Cybersecurity M&A Roundup: 21 Deals Announced in July 2026

Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm. The post Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 appeared first on SecurityWeek.

General
Trending
SecurityWeek8h ago

Adobe Commerce Bug Targeted Immediately After Disclosure

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek.

General
Trending
BleepingComputer9h ago

Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]

AI/ML
Trending
BleepingComputer9h ago

White House taps security firms for offensive hack-back operations

A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations. [...]

General
Trending
SecurityWeek10h ago

WordPress 7.0.4 Patches Remote Code Execution Vulnerability

Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek.

General
Trending
BleepingComputer11h ago

WhatsApp rolls out new feature that flags potential scam messages

WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [...]

AI/ML
Trending
CyberScoop11h ago

Trump turns to private sector in offensive hacking operations memo

One expert called it a “pretty big shift in U.S. cyber policy,” and there have been reservations in the past about opening the door to private sector involvement in cyber offense. The post Trump turns to private sector in offensive hacking operations memo appeared first on CyberScoop.

General
Trending
SecurityWeek11h ago

Venture Firm Team8 Secures Additional $365 Million

The Israeli company has nearly $2 billion in total assets under management since 2014. The post Venture Firm Team8 Secures Additional $365 Million appeared first on SecurityWeek.

General
Trending
The Register Security11h ago

AWS key exposed in JavaScript may have lit way to Beacon's charity data

CRM provider confirms customer database was copied and probably downloaded in readable form

Cloud Security
Trending
SecurityWeek12h ago

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek.

Cloud Security
Trending
SecurityWeek13h ago

White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs

Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. The post White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs appeared first on SecurityWeek.

AI/ML
Trending
WIRED Security13h ago

CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues

Records obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up romantic interests and track colleagues’ cell phones.

AI/ML
Trending
SecurityWeek14h ago

Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.

AI/ML
Trending
SecurityWeek14h ago

Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek.

Zero-DayMicrosoft
Trending
The Register Security16h ago

Passwords stored in public Google Doc then showed up in search results

Developer spotted hostname and credential string lurking in autocomplete

General
Trending
The Hacker News17h ago

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication....

Zero-DayMicrosoft
Trending
The Register Security20h ago

Chinese Loongson processors have leaky caches, researchers find

Attackers could extract data, even working from inside a guest VM

Data Breach
Trending
BleepingComputer1d ago

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]

AI/MLCloud Security
Trending
BleepingComputer1d ago

Android malware combo takes out loans and relays victims' credit cards

A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...]

Malware
Trending
The Register Security1d ago

'Near-autonomous' AI agents attack Taiwan's nuclear safety agency

Some say the world will end in fire, some say an agentic swarm

AI/ML
Trending
BleepingComputer1d ago

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]

General
Trending
The Register Security1d ago

Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible

Eight years on, we're still paying to hide the future glimpsed during speculative execution

AI/ML
Trending
BleepingComputer1d ago

Hundreds of fake Chrome VPN extensions route traffic through a proxy

More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. [...]

General
Trending
The Hacker News1d ago

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activit...

AI/MLZero-DayMalware
Trending
CyberScoop1d ago

Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan

Israeli cyber firm Dream said the framework adapted mid-operation, corrected its mistakes and expanded as it went along. The post Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan appeared first on CyberScoop.

AI/ML
Trending
BleepingComputer1d ago

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...]

AI/MLMicrosoft
Trending
BleepingComputer1d ago

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]

AI/MLZero-DayMicrosoft
Trending
SecurityWeek1d ago

SharePoint Vulnerability Exploited Shortly After PoC Release

The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek.

Zero-DayMicrosoft
Trending
The Register Security1d ago

Uber Freight keeps on trucking after extortion crew breaks in

Helix claims nearly a million files, while the logistics biz says operations never hit the brakes

AI/MLRansomwareHardware/IoT
Trending
BleepingComputer1d ago

FBI: Hackers target online accounts to steal nude photos

The FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos. [...]

General
Trending
The Hacker News1d ago

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store develop...

AI/ML
Trending
BleepingComputer1d ago

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receiving access is the legi...

AI/ML
Trending
The Register Security1d ago

Exposed: Woeful security at UK criminal records office that led to sensitive data leak

Nobody patched the CMS or read the alerts, and ACRO still cannot tell whether info was exfiltrated

Data BreachMicrosoft
Trending
SecurityWeek1d ago

Mindgard Raises $30 Million to Protect AI Systems

The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams. The post Mindgard Raises $30 Million to Protect AI Systems appeared first on SecurityWeek.

AI/ML
Trending
SecurityWeek1d ago

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset appeared first on SecurityWeek.

AI/ML
Trending
The Register Security1d ago

Akira ransomware scum blocked victim's security tools – and broke their own encryptor

Gives a whole new meaning to Safe Mode

CryptoRansomware
Trending
SecurityWeek1d ago

WhatsApp Unveils New Scam Alert Feature

Signal has also made a security announcement: an automatic key verification feature to complement its safety number system. The post WhatsApp Unveils New Scam Alert Feature appeared first on SecurityWeek.

General
Trending
BleepingComputer1d ago

Hackers leverage new Microsoft SharePoint exploit in attacks

Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. [...]

Zero-DayMicrosoft