Categories Breaking News

Breaking News – Cyber Threats – 2026-07-23 08:00 PDT

Breaking News – Cyber Threats (last 6h)

Generated: 2026-07-23 08:00 PDT

  • OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
    Graham Cluley • 2026-07-23 07:18 • www.bitdefender.com
    You can’t have failed to hear the news headlines about “rogue” OpenAI models hacking into another AI organisation, Hugging Face.

    But what has actually happened, who is to blame, and is it as serious as some of the reports suggest?

    Find out in my article on the Hot for Security blog.
    https://www.bitdefender.com/en-us/blog/hotforsecurity/openais-hacks-hugging-face

  • FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
    BleepingComputer • 2026-07-23 07:00 • www.bleepingcomputer.com
    FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assurance. […]
    https://www.bleepingcomputer.com/news/security/fedramp-rev5-is-ending-what-the-20x-transition-really-requires/
  • When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)
    SANS ISC Diary (full) • 2026-07-23 06:40 • isc.sans.edu

    Two disclosures, five days apart, described the same intrusion from opposite ends —
    one from the victim, one from the party that turned out to be responsible — and
    together they make one of the more instructive incidents of the year for defenders.


    https://isc.sans.edu/diary/rss/33180

  • Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
    The Hacker News • 2026-07-23 06:27 • thehackernews.com
    Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.

    Accomplish AI, which shared details of the vulnerability with The Hacker News ahead of publication, said about 500,000 macOS users running
    https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html

  • Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
    The Hacker News • 2026-07-23 06:11 • thehackernews.com
    The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor.

    The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or Edge in headless mode and drives the browser
    https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html

  • EU fines Google $1 billion for search, app store antitrust violations
    BleepingComputer • 2026-07-23 05:33 • www.bleepingcomputer.com
    The European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union’s Digital Markets Act (DMA), which ensures fair online competition. […]
    https://www.bleepingcomputer.com/news/google/eu-fines-google-1-billion-for-digital-markets-act-breaches-in-search-and-play-store/
  • China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
    The Hacker News • 2026-07-23 05:20 • thehackernews.com
    An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.

    Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it was offline by the time the report
    https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html

  • How Synthetic Identity Fraud is Coming for Machine Identities
    The Hacker News • 2026-07-23 04:45 • thehackernews.com
    Most people understand identity theft as an attacker stealing a real person’s sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points with fabricated ones to create a person who doesn’t exist. Since no real victim monitors misuse, a
    https://thehackernews.com/2026/07/how-synthetic-identity-fraud-is-coming.html
  • New RefluXFS Linux flaw lets attackers gain root privileges
    BleepingComputer • 2026-07-23 04:40 • www.bleepingcomputer.com
    A nine-year-old race condition vulnerability in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. […]
    https://www.bleepingcomputer.com/news/linux/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/
  • Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
    The Hacker News • 2026-07-23 04:28 • thehackernews.com
    Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances.

    The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13,
    https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html

  • End-to-End Encryption and “Going Dark”
    Schneier on Security • 2026-07-23 04:03 • www.schneier.com

    New paper: “Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate“:

    Abstract: This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current controversies over end-to-end encryption (E2EE). Governments around the world have proposed, and in some cases enacted, laws limiting E2EE for law enforcemen…
    https://www.schneier.com/blog/archives/2026/07/end-to-end-encryption-and-going-dark.html

  • New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
    BleepingComputer • 2026-07-23 03:00 • www.bleepingcomputer.com
    The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. […]
    https://www.bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic/
  • Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
    The Hacker News • 2026-07-23 03:00 • thehackernews.com
    Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video.

    The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone number. The idea is to use a video selfie as a way to regain access if a user ever gets locked out or doesn’t have access
    https://thehackernews.com/2026/07/google-adds-selfie-video-recovery-for.html

  • Microsoft working to fix Exchange Online mailbox quarantine issue
    BleepingComputer • 2026-07-23 02:20 • www.bleepingcomputer.com
    Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers’ mailboxes since Sunday. […]
    https://www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-exchange-online-mailbox-quarantine-issue/

Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.

Written By

More From Author

You May Also Like