Security Affairs
Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION|Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems|Australian energy provider Origin Energy disclosed a data breach impacting customer data|Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices|Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged|UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations|The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating|US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers|U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog|Chaos ransomware deploys browser-based msaRAT to evade network detection|Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting|Check Point patches actively exploited SmartConsole authentication bypass flaw|Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION|Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems|Australian energy provider Origin Energy disclosed a data breach impacting customer data|Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices|Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged|UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations|The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating|US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers|U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog|Chaos ransomware deploys browser-based msaRAT to evade network detection|Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting|Check Point patches actively exploited SmartConsole authentication bypass flaw|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems Australian energy provider Origin Energy […]

newsletter

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems
Australian energy provider Origin Energy disclosed a data breach impacting customer data
Google Fined €890M Under EU Digital Markets Act Over Search and Play Store Practices
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations
The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
Chaos ransomware deploys browser-based msaRAT to evade network detection
Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting
Check Point patches actively exploited SmartConsole authentication bypass flaw
CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections
Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft
U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog
OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug
Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access
Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers
AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits

International Press – Newsletter

Cybercrime

Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware  

A blow against one of the world’s most dangerous phishing groups  

The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results

Swiss train maker tells ransomware crooks to get off at the next stop

Europol-led action against nihilistic violent extremist network “The Com”  

Illinois Man Sentenced to Over Six Years in Prison for Identity Theft and Wire Fraud  

Origin Energy investigates alleged cyber attack after hacker claims to have stolen data of two million customers in ransom bid 

Malware

SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor  

HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels  

AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware  

Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel  

Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI  

Hacking

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)      

World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

5-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533  

Smashing the ServiceNow Sandbox – Pre Authentication RCE  

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

OpenAI and Hugging Face partner to address security incident during model evaluation  

The Vulnerability That Turned Adobe’s 300M-Install Extension Into a Full WhatsApp Takeover 

CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

American Hackers-for-Hire Proposal Sparks Heavy Criticism  

Intelligence and Information Warfare  

Brochure Cybersecurity advisory Russian state actors are compromising IP cameras  

UAC-0145 Primary Compromise Vectors as of July 2026  

Inside Russia’s Camera-Hacking Espionage Campaign 

Blog JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake 

CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity  

UAC-0099: LUNCHPOKE, BURNYBEAR, updated to MATCHBOIL.V2 and using Notepad++ 8.8.3

Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458

Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged  

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure 

Cybersecurity

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Identity Attacks Overtake Exploits as Top Ransomware Cause  

LG to Ban Residential Proxies from Smart TV Apps  

Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains

Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber  

Google hit with $1 billion EU fine, in ‘constructive’ talks to avoid more penalties  

Is Patching Dead? Vulnerability Management in the Post-Mythos Era

How AI guardrails are impeding the work of offensive cybersecurity researchers  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)