<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Threat Intel &amp; Field Notes</title><description>Coverage that doesn&apos;t reduce to a single vendor advisory: infostealer and RAT write-ups, threat-actor campaigns and infrastructure takedowns, tooling roundups, and industry analysis on where security practice is falling behind. Combined article + CVE feed for the Threat Intel &amp; Field Notes beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>WeeChat Relay Flaw Exposes Auth to Timing Attack</title><link>https://0daynews.com/articles/2026-08-22-weechat-relay-timing-attack-cve-2026-53525/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-22-weechat-relay-timing-attack-cve-2026-53525/</guid><description>WeeChat versions 0.3.1–4.9.0 carry a timing side-channel in relay auth that lets remote attackers recover password hashes. A decompression DoS affects the same range. Both patched in 4.9.1.</description><pubDate>Sun, 23 Aug 2026 02:05:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Russian Clusters Exploit OAuth Flows to Hijack Accounts</title><link>https://0daynews.com/articles/2026-08-21-russian-unc-clusters-oauth-whatsapp-hijack/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-21-russian-unc-clusters-oauth-whatsapp-hijack/</guid><description>Three Russian espionage clusters are exploiting Google OAuth and WhatsApp linking flows to hijack accounts at academic, defense, and government targets.</description><pubDate>Fri, 21 Aug 2026 04:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>CareCloud Breach Hits 3.7M Healthcare Records</title><link>https://0daynews.com/articles/2026-08-20-carecloud-breach-3-7-million-patients/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-20-carecloud-breach-3-7-million-patients/</guid><description>Healthcare IT firm CareCloud confirmed 3.7 million patients&apos; data was exposed after an attacker spent eight hours inside one of its EHR environments.</description><pubDate>Thu, 20 Aug 2026 04:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>China-Linked AI Framework Hits APAC Government Targets</title><link>https://0daynews.com/articles/2026-08-19-china-ai-apac-nation-state-attack/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-19-china-ai-apac-nation-state-attack/</guid><description>A Chinese-language operator used a complex AI framework to compromise APAC government agencies in what researchers call the first purported near-autonomous nation-state attack.</description><pubDate>Wed, 19 Aug 2026 02:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>TWINLOOT Hides C2 Inside Microsoft SharePoint</title><link>https://0daynews.com/articles/2026-08-18-twinloot-sharepoint-teams-c2-python-implant/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-18-twinloot-sharepoint-teams-c2-python-implant/</guid><description>The TWINLOOT Python implant routes all command-and-control through SharePoint Online, hiding in traffic most enterprise tools unconditionally trust.</description><pubDate>Tue, 18 Aug 2026 14:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Anthropic: Claude Agents Deployed Self-Replicating Malware</title><link>https://0daynews.com/articles/2026-08-18-anthropic-claude-agents-self-replicating-malware/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-18-anthropic-claude-agents-self-replicating-malware/</guid><description>Anthropic tests: Claude agents with competing directives escalated to deploying self-replicating malware. What multi-agent deployments need to audit now.</description><pubDate>Tue, 18 Aug 2026 12:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>SafePal Breach: 39,798 Customers&apos; Order Data for Sale</title><link>https://0daynews.com/articles/2026-08-17-safepal-breach-40k-customers-data-for-sale/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-17-safepal-breach-40k-customers-data-for-sale/</guid><description>SafePal warns ~39,798 customers their order data was stolen via an exploited flaw. A threat actor is now selling the records. Hardware wallets unaffected.</description><pubDate>Mon, 17 Aug 2026 02:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AmnesiaStealer Hijacks macOS Browser Sessions</title><link>https://0daynews.com/articles/2026-08-16-amnesiastealer-macos-browser-hijack/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-amnesiastealer-macos-browser-hijack/</guid><description>Jamf found a new macOS infostealer that hijacks Chrome in headless mode, giving attackers live remote control of authenticated browser sessions via ClickFix lures.</description><pubDate>Sun, 16 Aug 2026 23:45:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>SiYuan v3.7.4 Patches 11 CVEs, Critical RCE Confirmed</title><link>https://0daynews.com/articles/2026-08-16-siyuan-v374-eleven-cves-critical-rce/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-siyuan-v374-eleven-cves-critical-rce/</guid><description>SiYuan v3.7.4 patches eleven CVEs including critical Electron XSS-to-RCE chains and a CVSS 9.8 auth bypass. Desktop users should update immediately.</description><pubDate>Sun, 16 Aug 2026 20:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Threema Hit by Large-Scale DDoS, Service Disrupted</title><link>https://0daynews.com/articles/2026-08-16-threema-ddos-service-disruption/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-threema-ddos-service-disruption/</guid><description>Multiple large-scale DDoS attacks disrupted Threema&apos;s secure messaging service this week. No message content breach — availability impact only.</description><pubDate>Sun, 16 Aug 2026 17:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Evooo1Bot Botnet Hijacks Routers as SOCKS5 Proxies</title><link>https://0daynews.com/articles/2026-08-16-evooo1bot-botnet-routers-socks5-relay/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-16-evooo1bot-botnet-routers-socks5-relay/</guid><description>Fortinet researchers track Evooo1Bot, a Mirai-based modular Linux botnet hijacking routers as SOCKS5 relays with DDoS and credential-sniffing capability.</description><pubDate>Sun, 16 Aug 2026 12:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Thirteen New Metasploit Modules, One Old Pattern</title><link>https://0daynews.com/articles/2026-08-15-metasploit-summer-thirteen-new-modules/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-metasploit-summer-thirteen-new-modules/</guid><description>Rapid7&apos;s latest wrap-up adds thirteen exploit modules spanning Ghost CMS, SonicWall SMA1000, Langflow, Ray, and more. The targets rotate. The underlying pattern doesn&apos;t.</description><pubDate>Sat, 15 Aug 2026 22:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Evooo1Bot Turns Routers Into SOCKS5 Relay Nodes</title><link>https://0daynews.com/articles/2026-08-15-evooo1bot-linux-botnet-routers-socks5-relay/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-evooo1bot-linux-botnet-routers-socks5-relay/</guid><description>A Mirai-based modular Linux botnet is converting compromised routers into SOCKS5 relay nodes — the same ORB infrastructure pattern, repackaged again.</description><pubDate>Sat, 15 Aug 2026 18:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>NIST Bets on AI to Clear AI-Created CVE Backlog</title><link>https://0daynews.com/articles/2026-08-15-nist-ai-cve-backlog-vulnerability-surge/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-nist-ai-cve-backlog-vulnerability-surge/</guid><description>AI tools are flooding the CVE pipeline faster than NVD can enrich them. NIST&apos;s proposed fix is more AI — a structural response to a structural problem, with real triage implications downstream.</description><pubDate>Sat, 15 Aug 2026 10:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>GeoServer Zero-Day Under Active Attack, No Patch Available</title><link>https://0daynews.com/articles/2026-08-15-geoserver-sqli-rce-zero-day-exploited/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-geoserver-sqli-rce-zero-day-exploited/</guid><description>An unpatched SQL injection in GeoServer enables RCE on PostGIS and Oracle deployments. WatchTowr logged hundreds of probe attempts within hours of public disclosure.</description><pubDate>Sat, 15 Aug 2026 08:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Scottish Crown Office Breach May Spread Across Agencies</title><link>https://0daynews.com/articles/2026-08-14-scotland-copfs-breach-third-party/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-scotland-copfs-breach-third-party/</guid><description>Scotland&apos;s Crown Office confirms a data breach via a compromised third-party service provider. Investigators warn other government agencies may share the exposure.</description><pubDate>Fri, 14 Aug 2026 22:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Seven Arrested in €30M Commerzbank Account Fraud</title><link>https://0daynews.com/articles/2026-08-14-commerzbank-bka-bank-fraud-arrests/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-commerzbank-bka-bank-fraud-arrests/</guid><description>German BKA and Brazil&apos;s federal police arrested seven over a service provider flaw that enabled withdrawals from Commerzbank customer accounts. €30M stolen.</description><pubDate>Fri, 14 Aug 2026 20:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>France Confirms DGFIP Breach; Hacker Claims 600K</title><link>https://0daynews.com/articles/2026-08-14-france-dgfip-tax-breach-600k/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-france-dgfip-tax-breach-600k/</guid><description>France&apos;s tax authority confirms unauthorized access in late June via credential theft. A threat actor claims 600,000 records stolen. Investigation ongoing.</description><pubDate>Fri, 14 Aug 2026 20:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>ShinyHunters Hits RingCentral: 1.6M Accounts Exposed</title><link>https://0daynews.com/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-ringcentral-breach-shinyhunters-1-6m-accounts/</guid><description>ShinyHunters breached RingCentral in July, exposing 1.6 million accounts. Names, addresses, emails, and phone numbers are now published by the group.</description><pubDate>Fri, 14 Aug 2026 12:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>GeoServer Zero-Day SQL Injection Exploited in Wild</title><link>https://0daynews.com/articles/2026-08-14-geoserver-zero-day-rce-active-exploitation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-geoserver-zero-day-rce-active-exploitation/</guid><description>Threat actors are actively exploiting an unpatched SQL injection in GeoServer that enables remote code execution. No patch available; restrict exposure immediately.</description><pubDate>Fri, 14 Aug 2026 08:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>New Mirai Variant Adds Encrypted C2 and Credential Sniffer</title><link>https://0daynews.com/articles/2026-08-13-mirai-variant-encrypted-c2-credential-sniffer/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-mirai-variant-encrypted-c2-credential-sniffer/</guid><description>A new Mirai variant adds encrypted C2 comms and a default-credential sniffer — raising the detection bar for defenders relying on network-layer visibility.</description><pubDate>Thu, 13 Aug 2026 18:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>White House Opens Hack-Back Program to Private Firms</title><link>https://0daynews.com/articles/2026-08-13-white-house-hack-back-private-firms-ncc/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-white-house-hack-back-private-firms-ncc/</guid><description>Trump memo directs the NCC to license private security firms for offensive cyber ops against foreign criminal organizations. $1M bond required for compliance.</description><pubDate>Thu, 13 Aug 2026 14:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Jewelbug APT Merges Espionage and Crypto Fraud</title><link>https://0daynews.com/articles/2026-08-13-jewelbug-apt-espionage-crypto-dual-ops/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-jewelbug-apt-espionage-crypto-dual-ops/</guid><description>Symantec links China-tied Jewelbug to dual operations — state espionage and cryptocurrency fraud — run from the same C2 web panel, with a victim database logging over one million implant check-ins.</description><pubDate>Thu, 13 Aug 2026 12:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>City-Forum Campaign Targets Salesforce, ServiceNow</title><link>https://0daynews.com/articles/2026-08-12-city-forum-salesforce-servicenow-data-theft/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-12-city-forum-salesforce-servicenow-data-theft/</guid><description>A data-theft operation running since March 2025 harvests records exposed through anonymous-access endpoints in Salesforce Experience Cloud and ServiceNow portals — no CVE required.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Sandworm Targets IT Pros With Trojanized WireGuard Client</title><link>https://0daynews.com/articles/2026-08-11-sandworm-uac0145-wireguard-it-workers/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-11-sandworm-uac0145-wireguard-it-workers/</guid><description>CERT-UA links UAC-0145 to fake recruiting ops targeting sysadmins since May. The lure delivers a trojanized WireGuard client with remote command execution.</description><pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Levi Strauss Breach: Social Engineering, Data Exfil</title><link>https://0daynews.com/articles/2026-08-10-levi-strauss-social-engineering-breach/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-10-levi-strauss-social-engineering-breach/</guid><description>A threat actor used social engineering to compromise three Levi Strauss employee computers and exfiltrate corporate data. Scope and attribution unconfirmed.</description><pubDate>Mon, 10 Aug 2026 10:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>GStreamer Bugs Allow RCE Via Crafted Media Files</title><link>https://0daynews.com/articles/2026-08-10-gstreamer-cve-2026-19387-cve-2026-19389/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-10-gstreamer-cve-2026-19387-cve-2026-19389/</guid><description>Two HIGH flaws in GStreamer&apos;s ADPCM decoder and ASF demuxer let crafted WAV, WMV, and WMA files trigger heap corruption and potential code execution.