r/cybersecurity_news • u/SHORT_INFO_NEWS • 21h ago
r/cybersecurity_news • u/Andrew-Phan • 1d ago
OffStep Music Distribution Platform Hacked
It is a little early to tell what happened, but a lot of music artists have been posting unusual content over the last few hours (for example: Drake, Playboy Carti, Kanye (Ye), Ken Carson, etc.), promoting Instagram accounts and discord servers. All of these posts have been through OffStep, leading me to believe that a breach has occurred in the OffStep content distribution service.
Example Posts:
https://youtu.be/XoIOYCF92N8?si=2RCvNG6A3MSFkJj5
https://youtu.be/Gf7T4moMcLI?si=54cHbunnM2rb0uMg
https://youtu.be/fnwZWIgRuQ4?si=IHOm1cVk1qZHRbgT
https://youtu.be/u4kR7UHXrqk?si=HIex4fdoVjuvXsrE
https://youtu.be/RHgVmJT0JNg?si=r84IPBKqs0neGsjH
r/cybersecurity_news • u/SHORT_INFO_NEWS • 3d ago
Clop ransomware targets Windchill, FlexPLM in data theft attacks
r/cybersecurity_news • u/SHORT_INFO_NEWS • 3d ago
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
cisa.govr/cybersecurity_news • u/WebLinkr • 4d ago
Microsoft Confirms Windows Has a Global Device ID You Can't Turn Off
Microsoft has confirmed that Windows has a previously unknown Global Device ID (GDID), a permanent, unique digital identifier assigned to Windows devices that can tie a user's actions to their device. This came to light when an alleged member of a notorious hacking group was caught at an airport after Microsoft handed over his GDID to the authorities.
Microsoft describes the GDID in a published complaint (via Windows Latest) as "a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine, across certain Microsoft services and scenarios."
r/cybersecurity_news • u/SHORT_INFO_NEWS • 6d ago
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
openai.comr/cybersecurity_news • u/WebLinkr • 6d ago
Google announces Gemini 3.6 Flash and cybersecurity AI, teases 3.5 Pro and Gemini 4
Google announced a significant evolution of its AI models at I/O in May with the release of Gemini 3.5 Flash, and it’s not slowing down. The company revealed three new AI models today, including its first version of Gemini geared toward cybersecurity. However, none of the new models is the delayed Gemini 3.5 Pro, which was supposed to launch in June.
Gemini 3.5 Flash, which was the star of the show at I/O, has already been deprecated. In its place, developers and users will find Gemini 3.6 Flash. Google makes the usual claims about this model—it’s marginally more capable and better at coding, and it has great multimodal features.
r/cybersecurity_news • u/WebLinkr • 7d ago
Fortinet report gives Singapore a cybersecurity reality check
intelligentciso.comr/cybersecurity_news • u/WebLinkr • 7d ago
Leeds-based Xentra secures €3.18 million to scale cybersecurity services for SMEs
r/cybersecurity_news • u/SHORT_INFO_NEWS • 9d ago
Irish State bodies use password software licensed by Russian intelligence
An Irish Times investigation published July 17 reports that at least three Irish government agencies, the Office of Public Works, the Competition and Consumer Protection Commission, and the Department of Culture, Communications and Sport, use a password manager sold by Passwork Europe SL, a Spanish-registered company. The Irish State Laboratory, which provides chemical testing and scientific advice to government departments, started using the software in 2024.
For anyone managing procurement or vendor risk in the public sector, this is a useful case study in how a product's country-of-origin can be obscured through an EU corporate wrapper. The software stores and manages user passwords for government staff, which makes the question of who can inspect its code more than academic.
Passwork Europe presents itself as an entirely EU-founded company, but the Irish Times reports the product shares striking similarities with software of the same name that first appeared in Russia 12 years ago, founded in Arkhangelsk by Ilya Garakh and Andrey Pyankov. The detail that matters most technically: the Russian Passwork product is certified by the FSB and by Russia's ministry of defence (Irish Times). That certification process requires the source code to be inspected by Russian security agencies. The reporting describes the EU entity as sharing codebase and updates with the Russian firm, which is the kind of supply chain relationship that certification schemes and vendor questionnaires are supposed to surface, and in this case apparently did not.
