Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 18:09 24/07/2026 UTC
Last updated: 06:49 24/07/2026 UTC

Latest updates

Browse →

Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign

Campaign

Updated: 24.07.2026 20:50 · First: 24.07.2026 20:50 · 📰 1 src / 1 articles · H score: 34

Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can expose business email, documents, and other sensitive data. The operation has been active since at least June and has reached organizations across financial services, professional services, legal, health care, energy, and retail in the U.S. and abroad. Attackers are using DNS changes, device-code authentication tricks, and in some cases WPAD abuse to push victims onto attacker-controlled login pages and bypass MFA.

Microsoft Azure and Microsoft 365 outage caused by maintenance bug

Service Disruption

Updated: 24.07.2026 18:41 · First: 24.07.2026 18:41 · 📰 1 src / 1 articles · H score: 0

A maintenance-system bug triggered a massive Microsoft outage that disrupted access to Azure and Microsoft 365 services for customers tied to West US infrastructure. The disruption affected core collaboration and admin tools, including OneDrive, SharePoint Online, Teams, and the Microsoft 365 Admin Center. Microsoft reverted the networking change and said affected services had recovered by 3:41 PM ET. The event shows how an automated maintenance workflow can create broad availability and functionality failures across a large cloud stack.

BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign

Campaign

Updated: 24.07.2026 18:12 · First: 24.07.2026 18:12 · 📰 1 src / 1 articles · H score: 38

BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value crypto targets. The operation combines trusted-contact compromise, wallet reconnaissance, and self-propagating messaging to turn one account takeover into the next. The result is a repeatable victim-acquisition pipeline that raises the risk of account theft, malware infection, and follow-on targeting across the cryptocurrency sector.

Microsoft AD CS security update for CVE-2026-54121

Security Patch Release

Updated: 24.07.2026 17:15 · First: 24.07.2026 17:15 · 📰 1 src / 1 articles · H score: 29

Microsoft's July 14 update patched CVE-2026-54121 in Active Directory Certificate Services (AD CS), closing an improper authorization flaw that could let a low-privileged domain user impersonate a Domain Controller. The release matters because the resulting credential path could reach DCSync and expose krbtgt. Administrators running an Enterprise CA were told to install the update on AD CS hosts.

Microsoft AD CS Certighost improper authorization flaw (CVE-2026-54121)

Vulnerability

Updated: 24.07.2026 17:15 · First: 24.07.2026 17:15 · 📰 1 src / 1 articles · H score: 29

Microsoft Active Directory Certificate Services (AD CS) CVE-2026-54121 now has a public working exploit, exposing low-privileged domain users to Domain Controller impersonation and DCSync risk.

Europol Referral Action Days takedown against The Com

Law Enforcement

Updated: 24.07.2026 15:56 · First: 24.07.2026 15:56 · 📰 1 src / 1 articles · H score: 7

Europol led a takedown referral action against The Com, flagging 4,340 URLs for removal to disrupt an extremist online ecosystem and generate new investigative leads. The multi-week Referral Action Days operation involved investigators from nine countries between June and July 2026. The targeted content included self-harm, CSAM, grooming, extortion, doxing, swatting, and violent attack material.

AegisAI Series A funding round

Industry Action

Updated: 24.07.2026 15:01 · First: 24.07.2026 15:01 · 📰 1 src / 1 articles · H score: 11

AegisAI raised $36 million in a Series A led by Battery Ventures, giving the email security startup capital to expand AI detection agents and its enterprise go-to-market. The round also included Accel and Foundation Capital, and it lifted the company’s total funding to $49 million. AegisAI is using the money to push Vanguard toward general availability and scale its phishing and business email compromise defense platform.

ReliaQuest DNS poisoning mitigation guidance

Advisory/Mitigation

Updated: 24.07.2026 15:00 · First: 24.07.2026 15:00 · 📰 1 src / 1 articles · H score: 26

ReliaQuest issued mitigation advice for DNS poisoning that can redirect legitimate traffic and expose endpoints to credential-harvesting. The guidance targets operators of hotel and other captive Wi‑Fi environments facing the same attack surface. It recommends preventing the poisoning from reaching endpoints, eliminating the attack surface, and detecting credential-harvesting activity if it occurs.

