July 28, 2026 A little-known Chinese company may have helped build the hidden network used to support military-linked cyber operations around the world. Researchers say Guangdong Chanming, a firm with …
New Tengu Mirai Botnet Reboots Your IoT Device When You Try to Kill It
July 28, 2026 Tengu, a newly observed Mirai-based botnet, is making infected IoT devices far harder to clean. It targets internet-facing embedded Linux systems, particularly devices that leave Telnet or …
libssh2 Vulnerabilities Allows a Malicious SSH Server to Corrupt Client Memory
July 28, 2026 A set of high-severity vulnerabilities in libssh2 could expose SSH and SFTP client applications to memory corruption, crashes, and potential code execution when connecting to a malicious …
LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches Installed
July 28, 2026 A newly disclosed exploit dubbed LegacyHive is raising alarms across the cybersecurity community after researchers confirmed it executes successfully on fully patched Windows systems running the July …
Scammers Pose as ShinyHunters to Blackmail Data-Breach Victims With Fake Webcam Videos
July 28, 2026 Victims of recent data breaches are receiving alarming emails that claim hackers recorded them through their webcams. The messages borrow the ShinyHunters name and cite a recipient’s …
Five Progress LoadMaster Flaws Let Attackers Execute Commands and Gain Root Access
July 28, 2026 Progress has addressed five serious vulnerabilities affecting Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale appliances. These vulnerabilities, tracked as CVE-2026-59686 through CVE-2026-59690, impact several …
Multiple FFmpeg Vulnerabilities Allow Attackers to Corrupt Memory Via Malicious Video File
July 28, 2026 Multiple high-severity vulnerabilities have been identified in FFmpeg, the widely used open-source multimedia framework. These flaws impact media parsing, decoding, filtering, and encoding components and can be …
Microsoft Teams Vishing Attack Uses Quick Assist to Deploy GoGRPC Backdoor
A new Microsoft Teams vishing campaign is using fake IT support calls to gain remote access to corporate systems. The attackers then deploy GoGRPC, a Go-based backdoor that can run …
PortSwigger Launches Burp AT Agentic AI for Human-Led Web Penetration Testing
July 28, 2026 PortSwigger has officially launched Burp AT in public beta, bringing agentic AI capabilities directly into Burp Suite Professional for the first time. The new feature allows penetration …
Operation STANDOFF Hides Command-and-Control Traffic Behind GitHub Redirects
July 28, 2026 Operation STANDOFF is a Russian-speaking cybercrime campaign that turns a single infection into a wider compromise. Its installer delivers information stealers, loaders, a cryptocurrency miner, and botnet …
