Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed OperationCameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files across 234 subdirectories, including tooling, logs, shell history, and campaign records, with the researchers saying confirmed compromises were concentrated in Ukraine and Russia.
Most email defenses still operate on a decade-old model of scanning messages for malicious payloads, but the threat landscape has shifted dramatically as attackers deploy AI-powered phishing agents that can adapt and respond in real time. These next-generation phishing attacks use large language models to craft convincing messages, engage targets in conversation, and dynamically alter their approach based on victim responses.
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity."The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software working together – some components encrypt files, others silently steal documents or lock the screen, and another acts as a live chat between the attackers and their victims," Check Point Research's Jaromír Hořejšísaid. The large-scale campaign is being tracked by the cybersecurity company under the monikerStopAndProtectafter discovering a ransomware family of the same name in mid-May 2026.
Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems.
The Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, impacting Apple macOS, Microsoft SharePoint, VMware vCenter Server, and Microsoft Internet Information Services (IIS). The vulnerabilities include CVE-2025-24212 (Apple macOS SwiftExtension privilege escalation), CVE-2026-3413 (Microsoft SharePoint Server remote code execution), CVE-2023-34048 (VMware vCenter Server out-of-bounds write), and a Babuk-derived ransomware variant that exploits these flaws.