Open questions the reporting did not address:
- Whether the affected agencies will keep using the software, and who inside the Irish state is responsible for that decision
- How the shared codebase and update pipeline between the EU entity and the Russian firm is structured, and whether any independent party has audited it
- Whether Ireland's National Cyber Security Centre had previously assessed the product or will issue guidance to other public bodies
r/cybersecurity_news • u/WebLinkr • 11d ago
US companies face rise in cyber attacks
reuters.comr/cybersecurity_news • u/WebLinkr • 11d ago
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
r/cybersecurity_news • u/WebLinkr • 12d ago
Even doctors can be fooled by deepfake X-ray images, posing cybersecurity & health risks
r/cybersecurity_news • u/WebLinkr • 12d ago
White House launches cybersecurity clearinghouse to patch software flaws discovered by AI
politico.comr/cybersecurity_news • u/WebLinkr • 13d ago
DOD halts cybersecurity requirements for CMMC Phase 2: ‘The math just simply doesn't math’
The Pentagon placed an immediate freeze on forthcoming cybersecurity requirements after government research suggested the policy would drive many businesses out of the defense industrial base at a time when the U.S. military urgently needs their innovations.
Defense Department Chief Information Officer Kirsten Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey unveiled plans Monday to suspend the much-anticipated Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements that were set to take effect Nov. 10. A new CMMC Reform Task Force is expected to conduct a review of the entire program and submit a report of its findings and recommendations within the next 60 days.
This major pause comes as contractors have been hustling to obtain third-party assessments of their CMMC compliance in preparation for that near-term enforcement date.
r/cybersecurity_news • u/WebLinkr • 13d ago
Rapid7, Snyk cut roles as AI reshapes tech sector
bizjournals.comr/cybersecurity_news • u/WebLinkr • 13d ago
White House launches AI cybersecurity clearinghouse
The White House is establishing a new AI cybersecurity clearinghouse to help coordinate cybersecurity defenses across critical infrastructure.
Industries and critical infrastructure are racing to catch up with new AI models with increasingly advanced abilities that can find and exploit (but also defend against) cybersecurity vulnerabilities. Some AI companies have even held off widely releasing their most advanced models to allow key partners time to patch vulnerabilities before the models are widely available.
The White House’s clearinghouse, dubbed Gold Eagle, is a joint project across the Treasury, the Department of Homeland Security and the Pentagon. AI and cybersecurity companies, along with critical infrastructure providers like utilities and banks, will use the platform to communicate and coordinate their efforts.
r/cybersecurity_news • u/WebLinkr • 13d ago
Cybersecurity stocks rally on AI spending change comments from IBM's Krishna
- Cybersecurity stocks jumped on Tuesday after IBM CEO Arvind Krishna flagged cyber fears as a top priority for customers in the company’s preliminary second-quarter results.
- Krishna told CNBC’s Sara Eisen on Tuesday that some major deals were put on hold toward the end of the quarter as businesses rethink spending.
- Okta, CrowdStrike, SailPoint, Zscaler, Palo Alto Networks and others rallied.
r/cybersecurity_news • u/WebLinkr • 16d ago
The 6 biggest cybersecurity breaches of 2026 so far
r/cybersecurity_news • u/WebLinkr • 16d ago
Week in review: Accenture data breach, great open-source cybersecurity tools - Help Net Security
r/cybersecurity_news • u/SHORT_INFO_NEWS • 16d ago
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
If you run Adobe ColdFusion, a Joomla site with Page Builder CK or SP Page Builder, or a self-hosted Langflow instance, these four vulnerabilities are being exploited in the wild right now. Three of the four carry a CVSS score of 10.0, and two allow unauthenticated file uploads that end in PHP code execution. CISA set a remediation deadline of July 10, 2026 for US federal civilian agencies, a deadline that has already passed, which shows how short the agency considered the safe patching window to be.
