Visualização normal

Antes de ontemHackread – Latest Cybersecurity, Tech, Crypto & Hacking News

Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows

At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines.

Thermo Fisher Patches Forensic DNA File Tampering Flaw in Its Software

Thermo Fisher patched CVE-2026-17583 in five supported DNA analysis products by adding digital signatures that help laboratories detect modified forensic files.

COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft

Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on devices.

Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short

N-able says attackers bypassed N-central authentication, reached managed client devices and installed Cloudflare tunnels that survived server access revocation.

Wordfence Finds Critical Backdoor in ARVE WordPress Plugin

A backdoored ARVE WordPress Plugin release could grant attackers administrator access with one token, but WordPress.org blocked automatic distribution to WordPress sites.

Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover

Cybersecurity researchers at Wiz found CosmosEscape in Azure's Gremlin API, exposing a master key that could access any Cosmos DB account. Microsoft fixed it, with no customer impact found.

CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In

Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.

💾

22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking

Researchers found 24,650 public BMC interfaces leaking IPMI password hashes, exposing servers to offline password cracking through a decades-old protocol flaw.

Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation

Certighost allowed a low-privilege domain user obtain a valid Domain Controller certificate through AD CS. Microsoft patched the issue in the July security updates.

Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks

Russian hackers from the TA488 group exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.

OpenAI Models Breached Hugging Face During Internal Cyber Test

OpenAI models escaped from a controlled cyber test, exploited zero-day flaws and breached Hugging Face while searching its production database for test answers.

New Ubuntu Desktop Vulnerability Turns Local Access Into Root Control

A vulnerability in snap-confine lets an unprivileged user gain root access on affected Ubuntu Desktop systems. Install the latest snapd update to fix the issue.

PromptFiction Flaw Auto-Submitted Hidden Prompts in Claude Desktop

A one-click Claude Desktop flaw allowed attackers to submit concealed instructions without review, exposing chats and enabling code execution on some systems remotely.

Microsoft’s July 2026 Patch Tuesday fixes 622 flaws and 2 exploited zero-days

Microsoft’s July 2026 Patch Tuesday fixes 622 CVEs, including exploited AD FS and SharePoint flaws, plus the disclosed BitLocker bypass requiring urgent action.

Upwind Finds Coordinated Supply Chain Campaign Compromising Multiple AsyncAPI npm Packages

Upwind links compromised AsyncAPI npm packages to a coordinated supply chain attack spanning repositories, publishing pipelines, and developer systems at risk.

UNK_MassTraction Exploits Roundcube Flaws Against US, Canadian Universities

China-linked UNK_MassTraction targets US and Canadian universities through Roundcube flaws, stealing sessions and opening access to research mail servers.

GitLost: GitHub’s AI Agent Tricked Into Leaking Private Repository Data

Noma Labs details GitLost, a prompt injection flaw that made GitHub's AI agent expose private repo data through a crafted public issue and guardrail failures.
❌
❌