- Hackers Are Exploiting Recently Patched WordPress Bugs, Putting Millions of Websites at Risk21 July 2026, 3:30 am
An anonymous reader quotes a report from TechCrunch: Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday. Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it "immediately." The vulnerabilities are so severe that WordPress enabled force... 
- Hacker Wipes Romania's Entire Land Registry Database20 July 2026, 5:05 pm
A hacker reportedly wiped Romania's entire land registry database after a failed extortion attempt, halting property transactions across the country and preventing notaries from issuing land extracts, authenticating sales, or registering mortgages. "On the dark web, the hacker also boasted to have begun backup copies of stolen data in an attempt to prevent it from being restored," reports Cybernews. "However, Romanian officials have managed to at least restore the ANCPI's website and post a mess... 
- As AI Transforms Silicon Valley, Some Tech Workers Face Evaporating Financial Security20 July 2026, 2:15 am
The Washington Post describes a mid-tier executive at Meta as one of Silicon Valley's "winners" whose financial security suddenly "evaporated" as their workforce "pushed headlong into AI and heavy job cuts," creating a transformed job market. "Her ex-husband, a designer at Meta who was laid off in 2020, eventually gave up looking for jobs in his profession. He now lifts boxes at a warehouse."
Layoffs.fyi, which tracks announced job cuts, counts more than 800,000 tech workers laid off since 202...
- Windows 10 Still Being Used, Often Unpatched and Insecure19 July 2026, 4:34 pm
Windows 10 still runs on 16.9% of the Windows devices monitored by asset-tracking service Lansweeper. That's more than one in six, The Register points out.
A year ago, the operating system accounted for about half of the machines in its dataset, falling to the low-to-mid 40% range by the time Microsoft ended standard support. The decline continued after that, reaching 18.6% in June, but Lansweeper says migration has now slowed to a crawl... Small and medium-sized businesses are particularly ...
- Are There Cybersecurity Risks in Over-the-Air Tech Used in Autos?19 July 2026, 11:34 am
CNBC reports:
The automotive industry's increasing use of over-the-air technology to update vehicle systems makes it more susceptible to cyberattacks, analysts say, urging more intervention in the sector... Its use represents "a unique national security concern," Gabriel Lim, senior analyst at the S. Rajaratnam School of International Studies in Singapore, told CNBC. "Aside from data privacy concerns, the potential of a foreign actor sabotaging the controls of a moving vehicle is a possibility...
- OpenAI Acknowledges GPT-5.6 May Accidentally Delete Files, Calls It 'Honest Mistake'19 July 2026, 1:34 am
"OpenAI has finally confirmed reports that its latest family of large language models can accidentally delete files," reports InfoWorld, "while stressing that such incidents are rare and should be viewed as 'honest mistakes.'"
Reports of the flagship LLMs deleting files emerged shortly after the company launched them earlier this month, with investor Matt Shumer taking to X to report that GPT-5.6-Sol had "just accidentally deleted almost all" of his Mac's files. Just days later, software engi...
- Billing Software Error Sends Billion-Dollar AWS Estimates17 July 2026, 9:00 pm
AWS says a billing software bug caused some customers to see wildly inflated estimated charges, including reports of accounts showing bills in the billions or even trillions of dollars. The Register reports: An open issue on the AWS Health Dashboard (archived copy at the time of writing) popped up at 1:33 am Pacific time on Friday informing users that Cost Explorer was "reflecting inaccurate estimated billing data." As of writing, the issue is still unresolved despite AWS trying several differen...
- 1Password Lets Claude Use Credentials Without Exposing Passwords16 July 2026, 8:00 pm
BrianFagioli writes: 1Password has launched a Claude integration that allows the AI agent to sign in to websites using credentials stored in a 1Password vault. The password manager says Claude never sees the password or one-time code. Instead, users approve each request, and 1Password injects the credentials directly into the target website while locking down access to the rest of the vault. The design appears safer than simply handing passwords to an AI model, but it does not remove every risk....
- Microsoft Patches a Record 570 Security Flaws15 July 2026, 3:00 pm
An anonymous reader quotes a report from Krebs on Security: Microsoft today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. Nearly 60 of the bugs quashed in July's Patch Tuesday earned a "critica...
