Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-28 03:00 PDT
- Data breach at medical billing firm MCBS affects 1.26 million people
BleepingComputer • 2026-07-28 02:10 • www.bleepingcomputer.com
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. […]
https://www.bleepingcomputer.com/news/security/data-breach-at-medical-billing-firm-mcbs-affects-126-million-people/ - Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
The Hacker News • 2026-07-28 01:11 • thehackernews.com
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution.The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already
https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html - Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
The Hacker News • 2026-07-28 01:04 • thehackernews.com
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel’s network traffic-control subsystem.Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and speed up exploit development. This is local
https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html - Mirage Kitten targets Middle East and Africa region with new malware
Securelist • 2026-07-28 01:00 • securelist.com
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
https://securelist.com/mirage-kitten-new-tools/120811/ - AutoIT Payload Injector , (Tue, Jul 28th)
SANS ISC Diary (full) • 2026-07-28 00:42 • isc.sans.eduFor a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you'll see below.
- Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
The Hacker News • 2026-07-27 23:07 • thehackernews.com
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness.The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved
https://thehackernews.com/2026/07/microsoft-says-new-cybersecurity-ai.html - Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News • 2026-07-27 21:43 • thehackernews.com
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.
“VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue
https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
