July 30, 2026 North Korean-linked hackers are turning trusted npm packages into an entry point for widespread software supply-chain attacks. By compromising the accounts of legitimate package maintainers, the attackers …
TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft’s Emergency Patch
TA488 has been linked to a new campaign that turns a routine Outlook Web Access email into a gateway for mailbox compromise. The operation abused a now-patched cross-site scripting flaw, …
Cisco Firewall Management Center 0-Day Actively Exploited to Access Sensitive Data
July 30, 2026 Cisco has released security updates for an actively exploited zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software. This vulnerability, tracked as CVE-2026-20316, arises from static …
Microsoft Word Copilot Vulnerability Turns Hidden Prompts Into Self‑Propagating AI Worms
July 30, 2026 A new vulnerability in Microsoft Copilot for Word shows how hidden prompts inside documents can transform routine editing into a self‑propagating “AI worm” that tampers with business …
Critical Rails Flaw Lets Attackers Read Arbitrary Files and Execute Malicious Code Remotely
A severe security vulnerability in Ruby on Rails Active Storage tracked as CVE-2026-66066 can let unauthenticated attackers read sensitive files from a server and potentially escalate to remote code execution. …
AI-Generated Phishing No Longer Needs Malware: It Can Steal Your Session Inside the Browser
AI-generated phishing campaigns are rapidly evolving beyond traditional malware delivery, shifting the battleground directly into the web browser where attackers can hijack active sessions, bypass multi-factor authentication (MFA), and evade …
NVIDIA BlueField Vulnerability Enables Code Execution Attacks
July 29, 2026 NVIDIA has disclosed a serious vulnerability affecting its BlueField DPUs and ConnectX networking platforms that could allow attackers to execute code on affected systems if successfully exploited. …
Critical Ruflo MCP Bridge Flaw Lets Attackers Execute Commands and Hijack AI Agents
July 29, 2026 A critical security flaw in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to execute arbitrary commands and fully compromise AI agent environments. …
Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts and Messages
July 29, 2026 Russian intelligence-linked hackers are trying to seize Signal accounts by posing as support staff and asking targets for backup recovery keys. The campaign targets people with access …
Hijacked Joyfill npm Packages Deploy Worm-Like RAT and Steal Developer Credentials
A fresh supply chain scare hit software teams after attackers slipped malware into trusted open source libraries. On July 28, 2026, malicious beta builds of two Joyfill packages appeared on …