- Iran Abused Mobile Networks' Vulnerabilities To Locate US Military In Middle East15 July 2026, 3:30 am
An anonymous reader quotes a report from TechCrunch: The Iranian government abused well-known vulnerabilities in the global telecoms infrastructure to locate U.S. military personnel in the build-up to the Iran War, as well as in the early days of the conflict, according to Financial Times. The Iranian government exploited Signaling System 7, or SS7, a set of protocols for 2G and 3G networks that has long been the backbone of how cellular networks connect to each other to route subscribers' calls...
- OnePlus to Exit US and Europe as Oppo Restructures, With Full Shutdown in China and India Expected by 202721 July 2026, 8:56 am
Oppo is reorganizing its smartphone division, reportedly ending sales and operations for OnePlus in the United States and Europe as soon as this week, according
Thank you for being a Ghacks reader. The post OnePlus to Exit US and Europe as Oppo Restructures, With Full Shutdown in China and India Expected by 2027 appeared first on gHacks.... 
- Book Writers Sue Google Over Alleged Use of Copyrighted Books to Train Gemini21 July 2026, 8:53 am
Hachette Book Group, Cengage Learning, Elsevier, author Scott Turow, and S.
Thank you for being a Ghacks reader. The post Book Writers Sue Google Over Alleged Use of Copyrighted Books to Train Gemini appeared first on gHacks.... 
- ChromeOS 150 Adds Gemini in Class Tools, Local PIN Authentication, and Ends Chrome Apps in Kiosk Mode21 July 2026, 8:44 am
Google is rolling out ChromeOS 150 to compatible Chromebooks, introducing new Gemini-based classroom management tools and two enterprise policies for local PIN
Thank you for being a Ghacks reader. The post ChromeOS 150 Adds Gemini in Class Tools, Local PIN Authentication, and Ends Chrome Apps in Kiosk Mode appeared first on gHacks.... 
- BLAST Bounty Season 2 2026 Runs July 21 to August 2 With 32 Teams and Malta LAN Finals21 July 2026, 8:36 am
BLAST Bounty Season 2 2026 begins on July 21 with a 32-team online stage and concludes with a LAN final in Malta from July 30 to August 2, according to the tour
Thank you for being a Ghacks reader. The post BLAST Bounty Season 2 2026 Runs July 21 to August 2 With 32 Teams and Malta LAN Finals appeared first on gHacks.... 
- Ubisoft Launches Ghost Recon: Wildlands Definitive Edition on PS5 and Xbox Series X20 July 2026, 8:58 am
Ubisoft has quietly listed Ghost Recon: Wildlands Definitive Edition on the PlayStation Store, Xbox Store, and PC storefronts, priced at $99.
Thank you for being a Ghacks reader. The post Ubisoft Launches Ghost Recon: Wildlands Definitive Edition on PS5 and Xbox Series X appeared first on gHacks....
- FBI Arrests Florida Man Accused of Distributing Malware Through Steam Games in $220,000 Crypto Theft20 July 2026, 8:52 am
The FBI has arrested a 21-year-old Florida resident accused of running a cybercrime operation that infected around 8,000 PCs with malware spread through video g
Thank you for being a Ghacks reader. The post FBI Arrests Florida Man Accused of Distributing Malware Through Steam Games in $220,000 Crypto Theft appeared first on gHacks....
- Windows 11 Version 26H2 Ships as an Enablement Package With No New Features Over 25H220 July 2026, 8:24 am
Microsoft is gearing up to release Windows 11 version 26H2, the 2026 feature update, as an enablement package based on the same platform as version 25H2, accord
Thank you for being a Ghacks reader. The post Windows 11 Version 26H2 Ships as an Enablement Package With No New Features Over 25H2 appeared first on gHacks....
- Samsung Sets Galaxy Unpacked for July 22 in London With Z Fold 8 Ultra, Z Fold 8, Z Flip 8, and Galaxy Glasses Expected20 July 2026, 8:19 am
Samsung has announced its next Galaxy Unpacked event, scheduled for July 22, 2026, in London.
Thank you for being a Ghacks reader. The post Samsung Sets Galaxy Unpacked for July 22 in London With Z Fold 8 Ultra, Z Fold 8, Z Flip 8, and Galaxy Glasses Expected appeared first on gHacks....
- San Francisco Orders Apple and Google to Remove Nudify Apps From App Stores19 July 2026, 10:37 am
San Francisco City Attorney David Chiu has instructed Apple and Google to remove dozens of "nudify" apps from the App Store and Google Play.