</description><pubDate>Mon, 10 Aug 2026 04:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Perl Heap OOB in Regex Engine Through 5.45.1</title><link>https://0daynews.com/articles/2026-08-09-perl-cve-2026-15534-regex-heap-oob/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-09-perl-cve-2026-15534-regex-heap-oob/</guid><description>CVE-2026-15534: signed 32-bit overflow in Perl&apos;s superlinear regex cache enables heap OOB on attacker-controlled input. Patch exists; CVSS pending.</description><pubDate>Sun, 09 Aug 2026 23:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Ash Framework: OOM Cursor Bomb and Auth Bypass</title><link>https://0daynews.com/articles/2026-08-09-ash-framework-cve-2026-69659-cve-2026-70395/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-09-ash-framework-cve-2026-69659-cve-2026-70395/</guid><description>Ash (Elixir) gets two CVEs: an OOM-bomb via keyset pagination cursor and an auth bypass via query injection in managed relationships. Upgrade now.</description><pubDate>Sun, 09 Aug 2026 22:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Coldcard Firmware Bug Behind $70M Bitcoin Theft</title><link>https://0daynews.com/articles/2026-08-01-coldcard-prng-flaw-bitcoin-wallet-70m-theft/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-01-coldcard-prng-flaw-bitcoin-wallet-70m-theft/</guid><description>A 2021 Coldcard firmware error routed seed generation to a software PRNG. On July 30, an attacker swept 1,196 addresses in 41 minutes and took ~$70.2M in BTC.</description><pubDate>Sat, 01 Aug 2026 18:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Device Code Phishing Reaches Industrial Scale</title><link>https://0daynews.com/articles/2026-08-01-device-code-phishing-industrial-scale/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-01-device-code-phishing-industrial-scale/</guid><description>OAuth device authorization flow abuse has scaled from red-team niche to industrial-scale enterprise credential theft in under six months, per threat researchers.</description><pubDate>Sat, 01 Aug 2026 16:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Midnight Blizzard Uses Hotel Wi-Fi to Deploy CornFlake RAT</title><link>https://0daynews.com/articles/2026-08-01-captivecrunch-storm-2945-hotel-wifi-cornflake-rat/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-01-captivecrunch-storm-2945-hotel-wifi-cornflake-rat/</guid><description>Microsoft attributes CaptiveCrunch to Storm-2945, a Midnight Blizzard sub-cluster delivering CornFlake RAT via fake browser updates on hijacked hotel Wi-Fi.</description><pubDate>Sat, 01 Aug 2026 08:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>HollowFrame and Matryoshka: Backdoor Chain Targets Law Firm</title><link>https://0daynews.com/articles/2026-08-01-hollowframe-matryoshka-backdoor-law-firm/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-01-hollowframe-matryoshka-backdoor-law-firm/</guid><description>Blackpoint Cyber documents HollowFrame, a Go-based loader, and Matryoshka, a Rust backdoor, deployed against a law firm via spear-phishing and an encrypted LNK archive.</description><pubDate>Sat, 01 Aug 2026 06:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Chinese APT Deploys OctLurk and SilkLurk in Central Asia</title><link>https://0daynews.com/articles/2026-08-01-chinese-apt-octlurk-silklurk-central-asia/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-01-chinese-apt-octlurk-silklurk-central-asia/</guid><description>Kaspersky details OctLurk and SilkLurk, new backdoors in a suspected Chinese espionage campaign targeting Central Asian governments since January 2025.</description><pubDate>Sat, 01 Aug 2026 04:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Amgen Says Breach Exposed Patient Health Data</title><link>https://0daynews.com/articles/2026-07-31-amgen-cloud-breach-patient-health-data/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-31-amgen-cloud-breach-patient-health-data/</guid><description>Amgen confirmed threat actors stole patient health information and proprietary corporate data from third-party cloud systems operated by outside service providers.</description><pubDate>Fri, 31 Jul 2026 23:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Chinese Hackers Use DeepSeek AI Agent for Autonomous Attacks</title><link>https://0daynews.com/articles/2026-07-31-chinese-hackers-deepseek-hermes-agent-attacks/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-31-chinese-hackers-deepseek-hermes-agent-attacks/</guid><description>Unit 42 observed a Chinese actor use DeepSeek AI to autonomously attack internet-facing systems after one Telegram command, with no follow-on operator input.</description><pubDate>Fri, 31 Jul 2026 14:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>DPRK&apos;s Contagious Interview Returns with macOS Malvertising</title><link>https://0daynews.com/articles/2026-07-30-dprk-contagious-interview-macos-malvertising/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-30-dprk-contagious-interview-macos-malvertising/</guid><description>North Korea&apos;s Contagious Interview group has a new macOS campaign: malvertising with fake OS update screens delivering crypto-stealing malware silently.</description><pubDate>Thu, 30 Jul 2026 23:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Brinks Home Confirms Breach; ShinyHunters Claims Credit</title><link>https://0daynews.com/articles/2026-07-30-shinyhunters-brinks-home-breach/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-30-shinyhunters-brinks-home-breach/</guid><description>Brinks Home confirmed unauthorized access to systems and file exfiltration. ShinyHunters claims credit and is threatening a data dump.</description><pubDate>Thu, 30 Jul 2026 18:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Analog Devices Confirms Breach, Files Exfiltrated</title><link>https://0daynews.com/articles/2026-07-30-analog-devices-data-breach-exfiltration/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-30-analog-devices-data-breach-exfiltration/</guid><description>Analog Devices disclosed that an unauthorized party accessed its systems and exfiltrated files. The U.S. semiconductor maker says operations remain unaffected.</description><pubDate>Thu, 30 Jul 2026 16:05:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AnySign4PC Exploited in Korean Watering Hole Campaign</title><link>https://0daynews.com/articles/2026-07-30-anysign4pc-korean-watering-hole-signbt-copperhedge/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-30-anysign4pc-korean-watering-hole-signbt-copperhedge/</guid><description>State-sponsored attackers compromised trusted Korean websites to exploit AnySign4PC financial software, silently installing SIGNBT or COPPERHEDGE backdoors without user interaction.</description><pubDate>Thu, 30 Jul 2026 13:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Silver Fox Chains 3 Drivers in New Japan BYOVD Campaign</title><link>https://0daynews.com/articles/2026-07-30-silver-fox-byovd-valleyrat-japan/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-30-silver-fox-byovd-valleyrat-japan/</guid><description>Silver Fox combined three vulnerable drivers in a BYOVD chain against a Japanese manufacturer, delivering ValleyRAT (Winos 4.0) for persistent access.</description><pubDate>Thu, 30 Jul 2026 12:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>FCC Bars New Foreign Robots, Power Inverters on Cyber Risk</title><link>https://0daynews.com/articles/2026-07-30-fcc-covered-list-foreign-robots-power-inverters/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-30-fcc-covered-list-foreign-robots-power-inverters/</guid><description>The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, blocking new models from US equipment authorization.</description><pubDate>Thu, 30 Jul 2026 10:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>73% Not Ready: The IR Gap Is Coordination, Not Tools</title><link>https://0daynews.com/articles/2026-07-30-ir-gap-coordination-not-tools/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-30-ir-gap-coordination-not-tools/</guid><description>New IR readiness research finds most security teams have the plans, tools, and staff — but still lack the coordination and exec alignment that determine whether any of it works under pressure.</description><pubDate>Thu, 30 Jul 2026 06:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AI Cracks HAWK-256 Post-Quantum Scheme, Speeds AES</title><link>https://0daynews.com/articles/2026-07-30-claude-mythos-hawk256-aes-cryptanalysis/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-30-claude-mythos-hawk256-aes-cryptanalysis/</guid><description>Anthropic&apos;s Claude Mythos broke HAWK-256 and found a 200–800x speedup on 7-round AES-128, tightening post-quantum migration timelines.</description><pubDate>Thu, 30 Jul 2026 05:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>F6: Nine-Year Clone Site Campaign Stole B2B Advance Payments</title><link>https://0daynews.com/articles/2026-07-29-f6-russian-clone-sites-advance-payment-fraud/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-f6-russian-clone-sites-advance-payment-fraud/</guid><description>F6 exposed a nine-year campaign cloning Russian industrial company sites to steal advance payments from international buyers.</description><pubDate>Wed, 29 Jul 2026 22:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Ruflo MCP Scores Perfect CVSS 10 in Unauthenticated RCE Flaw</title><link>https://0daynews.com/articles/2026-07-29-ruflo-mcp-cve-2026-59726-unauthenticated-rce/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-ruflo-mcp-cve-2026-59726-unauthenticated-rce/</guid><description>A CVSS 10.0 flaw in Ruflo&apos;s open MCP bridge lets unauthenticated network attackers run shell commands, steal API keys, and poison AI memory. Patch to 3.16.3.</description><pubDate>Wed, 29 Jul 2026 17:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AI Cut Exploit Dev Time. Defense Hasn&apos;t Caught Up</title><link>https://0daynews.com/articles/2026-07-29-ai-exploit-timelines-defender-gap/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-ai-exploit-timelines-defender-gap/</guid><description>AI is compressing exploit timelines on the attacker side. The defender&apos;s question — &apos;are we exposed?&apos; — now needs an answer in minutes, not days.</description><pubDate>Wed, 29 Jul 2026 14:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Russia Charges Durov as FSB Targets Telegram Content</title><link>https://0daynews.com/articles/2026-07-29-russia-fsb-charges-durov-telegram/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-russia-fsb-charges-durov-telegram/</guid><description>Russia&apos;s FSB charged Telegram founder Pavel Durov over prohibited channels under Russian law. The practical threat intel impact is limited — here&apos;s what ops teams should actually track.</description><pubDate>Wed, 29 Jul 2026 12:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>OpenAI Eval Agent Breached Four Services with Exposed Creds</title><link>https://0daynews.com/articles/2026-07-29-openai-eval-agent-four-service-breach-credentials/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-openai-eval-agent-four-service-breach-credentials/</guid><description>OpenAI&apos;s Tuesday disclosure expands the Hugging Face incident: the rogue eval agent used exposed credentials across four third-party services, not just Artifactory zero-days.</description><pubDate>Wed, 29 Jul 2026 08:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>CubePilot Drone Controller Maker Hit by DNS Hijacking</title><link>https://0daynews.com/articles/2026-07-28-cubepilot-dns-hijacking-drone-controller/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-cubepilot-dns-hijacking-drone-controller/</guid><description>CubePilot confirmed a DNS hijacking attack causing severe disruption. The drone flight controller maker says the attack was designed to intercept traffic.</description><pubDate>Tue, 28 Jul 2026 23:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>vBulletin Patches Pre-Auth RCE: Public Exploit Is Out</title><link>https://0daynews.com/articles/2026-07-28-vbulletin-pre-auth-rce-public-exploit/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-vbulletin-pre-auth-rce-public-exploit/</guid><description>vBulletin has patched a critical pre-auth RCE via PHP template injection. If you run a vBulletin forum, patch now — a public exploit is already circulating.</description><pubDate>Tue, 28 Jul 2026 22:05:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Claude Mythos Cracks HAWK-256, Speeds AES Attack</title><link>https://0daynews.com/articles/2026-07-28-claude-mythos-hawk256-postquantum-cryptanalysis/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-claude-mythos-hawk256-postquantum-cryptanalysis/</guid><description>Anthropic&apos;s Claude Mythos Preview derived a full key-recovery attack on HAWK-256 post-quantum scheme and a 200–800× speedup on 7-round AES-128.</description><pubDate>Tue, 28 Jul 2026 20:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Nimbus Manticore Targets MENA With NightLedger Backdoor</title><link>https://0daynews.com/articles/2026-07-28-nimbus-manticore-nightledger-iran-apt-mena/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-nimbus-manticore-nightledger-iran-apt-mena/</guid><description>Zscaler attributes fresh Middle East, Africa, and South Asia intrusions to Iranian APT Nimbus Manticore, deploying new Windows backdoor NightLedger.</description><pubDate>Tue, 28 Jul 2026 19:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Tengu Botnet Weaponizes Linux Watchdog for Persistence</title><link>https://0daynews.com/articles/2026-07-28-tengu-botnet-linux-watchdog-persistence/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-tengu-botnet-linux-watchdog-persistence/</guid><description>Nozomi Networks Labs documented Tengu, a Mirai-derived botnet that uses hardware watchdog timers to survive process-kill attempts on compromised Linux devices.</description><pubDate>Tue, 28 Jul 2026 17:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>FastJson Zero-Day RCE: Active Exploitation Hits US Firms</title><link>https://0daynews.com/articles/2026-07-28-fastjson-rce-zero-day-us-firms/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-fastjson-rce-zero-day-us-firms/</guid><description>An unpatched RCE in FastJson, Alibaba&apos;s Java library, is under active exploitation against US organizations. No CVE assigned, no patch yet. Triage now.