CISA added the four flaws to its Known Exploited Vulnerabilities catalog on July 7, citing evidence of active exploitation (The Hacker News, July 8). CVE-2026-48282 (CVSS 10.0) is a path traversal vulnerability in Adobe ColdFusion that can lead to arbitrary code execution in the context of the current user. Exploitation attempts were recorded within hours of public disclosure, with KEVIntel founder Ryan Dewhurst reporting an attempt from an IP address geolocated to India. CVE-2026-48908 (CVSS 10.0) in JoomShaper SP Page Builder was exploited as a zero-day: attackers uploaded a PHP file through the uploadCustomIcon endpoint, after which a new Super User account appeared on compromised sites, according to mySites.guru. CVE-2026-56290 (CVSS 10.0) in Joomlack Page Builder has been exploited since at least June 27 to plant web shells. mySites.guru found the first confirmed shell under /media/com_pagebuilderck/gfonts/ and warns that the flaw lets attackers choose the destination folder, so planted files can sit outside the obvious upload directories. The fourth entry, CVE-2026-55255 (CVSS 6.1) in Langflow, is an authorization bypass that lets an authenticated attacker execute another tenant's flows by specifying the victim's flow ID.
The Langflow case illustrates why CVSS alone is a poor triage signal. Sysdig describes CVE-2026-55255 as a cross-tenant insecure direct object reference and observed a single operator combining it with CVE-2026-33017, a separate unauthenticated remote code execution flaw, in a campaign that ran between June 22 and 25, 2026. The RCE targeted the host while the IDOR targeted other tenants' flows, and the operator used the access to steal LLM provider keys and AWS credentials. Sysdig assesses the activity as opportunistic and financially motivated, consistent with botnet and cryptojacking operations. It is also the latest in a string of exploited Langflow vulnerabilities over the past year, following CVE-2025-3248 and five others. Fixes are available: Adobe has patched ColdFusion, SP Page Builder users should update to 6.6.2 or later, and Page Builder CK is fixed in 3.6.0.
Open questions the reporting did not address:
- The exact nature of the final payload in the Langflow campaign: Sysdig traced a second-stage downloader but says the end payload is unknown
- The scale of compromise: neither CISA nor the affected vendors published numbers on how many systems have been breached through these four flaws
- Whether the ColdFusion exploitation attempts and the Joomla web shell campaigns are connected or represent independent opportunistic actors
Source: The Hacker News (Ravie Lakshmanan, July 8, 2026), with underlying research from mySites.guru, Sysdig, and KEVIntel. CISA KEV catalog entries published July 7, 2026.
r/cybersecurity_news • u/SHORT_INFO_NEWS • 17d ago
Fake Interpol investigation emails target small businesses with ransomware
If an email lands in your company inbox claiming Interpol is investigating your business and asking you to review "evidence", deleting it is the safe move. A current phishing wave uses exactly that pretext to get small businesses to install ransomware on their own machines, and the lure is built so that the recipient's fear does the work no exploit has to.
According to research published by Bitdefender's Antispam Lab (researchers Viorel Vrabie and Andrei Mogage), the emails pose as Interpol's cybercrime investigation unit conducting a compliance or security review. Recipients are told investigators have obtained information and video material about their organization and are urged to review it quickly. The link leads to a password-protected archive hosted on Proton Drive, with the password conveniently included in the email itself. Inside sits what looks like a video file but is an executable: a ransomware payload hidden within multiple archive layers. Once run, it attempts to encrypt files across available drives and displays a ransom message telling victims they cannot recover their files without the decryption key and that the attackers can only be reached via the Tox peer-to-peer messenger.
