APT42 Uses AI-Assisted Phishing and TAMECAT Malware to Target Government and Defense Officials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 APT42, an Iran-linked cyber espionage group, has expanded its phishing operations with AI-assisted research, convincing personas, and a more resilient version of its TAMECAT malware. The campaign …

Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A newly disclosed vulnerability, tracked as CVE-2026-50522, is rattling enterprise IT teams as it allows unauthenticated attackers to remotely execute code on on-premises Microsoft SharePoint servers. The …

AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 Malware operators are increasingly using tools built to extend artificial intelligence as a delivery route. A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model …

Hackers Hide Malware Commands in Outlook Events Dated 2050 and Use as C2 Channel

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A newly identified malware component linked to the Project CAV3RN framework is abusing Microsoft Outlook calendar events scheduled for 2050 to conceal command-and-control (C2) traffic. The tool …

Agentic JADEPUFFER Exploits Langflow Flaw to Deploy ENCFORGE AI Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A ransomware campaign is now targeting the assets behind artificial intelligence systems. The threat actor known as JADEPUFFER has evolved from damaging databases to deploying ENCFORGE, a …

Healthcare Giant Abbott Investigating Cyber Incident Following ShinyHunters Claims

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Abbott has confirmed that it is investigating a cyber incident involving unauthorized access to a limited number of internal systems used by its Cancer Diagnostics business. This follows claims associated …

SonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 Attackers actively exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) VPN appliances to gain root access and deploy custom malware. In early July 2026, the …

Microsoft Defender XDR Blind Spot Can Hide Public Connections Behind FourToSixMapping

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 Security teams relying on Microsoft Defender XDR’s DeviceNetworkEvents table for hunting and detection may be missing critical external network connections due to a lesser-known IP address classification …