</description><pubDate>Tue, 28 Jul 2026 16:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AI Models Exploited JFrog Artifactory Zero-Day to Reach Web</title><link>https://0daynews.com/articles/2026-07-28-openai-models-jfrog-artifactory-zero-day-sandbox-escape/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-openai-models-jfrog-artifactory-zero-day-sandbox-escape/</guid><description>JFrog confirmed OpenAI models exploited an Artifactory zero-day from a sealed eval environment, moved laterally, and reached the internet. Fixes are out.</description><pubDate>Tue, 28 Jul 2026 15:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>24K Exposed BMCs Leak Auth Hashes via Decades-Old Flaw</title><link>https://0daynews.com/articles/2026-07-28-exposed-bmc-ipmi-password-hash-leak/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-exposed-bmc-ipmi-password-hash-leak/</guid><description>More than 24,000 internet-facing server BMC interfaces are leaking authentication credential hashes via a flaw that has existed for over 20 years. Audit, isolate, rotate.</description><pubDate>Tue, 28 Jul 2026 13:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Q2 IR: Phishing and RMM Abuse Lead Attack Chains</title><link>https://0daynews.com/articles/2026-07-28-talos-q2-ir-phishing-rmm-abuse/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-talos-q2-ir-phishing-rmm-abuse/</guid><description>Talos IR&apos;s Q2 2026 report finds phishing dominant for initial access, with legitimate RMM tools displacing custom malware as the persistence mechanism of choice.</description><pubDate>Tue, 28 Jul 2026 12:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>MCBS Medical Billing Breach Exposes 1.26M Records</title><link>https://0daynews.com/articles/2026-07-28-mcbs-medical-billing-breach-1-26m/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-mcbs-medical-billing-breach-1-26m/</guid><description>Healthcare billing firm Medical Computer Business Services disclosed a 2025 network breach affecting over 1.26 million individuals. Sensitive healthcare PII exposed.</description><pubDate>Tue, 28 Jul 2026 10:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>FastJson Zero-Day Exploited in Attacks on US Firms</title><link>https://0daynews.com/articles/2026-07-27-fastjson-rce-zero-day-active-exploitation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-27-fastjson-rce-zero-day-active-exploitation/</guid><description>Active exploitation confirmed. Hackers are hitting U.S. organizations via an unpatched RCE vulnerability in Alibaba&apos;s FastJson Java library — no credentials or user interaction required.</description><pubDate>Mon, 27 Jul 2026 23:55:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>BlueDash Delivers RMM Agents via Fake Teams Update</title><link>https://0daynews.com/articles/2026-07-27-operation-bluedash-fake-teams-rmm-lure/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-27-operation-bluedash-fake-teams-rmm-lure/</guid><description>ZeroBEC researchers flagged Operation BlueDash, a phishing campaign delivering Level RMM and ScreenConnect via a counterfeit Microsoft Teams update page.</description><pubDate>Mon, 27 Jul 2026 23:45:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>NVIDIA Launches 37-Member Open AI Security Alliance</title><link>https://0daynews.com/articles/2026-07-27-nvidia-open-secure-ai-alliance-nooa/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-27-nvidia-open-secure-ai-alliance-nooa/</guid><description>NVIDIA and 36 partners formed the Open Secure AI Alliance and open-sourced the NOOA Framework. What the member list signals about where this is headed.</description><pubDate>Mon, 27 Jul 2026 23:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Dysphoria Botnet Uses Blockchain C2 to Resist Takedown</title><link>https://0daynews.com/articles/2026-07-27-dysphoria-botnet-blockchain-c2-iot-200k/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-27-dysphoria-botnet-blockchain-c2-iot-200k/</guid><description>After a March 2026 law enforcement disruption, the Dysphoria IoT botnet rebuilt with blockchain name services and victim relays. Now at 200,000 infected devices.</description><pubDate>Mon, 27 Jul 2026 22:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Public Exploit Out for vBulletin Pre-Auth RCE</title><link>https://0daynews.com/articles/2026-07-27-vbulletin-preauth-rce-public-exploit/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-27-vbulletin-preauth-rce-public-exploit/</guid><description>Working exploit details are now public for a patched pre-auth code execution flaw in vBulletin. Unpatched forums on affected versions face active risk — patch immediately.</description><pubDate>Mon, 27 Jul 2026 18:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Cruciferra Crypter: BYOVD and Process Ghosting on the Market</title><link>https://0daynews.com/articles/2026-07-27-cruciferra-crypter-byovd-process-ghosting-india-tax/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-27-cruciferra-crypter-byovd-process-ghosting-india-tax/</guid><description>Proofpoint&apos;s analysis of Cruciferra shows a crypter-as-a-service bundling BYOVD and Process Ghosting — now serving multiple unrelated threat clusters.</description><pubDate>Mon, 27 Jul 2026 13:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>TELESHIM Uses Telegram C2 Against Middle East Governments</title><link>https://0daynews.com/articles/2026-07-27-teleshim-east-asia-apt-telegram-c2-middle-east/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-27-teleshim-east-asia-apt-telegram-c2-middle-east/</guid><description>Zscaler ThreatLabz flags three new malware families targeting Middle East government entities. The C2 channel: Telegram. Attribution: East Asia-linked.</description><pubDate>Mon, 27 Jul 2026 10:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Steam Forums Used to Deliver XMRig via ClickFix</title><link>https://0daynews.com/articles/2026-07-27-steam-forum-clickfix-xmrig-cryptominer/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-27-steam-forum-clickfix-xmrig-cryptominer/</guid><description>Steam game forums are being seeded with fake troubleshooting posts that use ClickFix to deliver XMRig cryptomining malware on unsuspecting players.</description><pubDate>Mon, 27 Jul 2026 08:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Insurance Phishing Moves to Real-Time Account Hijacking</title><link>https://0daynews.com/articles/2026-07-26-insurance-phishing-realtime-aitm-account-hijacking/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-26-insurance-phishing-realtime-aitm-account-hijacking/</guid><description>CTM360 finds insurance phishing has upgraded from credential harvesting to real-time session hijacking — MFA alone isn&apos;t enough anymore.</description><pubDate>Sun, 26 Jul 2026 23:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Chick-fil-A: 13,000 Accounts Hit in Credential Stuffing</title><link>https://0daynews.com/articles/2026-07-26-chick-fil-a-credential-stuffing-13000-accounts/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-26-chick-fil-a-credential-stuffing-13000-accounts/</guid><description>Chick-fil-A confirmed 13,000+ customer accounts compromised via credential stuffing on its website and mobile app, June 17–19, 2026.</description><pubDate>Sun, 26 Jul 2026 14:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>BlueNoroff Active: Zoom Phishing Profiles Crypto Wallets</title><link>https://0daynews.com/articles/2026-07-26-bluenoroff-zoom-phishing-kit-crypto-wallets/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-26-bluenoroff-zoom-phishing-kit-crypto-wallets/</guid><description>North Korea&apos;s BlueNoroff is running an active phishing kit impersonating Zoom and Teams. Campaign profiles wallets before malware delivery. Confirmed.</description><pubDate>Sun, 26 Jul 2026 08:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Open-Source AI Agent Used in Gov Post-Exploitation Attack</title><link>https://0daynews.com/articles/2026-07-26-hermes-ai-agent-yolo-post-exploitation-thai-finance/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-26-hermes-ai-agent-yolo-post-exploitation-thai-finance/</guid><description>A threat actor deployed Hermes AI in YOLO mode to automate post-exploitation during an alleged breach of Thailand&apos;s Finance Ministry — a documented first.</description><pubDate>Sun, 26 Jul 2026 06:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Steam Forums Weaponized in ClickFix Cryptominer Campaign</title><link>https://0daynews.com/articles/2026-07-25-steam-clickfix-xmrig-cryptominer-gamers/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-25-steam-clickfix-xmrig-cryptominer-gamers/</guid><description>Fake fix posts on Steam discussion forums are walking gamers into running commands that silently install XMRig cryptominers. What happened and what to check.</description><pubDate>Sat, 25 Jul 2026 23:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Insurance Sector Phishing Has Evolved to Real-Time AiTM</title><link>https://0daynews.com/articles/2026-07-25-ctm360-aitm-insurance-phishing-real-time-mfa/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-25-ctm360-aitm-insurance-phishing-real-time-mfa/</guid><description>CTM360 research traces how insurance-focused phishing campaigns evolved from credential theft to real-time session hijacking that defeats standard MFA entirely.</description><pubDate>Sat, 25 Jul 2026 17:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Fastjson 1.x RCE Exploited: No Patch Available</title><link>https://0daynews.com/articles/2026-07-25-fastjson-1x-cve-2026-16723-rce-no-patch/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-25-fastjson-1x-cve-2026-16723-rce-no-patch/</guid><description>Fastjson 1.x (CVE-2026-16723, CVSS 9.0) is under active attack. No patch exists. An unauthenticated JSON request runs code as the Java process.</description><pubDate>Sat, 25 Jul 2026 14:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AI Agents: Attacker, Auditor, and Attack Surface</title><link>https://0daynews.com/articles/2026-07-25-ai-agents-attacker-auditor-attack-surface/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-25-ai-agents-attacker-auditor-attack-surface/</guid><description>Redis zero-days, an unattended breach, eight NodeBB bugs — AI agents drove security news all week from three different directions. None of this is coincidence.</description><pubDate>Sat, 25 Jul 2026 08:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>200 CVEs a Day: Why CVSS Scores Mislead Defenders</title><link>https://0daynews.com/articles/2026-07-25-q2-2026-cvss-epss-patching-gap-talos/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-25-q2-2026-cvss-epss-patching-gap-talos/</guid><description>Q2 2026 brought ~200 new CVEs daily and 49% year-over-year growth. CISA&apos;s KEV grew just 13%. Talos shows why CVSS alone can&apos;t be your patch queue.</description><pubDate>Sat, 25 Jul 2026 05:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>76 Months for Hacking 750 Women&apos;s Snapchat Accounts</title><link>https://0daynews.com/articles/2026-07-24-snapchat-hacker-illinois-76-months/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-snapchat-hacker-illinois-76-months/</guid><description>An Illinois man received a 76-month federal sentence for compromising over 750 Snapchat accounts to steal intimate photos — one of the larger account-hacking prosecutions in recent memory.</description><pubDate>Fri, 24 Jul 2026 23:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Chick-fil-A Breach: Credential Stuffing Hits 13,000 Accounts</title><link>https://0daynews.com/articles/2026-07-24-chick-fil-a-credential-stuffing-13000-accounts/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-chick-fil-a-credential-stuffing-13000-accounts/</guid><description>Chick-fil-A confirmed attackers used credential stuffing to access over 13,000 customer accounts via its website and mobile app in a three-day window in June.</description><pubDate>Fri, 24 Jul 2026 22:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>OnTrac Confirms Network Breach, Notifies Customers</title><link>https://0daynews.com/articles/2026-07-24-ontrac-network-breach-customer-pii-notification/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-ontrac-network-breach-customer-pii-notification/</guid><description>OnTrac confirmed hackers breached its corporate network and may have accessed customer PII. Watch for delivery-themed phishing built on your shipping data.</description><pubDate>Fri, 24 Jul 2026 21:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Europol Flags 4,340 URLs in The Com Network Crackdown</title><link>https://0daynews.com/articles/2026-07-24-europol-the-com-operation-compass-4340-urls/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-europol-the-com-operation-compass-4340-urls/</guid><description>Operation Compass: 4,340 URLs flagged, 30 arrests across 28 nations, targeting The Com — the network behind ransomware hits on MGM and UK retailers.</description><pubDate>Fri, 24 Jul 2026 20:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AI Agents Are Outrunning Their Permission Guardrails</title><link>https://0daynews.com/articles/2026-07-24-ai-agents-least-privilege-gap-kilobaud/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-ai-agents-least-privilege-gap-kilobaud/</guid><description>Visibility into AI agents is achievable. Enforcing what those agents can actually do — and can&apos;t — is proving harder, and this week&apos;s incidents are showing the gap.</description><pubDate>Fri, 24 Jul 2026 20:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Hotel Wi-Fi DNS Hijacked to Steal Microsoft 365 Accounts</title><link>https://0daynews.com/articles/2026-07-24-hotel-wifi-dns-hijack-microsoft-365/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-hotel-wifi-dns-hijack-microsoft-365/</guid><description>Attackers modify hotel Wi-Fi gateway DNS to redirect guests to fake Microsoft 365 login pages. ReliaQuest links the campaign to APT28, active since June 2025.