DNS poisoning campaign targeting captive Wi‑Fi routers to harvest corporate credentials

Campaign

Updated: 24.07.2026 15:00 · First: 24.07.2026 15:00 · 📰 1 src / 1 articles · H score: 34

An ongoing DNS poisoning campaign is redirecting traffic from hotel and conference venue Wi‑Fi routers to harvest corporate login credentials, putting traveling employees and their accounts at risk. The operation uses exposed management interfaces and weak or reused admin credentials to take control of public Wi‑Fi gateways. Compromised gateways have been seen across multiple US cities, India and Saudi Arabia, showing a geographically broad operation. The attack can capture sensitive information without phishing links or malicious attachments by funneling legitimate domains through attacker-controlled infrastructure.

OpenAI ChatGPT Workspace Agents AgentForger fix

Security Patch Release

Updated: 24.07.2026 14:53 · First: 24.07.2026 14:53 · 📰 1 src / 1 articles · H score: 20

OpenAI addressed AgentForger in ChatGPT Workspace Agents / Agent Builder, closing a flaw that could let a single phishing link create and deploy an autonomous agent inside a victim organization.

ChatGPT Workspace Agents CSRF AgentForger security flaw

Vulnerability

Updated: 24.07.2026 14:53 · First: 24.07.2026 14:53 · 📰 1 src / 1 articles · H score: 40

OpenAI's ChatGPT Workspace Agents faced a cross-site request forgery (CSRF) flaw that let a single phishing link create and deploy an attacker-controlled agent inside a victim organization's trust boundary. The bug, dubbed AgentForger by Zenity Labs, could run in a logged-in user's session and turn approved connectors into a persistence mechanism. OpenAI addressed the issue on June 8, 2026, closing a path to unauthorized agent creation, internal reconnaissance, and data theft.

Bing image search SVG command injection (multiple vulnerabilities)

Vulnerability

Updated: 24.07.2026 14:45 · First: 24.07.2026 14:45 · 📰 1 src / 1 articles · H score: 41

A crafted SVG in Bing image search triggered OS command injection in Bing image-processing workers, causing code execution as NT AUTHORITY\SYSTEM on Windows and root on Linux through CVE-2026-32194 and CVE-2026-32191.

Kyle Svara Snapchat account-takeover phishing campaign

Campaign

Updated: 24.07.2026 14:17 · First: 24.07.2026 14:17 · 📰 1 src / 1 articles · H score: 29

The Kyle Svara campaign used social engineering to phish Snapchat access codes from a large victim pool, enabling account takeover and the theft of intimate photos. The operation ran from May 2020 to February 2021 and reached more than 4,500 victims, making it a sustained credential-theft and privacy-abuse campaign.

Over 750 women’s Snapchat nude photos traded or sold online

Data Leak

Updated: 24.07.2026 14:17 · First: 24.07.2026 14:17 · 📰 1 src / 1 articles · H score: 31

Private nude and semi-nude photos from approximately 517 Snapchat accounts were stolen and later traded or sold online, exposing intimate images from over 750 women. The leak stemmed from credential theft and unauthorized account access rather than an open public database dump. The actor also used two-factor authentication to lock victims out after the theft. The result was a privacy breach that enabled further redistribution of highly sensitive images.

Q2 2026 brand phishing expands to ChatGPT impersonation

Trend

Updated: 24.07.2026 14:15 · First: 24.07.2026 14:15 · 📰 1 src / 1 articles · H score: 35

Phishing impersonation of technology brands rose in Q2 2026, with ChatGPT entering the top 10 of most impersonated brands for the first time and signaling growing attacker attention toward AI services. Microsoft remained the most impersonated brand at 23% of all attempts, showing how heavily major tech platforms are still abused for brand-phishing lures.

