📡 Tech & Security Digest — 2026-07-24
Curated from Hacker News, security blogs, and tech publications.
Ars Technica
- OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face — “This is day one for cybersecurity in the age of agents,” Hugging Face CEO says. …
BleepingComputer
- Russian hackers exploit Zimbra zero-click flaw for email theft — CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Coll…
- New msaRAT malware uses Chrome, Edge browsers to route C2 traffic — The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or …
- Check Point warns of SmartConsole zero-day exploited in attacks — Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company’s SmartConsole graphical user interfa…
- New RefluXFS Linux flaw lets attackers gain root privileges — A nine-year-old race condition vulnerability in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite prot…
- Hackers abuse Notepad++ plugins to stealthily install malware — Ukraine’s CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke …
- South Korea discloses data breach impacting diplomats worldwide — South Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months and stole personal information be…
Hacker News
- Kimi K3 exploited the latest Redis server (56 pts)
- OpenAI’s accidental attack against Hugging Face is science fiction that happened (497 pts)
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication — A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.
The vu…
- Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access — Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) product…
- Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data — Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million …
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC — A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTow…
- Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access — Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka…
- Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs — Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can…
- Why Modern SOCs Need Multi-Layered Detections — The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today…
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning — Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (…
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution — Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber.
In a post …
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution — F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with …