Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-21 08:00 PDT
- Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
The Hacker News • 2026-07-21 07:04 • thehackernews.com
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway
https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html - Closing the Identity Gaps in Critical Infrastructure Security
BleepingComputer • 2026-07-21 07:00 • www.bleepingcomputer.com
Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. […]
https://www.bleepingcomputer.com/news/security/closing-the-identity-gaps-in-critical-infrastructure-security/ - Captive Portal Detection, (Tue, Jul 21st)
SANS ISC Diary (full) • 2026-07-21 06:44 • isc.sans.eduNot everything our honeypots detect is an attack. Sometimes it is just “odd traffic”, and this is one example: Our “First Seen” list currently includes “http://detectportal.firefox.co
m/success.txt” as one of the new URLs detected by our honeypots. The hostname “detectportal” kind of gives away what is happening here. - Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
The Hacker News • 2026-07-21 06:18 • thehackernews.com
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component.As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.
Also patched
https://thehackernews.com/2026/07/zimbra-patches-critical-snmp-command.html - A new extortion cocktail: office printers, small ransoms, and BitLocker
Securelist • 2026-07-21 06:00 • securelist.com
We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.
https://securelist.com/new-extortion-scheme-printers-bitlocker/120718/ - Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
The Hacker News • 2026-07-21 04:58 • thehackernews.com
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent.Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX,
https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html - N-day is Becoming N-Hour. Patching Faster Won't Save You.
The Hacker News • 2026-07-21 04:42 • thehackernews.com
Every patch is a confession.The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn’t updated yet. This is N-day exploitation, and it’s always been a race: the vendor patches, the clock starts, and defenders try to deploy
https://thehackernews.com/2026/07/n-day-is-becoming-n-hour-patching.html - New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
The Hacker News • 2026-07-21 04:24 • thehackernews.com
A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in.That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR’s hardware-security conference, and the evidence splits in two: they measured the power
https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html - MIT to Become Hotbed of AI Video Surveillance
Schneier on Security • 2026-07-21 04:07 • www.schneier.comIt’s a lot:
According to information obtained by The Tech, MIT is spending over $3 million on more than 500 AI surveillance cameras in academic buildings, residence halls, and outdoor areas along Memorial Drive. Installation of the new cameras, along with the wiring and infrastructure that will support them, began November 2025 and will likely continue until September 2026.
Technical specifications for the cameras suggest that they will be capable of collecting real-time face and o…
https://www.schneier.com/blog/archives/2026/07/mit-to-become-hotbed-of-ai-video-surveillance.html - US seizes over 1,000 websites in FIFA World Cup piracy crackdown
BleepingComputer • 2026-07-21 04:07 • www.bleepingcomputer.com
The U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization. […]
https://www.bleepingcomputer.com/news/security/us-seizes-over-1-000-fifa-world-cup-illegal-streaming-domains/ - Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
BleepingComputer • 2026-07-21 03:12 • www.bleepingcomputer.com
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecurity company Arctic Wolf. […]
https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/ - Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Graham Cluley • 2026-07-21 02:51 • www.bitdefender.com
Ukraine’s computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code.Read more in my article on the Hot for Security blog.
https://www.bitdefender.com/en-us/blog/hotforsecurity/ukraine-fake-captchas-hack-yourself - Microsoft shares manual fix for WSUS sync delays and timeouts
BleepingComputer • 2026-07-21 02:05 • www.bleepingcomputer.com
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-manual-fix-for-wsus-sync-delays-and-timeouts/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