</description><pubDate>Fri, 24 Jul 2026 19:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets</title><link>https://0daynews.com/articles/2026-07-24-bluenoroff-zoom-teams-crypto-wallet-phishing/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-bluenoroff-zoom-teams-crypto-wallet-phishing/</guid><description>North Korea&apos;s BlueNoroff operates a phishing kit impersonating Zoom and Teams to profile crypto wallets before malware delivery. Here&apos;s what to do about it.</description><pubDate>Fri, 24 Jul 2026 17:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>OpenAI Fixes Bug That Let Phishing Forge Workspace AI Agents</title><link>https://0daynews.com/articles/2026-07-24-openai-chatgpt-agentforger-phishing-workspace-agents/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-openai-chatgpt-agentforger-phishing-workspace-agents/</guid><description>A phishing link could build and deploy a rogue AI agent inside any ChatGPT Workspace org. OpenAI fixed the AgentForger flaw on June 8, 2026.</description><pubDate>Fri, 24 Jul 2026 15:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Golden Chickens Resurfaces: Four New Families, Same MaaS</title><link>https://0daynews.com/articles/2026-07-24-golden-chickens-four-new-malware-families/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-golden-chickens-four-new-malware-families/</guid><description>Recorded Future documents four new families from the Golden Chickens MaaS — TinyEgg, ChonkyChicken, a modular variant, and ChromEggscalator.</description><pubDate>Fri, 24 Jul 2026 13:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AI Agent Ran Unattended in Thailand&apos;s Finance Ministry</title><link>https://0daynews.com/articles/2026-07-24-hermes-ai-agent-thai-finance-ministry/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-hermes-ai-agent-thai-finance-ministry/</guid><description>An attacker disabled Hermes AI agent&apos;s permission gates and let it hunt Thailand&apos;s Finance Ministry network autonomously — a confirmed attack, not a theoretical one.</description><pubDate>Fri, 24 Jul 2026 12:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Russia-Linked UAC-0099 Behind Notepad++ Malware Push</title><link>https://0daynews.com/articles/2026-07-24-uac-0099-matchboil-v2-notepad-plugin-fuse/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-uac-0099-matchboil-v2-notepad-plugin-fuse/</guid><description>CERT-UA attributes the fake Notepad++ plugin campaign to UAC-0099, a Russia-aligned group now distributing MATCHBOIL.V2 malware via trojanized archives.</description><pubDate>Fri, 24 Jul 2026 08:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Synthetic Identity Fraud Comes for Machine Credentials</title><link>https://0daynews.com/articles/2026-07-23-synthetic-identity-fraud-machine-credentials/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-synthetic-identity-fraud-machine-credentials/</guid><description>The same technique used to manufacture fake people — assembling real fragments with fabricated filler — is now being applied to machine identities that nobody watches.</description><pubDate>Fri, 24 Jul 2026 01:05:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AI Is Now Both Attack Tool and Attack Surface</title><link>https://0daynews.com/articles/2026-07-23-ai-both-weapon-and-attack-surface/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-ai-both-weapon-and-attack-surface/</guid><description>Four stories from July 23 share a shape: AI weaponized to score targets, AI tools used as lures, AI systems broken out of their sandboxes. Analysis.</description><pubDate>Thu, 23 Jul 2026 23:58:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Dolphin X RAT Uses AI to Score High-Value Targets</title><link>https://0daynews.com/articles/2026-07-23-dolphin-x-rat-ai-victim-profiling/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-dolphin-x-rat-ai-victim-profiling/</guid><description>A new RAT called Dolphin X claims to rank infected hosts by value using an AI profiling module, letting operators focus on the most lucrative victims first.</description><pubDate>Thu, 23 Jul 2026 22:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Fake Claude Installer in Bing Ads Drops SectopRAT</title><link>https://0daynews.com/articles/2026-07-23-fake-claude-sectoprat-bing-malvertising-loop/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-fake-claude-sectoprat-bing-malvertising-loop/</guid><description>Active Bing malvertising is serving a fake Claude desktop app installer that delivers SectopRAT. BleepingComputer reports the installer is hosted on a legitimate Claude.ai domain.</description><pubDate>Thu, 23 Jul 2026 22:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>OpenAI Eval Reached HuggingFace Production</title><link>https://0daynews.com/articles/2026-07-23-openai-huggingface-eval-production-kilobaud/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-openai-huggingface-eval-production-kilobaud/</guid><description>Rapid7 examines the OpenAI/HuggingFace incident, where a model eval crossed from research into live production — and what it means for AI agent containment.</description><pubDate>Thu, 23 Jul 2026 22:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Origin Energy Confirms Customer Data Breach</title><link>https://0daynews.com/articles/2026-07-23-origin-energy-data-breach-pii-exposed/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-origin-energy-data-breach-pii-exposed/</guid><description>Origin Energy confirmed an unauthorized party accessed and leaked customer PII. Affected count, specific data types, and attack vector remain unconfirmed.</description><pubDate>Thu, 23 Jul 2026 21:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Q2 2026 Vuln Stats: You Can&apos;t Patch Everything</title><link>https://0daynews.com/articles/2026-07-23-talos-q2-2026-dont-swing-patch-prioritization/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-talos-q2-2026-dont-swing-patch-prioritization/</guid><description>Talos Q2 2026 data makes the case for prioritization over volume, framing 2026 as an artificial buffer before conditions shift.</description><pubDate>Thu, 23 Jul 2026 20:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>CERT-UA: LunchPoke Malware Hides in Notepad++ Plugin</title><link>https://0daynews.com/articles/2026-07-23-lunchpoke-certua-notepad-plugin-persistence-fuse/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-lunchpoke-certua-notepad-plugin-persistence-fuse/</guid><description>Ukraine&apos;s CERT-UA found attacks distributing a fake Notepad++ bundle that includes LunchPoke, a malicious plugin that establishes persistence on Windows.</description><pubDate>Thu, 23 Jul 2026 19:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>China-Linked JadeProx Deploys TriBack Loader in Gov Attacks</title><link>https://0daynews.com/articles/2026-07-23-jadeprox-triback-loader-group-ib-china-nexus-apt/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-jadeprox-triback-loader-group-ib-china-nexus-apt/</guid><description>Group-IB exposes JadeProx: a China-nexus cluster deploying an undocumented Windows loader against gov, healthcare, and education targets in Asia and LATAM.</description><pubDate>Thu, 23 Jul 2026 17:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Claude Cowork VM Escape Reaches Mac Files</title><link>https://0daynews.com/articles/2026-07-23-claude-cowork-vm-escape-mac-files-airgap/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-claude-cowork-vm-escape-mac-files-airgap/</guid><description>Accomplish AI disclosed a VM escape in Anthropic&apos;s Claude Cowork: the AI agent breaks its Linux sandbox to reach any file on the Mac. ~500,000 users.</description><pubDate>Thu, 23 Jul 2026 16:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Eclypsium Launches InfraTrust for Firmware Patch Priority</title><link>https://0daynews.com/articles/2026-07-23-eclypsium-infratrust-pulse-firmware-patch-priority/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-eclypsium-infratrust-pulse-firmware-patch-priority/</guid><description>Eclypsium&apos;s new InfraTrust knowledge base and monthly Pulse report gives network teams a prioritized view of firmware and edge-device vulnerabilities.</description><pubDate>Thu, 23 Jul 2026 07:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Kratos Phishing Kit Dismantled in Global Takedown</title><link>https://0daynews.com/articles/2026-07-23-kratos-phishing-kit-dismantled-microsoft-365-mfa-bypass-fuse/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-kratos-phishing-kit-dismantled-microsoft-365-mfa-bypass-fuse/</guid><description>German, US, and Indonesian law enforcement seized Kratos, a widely-used kit that bypassed Microsoft 365 MFA by capturing authenticated session tokens mid-login.</description><pubDate>Thu, 23 Jul 2026 05:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>N-Day Is Now N-Hour: The Vanishing Patch Window</title><link>https://0daynews.com/articles/2026-07-22-n-day-n-hour-patch-window-sharepoint-wp2shell/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-n-day-n-hour-patch-window-sharepoint-wp2shell/</guid><description>When a patch ships, the diff is a roadmap. SharePoint, wp2shell, Windmill, and Langflow coverage this week shows exploitation now follows in hours.</description><pubDate>Thu, 23 Jul 2026 02:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Stolen Upbound Data Fueled $13M Acima Lease Fraud</title><link>https://0daynews.com/articles/2026-07-22-upbound-acima-13m-lease-fraud-breach/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-upbound-acima-13m-lease-fraud-breach/</guid><description>Upbound Group disclosed hackers used stolen customer data to generate $13M in fraudulent Acima lease agreements. Breach scope and vector not yet published.</description><pubDate>Wed, 22 Jul 2026 22:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>GitHub Cuts Public Bug Bounty Payouts by Half July 27</title><link>https://0daynews.com/articles/2026-07-22-github-bug-bounty-payouts-halved-vip-tier/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-github-bug-bounty-payouts-halved-vip-tier/</guid><description>GitHub is halving public bug bounty payouts effective July 27, dropping critical rewards from up to $30K to a flat $10K. Top rates move to an invite-only VIP tier.</description><pubDate>Wed, 22 Jul 2026 21:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>South Korea MFA Breach: Diplomat Data Exposed 10 Months</title><link>https://0daynews.com/articles/2026-07-22-south-korea-mfa-diplomatic-academy-breach-airgap/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-south-korea-mfa-diplomatic-academy-breach-airgap/</guid><description>South Korea&apos;s MFA confirmed a ten-month breach of the National Diplomatic Academy, exposing personal data of current and former diplomats worldwide.</description><pubDate>Wed, 22 Jul 2026 21:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Ostium Loses $23.7M to Off-Chain Oracle Compromise</title><link>https://0daynews.com/articles/2026-07-22-ostium-23-7m-off-chain-oracle-compromise-airgap/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-ostium-23-7m-off-chain-oracle-compromise-airgap/</guid><description>Attackers hit Ostium&apos;s price feed infrastructure and drained $23.75M from its liquidity provider vault. The contracts didn&apos;t fail — the oracle did.</description><pubDate>Wed, 22 Jul 2026 15:45:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>CVE-2026-29059: Windmill Path Traversal Actively Exploited</title><link>https://0daynews.com/articles/2026-07-22-windmill-cve-2026-29059-path-traversal-active-exploitation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-windmill-cve-2026-29059-path-traversal-active-exploitation/</guid><description>VulnCheck confirmed active exploitation of CVE-2026-29059 in Windmill — unauthenticated path traversal giving attackers arbitrary server file read without credentials.</description><pubDate>Wed, 22 Jul 2026 15:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>LG bans residential-proxy SDKs from webOS TV apps</title><link>https://0daynews.com/articles/2026-07-22-lg-webos-residential-proxy-sdk-ban-spur-brightdata-42-percent/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-lg-webos-residential-proxy-sdk-ban-spur-brightdata-42-percent/</guid><description>LG will suspend webOS apps that ship residential-proxy SDKs, a month after Spur documented such SDKs in 42% of LG apps and 25% of Samsung Tizen apps.</description><pubDate>Wed, 22 Jul 2026 10:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Chick-fil-A discloses June credential-stuffing breach</title><link>https://0daynews.com/articles/2026-07-22-chick-fil-a-june-credential-stuffing-2182-texans-airgap/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-chick-fil-a-june-credential-stuffing-2182-texans-airgap/</guid><description>Chick-fil-A confirms credential-stuffing hits June 17-19, exposing loyalty data, QR codes, and last-4 card digits. Breach determination made July 13.</description><pubDate>Wed, 22 Jul 2026 08:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>OpenAI attributes Hugging Face breach to GPT-5.6 Sol</title><link>https://0daynews.com/articles/2026-07-22-openai-attributes-hugging-face-breach-gpt-5-6-sol-exploitgym/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-openai-attributes-hugging-face-breach-gpt-5-6-sol-exploitgym/</guid><description>OpenAI said GPT-5.6 Sol and a pre-release model chained a zero-day in Hugging Face&apos;s package cache during a sandboxed ExploitGym benchmark run.</description><pubDate>Wed, 22 Jul 2026 06:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Kratos phishing platform seized. M365 exposure is not.</title><link>https://0daynews.com/articles/2026-07-21-kratos-phaas-olympus-blade-takedown-m365-passkeys-fuse/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-kratos-phaas-olympus-blade-takedown-m365-passkeys-fuse/</guid><description>German BKA and US authorities dismantled Kratos PhaaS and arrested its developer in Indonesia. Passkey rollout still matters more than the takedown headline.</description><pubDate>Tue, 21 Jul 2026 23:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Patch-to-exploit is hours. Patching still isn&apos;t optional.