Thailand's Ministry of Finance hit by network compromise

Incident

Updated: 24.07.2026 13:15 · First: 24.07.2026 13:15 · 📰 1 src / 1 articles · H score: 23

Thailand's Ministry of Finance suffered a post-exploitation intrusion that exposed internal systems and staff records after an unattended Hermes agent was run against the ministry network. The agent checked hosts for root access, crawled file systems, and reached a folder of personnel records dating back to 2012. Investigators also recovered a hidden web shell on a ministry web server, and Thailand's CERT was notified on July 15.

Golden Chickens TAG-195 shifts to modular operator-driven MaaS tooling

Threat Actor Meta

Updated: 24.07.2026 13:09 · First: 24.07.2026 13:09 · 📰 1 src / 1 articles · H score: 28

Golden Chickens operators, tracked as TAG-195, are refining their malware-as-a-service ecosystem with modular, operator-driven tooling, increasing defense-evasion and selective capability delivery across their malware stack. The shift expands the group’s ability to tailor payloads for initial access, credential theft, and post-exploitation control while reducing static exposure.

Golden Chickens TAG-195 resurfaces with four new malware families

Malware Activity

Updated: 24.07.2026 13:09 · First: 24.07.2026 13:09 · 📰 1 src / 1 articles · H score: 30

The Golden Chickens malware ecosystem has resurfaced with four new malware families, expanding its tooling for initial access, credential theft, and modular delivery. The activity is linked to TAG-195 and shows continued development despite prior public exposure of the group’s inner workings. The new tooling increases operator flexibility and reduces detection exposure through a more modular, operator-driven design.

Higher education ransomware attacks rose in H1 2026

Trend

Updated: 24.07.2026 12:15 · First: 24.07.2026 12:15 · 📰 1 src / 1 articles · H score: 86

Ransomware attacks on higher education providers rose 8% in H1 2026, increasing disruption and extortion risk across universities and colleges. The period also saw 104 ransomware incidents across the global education sector. The Gentlemen was a major driver of the surge, with its education-targeted activity rising sharply. The pattern left schools and universities facing higher ransom demands and heavier recovery pressure.

NodeBB federation flaw (CVE-2026-58593)

Vulnerability

Updated: 24.07.2026 10:41 · First: 24.07.2026 10:41 · 📰 1 src / 1 articles · H score: 1

A NodeBB federation flaw, CVE-2026-58593, lets an outside server post and send messages as any local account, including an administrator. The record was filed July 1, 2026, and no fixed version is named. The issue affects deployments with federation enabled.

NodeBB eight-flaw security patch release (4.14.2)

Security Patch Release

Updated: 24.07.2026 10:41 · First: 24.07.2026 10:41 · 📰 1 src / 1 articles · H score: 34

NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affected range is every version before 4.14.0, so administrators need to move off vulnerable releases now. Public exploit code was published with the disclosure, increasing pressure to upgrade quickly.

Clop Internet-exposed Windchill and FlexPLM data theft extortion campaign

Campaign

Updated: 24.07.2026 10:36 · First: 24.07.2026 10:36 · 📰 1 src / 1 articles · H score: 55

The Clop ransomware gang (Cl0p) is running a new data theft extortion campaign against Internet-exposed PTC Windchill and FlexPLM instances, putting enterprise PLM data at immediate risk. Reported exploitation of CVE-2026-12569 enables unauthenticated remote code execution and JSP web shell deployment. The operation is already producing extortion emails and threatens the exfiltration of sensitive product data from targeted companies.

Redis Streams shared-NACK use-after-free memory corruption flaw

Vulnerability

Updated: 24.07.2026 09:58 · First: 24.07.2026 09:58 · 📰 1 src / 1 articles · H score: 31

The Redis Streams shared-NACK use-after-free affects Redis branches fixed in 6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, and 8.6.5, leaving older releases exposed to authenticated RESTORE abuse and possible RCE. Public proof-of-concept code shows a corrupt RDB object can make two consumers free the same pending-entry record twice, turning the memory corruption into system() execution. Redis had not reported in-the-wild exploitation as of July 24, 2026, but patched releases are available for the affected branches.