Thank you for being a Ghacks reader. The post San Francisco Orders Apple and Google to Remove Nudify Apps From App Stores appeared first on gHacks....
- 2026 Game Release Schedule: GTA 6, Halo Campaign Evolved, and Forza Horizon 6 Headline the Year19 July 2026, 9:56 am
GameSpot has released its updated list of confirmed game release dates for 2026 across various platforms, including PC, PlayStation 5, Xbox Series X and S, Swit
Thank you for being a Ghacks reader. The post 2026 Game Release Schedule: GTA 6, Halo Campaign Evolved, and Forza Horizon 6 Headline the Year appeared first on gHacks....
- CISA Adds Three Known Exploited Vulnerabilities to Catalog16 July 2026, 12:00 pm
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability
CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal...
- Rockwell Automation Arena16 July 2026, 12:00 pm
View CSAF
Summary
Successful exploitation these vulnerabilities could allow an attacker to execute arbitrary code in the context of the current process.
The following versions of Rockwell Automation Arena are affected:
Arena <=V17.00.00 (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
Rockwell Automation
Rockwell Automation Arena
Out-of-bounds Write
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countr...
- Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT16 July 2026, 12:00 pm
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.
The following versions of Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT are affected:
1756-EN3 <=V12.001 (CVE-2026-9653)
1756-EN2 <=V12.001 (CVE-2026-9653)
1756-ENBT V6.006 (CVE-2026-9653)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Rockwell Automation
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
Improper Validation of Integrity Check V...
- Rockwell Automation FactoryTalk DataMosaix16 July 2026, 12:00 pm
View CSAF
Summary
Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious scripts on the server.
The following versions of Rockwell Automation FactoryTalk DataMosaix are affected:
DataMosaix Private Cloud <=8.02 (CVE-2026-9292)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.1
Rockwell Automation
Rockwell Automation FactoryTalk DataMosaix
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Background
Cr...
- SALTO ProAccess Space16 July 2026, 12:00 pm
View CSAF
Summary
Successful exploitation of this vulnerability allows an authenticated attacker to escalate privileges and access spaces outside their assigned partition, within the same Salto ProAccess Space installation or system. Exploitation requires valid authenticated operator credentials and the partition feature to be enabled; installations without partitioning are not affected.
The following versions of SALTO ProAccess Space are affected:
ProAccess Space <6.13 (CVE-2026-11889)
...
- AutomationDirect Productivity Suite16 July 2026, 12:00 pm
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a denial-of-service condition in the affected product.
The following versions of AutomationDirect Productivity Suite are affected:
Productivity Suite <=v4.6.2.2 (CVE-2026-60063, CVE-2026-61389, CVE-2026-60140, CVE-2026-57896, CVE-2026-60073, CVE-2026-61378)
CVSS
Vendor
Equipment...
- Rockwell Automation Flex 5000 Adapter16 July 2026, 12:00 pm
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product.
The following versions of Rockwell Automation Flex 5000 Adapter are affected:
Flex 5000 Adapter 6.011 (CVE-2026-12659)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Rockwell Automation
Rockwell Automation Flex 5000 Adapter
Double Free
Background
Critical Infrastructure Sectors: Critical Manufacturing, Information Technology
Countrie...
- Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix16 July 2026, 12:00 pm
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition.
The following versions of Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix are affected:
CompactLogix 5370 <=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)
Compact GuardLogix 5370 <=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)
ControlLogix 5570 <=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698)
...
- Siemens SICAM 816 July 2026, 12:00 pm
View CSAF
Summary
Multiple SICAM 8 products are affected by multiple vulnerabilities that could lead to denial of service, namely: - SICAM A8000 Device firmware - CPCI85 for CP-8031/CP-8050 - SICORE for CP-8010/CP-8012 - SICAM EGS Device firmware - CPCI85 - SICAM S8000 - SICORE Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens SICAM 8 are affected:
CPCI85 Central Processing/Communication vers:intdot/<...
- NASA Core Flight System (cFS) Health & Safety (HS) Application16 July 2026, 12:00 pm
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.
The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application are affected:
Core Flight System (cFS) Health & Safety (HS) Application
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
NASA
NASA Core Flight System (cFS) Health & Safety (HS) Application
NULL Pointer Dereference
Background
Critical Infrastructure Sectors: Tr...
- Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs21 July 2026, 11:58 am
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent.
Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX,... 
- N-day is Becoming N-Hour. Patching Faster Won't Save You.21 July 2026, 11:42 am
Every patch is a confession.
