A vulnerability linked to ClaudeBleed affects Chrome extensions, allowing them to access potentially sensitive information from users' Gmail and Calendar accounts. Despite eight patches being released, this flaw remains unaddressed, raising concerns for users who rely on these services. The issue stems from how extensions interact with the browser, which could lead to unauthorized data access. This poses a significant risk, as malicious extensions could exploit this vulnerability to harvest private data without user consent. Users of Chrome should be cautious about the extensions they install and regularly check for updates to ensure their security.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Help Net Security
Researchers at Tracebit have developed a new defense mechanism against AI-driven attacks, using a technique they call 'context bombs.' Instead of focusing on hijacking AI agents, this approach aims to disrupt them before they can compromise a targeted system. The concept involves deploying decoy resources and credentials, known as canaries, that alert defenders when they are targeted by attackers. This method provides an early warning system, allowing organizations to respond more quickly to potential breaches. The innovation is significant as it shifts the focus from purely offensive tactics in AI to defensive strategies that can protect sensitive environments.
Recent research indicates that passwords generated by AI chatbots may not be as secure as users expect. While these chatbots can create seemingly random strings of characters, studies show that they often produce passwords that are more predictable than traditional methods. This raises concerns for users who rely on AI for password generation, as it could leave them vulnerable to cyberattacks. Security experts advise against using AI-generated passwords and recommend sticking to established password management practices. This issue is particularly relevant as more individuals and businesses turn to AI tools for everyday tasks, highlighting the need for caution in their use.
Hackread – Cybersecurity News, Data Breaches, AI and More
Telegram's t.me links have stopped working due to the .ME registry placing the domain on serverHold. While users can still access the app itself, the disruption of these links raises questions about the reliability of the service. The exact reason for this action by the registry is unclear at this time. This incident could impact users who rely on t.me links for sharing content and connecting with others on the platform. It's important for Telegram users to stay informed about the situation as it develops, especially if the outage continues or expands.
The Cybersecurity and Infrastructure Security Agency (CISA), alongside the NSA, FBI, and international partners, has issued a warning about increased Russian cyber activity targeting essential sectors such as communications, energy, and government. This alert comes as tensions rise globally, and officials are concerned about potential disruptions to critical infrastructure. The advisory emphasizes the need for organizations in these sectors to bolster their cybersecurity measures to defend against possible attacks. The warning serves as a reminder of the ongoing threat posed by state-sponsored cyber actors. Companies and government agencies are urged to remain vigilant and proactive in safeguarding their systems against these risks.
ABB has identified multiple vulnerabilities in its T-MAC Plus version 4.0-24 software, which could allow attackers to exploit the system in various ways. These vulnerabilities include issues like file disclosure, broken access controls, cross-site scripting (XSS), and an insecure network protocol that could lead to denial-of-service attacks. Affected users are urged to update to version 4.0-25, which contains fixes for these issues. The vulnerabilities are considered serious, with CVSS scores ranging from 7.4 to 9.9, indicating that they pose significant risks to security. Companies using this software should prioritize applying the update to protect their systems from potential exploitation.
Rockwell Automation's 1715-AENTR EtherNet/IP Adapter has a serious vulnerability (CVE-2026-10577) affecting versions up to 3.003. This flaw exposes a debug port that lacks proper authentication controls, allowing attackers to gain unauthorized access to critical functions. If exploited, they could read or delete files, halt tasks, modify memory, and alter I/O states, threatening the device's confidentiality, integrity, and availability. This vulnerability is particularly concerning as it impacts sectors like energy and manufacturing, where security is crucial. Users are advised to upgrade to version 3.011 or later to mitigate the risks associated with this vulnerability.
