Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 17:34 20/07/2026 UTC
Last updated: 09:53 20/07/2026 UTC

Latest updates

Browse →

HollowGraph Windows malware uses Microsoft 365 calendars for covert C2

Malware Activity

Updated: 20.07.2026 15:30 · First: 20.07.2026 15:30 · 📰 3 src / 3 articles · H score: 15

HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future 2050-05-13 events and moving encrypted stolen files as attachments. Group-IB said the implant uses DNS tunnelling to refresh Entra ID (Azure AD) client credentials, including values written to logAzure.txt and delivered via cloudlanecdn[.]com. The activity was found on at least 12 systems, with three observed actively communicating during June 3, 2026 to July 9, 2026, and the compromised mailbox belonged to an Israeli organization. Group-IB linked the code to Cavern with high confidence, while stopping short of high-confidence attribution to a known threat actor; the targeting and traffic pattern point to a focused espionage operation.

HollowGraph Microsoft Graph API calendar C2 campaign targeting Israeli entities

Campaign

Updated: 20.07.2026 15:30 · First: 20.07.2026 15:30 · 📰 3 src / 3 articles · H score: 22

HollowGraph is a Windows espionage campaign that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as a covert two-way C2 channel. Group-IB said the implant hides tasking in 2050-05-13 calendar events, exfiltrates encrypted files as attachments, and also uses DNS tunneling to refresh Microsoft Entra ID (Azure AD) credentials from cloudlanecdn[.]com into logAzure.txt. The campaign was observed against Israeli entities, with victim communication seen from June 3, 2026 through July 9, 2026. Group-IB found the implant on at least 12 systems, with three actively communicating during that window, and linked the code to Cavern with high confidence while noting only lower-confidence similarity to Lyceum.

Gobf[.]mx CURP typosquat phishing campaign targeting Mexican users

Campaign

Updated: 20.07.2026 20:29 · First: 20.07.2026 20:29 · 📰 1 src / 1 articles · H score: 25

The gobf[.]mx operation used a CURP typosquat, a fake record-retrieval page, and WebDAV delivery to push malware at Windows users in Mexico, creating a live phishing and payload-delivery risk. Delivery logs showed 77,098 requests from 3,892 unique IPs across 101 countries, with Mexico accounting for 82.5% of traffic and 96.9% of launch activity. The lure flow used a search-ms: query and a disguised .scr file to open the operator's remote share, while the payload chain installed an infostealer in memory. The exposed toolkit also showed a broader testing pipeline, including alternate signed-binary hijack experiments and other delivery candidates.

Mexico CURP lure .NET infostealer delivery

Malware Activity

Updated: 20.07.2026 20:29 · First: 20.07.2026 20:29 · 📰 1 src / 1 articles · H score: 21

A .NET infostealer delivery operation now threatens Windows users in Mexico by using a CURP typosquat and WebDAV path abuse to reach victims. The payload arrived through an Inno Setup installer that unpacked a loader and ran in memory inside a signed Qihoo 360 process. It stole cryptocurrency wallets, browser credentials, session cookies, and Telegram sessions. Live delivery telemetry showed 2,441 launch events over about 5.5 days, with Mexico driving most observed activity.

WordPress core pre-auth RCE flaw

Vulnerability

Updated: 18.07.2026 00:20 · First: 18.07.2026 00:20 · 📰 3 src / 3 articles · H score: 77

WordPress Core's wp2shell chain combines CVE-2026-63030 and CVE-2026-60137 into pre-authentication remote code execution on 6.9.x and 7.0.x installs. Searchlight Cyber said GPT5.6 Sol Ultra helped build the multi-stage chain, which starts with REST API batch route confusion and SQL injection and then escalates to backdoor plugin upload. Public PoC exploits are now on GitHub, watchTowr says it is seeing in-the-wild exploitation, and WordPress has fixed the flaws in 6.9.5 and 7.0.2 while enabling forced auto-updates for affected sites.

WordPress core pre-auth RCE patch bundle (6.9.5, 7.0.2)

Security Patch Release

Updated: 18.07.2026 00:20 · First: 18.07.2026 00:20 · 📰 2 src / 2 articles · H score: 62

WordPress Core shipped 6.9.5 and 7.0.2 on July 17, 2026 to close a pre-auth RCE that can be triggered by an anonymous request on a default install with no plugins. The patch bundle also enabled forced automatic updates for affected installs, covering 6.9.0-6.9.4 and 7.0.0-7.0.1. Searchlight Cyber later reported a chained exploit, WP2Shell, built from CVE-2026-63030 and CVE-2026-60137, which can lead to remote code execution on affected WordPress 6.9.x and 7.0.x sites. The report also notes in-the-wild exploitation attempts and public proof-of-concepts after disclosure.

