Microsoft researchers identified MacSync Stealer's evasion techniques and developed behavioral hunting pivots that revealed over 30 related domains despite the malware's rapid domain rotation strategy. By focusing on consistent behavioral patterns rather than static indicators, the security team was able to track the stealer's infrastructure even as it continuously changes its network presence.
A threat actor calling itself Ransom Busters is contacting ransomware victims via email, claiming to have compromised ransomware operators' servers and offering to delete stolen data for fees between $20,000 and $60,000. The group presents itself as a recovery service, though security researchers flagged this approach as highly suspicious and anomalous. This represents a novel extortion vector where attackers exploit victims' vulnerability following ransomware incidents.
Adversaries are increasingly generating realistic device names that blend seamlessly into enterprise environments, making traditional detection methods based on recognizable tooling fingerprints less effective. Wiz's analysis examines how this evasion technique impacts Entra ID detection capabilities and identifies behavioral signals that can still expose rogue device join attempts. Security teams need to shift focus from naming patterns to behavioral anomalies to catch these sophisticated attacks.
A Wiz AI agent identified a critical security flaw in Snowflake's GitHub Actions workflow that had previously gone undetected by GitHub Advanced Security scanning. The discovery highlights a potential gap in automated security tooling, where advanced vulnerability scanning failed to catch a vulnerability that required more sophisticated analysis to uncover.
CISA has issued a three-day deadline for federal agencies to patch an actively exploited remote code execution vulnerability in Ray. The vulnerability is being leveraged through phishing and malvertising campaigns targeting developers as an initial access vector to corporate networks.
Enterprise applications contain significantly more critical and high-severity vulnerabilities compared to other software types, according to research from Sonatype. The findings highlight a growing security gap as organizations accelerate their enterprise software development efforts while vulnerability exposure increases in this critical application segment.
Apple has released updates addressing 27 vulnerabilities across iOS, iPadOS, and macOS Tahoe, with a notable image-processing flaw among them that could potentially lead to code execution. The severity and attack vector details for this flaw remain unclear from the available information.
GitLab has released an emergency patch addressing a critical code-injection vulnerability that allows unauthenticated attackers to delete or modify publicly accessible projects. The flaw poses a significant risk to organizations using GitLab, as it can be exploited without requiring valid credentials to compromise project integrity and availability.
Meta's advertising platform ran promotions for an application designed to generate non-consensual intimate imagery of female politicians using deepfake technology. The app featured explicit content depicting a recognizable US politician, and was subsequently removed from Apple's App Store following media inquiry. The incident highlights gaps in platform oversight regarding ads for tools that facilitate image-based sexual abuse.
Check Point Research has identified a large-scale operation targeting thousands of WordPress sites using a ransomware family called StopAndProtect, which employs a ClickFix social-engineering technique to trick victims into executing malicious PowerShell commands. The attack chain involves multiple stages of downloaders, suggesting a sophisticated distribution infrastructure behind the campaign.
A Python-based malware framework called TwinLoot operates entirely within Microsoft's cloud infrastructure, leveraging living-off-the-land techniques to achieve exceptional stealth. The modular implant is designed to steal credentials and establish persistent access while remaining undetected in the cloud environment.
A ransomware affiliate is impersonating legitimate incident-recovery services to contact victims, exploiting trust during their most vulnerable moments. The tactic aims to intercept and divert ransom payments rather than provide genuine assistance, representing a novel social-engineering angle within the ransomware threat landscape.
Rapid7's Q2 2026 Quarterly Threat Landscape Report reveals that vulnerability disclosure volume has doubled year-over-year to 8,539 high- and critical-severity CVEs, while attackers increasingly leverage AI-assisted automation to exploit vulnerabilities faster than traditional patch cycles can address them. The report identifies that 62% of exploited vulnerabilities require no user interaction, with missing-authentication flaws surging 247% year-over-year, and highlights persistent nation-state activity from Iranian, North Korean, and Russian clusters alongside continued ransomware campaigns led by Qilin. Organizations can no longer rely on patching volume alone; success requires understanding which exposures are actually reachable and prioritizing risk reduction based on exploitability rather than severity scores.
Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding
Researchers have disclosed TWINLOOT, a modular Python implant framework that leverages trusted Microsoft services like SharePoint Online and Teams to establish command-and-control infrastructure while remaining difficult to detect. The PyArmor-hardened malware is designed to steal credentials and facilitate lateral movement across networks by operating within legitimate Microsoft cloud services. This approach allows attackers to blend malicious activity with normal enterprise traffic on trusted platforms.
CISA Malcolm, a network traffic analysis tool suite, contains multiple vulnerabilities across versions prior to 26.08.0 that could allow authenticated attackers to execute arbitrary code, bypass access controls, or cause denial-of-service conditions. The flaws span archive extraction without resource limits, path traversal in file handling, unsafe file uploads with inadequate type validation, RBAC bypasses via path normalization issues, and insufficient protections against compressed data bombs. Users should upgrade to the patched versions (26.06.1, 26.07.0, or 26.08.0 depending on the vulnerability) to mitigate exploitation risks.
A stack overflow vulnerability in Siemens Simcenter Nastran and Simcenter Femap versions prior to V2606 could allow remote code execution when a user is tricked into running an affected application binary with a malicious string argument. The vulnerability carries a CVSS score of 7.8 and affects critical infrastructure sectors including manufacturing, defense, energy, healthcare, and transportation systems worldwide. Siemens has released patched versions and recommends users update immediately.