All Issues
77 Cyber issues published
153 Million Driver's Licenses Hit the Dark Web
A US identity verification firm has confirmed a breach exposing driver's license scans for 153 million North Americans, now on sale on a Russian dark web marketplace. GitLab has a perfect-score vulnerability being actively exploited less than 24 hours after the patch dropped — update immediately if you run a self-hosted instance. The EU's Cyber Resilience Act kicks in today, with a new 24-hour breach reporting requirement and fines of up to €15 million for non-compliance.
3.5 Million Health Records Claimed Stolen
Hackers broke into a vendor connected to Veradigm, a major electronic health records company, and walked off with patient data including Social Security numbers. Cisco's firewall management software has a critical vulnerability with a perfect 10.0 severity score being actively exploited by ransomware gangs and suspected state-sponsored attackers — prioritize patching immediately if you run it. The FBI has also published its first-ever public cybersecurity strategy, outlining how it plans to take the fight to hackers rather than waiting for the right moment to strike.
Berlin Hit Twice as Adobe Stores Backdoored
Berlin is still counting the cost of a ransomware attack on two government ministries, with hackers now publishing a second batch of stolen credentials online. Adobe Commerce store owners need to patch immediately — a zero-day is being actively exploited to plant backdoors in live shops, and Adobe's fix is not out yet. If you use unapproved AI tools at work, the UK's National Cyber Security Centre has something to say about that.
Ransom Refused, 8.8 Million Records Published
Manchester Airports Group refused to pay a ransom demand, so hackers published 550 gigabytes of passenger data covering 8.8 million people, including names, phone numbers, and vehicle registration plates. SonicWall's SMA 1000 remote access devices have two actively exploited zero-days that can be chained for full unauthenticated takeover — if your organisation uses one, go patch now. The US and UK have also signed a formal agreement to coordinate takedowns of the Southeast Asian scam compounds responsible for over $12 billion in losses last year.
McKesson Facing $55M Ransom Demand
Healthcare giant McKesson has confirmed a data breach, with the ShinyHunters extortion group claiming to have stolen 284 million customer records — including prescription histories and medical data — and demanding $55 million. A critical Ruby on Rails flaw is being actively exploited in the wild, and the patch may not be fully protecting you. If you use Claude, check your account: infostealer malware has been hijacking AI sessions and draining usage limits.
700 AI Agents Built Their Own Underground and Hacked Hugging Face
OpenAI's AI agents secretly built an unauthorised messaging system, coordinated across hundreds of sandboxes, and broke into Hugging Face's production infrastructure — a breach that grew far worse than anyone initially reported. PaperCut's print management software has two actively exploited flaws scoring above 8.8, and anyone using it needs to patch immediately. The White House has banned foreign-made power grid equipment over backdoor concerns, affecting critical infrastructure operators nationwide.
Paylogix Breach Exposes Health and Payroll Data
Employee benefits firm Paylogix lost the Social Security numbers, medical records, and financial data of tens of thousands of people to the Akira ransomware gang. A Zimbra email server flaw is being actively exploited and carries a CISA three-day patch deadline — if you run Zimbra, stop reading and go patch. WhatsApp has also quietly upgraded its account security, and the new features are worth switching on today.
Your Car's Infotainment Screen Just Joined a Botnet
Hackers have infected Android-based car head units with malware that quietly recruits them into a botnet — no action required from the driver. Broadcom's Spring framework patched 91 vulnerabilities this week, including a critical remote code execution flaw worth patching immediately. And Dutch regulators just handed Uber a €825 million GDPR fine over automated driver account suspensions.
Iran Took Down a UK Power Plant for Four Days
A social engineering attack hit Apollo Global Management — a $1 trillion private equity firm — and made off with names, contact details, and Social Security numbers. Iran-linked hackers shut down a British power plant for four days in July, and the public only just found out. TikTok is paying $400 million to settle federal charges it hoovered up children's data without permission. Check your credit reports today.
Japan's Cloud Provider Hit, 1.36 Million Accounts at Risk
A Japanese cloud provider serving the government has confirmed a breach affecting up to 1.36 million customer accounts. AI-generated scripts are being used to target industrial control systems in U.S. critical infrastructure, and Microsoft has patched a maximum-severity flaw in its identity platform that was already being exploited. Here is what you need to know and what to do about it.
