Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 18:34 25/07/2026 UTC
Last updated: 06:04 25/07/2026 UTC

Latest updates

Browse →

SourTrade malvertising campaign targeting retail traders and crypto investors

Campaign

Updated: 25.07.2026 18:21 · First: 25.07.2026 18:21 · 📰 1 src / 1 articles · H score: 30

The SourTrade malvertising campaign now uses fake Solana, Luno, and TradingView pages with malicious JavaScript to assemble malware in browser memory, reducing detection and widening risk for retail traders and crypto investors. It has been active since late 2024 and operates across 25 languages in 12 countries, mainly in Asia Pacific and Latin America. The current delivery flow uses ServiceWorker and SharedWorker logic to build a unique payload locally and evade static detection.

ShinyHunters impersonation sextortion email campaign

Campaign

Updated: 25.07.2026 17:16 · First: 25.07.2026 17:16 · 📰 1 src / 1 articles · H score: 17

A sextortion email campaign is using leaked email addresses and ShinyHunters impersonation to demand $2,000 in Bitcoin, broadening abuse of previously exposed breach data. The messages claim device compromise and threaten to release intimate videos, but there is no indication the sender accessed devices, installed malware, or monitored activity. The operation has reused addresses from published leaks tied to Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill. The campaign appears to have begun in April and has generated similar reports across multiple people and organizations.

Fastjson Spring Boot unauthenticated RCE (CVE-2026-16723)

Vulnerability

Updated: 25.07.2026 15:52 · First: 25.07.2026 15:52 · 📰 1 src / 1 articles · H score: 41

CVE-2026-16723 is a Fastjson RCE affecting Spring Boot fat-JAR deployments, letting attacker-controlled JSON execute with the Java process's privileges. ThreatBook and Imperva said they saw in-the-wild exploitation, while Alibaba had not released a fixed Fastjson 1.x build as of July 25. The confirmed chain requires Fastjson 1.2.68 through 1.2.83, a network-reachable parser path, and SafeMode left disabled. Mitigations include enabling -Dfastjson.parser.safeMode=true or using com.alibaba:fastjson:1.2.83_noneautotype.

Alibaba Fastjson SafeMode mitigation for CVE-2026-16723

Advisory/Mitigation

Updated: 25.07.2026 15:52 · First: 25.07.2026 15:52 · 📰 1 src / 1 articles · H score: 44

Alibaba issued SafeMode mitigation guidance for Fastjson 1.x after CVE-2026-16723, giving affected organizations a temporary defense against unauthenticated code execution in reachable Spring Boot deployments. The advisory says operators that cannot migrate immediately should enable `-Dfastjson.parser.safeMode=true` or switch to `com.alibaba:fastjson:1.2.83_noneautotype`. Fastjson2 remains the long-term fix, and no fixed Fastjson 1.x release was available as of July 25.

Insurance provider Google Ads real-time OTP phishing campaign

Campaign

Updated: 25.07.2026 13:14 · First: 25.07.2026 13:14 · 📰 1 src / 1 articles · H score: 29

The insurance-focused phishing campaign now uses Google Ads, lookalike domains, and real-time OTP relaying to hijack sessions before victims notice. The operation spans Saudi Arabia, Europe, the United States, and India, broadening exposure across multiple insurers. Instead of delayed credential theft, attackers can complete login and take over accounts during the same browsing session. That raises the risk of immediate access to customer data, policy records, and payment information.

Clop Internet-exposed Windchill and FlexPLM data theft extortion campaign

Campaign

Updated: 24.07.2026 10:36 · First: 24.07.2026 10:36 · 📰 2 src / 2 articles · H score: 55

The Cl0p campaign is targeting internet-exposed PTC Windchill and FlexPLM deployments in a data extortion operation, with CVE-2026-12569 enabling unauthenticated remote code execution and JSP web shell deployment. Researchers said the attackers chain a FlexPLM WSDL information disclosure with a flaw in the Windchill login servlet, then enumerate file systems, stage engineering and design data, and steal sensitive product data. The activity has hit manufacturing, automotive, aerospace, and retail sectors, while PTC issued patches and CISA added the flaw to its Known Exploited Vulnerabilities catalog. Companies have also received extortion emails from [email protected].