ABB has identified a vulnerability, CVE-2026-31431, in its ABB Ability Edgenius platform, which affects versions 3.2.0.0 to 3.2.4.0. This vulnerability is linked to a flaw in the Linux kernel's cryptographic interface that could allow a locally authenticated user to gain elevated privileges, potentially leading to full control of the system. While there have been no reports of this vulnerability being exploited in the wild, ABB recommends that users update to version 3.2.4.1 to mitigate the risk. Users should also limit access to their systems to enhance security. This incident underscores the importance of timely software updates and access controls in protecting against potential exploits.
ABB has identified a vulnerability in its Advant Master Online Builder products that could allow unauthorized code execution due to improper handling of search paths for loading dynamic link libraries (DLLs). Affected versions include Control Builder A versions up to 1.4/4 and multiple iterations of 800xA for Advant Master. To mitigate the risk, ABB has released updates that resolve the vulnerability, advising users to upgrade to specific patched versions. Importantly, the vulnerability requires physical access to the system, which limits its exploitability. However, users are still urged to manage access strictly and enforce strong security practices to prevent potential exploitation.
CISA has issued a warning about active exploitation of several vulnerabilities in on-premises SharePoint Server instances, specifically CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. These vulnerabilities allow attackers to execute remote code and potentially steal sensitive data from affected systems. All supported versions of SharePoint Server, including the Subscription Edition, 2019, and 2016, are at risk. Organizations are advised to monitor their SharePoint Servers for unusual activities and to apply the latest patches from Microsoft. Additional vulnerabilities have been identified but are not yet known to be exploited, emphasizing the need for prompt updates and hardening measures to prevent possible breaches.
The Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are being actively exploited in the wild. The vulnerabilities include two related to SonicWall SMA1000 Appliances, specifically a server-side request forgery and a code injection vulnerability. Additionally, there are two Microsoft vulnerabilities affecting Active Directory Federation Services and SharePoint Server, which involve insufficient access control and missing authentication for critical functions, respectively. These vulnerabilities pose significant risks, especially to federal agencies, as they can lead to total asset control by attackers post-exploitation. CISA's guidance encourages all organizations to prioritize remediation of these high-risk vulnerabilities to enhance their security posture.
A recent study by researchers at KU Leuven examined 85 popular crypto wallet extensions and discovered that many of them leak sensitive information, allowing for user tracking. The way these wallets communicate with websites and blockchain servers can inadvertently link different wallet addresses belonging to the same user, making it easier for outsiders to track their online activities. This poses a significant risk to user privacy, particularly for those who rely on these wallets for cryptocurrency transactions. The findings raise concerns about the security measures in place for these extensions and highlight the need for better user protection against potential tracking and data leaks.
SAP has issued a warning regarding 16 vulnerabilities in various products, with three of these classified as critical. The affected products include NetWeaver, Commerce Cloud, and AppRouter. These flaws could potentially allow attackers to exploit weaknesses in the systems, which is particularly concerning for organizations relying on these platforms for their operations. Users of these SAP products should take immediate action to address these vulnerabilities to protect their data and systems. The update comes as part of SAP's July 2026 security updates, emphasizing the ongoing need for vigilance in cybersecurity practices.
SAP has released patches for serious vulnerabilities found in its NetWeaver, Approuter, and Commerce Cloud products. These flaws could allow attackers to access and alter sensitive data, disrupt system availability, and create inconsistencies in request-response processes. This is a significant concern for businesses using these SAP solutions, as it could lead to data breaches or operational disruptions. Companies are urged to apply the patches promptly to safeguard their systems and data integrity. The vulnerabilities were disclosed recently, emphasizing the need for organizations to stay vigilant and proactive in updating their software.
FIFA's network has been found to have significant vulnerabilities that could be accessed by individuals with minimal permissions. This raises serious security concerns about the integrity of sensitive information within FIFA's systems. The implications are broad, particularly for user data and operational security, as attackers could potentially exploit these weaknesses to gain unauthorized access. It is crucial for FIFA and similar organizations to address these vulnerabilities to protect against potential breaches and ensure the safety of their digital infrastructure. The situation highlights the need for ongoing security assessments in high-profile organizations.