The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't updated yet. This is N-day exploitation, and it's always been a race: the vendor patches, the clock starts, and defenders try to deploy... 
- New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit21 July 2026, 11:24 am
A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in.
That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR's hardware-security conference, and the evidence splits in two: they measured the power... 
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning21 July 2026, 8:59 am
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.
The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell.
"By the early hours of Saturday morning (UTC), successful exploitation was already well... 
- New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack21 July 2026, 7:34 am
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month.
The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.
The entry... 
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution21 July 2026, 6:29 am
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber.
In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code.
Patches for the flaw were... 
- FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware20 July 2026, 6:23 pm
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit.
"FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP... 
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 July 2026, 5:29 pm
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.
What makes it more than a... 
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 205020 July 2026, 2:33 pm
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.
Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks... 
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More20 July 2026, 1:32 pm
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.
Here is the full... 
- Microsoft Patches a Record 570 Security Flaws14 July 2026, 7:22 pm
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence....
- Lessons Learned from CISA’s Recent GitHub Leak13 July 2026, 3:03 pm
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb....
- Felons, Fraudsters Flog Offensive Cybersecurity Startup8 July 2026, 12:31 pm
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names....
- FBI Seizes NetNut Proxy Platform, Popa Botnet2 July 2026, 7:27 pm
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software wi...
- Scattered Spider Hackers Plead Guilty on Day 1 of Trial23 June 2026, 4:12 pm
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial....
- ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm18 June 2026, 5:37 pm
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a "residential proxy" provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]....
- Who Runs the Ransomware Group ‘The Gentlemen?’10 June 2026, 2:03 pm
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group....
- A Record-Breaking Patch Tuesday for June 20269 June 2026, 10:07 pm
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at least three of the weaknesses is now publicly available....
- Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts1 June 2026, 5:32 pm
The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta's "AI support assistant" bot into resetting account passwords....
- Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks25 May 2026, 1:21 pm
Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus of a 2025 KrebsOnSecurity story about how their hosting companies had assumed control over the technical infrastructure of Stark Industries Solutions, an Internet service provider sanctioned last year by the EU as a frequ...
- MIT to Become Hotbed of AI Video Surveillance21 July 2026, 11:07 am
It’s a lot:
According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and infrastructure that will support them, began November 2025 and will likely continue until September 2026.
Technical specifications for the cameras suggest that they will be capable of collecting real-time face and object classi... 
- On Flock License Plate Tracking Cameras20 July 2026, 11:03 am
A recent story of a writer who was mistakenly identified, tracked, and arrested using data from Flock cameras has gone viral.
The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM. But when the police report was created and the plate was entered into Flock’s system, it was just recorded as 34 DTM. Just the five large characters, no little number in the middle. And Flock’s AI tech wasn’t registering that non-standard little number when it began pi...
- Friday Squid Blogging: Squid Washing Up on Cape Cod Beach17 July 2026, 9:01 pm
Lots of articles about this.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy....
- Details of Alan Turing’s Voice Encryption System17 July 2026, 11:02 am
Really interesting piece of cryptographic history:
In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars. The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-secret “Delilah” engineering project from 1943 to 1945. Delilah was Turing’s portable voice-encryption system, named after the biblical deceiver of men. There is also material written by ...
- Protecting Privacy in an AI Era16 July 2026, 2:34 pm
Daniel Solove argues in the Wall Street Journal (alternate link) that giving people control of their personal data is not an effective way to regulate privacy in this era. Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug companies. Measures such as rigorous data minimization, fiduciary duties, liability for negligent or reckless technological design, liability for algorithms that cause harm, and multi-stakeholder review of technologies wi...
- A Video Screen That Is Also a Camera15 July 2026, 11:04 am
Amazing:
Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel’s full potential for carrying information by manipulating light’s intensity, oscillation phases, and polarization. The team reported its findings in a paper published yesterday in Nature.
We are one step closer to 1984 technology:
The telescreen r...
- Upcoming Speaking Engagements14 July 2026, 4:04 pm
This is a current list of where and when I am scheduled to speak:
I’m speaking (virtually) at the Policy-Relevant Privacy Research Workshop in Calgary, Canada, on Monday, July 20, 2026.
I’m speaking at Boston Leadership Exchange in Boston, Massachusetts, USA, on Wednesday, July 22, 2026.