Russian intelligence security camera hijacking campaign across Europe and Ukraine

Campaign

Updated: 20.07.2026 15:13 · First: 20.07.2026 15:13 · 📰 1 src / 1 articles · H score: 88

Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, turning exposed devices into live surveillance on military transport routes, weapons shipments bound for Kyiv, and Ukrainian troop locations. The operation is ongoing and has already been used in Ukraine to support attempts to neutralise military personnel and destroy equipment. It also reaches EU and NATO states, where the same access is collecting military intelligence unrelated to the immediate battlefield. The campaign works by finding exposed cameras, fingerprinting brands, and logging into devices that still use default passwords or obsolete firmware.

Capital One open-sources VulnHunter AI security tool

Security Tool/Service

Updated: 20.07.2026 13:25 · First: 20.07.2026 13:25 · 📰 1 src / 1 articles · H score: 14

Capital One has released VulnHunter as open source, widening access to an AI-powered security tool built to find and fix code-level vulnerabilities. The tool departs from a traditional passive scanner by using agentic reasoning to identify potentially exploitable defects, map attack paths, and recommend targeted remediations. Its public release on GitHub gives defenders a new code-review workflow for reducing vulnerability backlogs. The release also signals a broader shift toward security tools that prioritize developer workflow and remediation precision over noisy alert generation.

Sentencing of Owen Flowers and Thalha Jubair in TfL cyber-attack case

Law Enforcement

Updated: 16.07.2026 14:51 · First: 16.07.2026 14:51 · 📰 3 src / 4 articles · H score: 53

Owen Flowers and Thalha Jubair were sentenced at Woolwich Crown Court for the 2024 Transport for London (TfL) hack, receiving five and a half years in prison each under Section 3ZA of the UK Computer Misuse Act. UK police and the National Crime Agency have used the case to push for Cybercrime Risk Orders (CCROs), arguing current powers leave a gap for managing high-risk cyber offenders during long investigations. The TfL intrusion is linked to Scattered Spider, with reported costs of £29m in damages and £10m in lost income and disruption affecting between seven and 10 million people across the UK.

ServiceNow security patch release for CVE-2026-6875

Security Patch Release

Updated: 20.07.2026 12:29 · First: 20.07.2026 12:29 · 📰 1 src / 1 articles · H score: 39

ServiceNow released CVE-2026-6875 security updates for the ServiceNow AI Platform, covering hosted and self-hosted instances. The patch addresses a pre-auth sandbox-escape RCE that can let unauthenticated threat actors execute code remotely. Customers who have not upgraded are being told to move to a patched release as soon as possible.

ServiceNow AI Platform pre-auth sandbox-escape RCE (CVE-2026-6875, actively exploited)

Vulnerability

Updated: 20.07.2026 12:29 · First: 20.07.2026 12:29 · 📰 1 src / 1 articles · H score: 34

CVE-2026-6875 is now actively exploited in the wild against the ServiceNow AI Platform, exposing unauthenticated systems to remote code execution. The flaw is a pre-auth sandbox-escape RCE that lets attackers reach code execution after breaking out of the platform sandbox. ServiceNow issued July 13th patches for hosted and self-hosted instances, but researchers observed the first attack attempts on Friday and confirmed abuse over the weekend.

7-Zip XZ chunked data heap-based buffer overflow security flaw (CVE-2026-14266)

Vulnerability

Updated: 20.07.2026 12:10 · First: 20.07.2026 12:10 · 📰 1 src / 1 articles · H score: 21

7-Zip's XZ chunked data parsing flaw, CVE-2026-14266, can let crafted archives trigger code execution in the current process. 7-Zip 26.02 fixed the issue on June 25, 2026. The bug is a heap-based buffer overflow in the archiver's XZ handling, and there is no public proof-of-concept or credible in-the-wild exploitation reported as of July 20, 2026. Users opening untrusted archives on affected systems face the main risk until patched builds are installed.

7-Zip 26.02 security update (CVE-2026-14266)

Security Patch Release

Updated: 20.07.2026 12:10 · First: 20.07.2026 12:10 · 📰 1 src / 1 articles · H score: 24

7-Zip 26.02 shipped on June 25, 2026 to fix CVE-2026-14266, a heap-based buffer overflow in XZ chunked data handling that could let a crafted archive run code in the current process. The update gives users a patched build before the July 15 public advisory and reduces exposure for systems that open untrusted archives. Machines running 7-Zip still need to move to 26.02 or later because the fix is a manual install.

