Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-30 13:00 PDT
- DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
The Hacker News • 2026-07-30 11:18 • thehackernews.com
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.The defining aspect of the attack is that bogus macOS software update screen stealthily
https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html - Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
BleepingComputer • 2026-07-30 11:13 • www.bleepingcomputer.com
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. […]
https://www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/ - VMware fixes three critical flaws allowing auth bypass, VM escapes
BleepingComputer • 2026-07-30 11:00 • www.bleepingcomputer.com
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. […]
https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/ - Google says AI helped Chrome fix 1,072 security bugs in two releases
BleepingComputer • 2026-07-30 10:00 • www.bleepingcomputer.com
Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser’s two most recent releases as it expands its use of AI. […]
https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-072-security-bugs-in-two-releases/ - Read This Before You Buy That TV Streaming Stick
KrebsOnSecurity • 2026-07-30 09:49 • krebsonsecurity.com
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/ - ShinyHunters claims Brinks Home breach, threatens to leak stolen data
BleepingComputer • 2026-07-30 09:46 • www.bleepingcomputer.com
Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. […]
https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/ - American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
Schneier on Security • 2026-07-30 09:20 • www.schneier.comHe’s being prosecuted for giving border officials a code that wiped his phone:
The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick’s attorneys confirmed GrapheneOS was running on his phone.
The software feature allows the device owner to set a passcode that deliberately wipes the contents of that…
https://www.schneier.com/blog/archives/2026/07/american-being-prosecuted-for-wiping-his-phone-before-handing-it-over-to-border-officials.html - Microsoft Teams vishing attacks lead to Chaos ransomware attacks
BleepingComputer • 2026-07-30 08:56 • www.bleepingcomputer.com
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. […]
https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/ - ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
The Hacker News • 2026-07-30 08:25 • thehackernews.com
A lot of security still comes down to trusting the wrong screen.This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder.
Some defenses improved. The loose parts still got found first. Anyway,
https://thehackernews.com/2026/07/threatsday-ai-powered-hacking-370.html - Analog Devices discloses data breach, says operations unaffected
BleepingComputer • 2026-07-30 08:12 • www.bleepingcomputer.com
American semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. […]
https://www.bleepingcomputer.com/news/security/analog-devices-discloses-data-breach-says-operations-unaffected/ - After the Break-In: What Attackers Do Once They're Already Inside
BleepingComputer • 2026-07-30 07:01 • www.bleepingcomputer.com
Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove the malware. […]
https://www.bleepingcomputer.com/news/security/after-the-break-in-what-attackers-do-once-theyre-already-inside/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
