Visualização normal

Antes de ontemHackread – Latest Cybersecurity, Tech, Crypto & Hacking News

“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails

Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services.

Kali365 Exploits Microsoft Device Login to Access US Corporate Data

Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks.

Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

Shai-Hulud npm worm spreads through Keyv and hundreds of packages with 2 billion monthly downloads, stealing npm, GitHub, cloud and CI credentials in real time.

COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft

Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on devices.

Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short

N-able says attackers bypassed N-central authentication, reached managed client devices and installed Cloudflare tunnels that survived server access revocation.

LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach

LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people.

PhantomEnigma Infects Organizations with Malware via Hijacked Government Websites

PhantomEnigma abuses Brazilian government websites and trusted email channels to spread malware, target banks, evade security checks, and maintain access.

ShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 Leak

EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data.

Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections

Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations

Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation

Certighost allowed a low-privilege domain user obtain a valid Domain Controller certificate through AD CS. Microsoft patched the issue in the July security updates.

Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts

Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens.

Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks

Russian hackers from the TA488 group exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.

OpenAI Models Breached Hugging Face During Internal Cyber Test

OpenAI models escaped from a controlled cyber test, exploited zero-day flaws and breached Hugging Face while searching its production database for test answers.

Hugging Face Says Autonomous AI Agent System Breached Production Infrastructure

An AI-led cyberattack breached limited Hugging Face datasets and service credentials, while public models, Spaces and published packages showed no signs of tampering.

Fake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones

Group-IB says scammers are targeting Céline Dion fans through Facebook, duplicate digital tickets and fake websites impersonating Ticketmaster, AXS and the venue site.

Microsoft’s July 2026 Patch Tuesday fixes 622 flaws and 2 exploited zero-days

Microsoft’s July 2026 Patch Tuesday fixes 622 CVEs, including exploited AD FS and SharePoint flaws, plus the disclosed BitLocker bypass requiring urgent action.

Upwind Finds Coordinated Supply Chain Campaign Compromising Multiple AsyncAPI npm Packages

Upwind links compromised AsyncAPI npm packages to a coordinated supply chain attack spanning repositories, publishing pipelines, and developer systems at risk.
❌
❌