📡 Tech & Security Digest — 2026-07-02
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- New ChocoPoC malware targets researchers via trojanized PoC exploits — Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can …
- Webinar: Why traditional email security is no longer enough — Modern phishing, business email compromise, and account takeover attacks increasingly exploit trusted identities and legitimate business workflows, ma…
- DHS confirms hackers breached HSIN info-sharing platform — The Department of Homeland Security is investigating a cyberattack that compromised the Homeland Security Information Network (HSIN), a sensitive info…
- Adobe patches seven max severity ColdFusion, Campaign flaws — Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic…
Hacker News
- Apple ‘Hide My Email’ vulnerability reveals peoples’ real email addresses (270 pts)
- A new Android malware from Google (297 pts)
- ArXiv’s Next Chapter (278 pts)
- Kimi K2.7 Code is generally available in GitHub Copilot (118 pts)
Krebs on Security
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos — Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, tra…
- Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse — A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against…
- Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts — A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from e…
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its …
- Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer — An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unrep…
- Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild — A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber.
The vulnerabil…
- ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More — This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door…
- AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android — Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining “unrealistic bro…
- New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets — DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough&nb…
- Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service — Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Ga…