July 23, 2026 Chaos ransomware has introduced a new way to hide attacker activity inside everyday web browsing. The group’s msaRAT remote-access tool turns Chrome or Microsoft Edge into a …
Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware
July 23, 2026 A simple mistake by cyber spies has pulled back the curtain on a wide ranging espionage effort. It reached hospitals, government offices, and schools across several continents …
Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks
Vercel has disclosed and patched nine security vulnerabilities in Next.js, the widely used React framework, addressing flaws that could enable server-side request forgery (SSRF), middleware authentication bypass, denial-of-service (DoS) attacks, …
Exim Directory Traversal Vulnerability Enables Privilege Escalation Attacks
July 23, 2026 A newly disclosed high-severity vulnerability in the Exim mail transfer agent allows local attackers to exploit a directory traversal flaw to escalate privileges on affected systems. Tracked …
Windows 11 and Server 2025 Exposed to High-Severity Brokering File System Vulnerability
July 23, 2026 Windows 11 and Windows Server 2025 high-severity vulnerability in Microsoft’s Brokering File System (BFS), identified as CVE-2026-50458, which allows for local privilege escalation on impacted systems. The …
New Dolphin X Malware Steals Credentials From 300+ Apps and Profiles Victims With AI
July 23, 2026 A newly identified Windows malware called Dolphin X is raising concerns because it can steal far more than browser passwords. The tool is marketed to criminals as …
Google Launches CodeMender AI Agent to Find, Validate, and Patch Vulnerabilities
July 23, 2026 Google has introduced CodeMender, a new AI-powered code security agent designed to find, validate automatically, and patch vulnerabilities at machine speed, as organizations face a surge in …
Microsoft Defender for Office 365 Adds New Prompt Injection Protection
July 23, 2026 Microsoft has introduced a new capability in Defender for Office 365 to protect against prompt injection attacks, which target AI-powered email workflows, such as Microsoft 365 Copilot. …
New Kimi K3 AI Agent Uncovers 0-Day Exploits in Redis Server
July 23, 2026 A newly reported research effort tied to the Kimi K3 AI agent has surfaced multiple authenticated remote code execution (RCE) paths in Redis, one of the world’s …
Hackers Breach South Korea’s Diplomatic Academy and Expose Foreign Ministry Staff Data
July 23, 2026 South Korea’s diplomatic community is facing a serious security incident after hackers breached the Korea National Diplomatic Academy’s online education system and accessed data on Ministry of …