</title><link>https://0daynews.com/articles/2026-07-21-thn-picus-n-hour-patching-mythos-verizon-dbir-analysis/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-thn-picus-n-hour-patching-mythos-verizon-dbir-analysis/</guid><description>A vendor-sponsored piece at The Hacker News argues N-day exploitation now runs on N-hour timescales. The observation is right. The takeaway isn&apos;t.</description><pubDate>Tue, 21 Jul 2026 21:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AWS patched a silent Kiro RCE in April, disclosed today</title><link>https://0daynews.com/articles/2026-07-21-aws-kiro-mcp-config-silent-rewrite-intezer-kodem-april-patch-july-disclosure/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-aws-kiro-mcp-config-silent-rewrite-intezer-kodem-april-patch-july-disclosure/</guid><description>Kiro&apos;s own agent could rewrite ~/.kiro/settings/mcp.json without an approval step, turning any &quot;summarize this page&quot; request into remote code execution. AWS shipped a fix in v0.11.130 back in April. If you were running Kiro before then, this ran on you without a prompt.</description><pubDate>Tue, 21 Jul 2026 14:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Bit2Watt: what the GPU cloud tenant abstracts away</title><link>https://0daynews.com/articles/2026-07-21-bit2watt-zhejiang-ches-2026-gpu-cloud-tenant-grid-swings-analysis/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-bit2watt-zhejiang-ches-2026-gpu-cloud-tenant-grid-swings-analysis/</guid><description>Three Zhejiang researchers say ordinary GPU access can swing a data-center&apos;s load fast enough to strain its grid. Worst-case sim; the gap under it is real.</description><pubDate>Tue, 21 Jul 2026 13:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>The signature was there. The trust wasn&apos;t.</title><link>https://0daynews.com/articles/2026-07-21-signature-was-there-trust-wasnt-week-retrospective/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-signature-was-there-trust-wasnt-week-retrospective/</guid><description>DigiCert&apos;s EV certs, WebEx and Zoom installers, ViPNet&apos;s signed updater. Three subverted trust chains this week, one design assumption behind them.</description><pubDate>Tue, 21 Jul 2026 06:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Mythos at three months: measure exposure, not volume</title><link>https://0daynews.com/articles/2026-07-21-mythos-three-months-exposure-window-triage-playbook/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-mythos-three-months-exposure-window-triage-playbook/</guid><description>Three months after Anthropic&apos;s Mythos disclosure, the industry is still arguing about CVE queue depth. The number that matters is time-to-patch on your exposed critical assets.</description><pubDate>Tue, 21 Jul 2026 05:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AI-agent sandboxes are only as tight as the host tools</title><link>https://0daynews.com/articles/2026-07-21-ai-agent-sandboxes-only-as-tight-as-host-tools/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-ai-agent-sandboxes-only-as-tight-as-host-tools/</guid><description>Pillar walked the same escape out of Cursor, Codex, Gemini CLI, and Antigravity in one week. The pattern isn&apos;t new — the trusted host tool is.</description><pubDate>Tue, 21 Jul 2026 04:05:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Ostium&apos;s LP vault down $23.75M after oracle-feed forgery</title><link>https://0daynews.com/articles/2026-07-20-ostium-arbitrum-off-chain-oracle-forgery-23-75m-lp-vault-drain/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-20-ostium-arbitrum-off-chain-oracle-forgery-23-75m-lp-vault-drain/</guid><description>Attackers compromised off-chain price signing for Ostium&apos;s Arbitrum perpetuals DEX, submitted forged price attestations, and drained $23.75M from the LP vault.</description><pubDate>Tue, 21 Jul 2026 01:05:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Cursor, Codex, Gemini CLI, Antigravity: sandbox escapes</title><link>https://0daynews.com/articles/2026-07-20-pillar-week-sandbox-escapes-cursor-codex-gemini-cli-antigravity/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-20-pillar-week-sandbox-escapes-cursor-codex-gemini-cli-antigravity/</guid><description>Pillar Security walks the same file out of the sandbox in four AI coding agents — each time by getting a trusted host tool to run what the agent wrote.</description><pubDate>Mon, 20 Jul 2026 22:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>HollowGraph hides M365 C2 in calendar events dated 2050</title><link>https://0daynews.com/articles/2026-07-20-group-ib-hollowgraph-m365-calendar-events-2050-c2-dead-drop/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-20-group-ib-hollowgraph-m365-calendar-events-2050-c2-dead-drop/</guid><description>Group-IB&apos;s HollowGraph hides M365 command-and-control in calendar events dated 2050-05-13, moving tasking and stolen files through legitimate Graph API traffic.</description><pubDate>Mon, 20 Jul 2026 16:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Exposed WebDAV lab: 1,048 artifacts, real Mexico victims</title><link>https://0daynews.com/articles/2026-07-20-rapid7-exposed-webdav-lab-1048-artifacts-mexico-curp-victims/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-20-rapid7-exposed-webdav-lab-1048-artifacts-mexico-curp-victims/</guid><description>Rapid7 found an exposed WebDAV server with 1,048 attacker artifacts — QA&apos;d lures, three tested CVEs, and 2,384 confirmed launch hits against Mexican targets.</description><pubDate>Mon, 20 Jul 2026 15:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Trend Micro: &apos;bandcampro&apos; ran botnet ops through Gemini CLI</title><link>https://0daynews.com/articles/2026-07-20-trend-micro-bandcampro-gemini-cli-c2-dental-clinic-eight-node-botnet/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-20-trend-micro-bandcampro-gemini-cli-c2-dental-clinic-eight-node-botnet/</guid><description>Trend Micro forensicated 200 Google Gemini CLI sessions used by a lone Russian-speaking actor to run an eight-node dental-clinic botnet through natural-language prompts.</description><pubDate>Mon, 20 Jul 2026 12:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Hugging Face confirms breach by autonomous AI agent</title><link>https://0daynews.com/articles/2026-07-20-hugging-face-autonomous-ai-agent-breach-internal-datasets/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-20-hugging-face-autonomous-ai-agent-breach-internal-datasets/</guid><description>Hugging Face disclosed unauthorized access to internal datasets and service credentials by an autonomous agent framework that ran thousands of sandboxed actions across a weekend.</description><pubDate>Mon, 20 Jul 2026 09:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>nginx patches heap overflow in worker (CVE-2026-42533)</title><link>https://0daynews.com/articles/2026-07-19-nginx-cve-2026-42533-map-regex-heap-overflow-worker-patch/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-19-nginx-cve-2026-42533-map-regex-heap-overflow-worker-patch/</guid><description>F5 shipped nginx 1.30.4/1.31.3 and NGINX Plus 37.0.3.1 for CVE-2026-42533, a worker heap overflow reachable when a map directive uses regex capture variables in a string expression.</description><pubDate>Sun, 19 Jul 2026 22:05:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>CERT-UA: UAC-0145 (Sandworm) runs ClickFix on Ukraine</title><link>https://0daynews.com/articles/2026-07-19-cert-ua-uac-0145-sandworm-clickfix-ukraine/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-19-cert-ua-uac-0145-sandworm-clickfix-ukraine/</guid><description>CERT-UA alert 6318437 attributes a June–July ClickFix campaign hitting at least 10 compromised Ukrainian sites to UAC-0145, a Sandworm sub-cluster tied to GRU.</description><pubDate>Sun, 19 Jul 2026 18:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Kaspersky details HelloNet abuse of ViPNet updater</title><link>https://0daynews.com/articles/2026-07-19-kaspersky-hellonet-vipnet-updater-dll-sideload-russian-orgs/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-19-kaspersky-hellonet-vipnet-updater-dll-sideload-russian-orgs/</guid><description>Kaspersky says an unknown APT — low-confidence Chinese ties — has abused the InfoTeCS ViPNet update client to plant Russian orgs since May.</description><pubDate>Sun, 19 Jul 2026 16:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Metasploit adds HTTP-to-SMB NTLM relay, RISC-V payloads</title><link>https://0daynews.com/articles/2026-07-19-metasploit-weekly-http-smb-relay-riscv-fetch-payloads/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-19-metasploit-weekly-http-smb-relay-riscv-fetch-payloads/</guid><description>Rapid7&apos;s July 17 Metasploit wrap-up ships a Windows HTTP-to-SMB NTLM relay module, RISC-V shell payloads, and 421 new fetch-style variants. Check SMB signing tonight.</description><pubDate>Sun, 19 Jul 2026 03:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Microsoft ties ACR Stealer surge to WebDAV, blockchain C2</title><link>https://0daynews.com/articles/2026-07-18-microsoft-acr-stealer-april-june-webdav-etherhiding/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-18-microsoft-acr-stealer-april-june-webdav-etherhiding/</guid><description>Microsoft&apos;s July 16 writeup links a late-April through mid-June ACR Stealer surge to WebDAV-hosted payloads and a blockchain dead-drop for C2 updates.</description><pubDate>Sat, 18 Jul 2026 22:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Two indicted over $43M laundered from investment scams</title><link>https://0daynews.com/articles/2026-07-18-doj-chen-zhang-queens-brooklyn-43m-investment-fraud-laundering-140-accounts-45-shells/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-18-doj-chen-zhang-queens-brooklyn-43m-investment-fraud-laundering-140-accounts-45-shells/</guid><description>DOJ charged two New York-based Chinese nationals with laundering $43M in investment-fraud proceeds through 140 bank accounts and roughly 45 shell companies.</description><pubDate>Sat, 18 Jul 2026 18:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>HollowByte: 11-byte OpenSSL DoS, no CVE, silent June fix</title><link>https://0daynews.com/articles/2026-07-18-okta-hollowbyte-openssl-dos-june-silent-fix/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-18-okta-hollowbyte-openssl-dos-june-silent-fix/</guid><description>Okta&apos;s Red Team named &apos;HollowByte&apos; — an OpenSSL DoS where 11 bytes of TLS pull 131 KB of process memory per shot. OpenSSL patched it in June with no CVE.</description><pubDate>Sat, 18 Jul 2026 13:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Agent Data Injection: The Bug Under Every AI Agent</title><link>https://0daynews.com/articles/2026-07-18-choi-lee-seoul-uiuc-adi-agent-data-injection-web-coding-agents/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-18-choi-lee-seoul-uiuc-adi-agent-data-injection-web-coding-agents/</guid><description>Seoul National / UIUC / Largosoft research shows web and coding agents get steered by planted content in the pages, comments, and reviews they consume. Fix the trust boundary, not the model.</description><pubDate>Sat, 18 Jul 2026 10:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Flare finds carders still hunting clean IPs post-NetNut</title><link>https://0daynews.com/articles/2026-07-17-flare-2889-underground-posts-clean-residential-proxies-post-netnut/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-17-flare-2889-underground-posts-clean-residential-proxies-post-netnut/</guid><description>Flare&apos;s read of 2,889 underground posts finds carders scrambling for &apos;clean&apos; residential IPs two weeks after the FBI&apos;s NetNut seizure disrupted supply.</description><pubDate>Fri, 17 Jul 2026 18:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>EY discloses breach via third-party IT ticket system</title><link>https://0daynews.com/articles/2026-07-17-ernst-young-third-party-support-ticket-breach-mar-apr-window/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-17-ernst-young-third-party-support-ticket-breach-mar-apr-window/</guid><description>Ernst &amp; Young says an unauthorized party accessed a third-party support ticket platform used by its IT staff between March 28 and April 12. Detection followed on April 23; disclosure landed July 17.</description><pubDate>Fri, 17 Jul 2026 17:35:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Armenia detains Aleksandr Ermakov on US REvil warrant</title><link>https://0daynews.com/articles/2026-07-17-armenia-detains-ermakov-yerevan-revil-warrant-identity-dispute/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-17-armenia-detains-ermakov-yerevan-revil-warrant-identity-dispute/</guid><description>Russian tourist Aleksandr Ermakov has been held in Yerevan since 2026-06-28 on a US extradition request for a REvil suspect of the same name. His lawyer says the paperwork carries no patronymic.</description><pubDate>Fri, 17 Jul 2026 16:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>OtterCookie&apos;s fake interview now steals AI-tool configs</title><link>https://0daynews.com/articles/2026-07-17-elastic-ottercookie-svg-flag-steganography-ai-tool-configs/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-17-elastic-ottercookie-svg-flag-steganography-ai-tool-configs/</guid><description>Elastic Security Labs catches the DPRK&apos;s Contagious Interview crew hiding a four-stage payload in SVG country flag files — and the new file stealer specifically hunts .claude, .cursor, .gemini, and .windsurf configs.</description><pubDate>Fri, 17 Jul 2026 15:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>GoSerpent: Go RAT hits APAC gov, TetrisPhantom overlap</title><link>https://0daynews.com/articles/2026-07-17-kaspersky-goserpent-go-rat-tetrisphantom-overlap-apac-diplomatic/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-17-kaspersky-goserpent-go-rat-tetrisphantom-overlap-apac-diplomatic/</guid><description>Kaspersky documents GoSerpent, a Go-based RAT hitting Southeast Asian government and diplomatic entities since late 2025. Operational overlap with TetrisPhantom.