I’m speaking at Cognitive Security Conference in Las Vegas, Nevada, USA. The conference runs August 6-7, 2026; my speaking time is TBD.
I’m speaking at DEF CON 34 in Las Vegas, Nevada, USA. The conventi...
- Vulnerability in FIFA’s Network14 July 2026, 11:06 am
FIFA’s network was vulnerable to anyone with even minimal access....
- AI Data Centers and the Concentration of Wealth13 July 2026, 11:01 am
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.
Opposition to AI data centers has emerged as a primary theme in US politics, one that—surprisingly—doesn’t fall along party lines. We applaud people coming together for constructive debate on any issue, and agree that communities need to evaluate whether any economic benefits these data centers bring is worth their costs. Still, we worry that a focus on data centers obscures the larger impacts of AI on ...
- Friday Squid Blogging: “Squidbleed” Vulnerability10 July 2026, 9:07 pm
In a rare combined cybersecurity/squid post, a twenty-nine-year-old squid proxy bug can leak HTTP requests.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy....
- 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover20 July 2026, 9:38 pm
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.... 
- Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push20 July 2026, 8:26 pm
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages, but cost and human-in-the-loop viability remain open questions.... 
- 25 Years After Code Red: What the Worm Era Can Teach Us About AI Security20 July 2026, 7:32 pm
Marc Maiffret reflects on Code Red's legacy and the security lessons helping organizations navigate AI risk today.... 
- CISOs Feel the Heat Over AI Risk20 July 2026, 7:07 pm
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.... 
- Attackers Combo Up Evasion Tactics for BEC Phishing20 July 2026, 6:30 pm
"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.... 
- Cybersecurity Keeps Events 'Uneventful'20 July 2026, 2:00 pm
From the World Cup to the United States' 250th celebration, this year's event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands.... 
- Inc Ransomware Exploits SonicWall SMA Zero-Days17 July 2026, 8:01 pm
When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances....
- The Real AI Threat Is Blind Trust17 July 2026, 4:43 pm
AI models left to both interpret and execute commands eliminate critical cybersecurity oversight....
- Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear17 July 2026, 1:00 pm
The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's being implemented....
- Google Bets 'Agentic Defense' Strategy Can Outpace Attackers17 July 2026, 11:50 am
Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks....
- US seizes over 1,000 websites in FIFA World Cup piracy crackdown21 July 2026, 11:07 am
The U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization. [...]... 
- Critical Palo Alto VPN bug now exploited by Qilin ransomware gang21 July 2026, 10:12 am
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]... 
- Microsoft shares manual fix for WSUS sync delays and timeouts21 July 2026, 9:05 am
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. [...]... 
- Windows LegacyHive zero-day flaw gets free, unofficial patches21 July 2026, 8:06 am
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. [...]... 
- Estée Lauder discloses data breach via Oracle E-Business flaw20 July 2026, 10:39 pm
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]... 
- SonicWall SMA1000 flaws exploited as zero-days to push custom malware20 July 2026, 10:23 pm
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...]... 
- Hackers steal $23.7 million in crypto from Ostium in off-chain attack20 July 2026, 10:22 pm
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. [...]... 
- Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes20 July 2026, 9:14 pm
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. [...]... 
- JadePuffer agentic attacks now target AI model data with ransomware20 July 2026, 9:08 pm
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. [...]... 
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms20 July 2026, 5:43 pm
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]... 
- Student Loan Breach Exposes 2.5M Records31 August 2022, 12:57 pm
2.5 million people were affected, in a breach that could spell more trouble down the line....
- Watering Hole Attacks Push ScanBox Keylogger30 August 2022, 4:00 pm
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool....
- Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms29 August 2022, 2:56 pm
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system....
- Ransomware Attacks are on the Rise26 August 2022, 4:44 pm
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group....
- Cybercriminals Are Selling Access to Chinese Surveillance Cameras25 August 2022, 6:47 pm
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed....
- Twitter Whistleblower Complaint: The TL;DR Version24 August 2022, 2:17 pm
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk....
- Firewall Bug Under Active Attack Triggers CISA Warning23 August 2022, 1:19 pm
CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP....
- Fake Reservation Links Prey on Weary Travelers22 August 2022, 1:59 pm
Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels....
- iPhone Users Urged to Update to Patch 2 Zero-Days19 August 2022, 3:25 pm
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack....
- Google Patches Chrome’s Fifth Zero-Day of the Year18 August 2022, 2:31 pm
An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack....
