Categories Breaking News

Breaking News – Cyber Threats – 2026-07-21 08:00 PDT

Breaking News – Cyber Threats (last 6h)

Generated: 2026-07-21 08:00 PDT

  • Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
    The Hacker News • 2026-07-21 07:04 • thehackernews.com
    Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.

    Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway
    https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html

  • Closing the Identity Gaps in Critical Infrastructure Security
    BleepingComputer • 2026-07-21 07:00 • www.bleepingcomputer.com
    Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. […]
    https://www.bleepingcomputer.com/news/security/closing-the-identity-gaps-in-critical-infrastructure-security/
  • Captive Portal Detection, (Tue, Jul 21st)
    SANS ISC Diary (full) • 2026-07-21 06:44 • isc.sans.edu

    Not everything our honeypots detect is an attack. Sometimes it is just “odd traffic”, and this is one example: Our “First Seen” list currently includes “http://detectportal.firefox.co
    m/success.txt” as one of the new URLs detected by our honeypots. The hostname “detectportal” kind of gives away what is happening here.


    https://isc.sans.edu/diary/rss/33172

  • Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
    The Hacker News • 2026-07-21 06:18 • thehackernews.com
    Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component.

    As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.

    Also patched
    https://thehackernews.com/2026/07/zimbra-patches-critical-snmp-command.html

  • A new extortion cocktail: office printers, small ransoms, and BitLocker
    Securelist • 2026-07-21 06:00 • securelist.com
    We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.
    https://securelist.com/new-extortion-scheme-printers-bitlocker/120718/
  • Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
    The Hacker News • 2026-07-21 04:58 • thehackernews.com
    An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent.

    Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX,
    https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html

  • N-day is Becoming N-Hour. Patching Faster Won't Save You.
    The Hacker News • 2026-07-21 04:42 • thehackernews.com
    Every patch is a confession.

    The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn’t updated yet. This is N-day exploitation, and it’s always been a race: the vendor patches, the clock starts, and defenders try to deploy
    https://thehackernews.com/2026/07/n-day-is-becoming-n-hour-patching.html

  • New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
    The Hacker News • 2026-07-21 04:24 • thehackernews.com
    A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in.

    That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR’s hardware-security conference, and the evidence splits in two: they measured the power
    https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html

  • MIT to Become Hotbed of AI Video Surveillance
    Schneier on Security • 2026-07-21 04:07 • www.schneier.com

    It’s a lot:

    According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and infrastructure that will support them, began November 2025 and will likely continue until September 2026.

    Technical specifications for the cameras suggest that they will be capable of collecting real-time face and o…
    https://www.schneier.com/blog/archives/2026/07/mit-to-become-hotbed-of-ai-video-surveillance.html

  • US seizes over 1,000 websites in FIFA World Cup piracy crackdown
    BleepingComputer • 2026-07-21 04:07 • www.bleepingcomputer.com
    The U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization. […]
    https://www.bleepingcomputer.com/news/security/us-seizes-over-1-000-fifa-world-cup-illegal-streaming-domains/
  • Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
    BleepingComputer • 2026-07-21 03:12 • www.bleepingcomputer.com
    The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecurity company Arctic Wolf. […]
    https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
  • Ukraine warns fake CAPTCHAs are being used to make you hack yourself
    Graham Cluley • 2026-07-21 02:51 • www.bitdefender.com
    Ukraine’s computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code.

    Read more in my article on the Hot for Security blog.
    https://www.bitdefender.com/en-us/blog/hotforsecurity/ukraine-fake-captchas-hack-yourself

  • Microsoft shares manual fix for WSUS sync delays and timeouts
    BleepingComputer • 2026-07-21 02:05 • www.bleepingcomputer.com
    Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. […]
    https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-manual-fix-for-wsus-sync-delays-and-timeouts/

Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.

Written By

More From Author

You May Also Like