Dental clinic hit by network compromise

Incident

Updated: 20.07.2026 12:07 · First: 20.07.2026 12:07 · 📰 1 src / 1 articles · H score: 12

A dental clinic suffered an unauthorized compromise after a threat actor used Google Gemini CLI to run C&C infrastructure that controlled eight computers and reached the OpenDental database. The intrusion gave the operator direct access to clinic systems and data, increasing the risk of further misuse or persistence. The activity was observed in logs covering March 19 to April 21, 2026.

Bandcampro Patriot Bait AI-assisted fraud campaign targeting politically engaged American audiences

Campaign

Updated: 20.07.2026 12:07 · First: 20.07.2026 12:07 · 📰 1 src / 1 articles · H score: 35

The Patriot Bait campaign tied to bandcampro ran AI-assisted fraud and credential-theft operations against politically engaged American audiences, creating a scalable path for account abuse and cryptocurrency scams. The operation used a Telegram channel and Google Gemini CLI to support impersonation, password cracking, botnet management, and C&C migration. It also extended to planning phone-based cryptocurrency fraud against elderly people in the U.S. and Canada and to abusing infrastructure against WordPress merchants and a dental clinic network.

Bandcampro's Gemini CLI-run disposable C&C model for AI-assisted cybercrime

Threat Actor Meta

Updated: 20.07.2026 12:07 · First: 20.07.2026 12:07 · 📰 1 src / 1 articles · H score: 36

Researchers found bandcampro outsourcing botnet and C&C operations to Google Gemini CLI, turning core operator work into a more disposable and replicable AI-assisted model. The setup let the actor migrate infrastructure in six minutes, manage bots, and support password cracking and WordPress compromise tasks. The workflow was portable through plaintext and markdown skill files, which can be shared on underground forums. That lowers the skill barrier for cybercrime and makes takedowns less effective across the March–April 2026 log window.

Hugging Face hit by network compromise

Incident

Updated: 20.07.2026 08:27 · First: 20.07.2026 08:27 · 📰 2 src / 2 articles · H score: 10

Hugging Face confirmed a production infrastructure breach that exposed a limited set of internal datasets and service credentials, creating risk of further internal access. The intrusion began through malicious dataset code execution paths in a remote code loader and a template injection in a dataset configuration. The company said it found no evidence the attacker tampered with public models, datasets, or Spaces.

RubyGems.org dead drop for stolen credential data

Data Leak

Updated: 20.07.2026 08:15 · First: 20.07.2026 08:15 · 📰 1 src / 1 articles · H score: 11

A malicious browser extension used RubyGems.org as a dead drop for stolen credential data, exposing 63 vault items with passwords, keys, and financial details. The uploaded material included plaintext passwords, SSH private keys, AWS credentials, crypto wallet seed phrases, and bank account details. Storing the loot in normal-looking package uploads increased the chance that the exposed secrets could be reused before detection.

SleeperGem RubyGems supply-chain campaign

Campaign

Updated: 20.07.2026 08:15 · First: 20.07.2026 08:15 · 📰 1 src / 1 articles · H score: 17

SleeperGem is an active RubyGems supply-chain campaign that used three malicious gems to stage second payloads, evade CI environments, and persist on developer machines. The operation is significant because the rogue releases were pushed directly to RubyGems from likely compromised or dormant accounts, letting the malicious code spread to existing users of the packages.

F5 nginx security patch release for CVE-2026-42533

Security Patch Release

Updated: 19.07.2026 23:42 · First: 19.07.2026 23:42 · 📰 1 src / 1 articles · H score: 39

F5 shipped security fixes for nginx and NGINX Plus to close CVE-2026-42533, a critical heap buffer overflow. Operators on nginx 1.30.4, 1.31.3, or NGINX Plus 37.0.3.1 are on the patched path; earlier builds need an upgrade. The release removes a remote unauthenticated request path that can crash the worker process and, in some configurations, may allow remote code execution.

Nginx heap buffer overflow remote code execution flaw (CVE-2026-42533)

Vulnerability

Updated: 19.07.2026 23:42 · First: 19.07.2026 23:42 · 📰 1 src / 1 articles · H score: 33

F5 shipped fixes for CVE-2026-42533, a critical nginx heap buffer overflow that can be triggered by crafted HTTP requests in a specific regex-map configuration. The flaw can crash or restart the worker process, creating denial of service, and F5 says it may also enable remote code execution when ASLR is disabled or bypassed. Affected core versions run from nginx 0.9.6 through 1.31.2, and the fix is available in nginx 1.30.4, 1.31.3, and NGINX Plus 37.0.3.1.

