Microsoft Defender XDR Blind Spot Can Hide Public Connections Behind FourToSixMapping

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 Security teams relying on Microsoft Defender XDR’s DeviceNetworkEvents table for hunting and detection may be missing critical external network connections due to a lesser-known IP address classification …

One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A single security alert has exposed an unusually detailed view of how a threat actor builds, tests, and delivers malware. The exposed WebDAV server held more than …

Linux Patches 400+ Kernel Vulnerabilities in 24 Hours With AI-Powered Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 The Linux kernel project has released fixes for over 400 vulnerabilities within approximately 24 hours. These vulnerabilities span various areas, including networking, filesystems, memory management, Bluetooth, virtualization, …

Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 Gitea users are urged to update immediately after a critical vulnerability was disclosed that allows public-only repository access tokens to indirectly write to private pull request branches …

The Privilege Paths Attackers See, That You Don’t – A Complete PAM Guide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Why identity fragmentation is the blind spot behind most breaches—and what a platform approach changes The Identity Problem Hiding in Plain Sight Identity is at the centre of nearly every …

Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A newly uncovered cyberespionage campaign has turned Telegram bots into quiet controllers for backdoors planted inside Middle Eastern government networks. The operation relies on familiar Windows components …

Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arctic Wolf …

Furtex – Linux Toolkit for Post-Exploitation and Evasion for Security Researchers and Red Teamers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A new open-source project, Furtex, has emerged as a Linux-focused post-exploitation and evasion research toolkit for authorized security researchers and red-team operators. The project combines raw io_uring …

Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 20, 2026 A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. HOLLOWGRAPH is a …