Categories Breaking News

Breaking News – Cyber Threats – 2026-07-24 03:00 PDT

Breaking News – Cyber Threats (last 6h)

Generated: 2026-07-24 03:00 PDT

  • NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
    The Hacker News • 2026-07-24 00:41 • thehackernews.com
    Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software’s source code.

    Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators should be on 4.14.2.

    The simplest one takes a settings change. A
    https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html

  • Clop ransomware targets Windchill, FlexPLM in data theft attacks
    BleepingComputer • 2026-07-24 00:36 • www.bleepingcomputer.com
    The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. […]
    https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
  • Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
    The Hacker News • 2026-07-23 23:58 • thehackernews.com
    Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.

    All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution.

    Redis 6.2.23, 7.2.15, and 7.4.10
    https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html

  • Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
    The Hacker News • 2026-07-23 23:50 • thehackernews.com
    The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems.

    The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed weaponizing security flaws in WinRAR software to
    https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html

Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.

Written By

More From Author

You May Also Like