An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them at their own game... All this and more in this episode of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White.
The White House has launched Gold Eagle, a coordinated initiative designed to enhance vulnerability management through artificial intelligence capabilities. The program aims to accelerate three critical phases of the vulnerability lifecycle: discovery of flaws, prioritization of remediation efforts, and deployment of patches.
A six-month phishing campaign has leveraged seasonal eCard messages as lures to trick users into installing legitimate remote management and monitoring (RMM) tools on their systems. By weaponizing trusted software rather than malware, attackers gained persistent access to victim environments while evading traditional detection methods. The campaign's longevity and targeting approach underscore the effectiveness of using seasonal social engineering combined with legitimate administrative tools for initial compromise.
Eleven Microsoft-signed UEFI shims that have been largely forgotten remain vulnerable to exploitation, enabling attackers to bypass Secure Boot protections on nearly any system. These legacy shims present a significant risk surface for machines relying on Secure Boot as a primary security boundary. The vulnerability highlights the importance of auditing and maintaining oversight of all signed bootloader components across systems.
Compromised login credentials have emerged as the primary attack vector for ransomware delivery, surpassing traditional software vulnerabilities according to recent incident analysis. The shift reflects adversaries' preference for identity-based threats including phishing and brute force attacks, which circumvent patching efforts by exploiting human and authentication weaknesses directly.
Progress has restored access to ShareFile Storage Zones Controller following a four-day service suspension that was implemented in response to a credible external security threat. The company's decision to temporarily disable access prioritized security over availability while the threat was addressed.
Microsoft released fixes for 570 CVEs in its July Patch Tuesday update, marking a record number of patches in a single release. Security experts attribute the dramatic increase in vulnerability discovery and patch volumes to AI-driven vulnerability detection, signaling a trend of accelerating patch demands for organizations.
Microsoft released updates addressing at least 570 security vulnerabilities across Windows and other software products, nearly tripling the number patched in the previous month's record-setting update. The company attributed the substantial increase in discovered flaws to artificial intelligence-assisted vulnerability research efforts.
Microsoft's July 2026 patch release is a record-breaking 621 CVEs—exceeding the year-to-date totals of any prior year—with 63 critical vulnerabilities including two actively exploited flaws in Active Directory Federation Services and SharePoint, plus multiple 9.8-9.9 CVSS issues in Windows VMSwitch, SharePoint RCE, and DHCP Server that demand immediate prioritization. Adobe released 88 CVEs across 12 bulletins with ColdFusion (CVSS 9.9) and Commerce as top priorities, though neither vendor's patches are currently under active exploit. The release spans an unusually broad attack surface from identity infrastructure and remote access services to filesystems and media frameworks, with notable clusters including 21 NTFS/ReFS RCEs, 95 total RCEs, and 260+ elevation-of-privilege bugs requiring urgent assessment and expedited patching schedules.
The US Department of Defense has announced an immediate suspension of Cybersecurity Maturity Model Certification Phase II requirements for defense contractors pending further review. This suspension pauses the implementation timeline for the elevated security maturity standards that were scheduled to take effect for the defense industrial base.
Bishop Fox has developed snowpick, a testing tool that identifies public data exposure in ServiceNow instances by examining both portal widgets and API endpoints, which can leak backend records despite appearing secure. In authorized testing across 166 ServiceNow instances, nearly one-third were found to be returning sensitive data through these public-facing mechanisms.
Researchers at Jamf Threat Labs have identified CrashStealer, a new macOS malware that leverages a legitimate developer ID to masquerade as Apple's crash reporter application. The malware is designed to steal sensitive data including passwords and cryptocurrency wallets from compromised systems. This attack demonstrates how threat actors can abuse trusted signing mechanisms to increase the credibility and effectiveness of their malicious campaigns.
ESET researchers have identified 11 vulnerable UEFI shim bootloaders that carry Microsoft signatures, enabling attackers to circumvent UEFI Secure Boot protections by exploiting security flaws dating back a decade. These forgotten shims represent a persistent attack surface that could allow adversaries to load malicious code during the boot process on affected systems. The findings highlight how legacy signed components can continue to pose security risks long after they've been superseded by newer versions.
A ransomware negotiation firm trusted by victim companies to handle communications with criminal gangs was simultaneously providing attackers with sensitive details about victims' cyber-insurance policies and negotiation strategies. This conflict of interest gave the criminal operators a significant advantage in extortion negotiations, allowing them to exploit inside knowledge of their targets' financial limits and defensive postures. The breach of trust highlights a critical vulnerability in the ransomware incident response supply chain where intermediaries have access to highly sensitive information on both sides of negotiations.
A misconfigured open directory has exposed operational details for three separate phishing operators leveraging Evilginx, a framework designed to bypass multi-factor authentication protections. The exposure of these threat actors' infrastructure and activities provides valuable intelligence on active MFA-evasion campaigns currently targeting organizations.
CISA has released a postmortem following a significant data leak where a contractor exposed dozens of internal credentials, including AWS Govcloud keys, in a public GitHub repository for nearly six months before KrebsOnSecurity alerted the agency. The incident revealed critical gaps in CISA's detection and response processes that security professionals should examine for applicability to their own organizations. The agency's analysis offers practical lessons on credential management, secret scanning, and incident response timelines that extend beyond government infrastructure.