- Empirical Security Raises $25 Million in Series A Funding21 July 2026, 12:47 pm
The startup will use the investment to accelerate the development of its threat prediction and discovery products.
The post Empirical Security Raises $25 Million in Series A Funding appeared first on SecurityWeek.... 
- SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity21 July 2026, 12:30 pm
Independently judged and sponsor-neutral, the new awards program honors the people, organizations, and technologies delivering proven impact in industrial cybersecurity; winners to be announced live at the 2026 ICS Cybersecurity Conference in Nashville
The post SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity appeared first on SecurityWeek.... 
- New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication21 July 2026, 11:55 am
Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.
The post New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication appeared first on SecurityWeek.... 
- CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG21 July 2026, 11:30 am
Gaetje’s story shows that you don’t need to be a ‘deep bit-crawler’ to become a Chief Information Security Officer.
The post CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG appeared first on SecurityWeek.... 
- Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack21 July 2026, 11:12 am
Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025.
The post Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack appeared first on SecurityWeek.... 
- Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data21 July 2026, 10:19 am
A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure.
The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek.... 
- Clover Health Investments Discloses Data Breach21 July 2026, 9:36 am
Using social engineering, hackers compromised employee accounts with access to personal and health information.
The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek.... 
- Exploitation of ServiceNow Vulnerability Seen Days After Disclosure21 July 2026, 8:41 am
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution.
The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek.... 
- Zimbra Update Patches Critical Vulnerabilities21 July 2026, 8:20 am
The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects.
The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek.... 
- Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software20 July 2026, 2:54 pm
Neo raised money across seed and Series A funding rounds from Andreessen Horowitz, Bessemer Venture Partners, and others.
The post Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software appeared first on SecurityWeek.... 
- ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)21 July 2026, 2:00 am
... 
- WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)20 July 2026, 6:41 pm
Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can lead to unauthenticated remote code execution. Shortly after being announced, the vulnerability started to be exploited.
... 
- ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th)20 July 2026, 2:00 am
...
- Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)19 July 2026, 3:00 pm
We have been following issues with Hikvision cameras for a long, long time. Like many similar products, Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans that our honeypot network detects.
...
- ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)17 July 2026, 2:00 am
...
- ISC Stormcast For Thursday, July 16th, 2026 https://isc.sans.edu/podcastdetail/10010, (Thu, Jul 16th)16 July 2026, 2:40 am
...
- ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th)15 July 2026, 2:00 am
...
- Recent DShield SIEM Update, (Tue, Jul 14th)15 July 2026, 1:38 am
The last update to the DShield SIEM [4] was in Sep 2025 which contained some minor tweaks. This update currently is using ELK stack version 8.19.15, contains some additional dashboards and new logs.
...
- Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)14 July 2026, 7:14 pm
This patch Tuesday includes a staggering&#;x26;#;xc2;&#;x26;#;xa0;622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft&#;x26;#;39;s Edge browser. 62 of the vulnerabilities are rated critical. One was disclosed before today, and two have already been exploited.
...
- ISC Stormcast For Tuesday, July 14th, 2026 https://isc.sans.edu/podcastdetail/10006, (Tue, Jul 14th)14 July 2026, 2:15 am
...
- Sophos joins Anthropic's Project Glasswing20 July 2026, 12:00 am
As a Project Glasswing member, Sophos gains access to Claude Mythos 5, an advanced frontier model not currently available to the public, to find and fix software vulnerabilities before AI-driven attackers can exploit them....
- Sophos ZTNA unlocks SaaS app control and so much more20 July 2026, 12:00 am
Sophos ZTNA customers now get Sophos Protected Browser as part of Sophos Workspace Protection, extending Zero Trust controls to SaaS and web apps while improving secure RDP and SSH access....
- In code we trust? Why the most trusted software receives the least scrutiny.20 July 2026, 12:00 am
Recent CVEs across GitHub, Anthropic, Google, dbt, and MISP expose a simple truth: the most trusted code is often the least questioned. As organizations connect AI agents to production systems, those overlooked assumptions can become powerful new attack paths....
- SonicWall SMA1000 vulnerabilities in active exploitation15 July 2026, 12:00 am
...
- The stack had a good run. Defense systems are the future.15 July 2026, 12:00 am
Introducing Sophos Fusion, the industry’s most complete AI-Native Cybersecurity Defense System....
