Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-22 03:00 PDT
- Chick-fil-A discloses data breach after credential stuffing attacks
BleepingComputer • 2026-07-21 23:40 • www.bleepingcomputer.com
American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. […]
https://www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/ - Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
The Hacker News • 2026-07-21 23:38 • thehackernews.com
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it.In a joint announcement on Monday, the Frankfurt public prosecutor’s cybercrime unit (ZIT) and Germany’s Federal Criminal Police Office (BKA)
https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html - Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
The Hacker News • 2026-07-21 23:00 • thehackernews.com
Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain.The package, named “Newtonsoftt.Json.Net,” masquerades as the Newtonsoft.Json library and is a trojanized fork. Seven versions of the package have been published to the
https://thehackernews.com/2026/07/trojanized-newtonsoftjson-fork-hides.html - OpenAI says its AI models hacked Hugging Face during testing
BleepingComputer • 2026-07-21 22:19 • www.bleepingcomputer.com
OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. […]
https://www.bleepingcomputer.com/news/security/openai-says-its-ai-models-hacked-hugging-face-during-testing/ - Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
The Hacker News • 2026-07-21 21:57 • thehackernews.com
A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds.The flaw is in Microsoft’s official Azure DevOps MCP server, and it works because one of its tools returns pull request descriptions without a prompt-injection guardrail the company had
https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html - OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
The Hacker News • 2026-07-21 21:18 • thehackernews.com
OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an “even more capable pre-release model,” was behind the security incident that targeted Hugging Face’s production infrastructure last week.The AI company said the models were operating with “reduced cyber refusals for evaluation purposes” that might otherwise limit their ability to
https://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
