Cyber Security News
56.4K subscribers
201 photos
3 videos
114K links
Be Cyber Aware. Subscribe.

Our chat: t.me/cybersecuritynewschat

Our vacancies channel: @CyberSecurityJobs

LinkedIn: https://www.linkedin.com/company/securitynews/

📩 Collab: cybersecnewsinfo@gmail.com

Paid Ads: @cybersecadmin
Download Telegram
Cyber Security News
⚡️Hugging Face Hacked in Autonomous AI Attack Hugging Face says it responded to the attack largely with its own AI, addressed the dataset code-execution paths exploited for initial access, evicted the attackers from its infrastructure, rebuilt the affected…
Hugging Face Breach: Rogue AI Agent Burned Through Sandboxes to Steal Internal Creds

Hugging Face confirmed a malicious dataset exploited a vulnerability to execute code on its servers, escalating access to internal datasets and service credentials.

The company blamed «an external AI agent, which executed many thousands of individual actions across a swarm of short-lived sandboxes» — detected by its own anomaly system.

Credentials have been rotated and the flaw patched; users are urged to rotate their access tokens.

@Cyber_Security_Channel
👍3
🔍 What if the Phishing Page that Steals Access Never Appears in the Security Scan you Trust?

Ghost Phishing can keep real lure hidden until the victim’s browser decrypts and renders it.

Static analysis may return a clean result while the user is already interacting with a fully active phishing page.

This risk can be reduced with browser-level visibility.

ANY.RUN helps security teams see what actually happens in the browser, including:

👻 Decrypted phishing content as it appears
🧩 Runtime DOM changes and hidden page elements
🌐 Requests and redirects behind the attack
Clear evidence for faster triage and response

Don’t let hidden phishing activity go unseen.

Get full visibility with ANY.RUN → click here to enhance security now.

-----

#ad #paidpromotion #sponsored

@Cyber_Security_Channel
11
1Password Partners with Anthropic to Give Claude Access to Your Credentials

1Password and Anthropic unveiled a «zero-exposure» framework that lets Claude AI agents retrieve credentials from a 1Password vault without the assistant ever seeing the raw values.

Authentication happens through a scoped broker; the model receives an authenticated session, not the secret itself.

Expect similar patterns from other agent-first stacks as autonomous workflows meet enterprise credential policies.

@Cyber_Security_Channel
👎122
ClickLock macOS Malware Hostage-takes Users Until They Type Their Password

Group-IB documented ClickLock, a macOS stealer delivered via a ClickFix «Cloudflare human verification» lure that runs a malicious Terminal command.

It shows a fake password dialog with the victims real username; if refused, it kills Finder and Terminal every 210 ms for up to 83 hours until the password is entered.

After that it grabs credentials, browser data, crypto wallet extensions, FileZilla configs and shell history, then self-deletes — ~100 infections across 33 countries since May.

@Cyber_Security_Channel
AgentBaiting: 800 Fake AI skills and MCP Servers Seed SmartLoader Malware

Island researchers uncovered ~7,600 malicious repos from ~6,600 fake profiles, 800+ posing as AI skills or MCP servers.

ZIP archives disguised as installers deliver SmartLoader, which injects StealC — pulling browser sessions, tokens, API creds, and screenshots.

Around 200 campaign repos accounted for over 14 million downloads before takedown.

@Cyber_Security_Channel
🔥4👍2
🤝 Cyber Security News is looking for ADVERTISERS

Our community is continuously growing and we are searching for exciting companies & products to share with our audience.

Requirements to Qualify

• Relevant to channels niche / industry
• Long-term approach and collaboration mindset
• $2,000+ monthly ad spend budget to invest in campaigns

What We Offer

Exposure to 80,000+ community members
• Personal success manager to scale your campaigns
• Brand awareness, leads, sign-ups, customers, followers, etc.

📩 Contact for Partnership

If you are serious about promoting your business, send us an introduction Email → cybersecnewsinfo@gmail.com

Important Note

Spots to become a sponsor are limited.

Reach out before they fill up.

(we only have 6 left)

- - - - -

@Cyber_Security_Channel
12
Microsoft Patch Tuesday: 622 CVEs, «the mother of all» Releases

Microsoft disclosed 622 vulnerabilities in July — triple Junes previous record of 206 — including 63 critical and two exploited zero-days (CVE-2026-56155 in AD FS, CVE-2026-56164 in SharePoint Server).