Redis Streams and RedisBloom/TDigest security release bundle

Security Patch Release

Updated: 24.07.2026 09:58 · First: 24.07.2026 09:58 · 📰 1 src / 1 articles · H score: 29

Redis shipped a July 23 security release bundle that fixes Streams and RedisBloom/TDigest memory flaws across supported branches, reducing authenticated remote code execution risk for deployed servers.

UAC-0099 fake Notepad++ plugin campaign

Campaign

Updated: 24.07.2026 09:50 · First: 24.07.2026 09:50 · 📰 1 src / 1 articles · H score: 31

A UAC-0099 phishing campaign is using a fake Notepad++ plugin chain to compromise Windows systems and deploy MATCHBOIL.V2 with scheduled-task persistence. The lure starts with a phishing email and an image attachment, then pivots through a shortened URL to EasySend[.]co and a ZIP archive. The payload chain hides a VBScript as a PDF, stages Evernote.zip, and loads a malicious NppExport.dll plugin to unpack the next components. The operation expands the group’s Windows intrusion toolkit and increases the risk of follow-on payload delivery and long-term access.

Origin Energy hit by network compromise

Incident

Updated: 23.07.2026 23:14 · First: 23.07.2026 23:14 · 📰 1 src / 1 articles · H score: 57

The Origin Energy incident involving unauthorized access to customer data has advanced into a confirmed breach response, creating identity and account risk for affected customers. The Australian energy retailer is still determining how many customers were impacted and is contacting them directly. The exposed records may include names, addresses, birth dates, phone numbers, and partial account details.

Origin Energy customer data exposed after Origin Energy breach

Data Leak

Updated: 23.07.2026 23:14 · First: 23.07.2026 23:14 · 📰 1 src / 1 articles · H score: 63

The Origin Energy data breach exposed customers' PII and put an estimated 4.8 million customers at risk of identity theft and account abuse. Exposed data includes full names, physical addresses, dates of birth, phone numbers, and account information. Origin says the partial credit card and bank account details are incomplete and cannot be used for unauthorized charges. A claimant calling themselves John Doe said they hold data for 2 million customers and threatened to leak it in two weeks unless contacted via Signal.

SectopRAT fake Claude installer delivery

Malware Activity

Updated: 23.07.2026 22:48 · First: 23.07.2026 22:48 · 📰 1 src / 1 articles · H score: 19

The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. The infection chain uses a legitimate Claude.ai domain and a malicious Claude Artifact to redirect targets toward a counterfeit ClaudeDesktop.exe download. A legitimate JetBrains Chromium component then sideloads libcef.dll to launch the trojan. The malware also adds persistence, making the compromise harder to remove.

FakeAgent Bing malvertising campaign pushing fake Claude installer

Campaign

Updated: 23.07.2026 22:48 · First: 23.07.2026 22:48 · 📰 1 src / 1 articles · H score: 25

The FakeAgent malvertising campaign is using Bing search ads and a malicious Claude Artifact to push a fake Claude desktop installer, exposing organizations to SectopRAT infections. At least 29 organizations were compromised during July 21-22, and the lure was downloaded 7,100 times before removal. The fake ClaudeDesktop.exe package sideloads libcef.dll to load the remote access trojan and steal data. The infection chain also uses DockerDesktop.exe for persistence and anti-analysis checks.

UAC-0099 Notepad++ plugin delivery campaign targeting organizations in Ukraine

Campaign

Updated: 23.07.2026 19:32 · First: 23.07.2026 19:32 · 📰 1 src / 1 articles · H score: 33

The UAC-0099 campaign is distributing ZIP/VBS lures that load a malicious Notepad++ plugin to establish persistence and stage additional tooling for organizations in Ukraine. The chain uses Evernote.zip with a legitimate Notepad++ 8.8.3 copy and NppExport.dll, then unpacks loaders such as BurnyBear and MatchBoil V2. The activity is tied to a cluster previously linked to initial access for APT44 / Sandworm, and it does not rely on a software exploit or supply-chain compromise.