July 10, 2026 A malicious NuGet package impersonating the Braintree .NET payment library has put production payment systems at risk. The package can collect live card details during transactions, then …
Six U-Boot FIT Signature Verification Flaws Enable Code Execution and DoS Attacks
July 10, 2026 A new security analysis by Binarly Research has uncovered six critical vulnerabilities in the widely used U-Boot bootloader, exposing embedded systems and server management platforms to denial-of-service …
Wireshark 4.6.7 Released With Fixes for Vulnerabilities Allowing Crashes via Malicious Packets
The Wireshark Foundation has released Wireshark 4.6.7, a security-focused update that fixes multiple vulnerabilities that can cause the popular network protocol analyzer to crash when processing specially crafted packets or …
OpenAI Releases GPT-5.6 and ChatGPT Work, a New Companion to Handle Your Tasks
July 10, 2026 OpenAI has released the GPT-5.6 model family for general availability, introducing three models aimed at different performance and cost requirements: Sol, the flagship system; Terra, a balanced …
GodDamn Ransomware Rebrands From Beast and Uses PoisonX Driver to Disable Defenses
July 9, 2026 GodDamn ransomware has emerged as a serious threat, marking the third rebrand of a family that has quietly evolved since 2022. What makes this variant stand out …
RedHook Android RAT Abuses ADB Wireless Debugging to Gain Shell-Level Access
July 9, 2026 A resurfaced Android banking trojan called RedHook has returned with a dangerous new trick, hijacking a legitimate developer feature to quietly seize deep control of infected phones. …
Microsoft Adopts AI-Powered Scanning to Find Vulnerabilities Before Attackers
July 9, 2026 Microsoft has formally expanded its use of artificial intelligence in vulnerability discovery, deploying a proprietary multi-model agentic scanning system across the Windows codebase to identify and patch …
A Hacker Used AI to Compromise an AWS Cloud Environment in Just 72 Hours
July 9, 2026 A large-scale AWS intrusion reveals how AI-assisted attackers can chain familiar cloud techniques to move from initial access to full environmental compromise in roughly 72 hours, not …
Roundcube 0-Click Vulnerability Enables Stored XSS Attack via MIME Type Attachment
July 9, 2026 Roundcube has released version 1.7 to patch six security vulnerabilities, including two critical stored cross-site scripting (XSS) flaws that require zero user interaction to exploit. The update …
Hackers Abuse Microsoft Entra Passkey Enrollment to Hijack Enterprise Accounts
Cybercriminals have found a new way to hijack corporate Microsoft accounts by exploiting the very feature meant to protect them: passkeys. A threat group tracked as O UNC 066, also …