Breakdown: 416 in Windows, 82 in Office, 46 in Edge; Trend Micros Dustin Childs called it «the mother of all releases».

Analysts credit AI-powered bug discovery — 2026 could top 2,000-3,000 CVEs, blowing past the 1,245 full-year record from 2020.

@Cyber_Security_Channel
3👍2
July 2026 in Cyber: AI Agents Went on Offense, Vuln Loads Broke Records

Autonomous AI agents showed up on both sides — Hugging Face was breached by an external agent looping through a swarm of sandboxes, and AgentBaiting seeded 800+ fake AI skills and MCP servers pushing SmartLoader.

Microsoft dropped 622 CVEs in one Patch Tuesday — triple June's record, plus zero-days in AD FS and SharePoint.

WordPress «wp2shell» RCE and a Windows «LegacyHive» privilege escalation piled on.

SonicWall SMA1000, ShareFile, and 11 Microsoft-signed Linux UEFI shims were all exploited or exposed pre-patch.

Qilin ransomware weaponized a critical Palo Alto GlobalProtect bug; Coca-Cola paused Fairlife dairy; two Scattered Spider members got 5.5 years each for the £29M TfL breach.

@Cyber_Security_Channel
10🔥2
CareCloud Breach Exposes Medical Records of 345,000 Patients

U.S. health tech giant CareCloud has confirmed that hackers stole patient data from one of its AWS-hosted health record stores.

New regulatory filings show the intrusion, which ran from March 10 to 16, has affected at least 345,000 people across the U.S. so far.

Stolen data includes names, Social Security numbers, passport and driver's license numbers, and financial account details.

CareCloud stores records for more than 45,000 healthcare providers, and no ransomware group has claimed responsibility.

@Cyber_Security_Channel
4👀3
Apple Challenges UK Government's iCloud Backdoor Demand

Apple has filed a legal complaint against the UK government over a secret order demanding backdoor access to encrypted iCloud data.

The company brought the case to the UK's Investigatory Powers Tribunal, which hears government surveillance disputes.

The challenge targets a technical capability notice issued last year that would force Apple to grant access to encrypted user data on demand.

The clash follows Apple's 2025 decision to pull Advanced Data Protection for UK users rather than build in a backdoor.

@Cyber_Security_Channel
👍93🔥1
The Assets You Don’t Know You Own: Attack Surface Sprawl Is a Discovery Problem, Not a Tooling Problem

Attack surface expansion is frequently framed as a tooling gap, but the evidence points elsewhere — toward a persistent, structural failure in attack surface discovery, asset discovery, and visibility.

Cyber_Security_Channel
👍3
Framework Discloses Data Breach via Metabase Zero-Day

Framework notified customers that a zero-day flaw in vendor Metabase let attackers into its cloud database, the company disclosed Thursday.

The breach exposed names, emails, phone numbers, and addresses, though payment data was untouched.

A spokesperson would not give an exact count, confirming only that "all customers" were hit among Framework's hundreds of thousands of buyers.

Metabase said it blocked the malicious endpoints and patched the underlying SQL injection bug.

@Cyber_Security_Channel
1👍1
🎥 Smile, You’re on Camera! North Korean IT Workers Got Hired and Exposed Live

Researchers created a fake company, hired suspected DPRK operatives linked to Lazarus Group, and watched their activity unfold inside controlled @anyrun_app Sandbox environments.

Along the way, they uncovered:

🪪 Fake IDs and stolen identities

🖥️ Remote access tools and system reconnaissance

🤖 AI-assisted coding and document alteration

🌐 VPN and VPS infrastructure

🔐 Shared 2FA services, crypto wallets, and account activity

A must-read for any company that doesn’t want its next remote hire to be a spy.

Read the full investigation – tap here to access the article.

-----

#ad #paidpromotion #sponsored

@Cyber_Security_Channel
10👍4
Ceva Logistics Breach Hits Banks, Retailers, and Steam Gamers

Shipping giant Ceva Logistics confirmed a cyberattack that breached eight European warehouses and stole customer data.

