Categories Breaking News

Breaking News – Cyber Threats – 2026-07-27 08:00 PDT

Breaking News – Cyber Threats (last 6h)

Generated: 2026-07-27 08:00 PDT

  • ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
    The Hacker News • 2026-07-27 07:10 • thehackernews.com
    Monday starts with the usual promise that everything is under control. Then the logs wake up.

    This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped.

    That is the mood. Here is the full recap.

    ⚡ Threat of the Week

    OpenAI Says Its AI Agent Went Rogue
    https://thehackernews.com/2026/07/weekly-recap-rogue-ai-agents-check.html

  • Shadow AI agents are multiplying. Here's how to find and secure them.
    BleepingComputer • 2026-07-27 07:01 • www.bleepingcomputer.com
    Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous actions create security risks. […]
    https://www.bleepingcomputer.com/news/security/shadow-ai-agents-are-multiplying-heres-how-to-find-and-secure-them/
  • n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
    The Hacker News • 2026-07-27 06:05 • thehackernews.com
    n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n’s February fix for CVE-2026-27577 for another bypass.

    The affected ranges are <2.31.5 and >=2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and
    https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html

  • Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
    The Hacker News • 2026-07-27 05:37 • thehackernews.com
    Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs “secure document” lures to deliver legitimate remote monitoring and management (RMM) tools.

    “The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened,” ZeroBEC said in
    https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html

  • Cognyte Sells a Mobile Cell Surveillance Van
    Schneier on Security • 2026-07-27 04:04 • www.schneier.com

    Yet another Israeli mass surveillance company:

    Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity ­ whether they’re owned by a suspect in a case or not. Cognyte’s contract with the state of Texas reveals that the simulator, called FalcoNet, can be concealed within the vehicles, hidden in a backpack…
    https://www.schneier.com/blog/archives/2026/07/cognyte-sells-a-mobile-cell-surveillance-van.html

  • Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
    The Hacker News • 2026-07-27 03:51 • thehackernews.com
    The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra.

    According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote
    https://thehackernews.com/2026/07/cruciferra-crypter-uses-byovd-and.html

  • Java Spring Boot "heapdump" scans, (Mon, Jul 27th)
    SANS ISC Diary (full) • 2026-07-27 03:04 • isc.sans.edu

    Spring Boot exposes the endpoint “/actuator/heapdump” to collect debug information. By default, the endpoint will return a file heapdump.hprof, which includes a binary heapdump that can be used to analyze the current state of the application. Non-Java readers may be familiar with a similar concept, core dumps, which are produced by binaries to expose a memory image at the time the software crashes. “heapdumps” are the Java analog to “core-dumps”. The heapdump often includes secrets used by the application to connect to backend systems. API keys, database passwords, and other sensitive da…
    https://isc.sans.edu/diary/rss/33188

Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.

Written By

More From Author

You May Also Like