Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-23 13:00 PDT
- Fake Claude app promoted by Bing ads pushes SectopRAT malware
BleepingComputer • 2026-07-23 12:48 • www.bleepingcomputer.com
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. […]
https://www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware/ - Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
The Hacker News • 2026-07-23 11:36 • thehackernews.com
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client.The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.
The NSA, CISA and partner agencies published
https://thehackernews.com/2026/07/russian-espionage-group-exploited.html - Russian hackers exploit Zimbra zero-click flaw for email theft
BleepingComputer • 2026-07-23 09:49 • www.bleepingcomputer.com
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. […]
https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/ - Hackers abuse Notepad++ plugins to stealthily install malware
BleepingComputer • 2026-07-23 09:32 • www.bleepingcomputer.com
Ukraine’s CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. […]
https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/ - Microsoft 365 outage affects Teams, SharePoint and other services
BleepingComputer • 2026-07-23 08:34 • www.bleepingcomputer.com
Microsoft is impacted by a massive outage affecting Teams and Microsoft 365 services, primarily affecting users in North America. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-affects-teams-sharepoint-and-other-services/ - ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
The Hacker News • 2026-07-23 08:02 • thehackernews.com
Most of this week’s trouble came dressed as something useful.A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic.
The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
The danger was
https://thehackernews.com/2026/07/threatsday-android-spyware-plc-attacks.html - OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
Graham Cluley • 2026-07-23 07:18 • www.bitdefender.com
You can’t have failed to hear the news headlines about “rogue” OpenAI models hacking into another AI organisation, Hugging Face.But what has actually happened, who is to blame, and is it as serious as some of the reports suggest?
Find out in my article on the Hot for Security blog.
https://www.bitdefender.com/en-us/blog/hotforsecurity/openais-hacks-hugging-face - FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
BleepingComputer • 2026-07-23 07:00 • www.bleepingcomputer.com
FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assurance. […]
https://www.bleepingcomputer.com/news/security/fedramp-rev5-is-ending-what-the-20x-transition-really-requires/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
