Microsoft to Discontinue Podcasts Option on Copilot and to Delete Contents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 Microsoft will retire the Podcasts feature in its consumer Copilot app on August 18, 2026, permanently removing access to both the creation tool and all previously generated podcast content. This change affects both free and paid Copilot …

AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 Malware operators are increasingly using tools built to extend artificial intelligence as a delivery route. A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model Context Protocol, or MCP, servers to distribute SmartLoader malware through …

Hackers Hide Malware Commands in Outlook Events Dated 2050 and Use as C2 Channel

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A newly identified malware component linked to the Project CAV3RN framework is abusing Microsoft Outlook calendar events scheduled for 2050 to conceal command-and-control (C2) traffic. The tool also uses DNS AAAA responses as a fallback channel to …

Agentic JADEPUFFER Exploits Langflow Flaw to Deploy ENCFORGE AI Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A ransomware campaign is now targeting the assets behind artificial intelligence systems. The threat actor known as JADEPUFFER has evolved from damaging databases to deploying ENCFORGE, a ransomware strain designed to encrypt AI models, training data, and …

Healthcare Giant Abbott Investigating Cyber Incident Following ShinyHunters Claims

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Abbott has confirmed that it is investigating a cyber incident involving unauthorized access to a limited number of internal systems used by its Cancer Diagnostics business. This follows claims associated with the ShinyHunters cybercrime group. The healthcare giant stated that …

SonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 Attackers actively exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) VPN appliances to gain root access and deploy custom malware. In early July 2026, the cybersecurity firm Volexity was involved in investigating an intrusion related …

Microsoft Defender XDR Blind Spot Can Hide Public Connections Behind FourToSixMapping

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 Security teams relying on Microsoft Defender XDR’s DeviceNetworkEvents table for hunting and detection may be missing critical external network connections due to a lesser-known IP address classification quirk. The issue centers on FourToSixMapping, a RemoteIPType value that …

One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A single security alert has exposed an unusually detailed view of how a threat actor builds, tests, and delivers malware. The exposed WebDAV server held more than 1,000 files, including phishing lures, shortcut files, droppers, testing notes, …

Linux Patches 400+ Kernel Vulnerabilities in 24 Hours With AI-Powered Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 The Linux kernel project has released fixes for over 400 vulnerabilities within approximately 24 hours. These vulnerabilities span various areas, including networking, filesystems, memory management, Bluetooth, virtualization, drivers, and security components. This rapid wave of Common Vulnerabilities …

Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 Gitea users are urged to update immediately after a critical vulnerability was disclosed that allows public-only repository access tokens to indirectly write to private pull request branches and trigger private Actions workflows. Tracked as CVE-2026-58443, the vulnerability …