Government Agencies Falling Victim to Ransomware Daily, Warns Study
Government organizations are targeted by attackers who know agencies cannot afford disruption to public services
23andMe Faces New Security Mandates in $18m Data Breach Settlement
23andMe has agreed to an $18 million settlement with 42 US state attorneys general stemming from its 2023 data breach. The settlement includes mandatory enhancements to the company's data protection practices going forward. This action represents coordinated enforcement by state-level regulators against the genetic testing company for the security incident.
Using MCP Agents for Penetration Testing
AI-powered MCP agents are accelerating penetration testing workflows by automating reconnaissance and vulnerability discovery across external, application, and cloud environments. In a real-world deployment, Bishop Fox leveraged this approach to uncover two information leaks comprising over 12 million records in a fraction of the traditional timeframe, demonstrating significant efficiency gains over conventional testing methodologies.
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
Unit 42 has published a technical analysis documenting three chained zero-day vulnerabilities affecting Siemens ROX II OT switches that can be exploited to achieve privilege escalation and maintain persistent root access. The vulnerability chain demonstrates a complete attack path through these industrial network devices, highlighting a significant threat to operational technology infrastructure.
CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities
CISA has mandated that US government agencies patch two critical Fortinet vulnerabilities by July 19 due to active exploitation in the wild. The urgent directive underscores the severity of these flaws and the immediate threat they pose to federal infrastructure.
The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat
Analysis of ransomware incidents by ReliaQuest indicates a shift in the ransomware landscape
Anubis ransomware: what you need to know
The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.
Phishing Campaign Hides Lua Loader as TrueType Font File
A widespread phishing campaign is using TrueType font files as a disguise to deliver a Lua-based loader, which subsequently deploys remote access trojans and information-stealing malware to compromised systems. This obfuscation technique leverages file type spoofing to evade detection while establishing a foothold for follow-on malicious payloads across multiple targets globally.
Modular macOS Stealer Uses Kill Loops to Force Password Entry
A new modular macOS stealer called ClickLock employs kill loops to lock victims out of their systems and coerce password entry. The malware forces users to surrender credentials by repeatedly terminating processes until they comply with the attacker's demands.
Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers Claim
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackers
"Selfish Bravado" Behind TfL Cyber-Attack, Judge Says as Pair Jailed
Two individuals responsible for the 2024 cyber-attack against Transport for London have been sentenced to five and a half years in prison after pleading guilty to Computer Misuse Act violations. According to the judge, the attackers were motivated by what was characterized as selfish bravado rather than ideological or financial objectives.
SANS Warns of AI Governance Gap as Use by Security Teams Surges
SANS Institute says governance programs are still nascent even as AI failures and threats grow
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them at their own game... All this and more in this episode of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White.
US Launches Gold Eagle to Coordinate AI-Driven Vulnerability Management
The White House has launched Gold Eagle, a coordinated initiative designed to enhance vulnerability management through artificial intelligence capabilities. The program aims to accelerate three critical phases of the vulnerability lifecycle: discovery of flaws, prioritization of remediation efforts, and deployment of patches.
Phishing Campaign Abuses eCards to Deploy RMM Tools
A six-month phishing campaign has leveraged seasonal eCard messages as lures to trick users into installing legitimate remote management and monitoring (RMM) tools on their systems. By weaponizing trusted software rather than malware, attackers gained persistent access to victim environments while evading traditional detection methods. The campaign's longevity and targeting approach underscore the effectiveness of using seasonal social engineering combined with legitimate administrative tools for initial compromise.
Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass
Eleven Microsoft-signed UEFI shims that have been largely forgotten remain vulnerable to exploitation, enabling attackers to bypass Secure Boot protections on nearly any system. These legacy shims present a significant risk surface for machines relying on Secure Boot as a primary security boundary. The vulnerability highlights the importance of auditing and maintaining oversight of all signed bootloader components across systems.
Compromised Logins Surge as the Most Common Entry Point for Ransomware Attacks
Compromised login credentials have emerged as the primary attack vector for ransomware delivery, surpassing traditional software vulnerabilities according to recent incident analysis. The shift reflects adversaries' preference for identity-based threats including phishing and brute force attacks, which circumvent patching efforts by exploiting human and authentication weaknesses directly.
Progress Restores ShareFile Storage Zones Access After Security Warning
Progress has restored access to ShareFile Storage Zones Controller following a four-day service suspension that was implemented in response to a credible external security threat. The company's decision to temporarily disable access prioritized security over availability while the threat was addressed.
Microsoft Patches 570 CVEs in Record Patch Tuesday
Microsoft released fixes for 570 CVEs in its July Patch Tuesday update, marking a record number of patches in a single release. Security experts attribute the dramatic increase in vulnerability discovery and patch volumes to AI-driven vulnerability detection, signaling a trend of accelerating patch demands for organizations.