ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 20, 2026 A new malware operation is using ClickFix pages to trick Windows users into running malicious commands themselves. The campaign delivers TELEPUZ, a lightweight but capable remote-access malware that can receive dozens of instructions from its operators. The …

Microsoft to End OneDrive Sync App Updates for Windows 10

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 20, 2026 Microsoft will stop delivering OneDrive sync app updates to systems running Windows 10 version 21H2 and earlier on August 15, 2026, creating a new support concern for organizations still operating legacy Windows endpoints. The change was announced …

Researchers Claim LG Monitors are Silently Installing Adware on Windows Using App

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 20, 2026 LG monitor software may install advertising-related components on Windows systems without clearly informing users through its companion application, which manages monitor settings, display profiles, and other device features. The software may silently install adware-like components in the …

Microsoft Releases KB5121767 Out-of-Band Update to Fix Dell USB-C Compatibility Bug

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 20, 2026 Microsoft has released the out-of-band update KB5121767 for Windows 11 to resolve a system performance and compatibility issue affecting a limited number of Dell devices. The update addresses issues with the Intel Innovation Platform Framework (Intel IPF) driver following …

Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 20, 2026 Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution, install persistent web shells, and steal cryptographic keys from exposed systems. The attacks put on-premises SharePoint deployments at risk of data theft, network compromise, …

Public PoC released for Critical ServiceNow Sandbox RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 20, 2026 ServiceNow has released security updates for a critical vulnerability in its AI platform after researchers published a proof of concept demonstrating pre-authentication remote code execution. The flaw, tracked as CVE-2026-6875, is a sandbox escape issue that could …

GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 20, 2026 GoldenEyeDog, a Chinese cybercrime group linked to the Golden Gh0st malware family, is back in focus after an intrusion at DigiCert exposed the risks around code-signing certificates. The attackers used the access to intercept customer certificate activation …

U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 20, 2026 Federal prosecutors have charged three Russian nationals over infrastructure that allegedly enabled ransomware, malware, phishing, and other cyberattacks against organizations in the United States and abroad. The seven-year investigation links the activity to more than $62 million …

North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 20, 2026 North Korean-linked hackers are hiding OTTERCOOKIE-aligned malware inside ordinary SVG flag images, turning a familiar part of a web project into a concealed delivery channel. The operation targets software developers who believe they are completing a coding …

15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 20, 2026 A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan Shaw reported the bug to F5 SIRT, which …