July 6, 2026 Multiple vulnerabilities have been disclosed in IBM WebSphere Application Server that could allow attackers to execute cross-site scripting (XSS) attacks and perform path traversal, potentially exposing sensitive …
Multiple PHP Vulnerabilities Enable DoS and Memory Corruption Attacks
July 6, 2026 Multiple security vulnerabilities in PHP have been disclosed that could allow attackers to trigger denial-of-service (DoS) conditions and cause memory corruption, impacting widely deployed web applications. The …
Moody Bible Institute Data Breach Exposes 2.3 Million Users’ Personal Data
July 6, 2026 Moody Bible Institute has confirmed a significant data breach after threat actors linked to the ShinyHunters extortion group published personal information belonging to over 2.3 million individuals. …
RedLine C2 Pivot Reveals Seven Fraudulent Domains Used in Maritime Phishing Attacks
July 6, 2026 A single leaked command and control server ended up unraveling an entire phishing operation aimed at the maritime shipping world. What started as a routine look at …
15-Year-Old Arrested Over Bandai Channel Cyberattack Using a ChatGPT-Assisted Tool
July 6, 2026 Japanese police have arrested a 15-year-old high school student from Tokorozawa City, Saitama Prefecture, on suspicion of fraudulent obstruction of business after he allegedly used a ChatGPT-assisted …
Agent Skill Malware Targets Claude Code and OpenAI Codex With Scanner-Evasion Techniques
July 6, 2026 A new class of malicious software is quietly slipping past the security tools meant to protect popular AI coding assistants. Researchers have found that malware hidden inside …
Gaslight macOS Malware Uses Prompt Injection to Evade AI Security Analysis
July 6, 2026 A fresh piece of Mac malware has surfaced, and it comes with a twist that security teams have not seen before. Written in Rust and tied to …
Opera GX 0-Click Vulnerability Lets Attackers Exfiltrate User Data via Malicious Website
July 6, 2026 A newly disclosed vulnerability in Opera GX allowed attackers to silently exfiltrate sensitive user data with no interaction required, simply by luring victims to a malicious website. …
New TrojPix Attack Lets Attackers Access Air-gapped Computers From 208 Meters
July 6, 2026 A novel electromagnetic (EM) covert-channel attack, dubbed TrojPix, can steal sensitive data from already-compromised air-gapped computers over distances of up to 208 meters, even through concrete walls, …
Hackers Abuse OpenAI Org Invites to Harvest Sensitive Prompts and API Activity
July 6, 2026 Hackers are actively abusing OpenAI’s organization invitation feature to launch a new form of “poisoned tenant” attack, allowing them to harvest sensitive prompts, API activity, and potentially …
