📡 Tech & Security Digest — 2026-07-08
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Accenture confirms breach after hacker offers stolen data for sale — IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other dat…
- CISA orders feds to patch max severity ColdFusion flaw by Friday — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw …
- Chinese hackers develop LONGLEASH malware to expand ORB network — Chinese hackers tracked as ‘UAT-7810’ are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet…
- BeyondTrust warns of critical flaws in remote access software — BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could al…
Hacker News
- Tenda firmware (multiple versions) contains hidden authentication backdoor (178 pts)
- Fixing analog audio on the $2.58 HDMI-to-VGA adapter (94 pts)
- AI Meets Cryptography 1: What AI Found in Cloudflare’s Circl (106 pts)
- GitLost: We Tricked GitHub’s AI Agent into Leaking Private Repos (94 pts)
- Chat Control 1.0 and 2.0 Explained (606 pts)
Krebs on Security
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure — Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig.
The vul…
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials — Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain…
- Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities — A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departm…
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos — Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, tra…
- New Avalon Malware Framework Packs CrownX Ransomware Capabilities — Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that’s distributed by means of a multi-…
- Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts — A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from e…
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its …
- 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros — Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take …
- BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA — BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that…
- AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android — Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining “unrealistic bro…