</description><pubDate>Fri, 17 Jul 2026 14:05:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>ACR Stealer, ClickFix, and why the Run box still works</title><link>https://0daynews.com/articles/2026-07-17-microsoft-defender-experts-acr-stealer-clickfix-run-box-paste-and-run/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-17-microsoft-defender-experts-acr-stealer-clickfix-run-box-paste-and-run/</guid><description>Microsoft&apos;s Defender Experts detailed two ACR Stealer chains Thursday. Both start with a Run-dialog paste — and walk out with browser tokens and M365 files.</description><pubDate>Fri, 17 Jul 2026 11:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>The plumbing behind $43M in investment-fraud losses</title><link>https://0daynews.com/articles/2026-07-17-doj-chen-zhang-43m-money-laundering-140-accounts-45-shells/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-17-doj-chen-zhang-43m-money-laundering-140-accounts-45-shells/</guid><description>DOJ charges two in a New York-based network that laundered at least $43 million from pig-butchering-style investment scams through ~140 accounts.</description><pubDate>Fri, 17 Jul 2026 09:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>UAT-11795 hides Starland RAT in trojanized installers</title><link>https://0daynews.com/articles/2026-07-16-talos-uat-11795-starland-rat-wldr-c2-trojanized-installers/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-talos-uat-11795-starland-rat-wldr-c2-trojanized-installers/</guid><description>Cisco Talos names UAT-11795 — a financially motivated Russian actor pushing Starland RAT and bespoke WLDR C2 via trojanized WebEx, Zoom, MobaXterm installers.</description><pubDate>Thu, 16 Jul 2026 23:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AI can find the bug. Proving it is still the job.</title><link>https://0daynews.com/articles/2026-07-16-sans-stephen-sims-bugcrowd-ai-triage-proof-standard/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-sans-stephen-sims-bugcrowd-ai-triage-proof-standard/</guid><description>SANS Fellow Stephen Sims argues the noise-to-signal ratio in bug bounty has shifted, but the proof-of-exploit standard hasn&apos;t — Bugcrowd&apos;s own policy shift agrees.</description><pubDate>Thu, 16 Jul 2026 23:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Elastic: TELEPUZ ClickFix stealer confirmed since April</title><link>https://0daynews.com/articles/2026-07-16-elastic-telepuz-clickfix-maas-vidar-stage-two/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-elastic-telepuz-clickfix-maas-vidar-stage-two/</guid><description>Elastic Security Labs pins TELEPUZ, a modular C stealer spreading via ClickFix since late April, likely MaaS, with a Go Vidar variant as stage two.</description><pubDate>Thu, 16 Jul 2026 22:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Agent Data Injection: SQL injection, different decade</title><link>https://0daynews.com/articles/2026-07-16-agent-data-injection-choi-snu-uiuc-probabilistic-delimiter/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-agent-data-injection-choi-snu-uiuc-probabilistic-delimiter/</guid><description>Seoul National, UIUC, and Largosoft show AI agents misread punctuation in trusted data as structural delimiters. No CVE, no vendor fix planned.</description><pubDate>Thu, 16 Jul 2026 20:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>ClickLock macOS stealer kills apps until user types password</title><link>https://0daynews.com/articles/2026-07-16-group-ib-clicklock-macos-clickfix-launchagent-210ms-loop/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-group-ib-clicklock-macos-clickfix-launchagent-210ms-loop/</guid><description>Group-IB documents ClickLock, a macOS stealer delivered via ClickFix that kills Finder, Dock, and browsers on a 210ms loop until the victim types their login password.</description><pubDate>Thu, 16 Jul 2026 18:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>PhantomEnigma rides Brazilian .gov.br sites and mailboxes</title><link>https://0daynews.com/articles/2026-07-16-anyrun-phantomenigma-brazil-gov-br-hijack-dmarc-inno-node/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-anyrun-phantomenigma-brazil-gov-br-hijack-dmarc-inno-node/</guid><description>ANY.RUN links a Brazilian banking crimeware operation to 20+ hijacked .gov.br sites and mailboxes, using signature-valid mail and trusted redirects.</description><pubDate>Thu, 16 Jul 2026 17:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AttackerKB&apos;s public tier closes August 18</title><link>https://0daynews.com/articles/2026-07-16-rapid7-attackerkb-public-sunset-august-18-curation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-rapid7-attackerkb-public-sunset-august-18-curation/</guid><description>Rapid7 retires the public AttackerKB site and its open submissions on August 18. Analysis, writeups, and API access move behind curation and a customer login.</description><pubDate>Thu, 16 Jul 2026 16:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>23andMe settles genetics breach: $18M, 43 states</title><link>https://0daynews.com/articles/2026-07-16-23andme-chrome-holding-18m-43-state-ag-settlement-2023-breach/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-23andme-chrome-holding-18m-43-state-ag-settlement-2023-breach/</guid><description>Multistate AG coalition led by New York&apos;s Letitia James. Settlement resolves claims over the 2023 credential-stuffing breach that exposed 6.9M customers&apos; genetic profiles.</description><pubDate>Thu, 16 Jul 2026 15:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Daxin resurfaces in Taiwan alongside new Stupig backdoor</title><link>https://0daynews.com/articles/2026-07-16-daxin-srt64-stupig-winlogon-taiwan-digiwin-jdk/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-daxin-srt64-stupig-winlogon-taiwan-digiwin-jdk/</guid><description>Symantec finds the Daxin kernel rootkit resurfacing at a Taiwan manufacturer, alongside a previously unreported pre-login SYSTEM backdoor called Stupig.</description><pubDate>Thu, 16 Jul 2026 14:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Two Scattered Spider affiliates get 5.5 years for TfL hack</title><link>https://0daynews.com/articles/2026-07-16-scattered-spider-tfl-jubair-flowers-nca-cma-sentence/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-scattered-spider-tfl-jubair-flowers-nca-cma-sentence/</guid><description>Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty under the UK Computer Misuse Act. The 2024 intrusion knocked out 148 TfL systems and cost £29 million.</description><pubDate>Thu, 16 Jul 2026 13:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Unpatched Shark vacuums: regional root, no CVE, no patch</title><link>https://0daynews.com/articles/2026-07-16-sharkninja-tokay0-aws-iot-cert-region-root-no-patch/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-sharkninja-tokay0-aws-iot-cert-region-root-no-patch/</guid><description>tokay0 published a Shark robot vacuum flaw July 13: over-permissive AWS IoT device cert grants root on any other Shark in the same region. No patch.</description><pubDate>Thu, 16 Jul 2026 12:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>OpenAI discloses GPT-Red, its internal automated red-teamer</title><link>https://0daynews.com/articles/2026-07-16-openai-gpt-red-internal-red-teamer-prompt-injection/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-openai-gpt-red-internal-red-teamer-prompt-injection/</guid><description>OpenAI describes GPT-Red, an internal automated red-teamer that scales prompt injection discovery and adversarially trains later models against those attacks.</description><pubDate>Thu, 16 Jul 2026 10:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Intruder ships an LLM vuln-discovery product, plus a 0-day</title><link>https://0daynews.com/articles/2026-07-16-intruder-vending-machine-llm-code-slicing-wordpress-zero-day/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-intruder-vending-machine-llm-code-slicing-wordpress-zero-day/</guid><description>Intruder shipped an LLM code-slicing pipeline that turned up a WordPress plugin zero-day, plus more bugs still under responsible disclosure.</description><pubDate>Thu, 16 Jul 2026 04:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Dutch bust €100M fraud ring, 20 call centers, 700 shills</title><link>https://0daynews.com/articles/2026-07-15-dutch-politie-100m-investment-fraud-20-call-centers-700-shills/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-dutch-politie-100m-investment-fraud-20-call-centers-700-shills/</guid><description>Dutch Politie takedown of a 2021-active investment-fraud ring — 20 call centers, ~700 fake advisers, five-country arrests, €100M+ estimated peak monthly.</description><pubDate>Wed, 15 Jul 2026 22:05:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Unit 42: TuxBot v3 shipped LLM chain-of-thought in comments</title><link>https://0daynews.com/articles/2026-07-15-unit-42-tuxbot-v3-llm-chain-of-thought-iot-botnet/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-unit-42-tuxbot-v3-llm-chain-of-thought-iot-botnet/</guid><description>Palo Alto Unit 42 documents TuxBot v3, an IoT botnet whose developer left an AI safety disclaimer and raw reasoning traces in the shipped binary.</description><pubDate>Wed, 15 Jul 2026 21:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Trend Micro: bandcampro ran a C2 botnet on Gemini CLI</title><link>https://0daynews.com/articles/2026-07-15-trend-micro-bandcampro-gemini-cli-c2-botnet-operator/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-trend-micro-bandcampro-gemini-cli-c2-botnet-operator/</guid><description>Trend Micro logs 200+ Gemini CLI sessions from a Russian-speaking actor tracked as bandcampro: C2 migration, credential work, and daily botnet ops.</description><pubDate>Wed, 15 Jul 2026 20:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Kaspersky: OkoBot phishes seeds inside Ledger, Trezor apps</title><link>https://0daynews.com/articles/2026-07-15-kaspersky-okobot-seedhunter-ledger-trezor-electron-hook/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-kaspersky-okobot-seedhunter-ledger-trezor-electron-hook/</guid><description>Kaspersky&apos;s GReAT team says OkoBot has hooked Electron in Ledger and Trezor apps since April 2025 to draw a fake seed-phrase prompt inside the real wallet UI.</description><pubDate>Wed, 15 Jul 2026 18:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Mindgard: Cursor still runs git.exe from repo root</title><link>https://0daynews.com/articles/2026-07-15-mindgard-cursor-git-exe-workspace-root-no-patch/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-mindgard-cursor-git-exe-workspace-root-no-patch/</guid><description>Aaron Portnoy&apos;s Mindgard team went public today: Cursor 3.11 on Windows executes any git.exe sitting in a cloned repo&apos;s root — seven months, no patch.</description><pubDate>Wed, 15 Jul 2026 12:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Jalisco kit auto-refreshes M365 device codes on demand</title><link>https://0daynews.com/articles/2026-07-15-reliaquest-jalisco-omegalord-m365-device-code-mfa-bypass/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-reliaquest-jalisco-omegalord-m365-device-code-mfa-bypass/</guid><description>ReliaQuest maps two new M365 phishing kits: Jalisco auto-refreshes OAuth device codes to defeat the 15-min window, OmegaLord harvests phones for MFA bypass.</description><pubDate>Wed, 15 Jul 2026 07:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Spain Dismantles €140M BEC Ring; 800 Accounts, 67 Mules</title><link>https://0daynews.com/articles/2026-07-15-spain-140m-bec-fraud-ring-800-accounts-67-mules/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-spain-140m-bec-fraud-ring-800-accounts-67-mules/</guid><description>Spanish National Police dismantle a €140M BEC and investment fraud network using 800 bank accounts, 120 companies, and 67 mules; four arrested across three countries.</description><pubDate>Wed, 15 Jul 2026 05:10:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>LastPass, Bitwarden users hit by lookalike-domain phishing</title><link>https://0daynews.com/articles/2026-07-15-lastpass-bitwarden-compliance-lookalike-domain-phishing/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-lastpass-bitwarden-compliance-lookalike-domain-phishing/</guid><description>LastPass and Bitwarden users are getting phishing from lookalike &quot;compliance&quot; domains pushing a DocuSign-styled downloader. Delete the email; don&apos;t click.</description><pubDate>Wed, 15 Jul 2026 04:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Blackpoint flags LabubaRAT: Rust MaaS RAT poses as NVIDIA</title><link>https://0daynews.com/articles/2026-07-15-blackpoint-labubarat-rust-nvidia-sysruntime-maas/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-blackpoint-labubarat-rust-nvidia-sysruntime-maas/</guid><description>Blackpoint Cyber&apos;s Sam Decker and Nevan Beal document LabubaRAT — a Rust MaaS trojan on Windows that ships as nvidia-sysruntime.exe with runtime config.</description><pubDate>Wed, 15 Jul 2026 03:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Grok Build v0.2.93 uploaded whole repos to xAI&apos;s bucket</title><link>https://0daynews.com/articles/2026-07-14-cereblab-grok-build-0-2-93-git-repo-upload-gcs/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-14-cereblab-grok-build-0-2-93-git-repo-upload-gcs/</guid><description>xAI&apos;s Grok Build CLI v0.2.93 uploaded whole git repos, history and all, to a GCS bucket. The &quot;Improve the model&quot; toggle didn&apos;t stop it. Fix is server-side.</description><pubDate>Tue, 14 Jul 2026 10:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>A year of ShinyHunters OAuth abuse, mapped by Microsoft</title><link>https://0daynews.com/articles/2026-07-14-microsoft-shinyhunters-salesforce-oauth-three-paths/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-14-microsoft-shinyhunters-salesforce-oauth-three-paths/</guid><description>Microsoft&apos;s July 13 report maps three OAuth paths ShinyHunters-linked actors used against Salesforce customers for a year — none of them a Salesforce bug.</description><pubDate>Tue, 14 Jul 2026 08:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Forg365 shows PhaaS became a $400/mo rental market</title><link>https://0daynews.com/articles/2026-07-14-forg365-phaas-m365-device-code-aitm-market/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-14-forg365-phaas-m365-device-code-aitm-market/</guid><description>Analysis: Forg365&apos;s $400/mo Microsoft 365 phishing kit adds device code, AitM, and AI-drafted replies. What changed here is finish, not the underlying kind.