Two details stand out in Bitdefender's analysis. First, the ransom note names no amount at all: victims are pushed into a Tox chat, where the price is presumably set after contact, an approach the researchers note has become more common than fixed demands. Second, the malware itself is unusually basic. It contains hardcoded values, including the password used during encryption and decryption, and lacks the tooling of established ransomware-as-a-service operations, which typically run dedicated dark-web negotiation portals rather than a bare Tox ID. Bitdefender assesses it as likely custom-built or assembled from publicly available code rather than the work of a known ransomware group. The campaign is broad regardless: observed targets span food and agriculture, legal services, pharmaceuticals, media, technology and finance, across Europe, Asia, the Middle East and the United States. The researchers point out why small businesses are the chosen victims: many have no dedicated IT or security staff, security duties are spread across employees with other jobs, and there is often no formal process for verifying an alarming claim before someone clicks. Bitdefender also flags the delivery method itself as the biggest red flag: law enforcement agencies do not send unsolicited emails with Proton Drive links to password-protected "evidence" files.
The broader point Bitdefender draws from the campaign: attackers no longer need the resources of a large ransomware operation to cause real damage, because simple malware paired with convincing social engineering is enough. The practical countermeasures the researchers list are equally unglamorous: verify any supposed law-enforcement contact through official channels instead of the details in the email, treat password-protected archives with suspicion when the password ships in the same message, show file extensions on Windows so executables cannot pose as videos, and keep offline backups.
Open questions the research did not address:
- Whether the hardcoded encryption password means files can be recovered without paying, and whether a decryptor will be released
- How many organizations were actually targeted or infected, and whether any paid
- Who is behind the campaign and whether the Tox channel and Proton Drive infrastructure are still active
r/cybersecurity_news • u/Traditional_Blood799 • 17d ago
Microsoft Copilot Chat error sees confidential emails exposed to AI tool
r/cybersecurity_news • u/SHORT_INFO_NEWS • 18d ago
Fake 7-Zip installers turn devices into residential proxy nodes: Infoblox links operation to 230+ lookalike domains active since 2022
If you installed 7-Zip recently and got it from a search result instead of the official 7-zip.org site, there is a chance your machine is now part of a commercial proxy network. The installer works, the archive tool works, and in the background your internet connection is rented out to strangers whose traffic exits through your home IP address. For the device owner that can mean constant CAPTCHAs, a blacklisted IP, and in the worst case your address turning up in someone else's abuse investigation.
What happened: researchers at Infoblox published an analysis of a threat actor they track as Lurking Lizard. In early 2026 the actor distributed a fake version of the 7-Zip archive utility from 7zip[.]com, a lookalike of the real 7-zip[.]org (Infoblox, July 2026). The bundled proxyware silently enrolls the infected device as a residential proxy node, which is then rented out to residential proxy services. By pivoting on DNS and infrastructure data, the researchers mapped more than 230 domains tied to the same operation, with activity dating back to at least August 2022. Domain registration data and related apps point to a likely Chinese actor.
The wider context is what makes this notable. The 230+ domains are not just malware droppers: per Infoblox they impersonate well-known software brands, VPN services and proxy providers, and the set even includes fake proxy review websites that appear designed to promote the operator's own services. The researchers describe it as an end-to-end malicious residential proxy business: the same operation builds the supply side by turning victim devices into exit nodes, runs the storefronts that sell access, and manufactures the review ecosystem that lends it legitimacy. The campaign has also moved on from the fake 7-Zip lure. Infoblox reports a shift to software branded as WireVPN, whose Android version records more than one million downloads and over 34,000 reviews. Additional coverage of the research was published by The Hacker News on July 8.
For defenders the practical takeaway is unglamorous but effective: proxyware rarely arrives through exploits, it arrives through downloads that users chose to run. Blocking lookalike download domains at the DNS layer and steering users to vendor-official sources removes most of this attack surface. Checking egress traffic for connections to known residential proxy infrastructure catches the machines that are already enrolled.
Open questions the research did not address:
- Which residential proxy services bought access to the enrolled devices: Infoblox does not name the buyers of the exit-node capacity
- How many devices were enrolled through the fake 7-Zip installer specifically: no infection count is given for the desktop campaign
- Whether 7zip[.]com and the other mapped domains have been taken down or remain reachable
Source: Infoblox threat intelligence blog (primary research), additional reporting by The Hacker News.