📡 Tech & Security Digest — 2026-07-25
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Russian hackers exploit Zimbra zero-click flaw for email theft — CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Coll…
- OnTrac notifies customers of data breach after network hack — OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its custom…
- Hermes AI agent used to automate attack on Thai Finance Ministry — A threat actor used the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation activity during an alleged breach of Thail…
- Hackers abuse Notepad++ plugins to stealthily install malware — Ukraine’s CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke …
Hacker News
- Be skeptical of OpenAI’s rogue hacker agent story (479 pts)
- My security camera shipped a GitHub admin token in its login page (573 pts)
- Kimi K3 exploited the latest Redis server (202 pts)
- Self-host your mail server (106 pts)
Krebs on Security
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
- Who Runs the Ransomware Group ‘The Gentlemen?’ — A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of…
The Hacker News
- Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication — A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.
The vu…
- Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access — Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) product…
- Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data — Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million …
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC — A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTow…
- Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access — Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka…
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link — Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link …
- NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats — Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and say…
- Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say — Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.
…
- Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs — Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can…
- Why Modern SOCs Need Multi-Layered Detections — The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today…