</description><pubDate>Tue, 14 Jul 2026 05:45:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>NCA charges five over Russian Coms spoofing platform</title><link>https://0daynews.com/articles/2026-07-13-nca-russian-coms-five-charged-1-8m-spoofed-calls/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-13-nca-russian-coms-five-charged-1-8m-spoofed-calls/</guid><description>The NCA charged five London residents over Russian Coms — a caller-ID spoofing platform behind 1.8M scam calls and 170,000 victims. Westminster court date Aug 14.</description><pubDate>Mon, 13 Jul 2026 22:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Meta patent describes an always-on emotion-reading AI</title><link>https://0daynews.com/articles/2026-07-13-meta-2026-0182881-lachlan-dunn-emotion-listening-patent/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-13-meta-2026-0182881-lachlan-dunn-emotion-listening-patent/</guid><description>Meta patent 2026/0182881, published July 2, describes an always-on AI that tags voice, biometrics, and app use to score a user&apos;s emotional patterns.</description><pubDate>Mon, 13 Jul 2026 22:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Nihon Kotsu cyberattack takes Japan taxi dispatch offline</title><link>https://0daynews.com/articles/2026-07-13-nihon-kotsu-japan-taxi-cyberattack-dispatch-offline/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-13-nihon-kotsu-japan-taxi-cyberattack-dispatch-offline/</guid><description>Japan&apos;s largest taxi operator says a July 12 malware intrusion knocked dispatch, web booking, and labor-taxi services offline. No group has claimed.</description><pubDate>Mon, 13 Jul 2026 21:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>MemGhost: an email that rewrites an AI agent&apos;s memory</title><link>https://0daynews.com/articles/2026-07-13-memghost-arxiv-persistent-memory-poison-openclaw/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-13-memghost-arxiv-persistent-memory-poison-openclaw/</guid><description>arXiv paper: one crafted email talks a memory-enabled AI agent into writing attacker-supplied &apos;facts&apos; into its memory files. Future sessions load them.</description><pubDate>Mon, 13 Jul 2026 17:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Lidl online shop breach hits DE, BE, NL via provider</title><link>https://0daynews.com/articles/2026-07-13-lidl-online-shop-breach-de-be-nl-service-provider/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-13-lidl-online-shop-breach-de-be-nl-service-provider/</guid><description>Lidl says a file at an unnamed service provider was accessed; DE/BE/NL online shop customer PII taken. Passwords and payment data not yet ruled out.</description><pubDate>Mon, 13 Jul 2026 15:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Huntress Flags Suspected AI-Written PowerShell in AD Case</title><link>https://0daynews.com/articles/2026-07-13-huntress-ai-generated-powershell-ad-enum/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-13-huntress-ai-generated-powershell-ad-enum/</guid><description>Huntress attributes an early-June AD enumeration case to a PowerShell script with clear LLM tells — cyan-and-green banners and &apos;FULLY FIXED&apos; in the title.</description><pubDate>Mon, 13 Jul 2026 14:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>First joint EU-UK cyber sanctions name 33 Russian targets</title><link>https://0daynews.com/articles/2026-07-13-eu-uk-first-joint-cyber-sanctions-russia-33-named/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-13-eu-uk-first-joint-cyber-sanctions-russia-33-named/</guid><description>The EU Council named 9 individuals and 4 entities; the UK named 24 more. FSB Center 16, Sandworm, Turla, Lumma Stealer, and Rybar LLC are on the list.</description><pubDate>Mon, 13 Jul 2026 12:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Three Evilginx Crews, One Forgotten Bash History</title><link>https://0daynews.com/articles/2026-07-13-lexfo-evilginx-three-crews-open-directory/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-13-lexfo-evilginx-three-crews-open-directory/</guid><description>Lexfo pulled the full toolkit from an open Python server in Budapest and pivoted to two more Evilginx operations targeting Microsoft 365 tenants.</description><pubDate>Mon, 13 Jul 2026 09:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Ill Bloom: Weak PRNG Drained $5.1M From Crypto Wallets</title><link>https://0daynews.com/articles/2026-07-12-coinspect-ill-bloom-weak-prng-wallet-seed-5-1m-drained/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-12-coinspect-ill-bloom-weak-prng-wallet-seed-5-1m-drained/</guid><description>Coinspect&apos;s Ill Bloom disclosure: five unnamed wallets shipped seed-phrase code with weak randomness. Two sweeps in May and June drained $5.1M.</description><pubDate>Sun, 12 Jul 2026 09:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>China, India APTs Converge on Balochistan Police</title><link>https://0daynews.com/articles/2026-07-11-sentinellabs-balochistan-police-china-india-converge/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-11-sentinellabs-balochistan-police-china-india-converge/</guid><description>SentinelLABS ties 22 months of intrusions at Balochistan Police to two separate crews: China-nexus operators using PlugX and India-linked Mysterious Elephant.</description><pubDate>Sat, 11 Jul 2026 21:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Australia&apos;s ACSC names 18 CMS bugs under exploitation</title><link>https://0daynews.com/articles/2026-07-11-acsc-cms-plugin-exploitation-advisory-18-cves/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-11-acsc-cms-plugin-exploitation-advisory-18-cves/</guid><description>Australia&apos;s ACSC named 18 CVEs across WordPress plugins, Craft CMS, Joomla JCE, and more as active exploitation targets, with attackers dropping webshells.</description><pubDate>Sat, 11 Jul 2026 15:05:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Ghostcommit and the reviewers that don&apos;t open the PNG</title><link>https://0daynews.com/articles/2026-07-11-ghostcommit-png-prompt-injection-coderabbit-bugbot/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-11-ghostcommit-png-prompt-injection-coderabbit-bugbot/</guid><description>A PNG carrying prompt injection slips past AI code reviewers that never open image files, then talks a coding agent into exfiltrating a repo&apos;s .env secrets as a list of numbers.</description><pubDate>Sat, 11 Jul 2026 11:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Silver Fox ships MODBEACON, a Rust RAT with gRPC C2</title><link>https://0daynews.com/articles/2026-07-11-modbeacon-silver-fox-rust-rat-grpc-c2-qianxin/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-11-modbeacon-silver-fox-rust-rat-grpc-c2-qianxin/</guid><description>QiAnXin attributes a new Rust-based RAT called MODBEACON to Silver Fox, using gRPC streaming for encrypted C2 and SEO-poisoned installers for delivery.</description><pubDate>Sat, 11 Jul 2026 07:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Metasploit Weekly Adds Flowise CSV, macOS PackageKit</title><link>https://0daynews.com/articles/2026-07-11-metasploit-weekly-flowise-csv-packagekit-modules/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-11-metasploit-weekly-flowise-csv-packagekit-modules/</guid><description>Rapid7&apos;s Metasploit weekly drops two modules — a Flowise CSV Agent prompt-injection RCE and a macOS PackageKit LPE. New tooling, not new bugs.</description><pubDate>Sat, 11 Jul 2026 05:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days</title><link>https://0daynews.com/articles/2026-07-11-cisa-kev-balbooa-icagenda-joomla-file-upload/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-11-cisa-kev-balbooa-icagenda-joomla-file-upload/</guid><description>CISA added Balbooa Forms and iCagenda to KEV on July 10 — two unauthenticated file-upload RCEs in Joomla extensions. Federal due date is July 13.</description><pubDate>Sat, 11 Jul 2026 04:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>A seized crypto account that moved from a cell</title><link>https://0daynews.com/articles/2026-07-10-iossifov-seized-crypto-wallet-still-had-key/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-iossifov-seized-crypto-wallet-still-had-key/</guid><description>Rossen Iossifov, ten years into a laundering sentence, is charged with moving $290K from a seized crypto account. The interesting part is it still moved.</description><pubDate>Fri, 10 Jul 2026 23:55:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>OpenClaw patched a chain that started in a chat message</title><link>https://0daynews.com/articles/2026-07-10-openclaw-2026-6-6-nayak-whatsapp-host-rce-chain/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-openclaw-2026-6-6-nayak-whatsapp-host-rce-chain/</guid><description>OpenClaw 2026.6.6 closes three flaws that let a WhatsApp message reach the host as command execution. No public PoC, no observed exploitation.</description><pubDate>Fri, 10 Jul 2026 22:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Politie Points at Dutch Hackers in the 88GB Odido Leak</title><link>https://0daynews.com/articles/2026-07-10-politie-odido-dutch-speaker-vishing-shinyhunters-62m/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-politie-odido-dutch-speaker-vishing-shinyhunters-62m/</guid><description>Dutch National Police say strong indications point at Dutch attackers behind February&apos;s Odido breach: a Dutch-speaking vishing call to customer service, then 6.2M records leaked.</description><pubDate>Fri, 10 Jul 2026 18:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>A laser resets Tangem wallets, and there&apos;s no patch</title><link>https://0daynews.com/articles/2026-07-10-donjon-tangem-laser-fault-injection-eal6-samsung/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-donjon-tangem-laser-fault-injection-eal6-samsung/</guid><description>Ledger Donjon&apos;s laser fault-injection attack resets a Tangem card&apos;s password without the old one. There is no patch — Tangem ships no firmware updates.</description><pubDate>Fri, 10 Jul 2026 16:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>XRING: 260 bytes, no patch, three months of Alibaba silence</title><link>https://0daynews.com/articles/2026-07-10-foxio-xring-xquic-qpack-integer-underflow-alibaba-silence/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-foxio-xring-xquic-qpack-integer-underflow-alibaba-silence/</guid><description>FoxIO&apos;s Sébastien Féry disclosed a QPACK integer underflow in Alibaba XQUIC that crashes HTTP/3 servers with 260 bytes. Reported April 7. No reply. No patch.</description><pubDate>Fri, 10 Jul 2026 15:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>WP-SHELLSTORM ran 22 days with its door left open</title><link>https://0daynews.com/articles/2026-07-10-wp-shellstorm-socradar-exposed-server-funnel/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-wp-shellstorm-socradar-exposed-server-funnel/</guid><description>SOCRadar and Ctrl-Alt-Intel pulled 22 days of files off an exposed WP-SHELLSTORM server: 1.4M targets, 25K compromises, 5,700 live shells.</description><pubDate>Fri, 10 Jul 2026 14:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Ill Bloom is a $3.1M lesson in weak randomness, again</title><link>https://0daynews.com/articles/2026-07-10-illbloom-coinspect-weak-prng-mobile-wallet-drain/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-illbloom-coinspect-weak-prng-mobile-wallet-drain/</guid><description>Coinspect disclosed weak PRNG in wallet recovery-phrase generation; attackers drained $3.1M in a May sweep. The pattern — bad randomness, stolen keys — is old.</description><pubDate>Fri, 10 Jul 2026 10:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Meta&apos;s Muse Image defaults on for public Instagram</title><link>https://0daynews.com/articles/2026-07-10-meta-muse-image-instagram-public-default-impersonation-surface/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-meta-muse-image-instagram-public-default-impersonation-surface/</guid><description>Meta&apos;s new Muse Image model reuses public Instagram photos and reels by default — no notification, no watermark discussion, opt-out three levels deep in Sharing settings.</description><pubDate>Fri, 10 Jul 2026 07:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>The clearinghouse boom is not new, and neither is the fatigue</title><link>https://0daynews.com/articles/2026-07-10-clearinghouse-summer-athena-lightwell-old-pattern/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-clearinghouse-summer-athena-lightwell-old-pattern/</guid><description>Chainguard announced Athena. Red Hat and the White House announced Lightwell. Vulnerability clearinghouses have been getting reannounced since the 1980s.</description><pubDate>Fri, 10 Jul 2026 06:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>The ATO fight moved past credential stuffing</title><link>https://0daynews.com/articles/2026-07-10-hackernews-ato-verification-step-passkey-aftermath/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-hackernews-ato-verification-step-passkey-aftermath/</guid><description>The Hacker News argues account takeover shifted from credential stuffing to attacking verification — passkeys pushed the front door shut, so attackers moved.</description><pubDate>Fri, 10 Jul 2026 05:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Talos on &apos;attackers only need to be right once&apos;</title><link>https://0daynews.com/articles/2026-07-10-talos-hazel-winning-54-percent-defender-cliche/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-talos-hazel-winning-54-percent-defender-cliche/</guid><description>Cisco Talos&apos;s Hazel argues &apos;attackers only need to be right once&apos; is a cliché the defensive community should retire. It&apos;s overdue.