- The State of Ransomware 2026: Payments are dropping but encryption is climbing15 July 2026, 12:00 am
Insights from 2,158 IT and cybersecurity leaders across 17 countries whose organizations were hit by ransomware in the past year....
- Sophos Protected Browser Extension: Protection and visibility without changing browsers14 July 2026, 12:00 am
The Sophos Protected Browser Extension brings policy enforcement, data protection, GenAI visibility, and web security controls to existing Chromium-based browsers on Windows and Mac....
- Sophos Firewall v22 MR2 is now available13 July 2026, 12:00 am
AI app control, PQC detection, enhanced Chromebook support, and more....
- Sophos named a 2026 Gartner® Peer Insights™ Customers’ Choice for Email Security10 July 2026, 12:00 am
Sophos’ first ever recognition as a Customers’ Choice for Email Security....
- WPScan 4.0.0: We’re Back20 May 2026, 4:55 pm
WPScan 4.0.0 is here. We read through years of community issues. We addressed every major complaint. 75+ open issues → 0. Explicit scan control. Authentication‑based enumeration. Real‑time streaming. Consolidated codebase. This is WPScan shaped by what you asked for. You Control What Gets Scanned The #1 complaint: WPScan scanned plugins automatically, burning API requests and time you didn’t want […]...
- Unauthorized Plugin Installation/Activation in Hunk Companion10 December 2024, 9:03 pm
This report highlights a vulnerability in the Hunk Companion plugin < 1.9.0 that allows unauthenticated POST requests to install and activate plugins directly from the WordPress.org repository. This flaw poses a significant security risk, as it enables attackers to install vulnerable or closed plugins, which can then be exploited for attacks such as Remote Code Execution […]...
- Identifying Traffic from Shell Finder Bots1 November 2024, 11:04 pm
A shell finder is a type of reconnaissance tool that is used by threat actors to identify websites that have already been compromised and contain backdoor shells. A backdoor shell is a form of malware that is added by a threat actor after gaining unauthorized access to a website. The purpose of a backdoor shell is […]...
- Unpatched Vulnerability in TI WooCommerce Wishlist Plugin9 September 2024, 5:45 pm
A Few weeks ago an Sql Injection was discovered in the TI WooCommerce Wishlist plugin. After checking closer we found another entry point, affecting over 100,000 active installs. Despite the severity of this issue, the vendor have not yet provided a patch, leading to public disclosure. The vulnerability can be exploited by unauthenticated users, allowing […]...
- Unauthenticated Privilege Escalation in Profile-Builder plugin15 July 2024, 4:29 pm
During a routine audit of various WordPress plugins, we identified some issues in Profile Builder and Profile Builder Pro (50k+ active installs). We discovered an Unauthenticated Privilege Escalation Vulnerability which could allow attackers to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This vulnerability was fixed on […]...
- Object Injection vulnerability fixed in SEOPress 7.924 June 2024, 2:00 pm
During a routine audit of various WordPress plugins, we identified a few issues in SEOPress (300k+ active installs). More specifically, we discovered an authentication bug which could allow attackers to access certain protected REST API routes without having any kind of account on the targeted site. Digging deeper into what an attacker could do with this […]...
- 10 of the Best Website Security Tools to Stay Ahead of Hackers5 June 2024, 1:00 pm
Which website security tools are really necessary for your site? What to consider before investing in new software. 10 must-have tools you can’t skip....
- The 10 Best Vulnerability Scanners for Effective Web Security16 May 2024, 1:00 pm
7 factors for choosing the best vulnerability scanner. Top options compared on features, pros, cons, & pricing. 5 things that make a great scanner...
- A persistent twist in the current Malware Campaign13 May 2024, 7:12 pm
Recently while covering malware campaigns exploiting the LiteCache and WP‑Automatic WordPress plugins, we found that attackers were installing php‑everywhere, a plugin that allows users to run arbitrary PHP code in their site’s posts. This plugin was closed on April 25th per its author’s request. The reasoning behind this installation was to have persistent malware on the […]...
- Surge of JavaScript Malware in sites with vulnerable versions of LiteSpeed Cache Plugin3 May 2024, 3:01 pm
If you’ve recently encountered the admin user wpsupp‑user on your website, it means it’s being affected by this wave of infections. Identifying Contamination Signs: The malware typically injects code into critical WordPress files, often manifesting as : Or in the database, when the vulnerable version of LiteSpeed Cache is exploited : decoded version: Cleanup Procedures Identifying Malicious URLs and IPs […]...
