VulnerabilityKrebs on Security·1 month ago

Microsoft Patches a Record 570 Security Flaws

Microsoft released updates addressing at least 570 security vulnerabilities across Windows and other software products, nearly tripling the number patched in the previous month's record-setting update. The company attributed the substantial increase in discovered flaws to artificial intelligence-assisted vulnerability research efforts.

VulnerabilityZero Day Initiative·1 month ago

The July 2026 Security Update Review

Microsoft's July 2026 patch release is a record-breaking 621 CVEs—exceeding the year-to-date totals of any prior year—with 63 critical vulnerabilities including two actively exploited flaws in Active Directory Federation Services and SharePoint, plus multiple 9.8-9.9 CVSS issues in Windows VMSwitch, SharePoint RCE, and DHCP Server that demand immediate prioritization. Adobe released 88 CVEs across 12 bulletins with ColdFusion (CVSS 9.9) and Commerce as top priorities, though neither vendor's patches are currently under active exploit. The release spans an unusually broad attack surface from identity infrastructure and remote access services to filesystems and media frameworks, with notable clusters including 21 NTFS/ReFS RCEs, 95 total RCEs, and 260+ elevation-of-privilege bugs requiring urgent assessment and expedited patching schedules.

Policy & LegalInfosecurity Magazine·1 month ago

US: Pentagon Suspends CMMC Phase II Requirements for Defense Contractors

The US Department of Defense has announced an immediate suspension of Cybersecurity Maturity Model Certification Phase II requirements for defense contractors pending further review. This suspension pauses the implementation timeline for the elevated security maturity standards that were scheduled to take effect for the defense industrial base.

VulnerabilityBishop Fox·1 month ago

Introducing snowpick: Testing ServiceNow for Public Data Exposure

Bishop Fox has developed snowpick, a testing tool that identifies public data exposure in ServiceNow instances by examining both portal widgets and API endpoints, which can leak backend records despite appearing secure. In authorized testing across 166 ServiceNow instances, nearly one-third were found to be returning sensitive data through these public-facing mechanisms.

MalwareInfosecurity Magazine·1 month ago

New MacOS Malware Exploits Legitimate Developer ID to Pose as Apple Crash Reporter

Researchers at Jamf Threat Labs have identified CrashStealer, a new macOS malware that leverages a legitimate developer ID to masquerade as Apple's crash reporter application. The malware is designed to steal sensitive data including passwords and cryptocurrency wallets from compromised systems. This attack demonstrates how threat actors can abuse trusted signing mechanisms to increase the credibility and effectiveness of their malicious campaigns.

VulnerabilityWeLiveSecurity·1 month ago

Forgotten UEFI shims undermining Secure Boot

ESET researchers have identified 11 vulnerable UEFI shim bootloaders that carry Microsoft signatures, enabling attackers to circumvent UEFI Secure Boot protections by exploiting security flaws dating back a decade. These forgotten shims represent a persistent attack surface that could allow adversaries to load malicious code during the boot process on affected systems. The findings highlight how legacy signed components can continue to pose security risks long after they've been superseded by newer versions.

RansomwareGraham Cluley·1 month ago

The ransomware negotiator who was working for the other side

A ransomware negotiation firm trusted by victim companies to handle communications with criminal gangs was simultaneously providing attackers with sensitive details about victims' cyber-insurance policies and negotiation strategies. This conflict of interest gave the criminal operators a significant advantage in extortion negotiations, allowing them to exploit inside knowledge of their targets' financial limits and defensive postures. The breach of trust highlights a critical vulnerability in the ransomware incident response supply chain where intermediaries have access to highly sensitive information on both sides of negotiations.

PhishingInfosecurity Magazine·1 month ago

Open Directory Exposes Three Evilginx Phishing Operators

A misconfigured open directory has exposed operational details for three separate phishing operators leveraging Evilginx, a framework designed to bypass multi-factor authentication protections. The exposure of these threat actors' infrastructure and activities provides valuable intelligence on active MFA-evasion campaigns currently targeting organizations.

Data BreachKrebs on Security·1 month ago

Lessons Learned from CISA’s Recent GitHub Leak

CISA has released a postmortem following a significant data leak where a contractor exposed dozens of internal credentials, including AWS Govcloud keys, in a public GitHub repository for nearly six months before KrebsOnSecurity alerted the agency. The incident revealed critical gaps in CISA's detection and response processes that security professionals should examine for applicability to their own organizations. The agency's analysis offers practical lessons on credential management, secret scanning, and incident response timelines that extend beyond government infrastructure.

VulnerabilityInfosecurity Magazine·1 month ago

Novel OAuth Client ID Spoofing Technique Targets Cloud Environments

Researchers have identified a novel OAuth Client ID spoofing technique that allows attackers to spoof OAuth Client IDs within Microsoft Entra ID to gain unauthorized access to cloud environments. This attack method provides adversaries with a stealthy mechanism for infiltrating cloud infrastructure, representing a significant threat to organizations relying on Entra ID for authentication and authorization.

VulnerabilityInfosecurity Magazine·1 month ago

Progress Software Warns of "External Security Threat" to ShareFile

Progress Software has warned customers of an external security threat affecting ShareFile and is instructing them to shut down servers hosting the Storage Zone Controller component. The advisory indicates a potential compromise to the widely-used file-sharing and data storage platform, though specific attack details and remediation steps beyond the shutdown directive were not disclosed.

VulnerabilityTrail of Bits·1 month ago

Rust-proof your code with our new Testing Handbook chapter

Trail of Bits has released a comprehensive Testing Handbook chapter on security testing for Rust programs, covering dynamic analysis tools (Miri, proptest, coverage measurement), static analysis with Clippy, memory zeroization techniques, and specialized testing approaches like model checking with Kani. The chapter also documents common Rust security gotchas discovered during real audits and introduces rust-review, a Claude Code plugin for automated Rust security reviews that targets over a dozen vulnerability classes including memory safety, concurrency hazards, and FFI issues.

Nation-StateInfosecurity Magazine·1 month ago

Russian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory Warns

Cybersecurity agencies from 12 countries have issued a joint advisory warning that Russian state-backed hackers are actively exploiting vulnerable routers worldwide, leveraging weak SNMP credentials to gain access. The coordinated alert highlights a widespread campaign targeting infrastructure that often receives lower security attention than other network assets.

VulnerabilityInfosecurity Magazine·1 month ago

Australian Cyber Agency Warns of Global CMS Exploitation Campaign

The Australian Cyber Security Centre has issued a warning about widespread scanning and exploitation activity targeting content management systems globally. The campaign appears to involve mass reconnaissance efforts aimed at identifying and compromising vulnerable CMS installations across multiple organizations.

OtherGreyNoise Labs·1 month ago

Now Available: The Threat Brief Library in the GreyNoise Platform

GreyNoise has launched a Threat Brief Library within its Visualizer platform, enabling users to access and manage curated threat intelligence reports including weekly At The Edge briefs and Executive Situation Reports. The library allows security teams to browse, search, filter, and download these briefs, which are generated from GreyNoise's primary-source sensor data for threat analysis and situational awareness.

Load more