📡 Tech & Security Digest — 2026-07-04
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- New ChocoPoC malware targets researchers via trojanized PoC exploits — Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can …
- Cisco finally confirms attackers exploiting Unified CM flaw — Cisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June. […]…
- CISA: Microsoft SharePoint RCE flaw now actively exploited — CISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May….
Hacker News
- The bottleneck might be the air in the room (118 pts)
- MSI Center – How to gain SYSTEM privileges in seconds (79 pts)
- Jamesob’s guide to running SOTA LLMs locally (334 pts)
- New serious vulnerabilities spiked around release of Claude Mythos Preview (94 pts)
- Espionage Against the European Parliament (354 pts)
- Ask HN: Is anyone experimenting with different ways of using LLMs for coding? (148 pts)
Krebs on Security
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials — Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain…
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos — Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, tra…
- New Avalon Malware Framework Packs CrownX Ransomware Capabilities — Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that’s distributed by means of a multi-…
- Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts — A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from e…
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its …
- Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer — An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unrep…
- Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild — A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber.
The vulnerabil…
- ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More — This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door…
- AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android — Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining “unrealistic bro…
- AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack — Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent.
Its Threat …