Consulting News

News und Newsarchiv für unsere NC Consultants
Firefox Add-on

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Erfasst 20.07.2026 21:54 | The Hackers News
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Pro...
Quelle ansehen

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Erfasst 20.07.2026 20:09 | The Hackers News
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experime...
Quelle ansehen

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

Erfasst 20.07.2026 17:08 | The Hackers News
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as at...
Quelle ansehen

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

Erfasst 20.07.2026 15:53 | The Hackers News
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were oft...
Quelle ansehen

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

Erfasst 20.07.2026 14:53 | The Hackers News
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickl...
Quelle ansehen

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

Erfasst 20.07.2026 14:53 | The Hackers News
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport ...
Quelle ansehen

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

Erfasst 20.07.2026 12:08 | The Hackers News
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeere...
Quelle ansehen

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Erfasst 20.07.2026 12:08 | The Hackers News
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ c...
Quelle ansehen

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Erfasst 20.07.2026 07:37 | The Hackers News
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems...
Quelle ansehen

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

Erfasst 20.07.2026 07:37 | The Hackers News
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The co...
Quelle ansehen

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

Erfasst 19.07.2026 23:21 | The Hackers News
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-...
Quelle ansehen

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

Erfasst 19.07.2026 16:19 | The Hackers News
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days...
Quelle ansehen

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Erfasst 19.07.2026 16:19 | The Hackers News
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealin...
Quelle ansehen

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Erfasst 17.07.2026 23:43 | The Hackers News
An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Fri...
Quelle ansehen

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Erfasst 17.07.2026 22:43 | The Hackers News
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until...
Quelle ansehen

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Erfasst 17.07.2026 21:13 | The Hackers News
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The ...
Quelle ansehen

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Erfasst 17.07.2026 19:28 | The Hackers News
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details ...
Quelle ansehen

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

Erfasst 17.07.2026 19:28 | The Hackers News
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan ...
Quelle ansehen
Hinweis: Dies ist ein News-Aggregator. Das Copyright liegt bei den jeweiligen Webseiten. Die Links wurden zum Zeitpunkt der Abfrage als virenfrei und sicher bewertet. Bitte dennoch mit der nötigen Vorsicht prüfen.