Hackers Hijack 20+ Government Websites to Deliver Malware Through Trusted Links

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active malware campaign, dubbed PhantomEnigma, that abuses compromised Brazilian government infrastructure to distribute malicious payloads while evading detection. The operation has hijacked at least 20 official “.gov.br” municipal and …

Trump’s AI Safety Chief Quits Just Three Months After Taking Charge

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 Chris Fall has resigned as the director of the Center for AI Standards and Innovation (CAISI), leaving the Trump administration’s AI safety organization without a permanent leader …

Hackers Abuse GitHub Actions to Backdoor AsyncAPI npm Packages With Miasma RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A supply chain attack has pushed Miasma malware into trusted AsyncAPI npm packages, putting developer systems and automated build environments at risk. Attackers used a compromised release …

APT42 Uses AI-Assisted Phishing and TAMECAT Malware to Target Government and Defense Officials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 APT42, an Iran-linked cyber espionage group, has expanded its phishing operations with AI-assisted research, convincing personas, and a more resilient version of its TAMECAT malware. The campaign …

Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A newly disclosed vulnerability, tracked as CVE-2026-50522, is rattling enterprise IT teams as it allows unauthenticated attackers to remotely execute code on on-premises Microsoft SharePoint servers. The …

AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 Malware operators are increasingly using tools built to extend artificial intelligence as a delivery route. A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model …

Hackers Hide Malware Commands in Outlook Events Dated 2050 and Use as C2 Channel

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A newly identified malware component linked to the Project CAV3RN framework is abusing Microsoft Outlook calendar events scheduled for 2050 to conceal command-and-control (C2) traffic. The tool …

Agentic JADEPUFFER Exploits Langflow Flaw to Deploy ENCFORGE AI Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A ransomware campaign is now targeting the assets behind artificial intelligence systems. The threat actor known as JADEPUFFER has evolved from damaging databases to deploying ENCFORGE, a …