📡 Tech & Security Digest — 2026-07-14
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Hackers backdoor Jscrambler npm package with infostealer malware — The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloade…
- CISA warns of actively exploited RCE flaws in Joomla extensions — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa …
- Lidl discloses online shop breach after service provider hack — German discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole their personal information in …
- Australia warns of global campaign targeting vulnerable CMS platforms — The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS)…
- New U-Boot flaws could enable stealthy firmware attacks — Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot,…
Hacker News
- Show HN: Clawk – Give coding agents a disposable Linux VM, not your laptop (189 pts)
- Show HN: Hackney – Compare Uber, Lyft, Waymo, and Robotaxi Prices (44 pts)
- Linux on the Sega 32X. Who needs hardware synchronization primitives anyway? (121 pts)
- Apple’s new SpeechAnalyzer API, benchmarked against Whisper and its predecessor (526 pts)
- Show HN: Jacquard, a programming language for AI-written, human-reviewed code (82 pts)
- A Study of Microsoft’s Early 2026 Rollout of Claude Code and GitHub Copilot CLI (56 pts)
Krebs on Security
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges — Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public.
Th…
- Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws — Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully expl…
- 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros — Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take …
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensio…
- Attackers Exploit ‘Ill Bloom’ Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets — Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how s…
- Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS — Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi O…
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) cat…
- SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users — A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix l…
- ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More — Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That’s supposed to be the good news. The catch is tha…
- New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic — The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON.
Chinese cy…