July 9, 2026 GitHub Copilot can refuse harmful prompts in chat while still generating the same harmful content inside code workflows when the request is decomposed across a multi-step IDE …
GoodPersonRAT Uses Fake LetsVPN Installer to Give Attackers Full Remote Control
July 9, 2026 A fake installer for a popular Chinese VPN service is quietly handing full remote control of infected computers to unknown attackers. The malicious file poses as a …
Helix Data Extortion Group Uses Vishing and Device Code Phishing to Steal SharePoint Data
July 9, 2026 Helix has surfaced as a fast-moving data extortion group that targets Microsoft 365 users through phone scams and cloud-focused phishing instead of traditional malware drops. Attackers are …
Microsoft Released Patches for RoguePlanet Defender Zero-Day Vulnerability
July 9, 2026 Microsoft has released security updates to address a newly disclosed zero-day vulnerability in Microsoft Defender, publicly referred to as “RoguePlanet.” The flaw, tracked as CVE-2026-50656, affects the …
New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents
July 9, 2026 A newly disclosed vulnerability pattern dubbed “GhostApproval” has exposed a critical security flaw in six of the most widely used AI coding assistants: Amazon Q Developer, Anthropic …
Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic
July 9, 2026 Palo Alto Networks has disclosed a high-severity vulnerability in PAN-OS that could allow unauthenticated attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition by sending …
Accenture Confirms Data Breach – Hacker Claims Theft of Internal Source Code
July 9, 2026 IT services and consulting giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and …
Claude, Cursor, and Codex Trigger Endpoint Security Rules Used to Catch Hackers
July 9, 2026 AI coding agents such as Claude Code, Cursor, and OpenAI Codex are increasingly appearing in enterprise environments, and new telemetry shows they are unintentionally triggering security detections …
PromptSpy Android Malware Uses Google Gemini to Adapt During Runtime Execution
July 8, 2026 A newly identified strain of Android spyware called PromptSpy has become the first mobile malware known to call on generative AI while it is actually running on …
ClickFix Campaign Uses Fake Google Verification Page to Infect Mexican Bank Customers
July 8, 2026 A fake Google verification page is being used to infect customers of Mexican banks with a malware toolkit built for fraud, not just espionage. The campaign relies …
