The US Department of Defense (DoD) has suspended the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements until it reviews the program to allow for more innovation in the US defense industrial base (DIB). Originally scheduled to come into effect… Read More "Pentagon Suspends CMMC Phase II Requirements for Defense Contractors"
Compromised Logins Surge as the Most Common Entry Point for Ransomware
Identity-based attacks and abuse of compromised credentials have become the most common method cybercriminals use to hit networks with ransomware, analysis of real-world incidents has revealed. According to a new report by Sophos, 79% of ransomware attacks can be traced… Read More "Compromised Logins Surge as the Most Common Entry Point for Ransomware"
Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass
Attackers could bypass UEFI Secure Boot on a wide range of systems thanks to 11 Microsoft-signed UEFI shim bootloaders carrying vulnerabilities that have remained buried for more than a decade, according to new findings from ESET. ESET researchers reported the shims… Read More "Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass"
Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders
Following the sentencing of two young men for the 2024 Transport for London (TfL) hack, senior police officers have said the case makes a compelling argument for tougher legal powers in the UK, namely Cybercrime Risk Orders (CCROs). Owen Flowers,… Read More "Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders"
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2
A newly identified Windows malware sample abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command and control (C2) channel. Researchers at Group-IB dubbed the highly sophisticated malware sample HollowGraph and attributed it, with high… Read More "New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2"
Researchers Build WordPress Exploit Using OpenAI’s GPT
Security researchers at Searchlight Cyber have used OpenAI’s GPT5.6 Sol Ultra to successfully develop a full exploit chain for two critical WordPress Core vulnerabilities. The first vulnerability, tracked as CVE-2026-63030 is a critical REST API batch endpoint route confusion issue… Read More "Researchers Build WordPress Exploit Using OpenAI’s GPT"
JadePuffer Returns With Ransomware Designed to Wipe AI Models
The agentic operator documented as the first ransomware campaign run end-to-end by a large language model (LLM) has returned with a purpose-built locker designed to destroy trained AI model artifacts. According to new research from the Sysdig Threat Research Team (TRT)… Read More "JadePuffer Returns With Ransomware Designed to Wipe AI Models"
Cruciferra Crypter Uses Process Ghosting to Evade Detection
A crypter service used by multiple unrelated cyber-criminal groups has been documented cloaking commodity malware with process ghosting, kernel-driver abuse and more than 90 mix-and-match encryption routines. According to new research from Proofpoint published on July 20, the crypter, marketed… Read More "Cruciferra Crypter Uses Process Ghosting to Evade Detection"
Fake Bank of America Phishing Scam Installs Remote Access Malware
A new phishing scam that presents a fake Bank of America message is being used by cybercriminals to gain remote control of victims’ users. Identified by cybersecurity firm Huntress, the fake message imitates the bank’s visual style, layout and branding,… Read More "Fake Bank of America Phishing Scam Installs Remote Access Malware"
Frontier Models Engage in Unsanctioned Behavior During Testing
Frontier AI models recently engaged in “sustained, potentially harmful activity” targeting real people and organizations during testing, security evaluators have warned. The UK’s AI Security Institute (AISI) said it detected “unusual data transfers” leaving its systems on July 28. A… Read More "Frontier Models Engage in Unsanctioned Behavior During Testing"