DevMan-Funky Mantis ecosystem shift changes threat-actor operations

Threat Actor Meta

Updated: 25.07.2026 12:53 · First: 25.07.2026 12:53 · 📰 1 src / 1 articles · H score: 46

DevMan has consolidated its RaaS affiliate portal, tightening control over payload creation, victim handling, and payouts across its criminal service network. PRODAFT tracks the operation as Funky Mantis, and the portal's v3 update in January 2026 added structured victim records, lifecycle states, team controls, deadline tracking, and revenue fields. The platform also bundles build generation, finance, victim chat, support, and access brokerage, giving administrators more leverage over affiliate activity and attack tempo. That structure reduces affiliate autonomy and helps the operators scale multi-victim extortion while steering attacks toward targets outside the CIS and Serbia and toward SCADA-related operations.

DevMan ransomware locker capability update for Windows, ESXi, and Linux

Malware Activity

Updated: 25.07.2026 12:53 · First: 25.07.2026 12:53 · 📰 1 src / 1 articles · H score: 38

The DevMan ransomware locker now supports payload builds for Windows, ESXi, and Linux, expanding the operation's reach across server and workstation environments. Analysis of the Windows build shows features for privilege checks, process and service termination, recovery inhibition, event log clearing, lateral movement, and multi-threaded encryption, all of which increase the impact of an infection. The locker also uses ChaCha20-Poly1305 and can self-delete, making remediation harder after deployment.

GitLab notebook diff authenticated RCE flaw

Vulnerability

Updated: 25.07.2026 11:34 · First: 25.07.2026 11:34 · 📰 1 src / 1 articles · H score: 37

A public PoC exploit now shows an authenticated RCE path in GitLab that can run commands as git on vulnerable self-managed servers. The flaw affects GitLab CE/EE 15.2.0 through 18.10.7, 18.11.0 through 18.11.4, and 19.0.0 through 19.0.1, with the exploit demonstrated against GitLab 18.11.3. GitLab fixed the issue in 18.10.8, 18.11.5, and 19.0.2, and successful exploitation can expose source code, Rails secrets, service credentials, and CI/CD data.

Oj parser state corruption and ASLR leak analysis in the GitLab notebook diff exploit chain

Technical Analysis

Updated: 25.07.2026 11:34 · First: 25.07.2026 11:34 · 📰 1 src / 1 articles · H score: 23

Researchers published deep exploit analysis of Oj parser bugs in GitLab's notebook diff path, showing how callback-pointer corruption and a heap-address leak can be combined to drive authenticated RCE.

OnTrac hit by network compromise

Incident

Updated: 24.07.2026 22:55 · First: 24.07.2026 22:55 · 📰 1 src / 1 articles · H score: 10

OnTrac confirmed a corporate network breach that may have exposed customer personal details, creating identity-risk exposure for customers. The company detected the intrusion on March 23 and found the attacker accessed certain files between March 20 and 22. OnTrac says it is not aware of fraud or publication of stolen information, but it is offering 12 months of credit monitoring and identity protection through CyberScout.

Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign

Campaign

Updated: 24.07.2026 20:50 · First: 24.07.2026 20:50 · 📰 1 src / 1 articles · H score: 34

Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can expose business email, documents, and other sensitive data. The operation has been active since at least June and has reached organizations across financial services, professional services, legal, health care, energy, and retail in the U.S. and abroad. Attackers are using DNS changes, device-code authentication tricks, and in some cases WPAD abuse to push victims onto attacker-controlled login pages and bypass MFA.

Microsoft Azure and Microsoft 365 outage caused by maintenance bug

Service Disruption

Updated: 24.07.2026 18:41 · First: 24.07.2026 18:41 · 📰 1 src / 1 articles · H score: 0

A maintenance-system bug triggered a massive Microsoft outage that disrupted access to Azure and Microsoft 365 services for customers tied to West US infrastructure. The disruption affected core collaboration and admin tools, including OneDrive, SharePoint Online, Teams, and the Microsoft 365 Admin Center. Microsoft reverted the networking change and said affected services had recovered by 3:41 PM ET. The event shows how an automated maintenance workflow can create broad availability and functionality failures across a large cloud stack.

BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign

Campaign

Updated: 24.07.2026 18:12 · First: 24.07.2026 18:12 · 📰 1 src / 1 articles · H score: 38

BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value crypto targets. The operation combines trusted-contact compromise, wallet reconnaissance, and self-propagating messaging to turn one account takeover into the next. The result is a repeatable victim-acquisition pipeline that raises the risk of account theft, malware infection, and follow-on targeting across the cryptocurrency sector.