HelloInjector/HelloProxy malware activity in ViPNet update abuse

Malware Activity

Updated: 19.07.2026 17:23 · First: 19.07.2026 17:23 · 📰 1 src / 1 articles · H score: 23

The HelloInjector loader is running HelloProxy in memory and pulling additional modules from a C2 server, enabling expanded control over Windows hosts. The malware is delivered as wtsapi32.dll through the ViPNet Update System and sideloaded by itcsrvup64.exe at startup. It injects into svchost.exe to gain elevated privileges and persistence across reboots. The activity is part of HelloNet, which is targeting Russian organizations across multiple sectors.

HelloNet ViPNet update-abuse campaign targeting Russian organizations

Campaign

Updated: 19.07.2026 17:23 · First: 19.07.2026 17:23 · 📰 1 src / 1 articles · H score: 33

The HelloNet campaign is abusing the ViPNet update path to deliver malware to Russian organizations, including government agencies. Active since at least May, it plants wtsapi32.dll in the update directory so itcsrvup64.exe sideloads it at startup. The loader injects into svchost.exe to gain elevated privileges and persistence, then downloads follow-on modules from C2 servers. Impacted sectors include energy, transport, education, and logistics, while attribution to a Chinese-speaking APT remains low confidence.

UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets

Campaign

Updated: 19.07.2026 16:30 · First: 19.07.2026 16:30 · 📰 1 src / 1 articles · H score: 24

A UAC-0145 / Sandworm campaign is using ClickFix fake CAPTCHA pages on compromised websites to push malware onto Ukrainian targets, widening infection risk across at least 10 sites. The operation relies on PowerShell execution, page cloaking, and EtherHiding to steer victims toward malicious downloads. It also extends to Android lures packaged as security tools and a backdoor that can collect contacts, files, and geolocation.

ACR Stealer enterprise infostealer surge

Malware Activity

Updated: 18.07.2026 17:17 · First: 18.07.2026 17:17 · 📰 1 src / 1 articles · H score: 29

ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk. The malware used ClickFix, WebDAV, and MSHTA delivery chains to reach victims. The activity matters because it is built to collect browser credentials and corporate files for exfiltration.

Incode launches On-Device Age Estimation

Commercial Activity

Updated: 18.07.2026 16:15 · First: 18.07.2026 16:15 · 📰 1 src / 1 articles · H score: 74

Incode Technologies launched On-Device Age Estimation, shifting facial age checks to the user's phone, tablet, or laptop and keeping the face on the device. The product runs facial age estimation and passive liveness detection locally, while only the age-check result and non-biometric session data move onward. That design reduces exposure of biometric data and avoids transmitting or storing the face image. It also gives platforms a privacy-preserving way to meet age assurance requirements without centralizing sensitive identity data.

Incode acquires Identiq

Industry Action

Updated: 18.07.2026 16:15 · First: 18.07.2026 16:15 · 📰 1 src / 1 articles · H score: 70

Incode Technologies acquired Identiq, consolidating privacy-enhancing cryptographic anti-fraud collaboration capabilities under one cybersecurity vendor. The deal pairs the acquisition with a $100 million commitment to privacy-preserving identity infrastructure and expands Incode's fraud-prevention and age-verification stack. It strengthens a security-focused platform designed to reduce biometric exposure while improving cross-institution fraud intelligence.

Incode launches On-Device Age Estimation for local age checks

Security Tool/Service

Updated: 18.07.2026 16:15 · First: 18.07.2026 16:15 · 📰 1 src / 1 articles · H score: 76

Incode Technologies launched On-Device Age Estimation in July, moving facial age checks and liveness verification onto the user's phone, tablet, or laptop. The change reduces biometric exposure because the face is not transmitted or stored. The product preserves age-verification and anti-spoof controls while keeping the biometric processing local.

ShinyHunters social engineering campaign targeting employee SSO accounts

Campaign

Updated: 17.07.2026 23:45 · First: 17.07.2026 23:45 · 📰 1 src / 1 articles · H score: 79

The ShinyHunters extortion gang is running an ongoing social engineering campaign against employee Microsoft Entra, Okta, and Google SSO accounts, creating a path into connected business systems. The group uses vishing and SSO compromise to reach SaaS platforms and steal data for extortion. The operation has been active since last year and has increasingly focused on medtech companies. A successful login can expose multiple downstream services, broadening the blast radius of a single account takeover.

Abbott Laboratories hit by network compromise

Incident

Updated: 17.07.2026 23:45 · First: 17.07.2026 23:45 · 📰 1 src / 1 articles · H score: 65

Abbott Laboratories confirmed a cyber incident involving unauthorized access to a limited number of internal systems in its Cancer Diagnostics business. The company said the event did not affect operations, products, manufacturing, lab operations, or its ability to serve patients, limiting the immediate business impact. The incident is important because it involved a named healthcare company and internal systems tied to a diagnostics unit, even though Abbott says broader systems were not affected.