Supply Chain Security
GitHub and PyPI Implement Time-Based Defenses Against Supply Chain Attacks
GitHub and PyPI have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.
Malware
Malvertising Campaign Uses JavaScript to Build Malware in Browser Memory
A new malvertising campaign is leveraging fake cryptocurrency websites to build malware directly in browser memory using malicious JavaScript. This innovative technique poses a significant risk to user security.
Malware
FakeGit Campaign Uses 7,600 GitHub Repos to Push SmartLoader Malware
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.
Cyber Crime
Understanding APT Collision: What It Is and Its Impact
APT collision occurs when multiple cyber espionage groups target the same victim, complicating incident response and threat attribution. This article explores the implications and dynamics of this phenomenon.
Cyber Crime
Hackers Abuse ViPNet Software to Target Russian Government Agencies
An advanced threat actor is exploiting the update mechanism of ViPNet software to target Russian organizations, including government agencies. This incident highlights the vulnerabilities within critical infrastructures.
Malware
Microsoft Warns of Surge in ACR Stealer Attacks
Microsoft has observed a surge in attacks using the ACR Stealer malware, targeting enterprise customers by stealing browser-stored passwords and sensitive documents.
Artificial Intelligence
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
The European Commission has ordered Google to allow rival AI assistants access to Android's microphone, camera, and screen. This decision aims to promote fair competition in the AI assistant market.
Infrastructure Security
Flaw in Claude Chrome Extension Allows Malicious Extensions to Trigger AI Actions
A flaw in the Claude Chrome extension could allow malicious extensions to trigger AI actions by simulating user clicks, potentially compromising connected services like Gmail and Google Docs.
Critical Vulnerabilities
Seven Severe Vulnerabilities Patched in VMware Avi Load Balancer
Seven severe vulnerabilities have been patched in the VMware Avi Load Balancer, which can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal.
Infrastructure Security
Japan's largest taxi operator shuts systems after cyberattack
Japan's largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. The incident raises concerns about the security of critical infrastructure in the transportation sector.
Artificial Intelligence
Claude Fable 5 Stays Free for Paid Users Until July 19
Anthropic has extended access to Claude Fable 5 for paid subscribers until July 19, allowing users to continue using the powerful AI model for an additional week.
Critical Vulnerabilities
CVE-2026-13822: Inappropriate Implementation in Chromium
The CVE-2026-13822 vulnerability has been identified in Chromium, impacting Microsoft Edge. The flaw relates to an inappropriate implementation in extensions, posing significant security risks.