Microsoft AD CS security update for CVE-2026-54121

Security Patch Release

Updated: 24.07.2026 17:15 · First: 24.07.2026 17:15 · 📰 1 src / 1 articles · H score: 29

Microsoft's July 14 update patched CVE-2026-54121 in Active Directory Certificate Services (AD CS), closing an improper authorization flaw that could let a low-privileged domain user impersonate a Domain Controller. The release matters because the resulting credential path could reach DCSync and expose krbtgt. Administrators running an Enterprise CA were told to install the update on AD CS hosts.

Microsoft AD CS Certighost improper authorization flaw (CVE-2026-54121)

Vulnerability

Updated: 24.07.2026 17:15 · First: 24.07.2026 17:15 · 📰 1 src / 1 articles · H score: 29

Microsoft Active Directory Certificate Services (AD CS) CVE-2026-54121 now has a public working exploit, exposing low-privileged domain users to Domain Controller impersonation and DCSync risk.

Europol Referral Action Days takedown against The Com

Law Enforcement

Updated: 24.07.2026 15:56 · First: 24.07.2026 15:56 · 📰 1 src / 1 articles · H score: 7

Europol led a takedown referral action against The Com, flagging 4,340 URLs for removal to disrupt an extremist online ecosystem and generate new investigative leads. The multi-week Referral Action Days operation involved investigators from nine countries between June and July 2026. The targeted content included self-harm, CSAM, grooming, extortion, doxing, swatting, and violent attack material.

AegisAI Series A funding round

Industry Action

Updated: 24.07.2026 15:01 · First: 24.07.2026 15:01 · 📰 1 src / 1 articles · H score: 11

AegisAI raised $36 million in a Series A led by Battery Ventures, giving the email security startup capital to expand AI detection agents and its enterprise go-to-market. The round also included Accel and Foundation Capital, and it lifted the company’s total funding to $49 million. AegisAI is using the money to push Vanguard toward general availability and scale its phishing and business email compromise defense platform.

ReliaQuest DNS poisoning mitigation guidance

Advisory/Mitigation

Updated: 24.07.2026 15:00 · First: 24.07.2026 15:00 · 📰 1 src / 1 articles · H score: 26

ReliaQuest issued mitigation advice for DNS poisoning that can redirect legitimate traffic and expose endpoints to credential-harvesting. The guidance targets operators of hotel and other captive Wi‑Fi environments facing the same attack surface. It recommends preventing the poisoning from reaching endpoints, eliminating the attack surface, and detecting credential-harvesting activity if it occurs.

DNS poisoning campaign targeting captive Wi‑Fi routers to harvest corporate credentials

Campaign

Updated: 24.07.2026 15:00 · First: 24.07.2026 15:00 · 📰 1 src / 1 articles · H score: 34

An ongoing DNS poisoning campaign is redirecting traffic from hotel and conference venue Wi‑Fi routers to harvest corporate login credentials, putting traveling employees and their accounts at risk. The operation uses exposed management interfaces and weak or reused admin credentials to take control of public Wi‑Fi gateways. Compromised gateways have been seen across multiple US cities, India and Saudi Arabia, showing a geographically broad operation. The attack can capture sensitive information without phishing links or malicious attachments by funneling legitimate domains through attacker-controlled infrastructure.

OpenAI ChatGPT Workspace Agents AgentForger fix

Security Patch Release

Updated: 24.07.2026 14:53 · First: 24.07.2026 14:53 · 📰 1 src / 1 articles · H score: 20

OpenAI addressed AgentForger in ChatGPT Workspace Agents / Agent Builder, closing a flaw that could let a single phishing link create and deploy an autonomous agent inside a victim organization.

ChatGPT Workspace Agents CSRF AgentForger security flaw

Vulnerability

Updated: 24.07.2026 14:53 · First: 24.07.2026 14:53 · 📰 1 src / 1 articles · H score: 40

OpenAI's ChatGPT Workspace Agents faced a cross-site request forgery (CSRF) flaw that let a single phishing link create and deploy an attacker-controlled agent inside a victim organization's trust boundary. The bug, dubbed AgentForger by Zenity Labs, could run in a logged-in user's session and turn approved connectors into a persistence mechanism. OpenAI addressed the issue on June 8, 2026, closing a path to unauthorized agent creation, internal reconnaissance, and data theft.