Exposed records include names, home addresses, phone numbers, and email addresses, rippling out to Dutch retailer Bol, De Bijenkorf, football club Ajax, banking giant ING, and Ace & Tate.

Valve discovered the breach on August 7 and warned Steam hardware customers, while Ceva said it activated security protocols as the investigation with authorities continues.

@Cyber_Security_Channel
6
Join the Webinar: Cybersecurity, Privacy and Data Protection Law in 2026.

Stay ahead of latest privacy regulations, understand legal impact of AI, and earn CPE credits.

Key Insights:

Global overview of new cyber, privacy & data protection laws

Recent regulatory developments in cybersec and AI

Compliance requirements and penalties

Personal liability of CISOs, executives & professionals

Practical strategies: reduce legal & regulatory risks

Cyber insurance pitfalls: how to avoid in 2026

Best practices: data breach investigation & disclosure

How ImmuniWeb helps organizations strengthen compliance 

📅 Date & Time: August 20, 2026

• Session 1: Geneva 10am | Dubai 12pm | Singapore 4pm
• Session 2: Geneva 5pm | New York 11am | California 8am

🎤 Host: Dr. Ilia Kolochenko, Founder, Chief Architect & CEO at ImmuniWeb.

Register: tap here to claim your spot.

-----

#ad #paidpromotion #sponsored

@Cyber_Security_Channel
6🔥1
China-Linked JDY Botnet Scouts Networks for Rapid Exploitation

Lumen's Black Lotus Labs uncovered a resurgence of the China-nexus JDY botnet, spanning over 1,500 compromised SOHO and IoT devices.

The network scans and fingerprints targets to identify vulnerable infrastructure within hours of new vulnerability disclosures.

Compromised routers evade IP-based defenses while serving as distributed reconnaissance infrastructure.

Researchers found a particular focus on U.S. military-related networks, raising concerns over follow-on attacks.

@Cyber_Security_Channel
4👍2🔥1🤩1
Cheaper Mid-Tier AI Models Show Sharp Rise in Hacking Skill

New research from XBOW revealed that mid-priced AI models like GLM-5.2, Grok 4.5, and Claude Opus 4.7 now perform strongly at real-world hacking tasks.

GPT-5.5 missed only 10% of vulnerabilities in testing, down sharply from GPT-5's 40% miss rate, and did best without source code access, mirroring real attacker conditions.

Researchers warned that because these models are far cheaper to run than frontier systems, attackers can query them repeatedly at scale, gaining an edge with no budget limits.

@Cyber_Security_Channel
6👏1
🌎 Prevent Critical Incidents with Early Knowledge about Emerging Attacks from 16K Orgs

Actionable threat intelligence is a №1 priority for modern SOCs, as it gives them the REAL advantage against attackers.

@anyrun_app TI Feeds provide leading companies with a live stream malware & phishing IPs, domains, and URLs from 16K SOCs and 700K analysts globally.

🎯 Early detection of campaigns launched in the previous 24 hours

🔎 Faster incident response with actionable sandbox reports for every IOC

🚨 Proactive threat blocking and containment that reduces attacker dwell time

For CISOs, this means turning global attack activity into an early-warning layer for your own security program.

Reduce risks from emerging threats for your company with TI Feeds → tap here and test the method today.

-----

#ad #paidpromotion #sponsored

@Cyber_Security_Channel
2💯1👀1
Four in Five Data Breach Cases go Unsolved as Cyberattacks Surge

Arrests have consistently lagged far behind incident counts.

The arrest rate stood at 20 percent (729 cases) in 2022, 28 percent (1,184 cases) in 2023, 21 percent (985 cases) in 2024 and 26 percent (1,265 cases) last year.

So far this year, only 544 arrests have been made out of 2,844 cases through June, pushing the arrest rate down to 19 percent — roughly one arrest for every five incidents.

Cyber_Security_Channel
5👍2💯1👀1
AI Data Giant Alation Confirms Cyberattack

Alation, an AI-powered data intelligence platform serving about 500 enterprises including roughly half of the Fortune 1000, confirmed a cyberattack this week.

The incident began as service degradation before the company acknowledged unauthorized access to an isolated AWS-hosted system.

Alation has not said whether data was stolen or detailed the attack's cause.

It says it is investigating and will share updates as they become available.

@Cyber_Security_Channel
👍1💯1