- Gitea 1.27 Delivers 45 Security Fixes for Self-Hosted Git Servers20 July 2026, 3:38 pm
For organizations that run a self-hosted Git platform, it’s no longer just about hosting static code repositories. Today, Git servers are responsible for deployment pipelines, API tokens, SSH keys, package repositories, and the automation scripts that push code directly. Confirm that the upgrade addresses known vulnerabilities but also provides production environments. ... 
- How to Apply the Principle of Least Privilege in Modern Linux Environments20 July 2026, 1:24 pm
We all spend a lot of time defending our systems from external threats, but the amount of damage an attacker can cause often depends on what happens after they get in. A single compromised account doesn't always lead to a major incident. The real danger begins when that account has far more access than it actually needs. That's exactly what the principle of least privilege is designed to prevent. By limiting users, services, and applications to only the permissions required for their jobs, yo...... 
- What Happens When AI Agents Start Handling Tier-1 Linux Support Tickets17 July 2026, 11:00 pm
Every system admin has lived through the same Monday morning ritual. A queue of forty tickets, half of them password resets, permission errors, or disk space warnings that any experienced technician could resolve in under two minutes. The other half require actual judgment. For years, automation promised that software would eventually sort the two apart on its own. That promise is now being tested in production Linux environments....
- Why Mobile Proxies Are Harder to Block Than Datacenter IPs17 July 2026, 4:24 pm
You're running a web scraping project to collect pricing data from e-commerce sites. You set up a pool of datacenter proxies, launch your scripts, and within minutes — banned. CAPTCHAs everywhere. Your data pipeline stops before it really begins....
- Business Email Compromise with AI Enhancements and New Defense Strategies17 July 2026, 4:10 pm
Business Email Compromise used to be a numbers game — mass-blasted emails, broken English, an obvious "URGENT WIRE TRANSFER" subject line. That era is over. Generative AI has turned BEC into a tailored, low-noise operation that mimics writing style, voice, and even video presence. This piece looks at what's actually changed under the hood, what defenders are testing in response, and why so many organizations are still structurally unprepared for it....
- Enhancing Linux Documentation with Security Icons for Clarity17 July 2026, 3:02 pm
Linux operating systems have gained prominence due to their stability, adaptability, and excellent security options. In the case of developing documentation, designing cybersecurity dashboards, or educational material, visuals are of vital importance when it comes to making things clear. The use of icons allows one to understand the message regarding alerts, authorization, encryption, authentication, or the state of the system just by looking at the visual cue without having to read long desc......
- How to Correlate Linux Logs for Faster Threat Detection17 July 2026, 2:32 pm
For small security and IT teams, the "enterprise" dream of a fully automated SIEM often feels like a distant luxury. It’s a vision built on massive budgets and dedicated engineering teams—things that, frankly, most of us don't have. But here is the reality: you don’t need a six-figure platform to maintain a secure environment....
- Linux IAM Misconfigurations That Put Cloud Environments at Risk17 July 2026, 2:08 pm
For years, we secured our Linux infrastructure by building walls: VPCs, security groups, and hardened SSH configurations. We treated the cloud like a virtual data center, assuming that if we kept the "bad guys" out of the network, our workloads were safe....
- Linux UEFI Shim Vulnerability Severe Exploitation of Obsolete Bootloaders16 July 2026, 3:10 pm
ESET researchers identified 11 old and forgotten Linux UEFI shim bootloaders at versions 0.9 and below that can be used to bypass UEFI Secure Boot on any UEFI-based machine that trusts Microsoft’s Microsoft Corporation UEFI CA 2011 third-party certificate authority, regardless of the installed operating system (OS). Reported shims can be exploited to execute untrusted code during system boot, enabling attackers to deploy malicious UEFI bootkits even on systems with UEFI Secure Boot enabled. ...
- Running Proxies Safely on Linux: A Hardening Guide for System Administrators16 July 2026, 12:50 pm
Proxies are a standard component of a Linux administrator's toolbox. You can use them to see how services respond in various locations, to run route monitoring checks, and to retrieve public data for internal tooling. However, a proxy is an outbound tunnel with credentials attached, and on a multi-user server, it is a security risk that should be treated with the same caution as SSH or sudo. This post explains the practical measures that prevent a proxy setup from becoming a weak point in an ......