Bing image search SVG command injection (multiple vulnerabilities)

Vulnerability

Updated: 24.07.2026 14:45 · First: 24.07.2026 14:45 · 📰 1 src / 1 articles · H score: 41

A crafted SVG in Bing image search triggered OS command injection in Bing image-processing workers, causing code execution as NT AUTHORITY\SYSTEM on Windows and root on Linux through CVE-2026-32194 and CVE-2026-32191.

Kyle Svara Snapchat account-takeover phishing campaign

Campaign

Updated: 24.07.2026 14:17 · First: 24.07.2026 14:17 · 📰 1 src / 1 articles · H score: 29

The Kyle Svara campaign used social engineering to phish Snapchat access codes from a large victim pool, enabling account takeover and the theft of intimate photos. The operation ran from May 2020 to February 2021 and reached more than 4,500 victims, making it a sustained credential-theft and privacy-abuse campaign.

Over 750 women’s Snapchat nude photos traded or sold online

Data Leak

Updated: 24.07.2026 14:17 · First: 24.07.2026 14:17 · 📰 1 src / 1 articles · H score: 31

Private nude and semi-nude photos from approximately 517 Snapchat accounts were stolen and later traded or sold online, exposing intimate images from over 750 women. The leak stemmed from credential theft and unauthorized account access rather than an open public database dump. The actor also used two-factor authentication to lock victims out after the theft. The result was a privacy breach that enabled further redistribution of highly sensitive images.

Q2 2026 brand phishing expands to ChatGPT impersonation

Trend

Updated: 24.07.2026 14:15 · First: 24.07.2026 14:15 · 📰 1 src / 1 articles · H score: 35

Phishing impersonation of technology brands rose in Q2 2026, with ChatGPT entering the top 10 of most impersonated brands for the first time and signaling growing attacker attention toward AI services. Microsoft remained the most impersonated brand at 23% of all attempts, showing how heavily major tech platforms are still abused for brand-phishing lures.

Thailand's Ministry of Finance hit by network compromise

Incident

Updated: 24.07.2026 13:15 · First: 24.07.2026 13:15 · 📰 2 src / 2 articles · H score: 23

Thailand's Ministry of Finance is linked to a post-exploitation intrusion in which an operator used Hermes AI agent in unattended YOLO mode to automate activity inside the ministry network. Hunt.io and Bob Diachenko tied the activity to July 9–July 13-era artifacts from three exposed directories on a server hosted in Hong Kong, with 585 files totaling about 470 MB that included web shells, stolen credentials, and Hermes logs. The recovered material points to checks for root access, filesystem crawling, and access to staff records dating to 2012, while the ministry has not confirmed a breach and the recovered files do not show data leaving the network.

Golden Chickens TAG-195 shifts to modular operator-driven MaaS tooling

Threat Actor Meta

Updated: 24.07.2026 13:09 · First: 24.07.2026 13:09 · 📰 1 src / 1 articles · H score: 28

Golden Chickens operators, tracked as TAG-195, are refining their malware-as-a-service ecosystem with modular, operator-driven tooling, increasing defense-evasion and selective capability delivery across their malware stack. The shift expands the group’s ability to tailor payloads for initial access, credential theft, and post-exploitation control while reducing static exposure.

Golden Chickens TAG-195 resurfaces with four new malware families

Malware Activity

Updated: 24.07.2026 13:09 · First: 24.07.2026 13:09 · 📰 1 src / 1 articles · H score: 30

The Golden Chickens malware ecosystem has resurfaced with four new malware families, expanding its tooling for initial access, credential theft, and modular delivery. The activity is linked to TAG-195 and shows continued development despite prior public exposure of the group’s inner workings. The new tooling increases operator flexibility and reduces detection exposure through a more modular, operator-driven design.

Higher education ransomware attacks rose in H1 2026

Trend

Updated: 24.07.2026 12:15 · First: 24.07.2026 12:15 · 📰 1 src / 1 articles · H score: 86

Ransomware attacks on higher education providers rose 8% in H1 2026, increasing disruption and extortion risk across universities and colleges. The period also saw 104 ransomware incidents across the global education sector. The Gentlemen was a major driver of the surge, with its education-targeted activity rising sharply. The pattern left schools and universities facing higher ransom demands and heavier recovery pressure.