Categories Breaking News

Breaking News – Cyber Threats – 2026-07-30 08:00 PDT

Breaking News – Cyber Threats (last 6h)

Generated: 2026-07-30 08:00 PDT

  • After the Break-In: What Attackers Do Once They're Already Inside
    BleepingComputer • 2026-07-30 07:01 • www.bleepingcomputer.com
    Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove the malware. […]
    https://www.bleepingcomputer.com/news/security/after-the-break-in-what-attackers-do-once-theyre-already-inside/
  • Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
    The Hacker News • 2026-07-30 06:34 • thehackernews.com
    A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service’s Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz.

    Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a
    https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html

  • Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
    The Hacker News • 2026-07-30 04:54 • thehackernews.com
    Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft.

    In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting session.

    Måløy’s
    https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html

  • The Network Has Become the Control Plane for AI Security
    The Hacker News • 2026-07-30 04:32 • thehackernews.com
    Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network security teams have built controls around a relatively stable model: users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations. Firewalls
    https://thehackernews.com/2026/07/the-network-has-become-control-plane.html
  • Should You Use AI for a Task? Here’s a Simple Way to Decide
    Schneier on Security • 2026-07-30 04:01 • www.schneier.com

    This essay originally appeared in The Guardian.

    I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come as no surprise to you that my students regularly use AI to complete their writing assignments. Doing so is a waste of their tuition money. But if their entire career is going to incl…
    https://www.schneier.com/blog/archives/2026/07/should-you-use-ai-for-a-task-heres-a-simple-way-to-decide.html

  • OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
    Securelist • 2026-07-30 04:00 • securelist.com
    Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
    https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/
  • Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
    The Hacker News • 2026-07-30 03:33 • thehackernews.com
    South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.

    A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or
    https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html

  • SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
    The Hacker News • 2026-07-30 03:32 • thehackernews.com
    The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent remote access.

    “In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate
    https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html

  • North Korea’s elite hackers turned on their own government – and got caught
    Graham Cluley • 2026-07-30 02:17 • www.bitdefender.com
    For years, North Korea’s state-trained hackers have been one of the world’s most prolific robbers of banks – stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country’s weapons programme.

    But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead. And, it doesn’t sound as if it has ended that well for them.

    Read more in my article on the Hot for Security blog.
    https://www.bitdefender.com/en-us/blog/hotforsecurity/north-korea-hackers-own-government

Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.

Written By

More From Author

You May Also Like