NEWSCar screens were infected through their own update channel
Kaspersky documents the first malware built for Android car head units. It did not arrive through a dodgy app: it came through the unit own update channel.
ReadIn-depth analysis, threat research and industry perspective to help you stay ahead of what's next – new CVEs, model releases and attack patterns, without the breathless coverage.
NEWSKaspersky documents the first malware built for Android car head units. It did not arrive through a dodgy app: it came through the unit own update channel.
Read
NEWSCVE-2026-59310 allows unauthenticated code execution on VMware vCenter. Broadcom shipped the fix on 29 July; exploitation began five days later. 361 victims across 47 countries.
Read
NEWSCVE-2026-71362 lets an attacker switch into another customer’s session on Adobe Commerce, with no account and nothing for the victim to click. CVSS 9.1, fixed in the August update.
Read
NEWSMicrosoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. The malware effectively bypasses standard defenses by targeting active sessions. To mitigate this risk, implement strict conditional access policies and mandate frequent re-authentication for all cloud resources.
Read
NEWSAI models left to both interpret and execute commands eliminate critical cybersecurity oversight. When systems perform actions autonomously, they become vulnerable to adversarial prompt injection that can lead to large-scale unauthorized activity. Organizations must move away from automated execution for sensitive tasks to prevent systemic failures. To protect your environment, implement mandatory manual approval workflows for all AI-initiated actions that modify system states or data.
Read
NEWSWhen chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances. This exploitation facilitates unauthorized network access and potential ransomware deployment. Patch your appliances immediately to the latest firmware version to defend against this critical threat.
Read
NEWSCybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem. The campaign, dubbed ViteVenom, uses blockchain-based infrastructure to hide C2 communication and deliver a remote access trojan. This attack highlights the ongoing risk of malicious dependencies in modern software development. Audit your development dependencies for unauthorized packages immediately.
Read
NEWSGovernment organizations are increasingly targeted by ransomware operators who understand that public service disruption is unacceptable. These attackers exploit critical IT infrastructure and sensitive citizen databases to force ransom payments. Implement a zero-trust architecture and ensure you have immutable, offline, and frequently tested backups to protect against operational disruption and data extortion.
ReadKaspersky documents the first malware campaign with an infection chain built for car head units. It arrived through TWCore, the legitimate system app that handles analytics and updates, delivered over the MQTT update channel. It calls home every 90 minutes and supports nine commands.

CVE-2026-59310 allows unauthenticated code execution on VMware vCenter. Broadcom shipped the fix on 29 July; exploitation began five calendar days later. 361 victim IPs across 47 countries, with Germany and France in the top five, and a Babuk-derived ransomware as the payload.

CVE-2026-71362 lets an attacker switch into another customer's session on Adobe Commerce, with no account, no admin rights and nothing for the victim to click. CVSS 9.1, patched in the August update. Adobe reports no known exploitation; Sansec says its WAF is already blocking attempts.

Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. The malware effectively bypasses standard defenses by targeting active sessions. To mitigate this risk, implement strict conditional access policies and mandate frequent re-authentication for all cloud resources.

AI models left to both interpret and execute commands eliminate critical cybersecurity oversight. When systems perform actions autonomously, they become vulnerable to adversarial prompt injection that can lead to large-scale unauthorized activity. Organizations must move away from automated execution for sensitive tasks to prevent systemic failures. To protect your environment, implement mandatory manual approval workflows for all AI-initiated actions that modify system states or data.

When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances. This exploitation facilitates unauthorized network access and potential ransomware deployment. Patch your appliances immediately to the latest firmware version to defend against this critical threat.

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem. The campaign, dubbed ViteVenom, uses blockchain-based infrastructure to hide C2 communication and deliver a remote access trojan. This attack highlights the ongoing risk of malicious dependencies in modern software development. Audit your development dependencies for unauthorized packages immediately.

Government organizations are increasingly targeted by ransomware operators who understand that public service disruption is unacceptable. These attackers exploit critical IT infrastructure and sensitive citizen databases to force ransom payments. Implement a zero-trust architecture and ensure you have immutable, offline, and frequently tested backups to protect against operational disruption and data extortion.

Noteworthy reports indicate Iranian state-affiliated actors are tracking U.S. military personnel via mobile telemetry, while a new macOS malware, CrashStealer, has emerged. Additionally, AI agents like OpenClaw have been exploited via WhatsApp, and defense contractor TKMS confirmed a ransomware attack. To protect your organization, treat all AI-integrated agents as high-risk components, conduct rigorous security assessments before deployment, and ensure mobile device location permissions are strictly managed to prevent sensitive data exposure.

Ukrainian President Volodymyr Zelensky has appointed Yevhenii Khmara, formerly the acting head of the Security Service of Ukraine (SBU), as the nation's new acting defense minister. Khmara, a major general with extensive counterintelligence and unconventional warfare experience, is tasked with modernizing military command and integrating intelligence-led operations into the national defense strategy. Partners and contractors are advised to review communication security protocols and prepare for tighter oversight in defense procurement processes.

The Colonel stops taking online orders and may close stores after a logistics partner's systems go down – another reminder that supply-chain outages hit customer-facing services first.

Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.
The Gold Eagle program will allow industry, critical infrastructure operators and the government to use artificial intelligence to rapidly detect, prioritize and patch cybersecurity vulnerabilities, officials said.

Progress Software has confirmed that a zero-day vulnerability in its ShareFile product was the cause of recent service disruptions for customers using the Storage Zones Controller. The company has since released a fix to address the security flaw and is actively working to restore services for impacted users. While initial reports highlighted instability, the company's subsequent patch is intended to remediate the underlying exploit. If you are operating a ShareFile Storage Zones Controller environment, verify that you have applied the latest vendor-supplied patch immediately to regain service stability and mitigate potential compromise.
Microsoft shipped the fix for CVE-2026-45659 in May's cumulative update but published the bulletin weeks later. CISA has confirmed active exploitation and added it to the KEV catalog: the CVSS 8.8 flaw is RCE via unsafe deserialization. On-prem SharePoint? Confirm you're on the May cumulative update.
CVE-2026-48558 scores maximum CVSS severity in SimpleHelp, an RMM tool widely used by managed service providers; exploitation is tracked via the "TaskWeaver" loader. One vulnerable MSP endpoint can fan out into every client network that MSP touches – if you outsource IT, this is the week to ask your provider directly.
A cluster of critical flaws across JetBrains' on-prem tools chains into auth bypass, account takeover and RCE – the sharpest a CVSS 9.8 from predictable account-restore codes. An IDE runs with your privileges: patch before opening untrusted repositories in any JetBrains product.
Claude Sonnet 5 went live June 30 and is the new default for Free and Pro users, pitched squarely at agentic work: planning, tool use and autonomous runs at a level that used to need a pricier model. If Claude is wired into your tooling, benchmark against your own eval set before switching wholesale.