30 Jul, 2026

Man gets six years for hacking 750 women’s Snapchat accounts

An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos, which he later traded or sold online. After being charged in December, 26-year-old defendant Kyle Svara admitted in February to having used various social engineering tactics to phish […]

2 mins read

Clop ransomware targets Windchill, FlexPLM in data theft attacks

The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecurity company ReliaQuest reported on […]

4 mins read

New Dolphin X malware uses AI to rank high-value targets

A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. The malware was analyzed by Varonis Threat Labs researcher Daniel Kelley, who spotted it being advertised on a cybercrime forum by a vendor using the alias “Kontraktnik,” […]

3 mins read

Australian energy provider Origin says data breach exposes client data

Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers’ personally identifiable information (PII). The company has 4.8 million customers and is currently investigating how many of them have been impacted to inform them of the risk via individual notifications. Origin Energy is Australia’s largest energy retailer, […]

2 mins read

Fake Claude app promoted by Bing ads pushes SectopRAT malware

A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. At least 29 organizations were compromised between July 21-22 during the malicious operation, which researchers call FakeAgent. The attackers used a malicious Claude Artifact hosted on Claude’s legitimate […]

2 mins read

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. According to CISA, Laundry Bear has targeted and compromised users in organizations associated with the Defense Industrial Base (DIB), […]

3 mins read

Hackers abuse Notepad++ plugins to stealthily install malware

Ukraine’s CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. The campaign has been attributed to a threat cluster tracked as UAC-0099, which primarily targets organizations in Ukraine and has previously been linked to providing initial access for attacks […]

2 mins read

Microsoft 365 outage affects Teams, SharePoint and other services

Microsoft is impacted by a massive outage affecting Teams and Microsoft 365 services, primarily affecting users in North America. At 11:11 AM ET on July 23, Downdetector recorded 2,403 reports, sharply above its normal baseline of 29. SharePoint accounted for 78% of the complaints, followed by Excel at 11% and the Microsoft 365 Admin Center at 6% […]

3 mins read

EU fines Google $1 billion for search, app store antitrust violations

The European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union’s Digital Markets Act (DMA), which ensures fair online competition. Google was designated a gatekeeper for Google Search in September 2023, with non-compliance investigations opened in March 2024. On Thursday, the Commission said the company favored its own services on […]

2 mins read

New RefluXFS Linux flaw lets attackers gain root privileges

A nine-year-old race condition vulnerability in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. Dubbed RefluXFS by the Qualys Threat Research Unit (TRU), which found and reported it, the security flaw affects systems with an XFS filesystem with reflink enabled (a default configuration on […]

3 mins read