July 16, 2026 A macOS information-stealing malware is turning stolen Telegram desktop data into immediate account access. Instead of guessing passwords or breaking two-factor authentication, it copies the local files that prove a user has already logged in. When those …
WhatsApp GhostPairing Lets Scammers Hijack Accounts Without Stealing Passwords
July 16, 2026 WhatsApp users are being targeted by a social-engineering technique called GhostPairing that can give scammers access to an account without requiring a password or one-time verification code. Instead of breaking into the service directly, the scam abuses …
Specter Turns Your Flipper Zero Into a Pocket Skimmer Detector
July 16, 2026 A new Flipper Zero app called Specter aims to turn the handheld device into a passive counter-surveillance tool for finding active 13.56 MHz NFC readers, including potentially suspicious readers hidden near payment terminals, access-control panels, desks, or …
GPT-Red – A Red Teamer to Find Prompt Injection Vulnerabilities in GPT 5.6 Sol
July 16, 2026 OpenAI has introduced GPT-Red, an internal automated red-teaming model designed to identify and remediate prompt injection vulnerabilities in GPT-5.6. This approach aims to tackle a growing safety challenge. While human red-team exercises are valuable, they cannot generate …
Kratos PhaaS Attacking Microsoft 365 Users Across the US, Europe to Steal Credentials
July 16, 2026 Kratos is a phishing-as-a-service operation built to steal Microsoft 365 credentials. It is targeting organizations across the United States, Europe, and other regions by using believable document, invoice, and file-sharing lures that lead victims to fake login …
New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks
July 16, 2026 A newly identified IoT botnet framework, TuxBot v3 Evolution, is targeting internet-connected devices and turning compromised systems into tools for distributed denial-of-service attacks. The malware can run across a wide range of device architectures, creating a broad …
Multiple Splunk Enterprise Vulnerabilities Enable Path Traversal and Information Disclosure Attacks
July 16, 2026 Splunk has released security updates addressing multiple vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These flaws could lead to issues such as path traversal, disclosure of stored credential hashes, and arbitrary execution of SPL (Search Processing …
CISA Warns of Oracle E-Business Suite Vulnerability Actively Exploited in Attacks
July 16, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in attacks. This flaw impacts Oracle …
Hackers Can Type a Secret Username at the Windows Login Screen to Open a SYSTEM Shell
July 16, 2026 A stealthy Windows backdoor has resurfaced alongside Daxin, a sophisticated espionage tool previously tied to China-linked activity. The newly documented implant lets an intruder type a special username at the Windows sign-in screen and, in some cases, …
F5 Patches Multiple NGINX Vulnerabilities Enabling Heap Buffer Overflow and Code Execution Attacks
July 16, 2026 F5 has disclosed three high-severity vulnerabilities affecting NGINX Plus and NGINX Open Source, warning that unauthenticated attackers could exploit them to trigger memory corruption, crash worker processes, or, in the worst case, execute arbitrary code. The flaws, …