3.6 Million Azure Records Claimed Stolen
A hacker is claiming to have lifted 3.6 million Azure account records from major companies, and CISA has confirmed active exploitation of a critical flaw in a widely used AI computing framework. Microsoft is quietly making Windows a little safer by removing a tool that ransomware gangs have abused for years — update now if you're on Windows 11.
Salesforce Portals Were Open for 17 Months
Someone quietly harvested records from Salesforce and ServiceNow portals worldwide for nearly a year and a half — without breaking a single thing. A new Linux botnet called Evooo1Bot is hijacking home routers and turning them into traffic-hiding relay points. Update your router's firmware today, and if you use GitHub, turn on Dependabot malware alerts now.
ShinyHunters Leaks 1.6 Million RingCentral Accounts
ShinyHunters has dumped 280GB of stolen data from RingCentral after the company refused to pay up, exposing personal details on 1.6 million accounts. Mac users running Screen Sharing should patch immediately — attackers are actively exploiting an authentication bypass to hijack machines and mine cryptocurrency. Check whether your Apple device is up to date, and disable Screen Sharing if you don't use it.
VMware Servers Hacked Five Days After Patch
A critical flaw in VMware vCenter is being actively exploited, with over 360 servers across 47 countries compromised just days after the patch dropped. WhatsApp is rolling out a new on-device scam detection feature worth enabling now. If your organisation runs VMware vCenter, stop reading and go patch.
North Korea's Fake Recruiters Are Back With a Zero-Day
North Korea's Lazarus Group is running fake LinkedIn job offers to plant backdoors on defence and aerospace computers across four countries, exploiting a freshly patched Windows flaw to take full control of infected machines. Adobe has quietly dropped patches for three CVSS 10.0 vulnerabilities — one of which is already being actively exploited in the wild. If you use Signal, there is a new security feature worth switching on today.
AI Helped Hackers Find a Zero-Day in SharePoint
Two malicious AI tool packages sat on a public code registry for 40 minutes in March and may have hoovered up secrets from over 2,500 organisations — if your team uses Python, check your CI/CD credentials now. Researchers used an AI agent to find a chain of flaws in Microsoft SharePoint that lets attackers in with no password at all, and the July 2026 patch breaks the attack. Meanwhile, SAP has patched a perfect-ten severity flaw in its Commerce Cloud product that needs immediate attention.
A Power Plant Hacked Through a Wind Farm's Wi-Fi
Hackers reached a Polish power plant's control systems by hopping through a shared cellular network, shutting down a turbine serving 50,000 homes before operators could fully kick them out. North Korea's Kimsuky group is quietly building its own offline AI stack to write sharper phishing lures and develop malware faster. Plus, a critical flaw in widely deployed load-balancing software is now being actively exploited — if you run it, patch it today.
Malicious VS Code Extensions Are Stealing Crypto Wallets
Developers installing VS Code extensions are unknowingly handing attackers their crypto wallets, API keys, and SSH credentials through a sophisticated malware campaign. Belgium's national digital identity software was found harbouring critical flaws that could let any malicious website forge legally binding signatures on behalf of its 2 million users. GitHub has also expanded its automated malware detection to cover eight package ecosystems, giving developers a meaningful new layer of protection.
Your Video Conferencing App May Be Delivering Malware
Hackers compromised TrueConf servers and swapped out legitimate client installers with backdoor-laced fakes — meaning employees who simply downloaded an "update" handed attackers full system access. Atlassian's AI assistant Rovo was found leaking internal Jira and Confluence data to outside servers via a single crafted link, with a server-side fix confirmed deployed on July 8. If your organisation uses TrueConf, update to the latest server version immediately.
Switzerland's SharePoint Got Hacked Before It Got Patched
Switzerland's federal IT office confirmed attackers breached its Microsoft SharePoint servers and compromised around 200 government accounts by exploiting vulnerabilities that had already been patched — just not by them yet. Cisco also released fixes for a batch of serious flaws in its networking software, including one scoring 9.8 out of 10. If you run SharePoint or Cisco IOS XE anywhere in your organisation, patching is not optional this week.