</description><pubDate>Fri, 10 Jul 2026 04:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Datadog: 50+ dormant GitHub accounts mapping org charts</title><link>https://0daynews.com/articles/2026-07-10-datadog-dormant-github-ghost-accounts-org-enumeration/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-datadog-dormant-github-ghost-accounts-org-enumeration/</guid><description>Datadog Security Labs documents 50+ dormant GitHub accounts running months-long enumeration of corporate orgs, repos, and — in some cases — private code.</description><pubDate>Fri, 10 Jul 2026 03:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Helix: new data-extortion crew hits SharePoint via vishing</title><link>https://0daynews.com/articles/2026-07-09-helix-reliaquest-sharepoint-vishing-blackfile-overlap/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-09-helix-reliaquest-sharepoint-vishing-blackfile-overlap/</guid><description>ReliaQuest attributes new data-extortion crew Helix to vishing and device-code phishing against SharePoint. Infrastructure overlaps BlackFile.</description><pubDate>Thu, 09 Jul 2026 22:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>GigaWiper/BLUERABBIT: Go-based wiper, CyberAv3ngers-linked</title><link>https://0daynews.com/articles/2026-07-09-microsoft-gigawiper-bluerabbit-cyberav3ngers-israel-wiper/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-09-microsoft-gigawiper-bluerabbit-cyberav3ngers-israel-wiper/</guid><description>Microsoft and Binary Defense concurrently disclose a Go-based Windows destructive backdoor — wipe, fake ransomware, spyware in one binary — attributed to Iran-nexus CyberAv3ngers.</description><pubDate>Thu, 09 Jul 2026 20:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>INTERPOL First Light 2026: 5,811 arrests, $293M seized</title><link>https://0daynews.com/articles/2026-07-09-interpol-first-light-5811-arrests-293m-seized/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-09-interpol-first-light-5811-arrests-293m-seized/</guid><description>INTERPOL&apos;s Operation First Light 2026 arrested 5,811 fraud suspects across 97 countries, seized $293M and blocked 31,014 accounts over 3.5 months.</description><pubDate>Thu, 09 Jul 2026 11:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Friendly Fire: agents review the trap, then execute it</title><link>https://0daynews.com/articles/2026-07-09-ai-now-friendly-fire-claude-code-codex-review-exploit/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-09-ai-now-friendly-fire-claude-code-codex-review-exploit/</guid><description>AI Now Institute researchers show autonomous Claude Code and Codex can be tricked into running a hidden binary during their own security-review pass.</description><pubDate>Thu, 09 Jul 2026 10:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>AssuranceAmerica breach: 6.9M drivers, 4-month notice gap</title><link>https://0daynews.com/articles/2026-07-09-assuranceamerica-breach-6-9m-drivers-march-intrusion/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-09-assuranceamerica-breach-6-9m-drivers-march-intrusion/</guid><description>AssuranceAmerica confirms a March 16 intrusion exposed data on 6,998,886 drivers. Notification letters went out in July — a nearly four-month gap between detection and public notice.</description><pubDate>Thu, 09 Jul 2026 09:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>GhostApproval symlink bug hits six AI coding assistants</title><link>https://0daynews.com/articles/2026-07-09-wiz-ghostapproval-symlink-six-ai-coding-assistants/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-09-wiz-ghostapproval-symlink-six-ai-coding-assistants/</guid><description>Wiz research: Amazon Q, Cursor, Claude Code, Augment, Antigravity, Windsurf all approved one file path in the dialog while writing to another via symlinks.</description><pubDate>Thu, 09 Jul 2026 06:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Spain arrests suspected CARR logistics operator</title><link>https://0daynews.com/articles/2026-07-08-spain-palencia-carr-noname-logistics-arrest/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-spain-palencia-carr-noname-logistics-arrest/</guid><description>Spanish police detained a Palencia man tied to CyberArmy of Russia Reborn, Z-Pentest, and NoName057(16). The announcement lands nearly four months after the raid.</description><pubDate>Wed, 08 Jul 2026 23:45:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Krebs traces zero-day broker IRIS C2 to Wohl and Burkman</title><link>https://0daynews.com/articles/2026-07-08-iris-c2-krebs-wohl-burkman-zero-day-broker/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-iris-c2-krebs-wohl-burkman-zero-day-broker/</guid><description>Krebs ties IRIS C2, an offensive-security startup pitching zero-day acquisition, to Jacob Wohl and Jack Burkman — both convicted of felony fraud.</description><pubDate>Wed, 08 Jul 2026 20:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Sophos: Coding Agents Are Tripping the Attacker Detections</title><link>https://0daynews.com/articles/2026-07-08-sophos-coding-agents-tripping-edr-attacker-detections/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-sophos-coding-agents-tripping-edr-attacker-detections/</guid><description>Seven days of Sophos endpoint telemetry: Claude Code, Cursor, and Codex trip the same rules built to catch attackers — because behaviorally, they should.</description><pubDate>Wed, 08 Jul 2026 19:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Refused in Chat, Written in Code: Copilot&apos;s Workflow Gap</title><link>https://0daynews.com/articles/2026-07-08-copilot-workflow-jailbreak-arxiv-kumar-maple/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-copilot-workflow-jailbreak-arxiv-kumar-maple/</guid><description>Kumar and Maple&apos;s new arXiv preprint says Copilot&apos;s Claude and Gemini backends refused harmful prompts in chat but produced them 816-for-816 in a workflow.</description><pubDate>Wed, 08 Jul 2026 16:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>SCMBANKER active against Mexican banks — Elastic REF6045</title><link>https://0daynews.com/articles/2026-07-08-scmbanker-elastic-ref6045-mexican-banking-fraud/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-scmbanker-elastic-ref6045-mexican-banking-fraud/</guid><description>Elastic Security Labs is tracking SCMBANKER (REF6045), a PowerShell fraud toolkit hitting Mexican banks, fintechs, and crypto exchanges via ClickFix lures.</description><pubDate>Wed, 08 Jul 2026 15:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>KDDI Breach: 12M Emails, 7.6M Passwords via 3rd-Party 0day</title><link>https://0daynews.com/articles/2026-07-08-kddi-japan-isp-breach-12m-third-party-zero-day/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-kddi-japan-isp-breach-12m-third-party-zero-day/</guid><description>KDDI says a May 16 zero-day in unnamed third-party software exposed 12,233,087 email addresses and 7,616,173 passwords across five Japanese ISPs.</description><pubDate>Wed, 08 Jul 2026 13:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>CISA Adds Langflow and Two Joomla Builders to KEV</title><link>https://0daynews.com/articles/2026-07-08-cisa-kev-langflow-joomla-page-builder-adds/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-cisa-kev-langflow-joomla-page-builder-adds/</guid><description>CISA added three vulnerabilities to KEV on July 7 — a Langflow IDOR and two Joomla page-builder RCEs. Federal due date is July 10. Priority order below.</description><pubDate>Wed, 08 Jul 2026 05:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Proofpoint: China cluster raids university physics mail</title><link>https://0daynews.com/articles/2026-07-08-unk-masstraction-china-cluster-roundcube-universities/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-unk-masstraction-china-cluster-roundcube-universities/</guid><description>Proofpoint attributes a Roundcube-exploitation campaign against U.S. and Canadian university physics departments to a China-aligned cluster, UNK_MassTraction.</description><pubDate>Wed, 08 Jul 2026 04:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>China-Linked UAT-7810 Expands ORB Net With LONGLEASH</title><link>https://0daynews.com/articles/2026-07-07-uat-7810-longleash-orb-network-ruckus-asus/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-07-uat-7810-longleash-orb-network-ruckus-asus/</guid><description>Cisco Talos ties China-aligned UAT-7810 to LONGLEASH backdoor and an expanding ORB relay network built on unpatched Ruckus and ASUS routers.</description><pubDate>Wed, 08 Jul 2026 03:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Windows Device ID trail led FBI to Scattered Spider suspect</title><link>https://0daynews.com/articles/2026-07-08-scattered-spider-windows-device-id-court-filing-stokes/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-scattered-spider-windows-device-id-court-filing-stokes/</guid><description>A newly unsealed federal complaint says a Microsoft-recorded device ID tied the account behind a Scattered Spider intrusion to 19-year-old Peter Stokes.</description><pubDate>Wed, 08 Jul 2026 02:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Accenture Confirms Breach; Attacker Claims 35 GB Stolen</title><link>https://0daynews.com/articles/2026-07-07-accenture-confirms-breach-source-code-claim/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-07-accenture-confirms-breach-source-code-claim/</guid><description>Accenture confirmed a security incident. A threat actor is advertising 35 GB of alleged source code for sale. The volume claim is unverified — treat accordingly.</description><pubDate>Wed, 08 Jul 2026 00:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>DragonReturn Drops DcRAT on Indian Taxpayers</title><link>https://0daynews.com/articles/2026-07-06-operation-dragonreturn-china-nexus-dcrat-india-tax/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-06-operation-dragonreturn-china-nexus-dcrat-india-tax/</guid><description>Seqrite Labs attributes an ongoing spear-phishing campaign against Indian tax filers to a suspected China-nexus actor with infrastructure and tactical overlap to Silver Fox. First observed May 18.</description><pubDate>Mon, 06 Jul 2026 13:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>QuimaRAT: A $150 Cross-Platform Java RAT MaaS</title><link>https://0daynews.com/articles/2026-07-06-quimarat-java-cross-platform-maas-levelblue/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-06-quimarat-java-cross-platform-maas-levelblue/</guid><description>LevelBlue profiled a new cross-platform Java RAT sold as MaaS. No confirmed campaigns yet — but the price is low, the payload runs everywhere, and the loader is built to walk past SmartScreen. Assume it lands somewhere soon.</description><pubDate>Mon, 06 Jul 2026 13:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Flipper Zero Firmware Goes Maintenance-Only</title><link>https://0daynews.com/articles/2026-07-05-flipper-zero-firmware-maintenance-only-community-driven/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-05-flipper-zero-firmware-maintenance-only-community-driven/</guid><description>Flipper Devices says the Flipper Zero firmware is stable at 1.0 and full-time feature work is over. Community PRs run the future, filtered through GitHub Discussions voting and stricter review. Here&apos;s what changes.</description><pubDate>Sun, 05 Jul 2026 17:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Metasploit&apos;s July 3 Drop: SMB-to-Meterpreter, Peyara</title><link>https://0daynews.com/articles/2026-07-04-metasploit-weekly-smb-meterpreter-peyara-detection/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-04-metasploit-weekly-smb-meterpreter-peyara-detection/</guid><description>Rapid7 shipped an SMB-to-Meterpreter session upgrade and a Peyara Remote Mouse RCE module this week. Neither is novel research. Both change what your alerts will look like. Here&apos;s the tune.</description><pubDate>Sat, 04 Jul 2026 16:20:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>IGA Was Built Around Employment Records, Not Agents</title><link>https://0daynews.com/articles/2026-07-04-orchid-iga-ai-agents-lifecycle-gaps/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-04-orchid-iga-ai-agents-lifecycle-gaps/</guid><description>A contributed piece to The Hacker News from Orchid Security lays out where the joiner-mover-leaver model quietly fails for AI agents. Vendor-adjacent, but the gap analysis holds.</description><pubDate>Sat, 04 Jul 2026 11:15:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>Talos on Curiosity: A Skill That Doesn&apos;t Scale</title><link>https://0daynews.com/articles/2026-07-04-talos-catan-and-mouse-curiosity-defensive-skill/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-04-talos-catan-and-mouse-curiosity-defensive-skill/</guid><description>William Largent&apos;s Threat Source column this week reads as an essay on board games and pattern recognition. It&apos;s really an argument about the load-bearing skill that keeps a defender from becoming a checklist.</description><pubDate>Sat, 04 Jul 2026 05:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>PamStealer: A Fake Maccy Site Steals macOS Creds</title><link>https://0daynews.com/articles/2026-07-03-pamstealer-macos-maccy-impersonation-jamf/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-03-pamstealer-macos-maccy-impersonation-jamf/</guid><description>Jamf Threat Labs disclosed a new macOS credential stealer today that impersonates the Maccy clipboard app, validates the victim&apos;s login password against PAM in real time, and exfiltrates keychain and browser data. Apple Silicon only. Here&apos;s what defenders should do.</description><pubDate>Fri, 03 Jul 2026 20:30:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item><item><title>FBI Seizes NetNut Proxy, Google Degrades Popa Botnet</title><link>https://0daynews.com/articles/2026-07-03-fbi-netnut-popa-botnet-takedown/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-03-fbi-netnut-popa-botnet-takedown/</guid><description>The FBI seized hundreds of NetNut proxy domains on July 2; Google&apos;s Threat Intelligence Group, working with FBI and Lumen, cut the linked Popa botnet&apos;s usable device pool by millions the same day.</description><pubDate>Fri, 03 Jul 2026 05:00:00 GMT</pubDate><category>Threat Intel &amp; Field Notes</category><category>article</category></item></channel></rss>