Critical

Hackers abuse ViPNet software to target Russian govt agencies

BleepingComputer
Actively Exploited

Overview

Hackers are exploiting the update mechanism of the ViPNet software, a private networking solution, to target Russian government agencies and other organizations. This sophisticated attack has raised concerns about the security of critical infrastructure in Russia, as ViPNet is widely used by various state entities. Researchers have identified the malicious activity, which indicates a significant threat to the integrity of communications within these agencies. The ability to manipulate software updates poses serious risks, as it could allow attackers to gain unauthorized access or disrupt operations. This incident underscores the need for heightened security measures and vigilance among users of ViPNet and similar products.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: ViPNet private networking product suite
  • Action Required: Organizations using ViPNet should immediately review their update mechanisms and implement additional security measures to prevent unauthorized access.
  • Timeline: Newly disclosed

Original Article Summary

An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]

Impact

ViPNet private networking product suite

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations using ViPNet should immediately review their update mechanisms and implement additional security measures to prevent unauthorized access. Regular security audits and monitoring for unusual activity are also recommended.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Update, Critical.

Related Coverage

Windows KB5121767 OOB update fixes shutdowns on some Dell PCs

BleepingComputer

Microsoft has issued an out-of-band update, KB5121767, to address a shutdown issue affecting certain Dell PCs that arose after the installation of July 2026 Windows 11 security updates. Users reported that their devices were unexpectedly shutting down, which raised concerns about system stability and user productivity. This fix specifically targets Dell systems, indicating that the problem may be linked to specific hardware configurations. Users of affected Dell PCs are encouraged to install this update to prevent further shutdowns and ensure their systems operate correctly. This incident serves as a reminder of the complexities involved in software updates, especially when they interact with various hardware.

Jul 20, 2026

Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders

Infosecurity Magazine

Two police chiefs in the UK are calling for the introduction of Cybercrime Risk Orders following a recent prosecution involving Transport for London (TfL). They argue that the TfL case illustrates the growing risks associated with cybercrime and the need for stronger legal tools to combat it. The proposed orders would allow authorities to impose restrictions on individuals deemed to pose a cyber risk, potentially preventing future attacks. This initiative aims to enhance public safety and protect critical infrastructure from cyber threats, highlighting the urgent need for proactive measures in cybersecurity. The push for these orders comes as cyber incidents continue to rise, affecting various sectors across the UK.

Jul 20, 2026

Critical ServiceNow code execution flaw now exploited in attacks

BleepingComputer

A serious vulnerability (CVE-2026-6875) in the ServiceNow AI Platform is currently being exploited by attackers, according to threat intelligence firm Defused. This flaw allows unauthorized code execution, which can lead to significant security breaches for organizations using the platform. Companies that rely on ServiceNow for their IT service management need to be particularly vigilant, as the exploitation of this vulnerability could compromise sensitive data and disrupt services. The urgency of the situation is heightened by the fact that attackers are already taking advantage of this weakness, making it essential for affected organizations to act quickly to protect their systems.

Jul 20, 2026

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

The Hacker News

A newly discovered vulnerability in 7-Zip, identified as CVE-2026-14266, could allow attackers to execute arbitrary code on a user's machine when they open a specially crafted XZ archive. This security flaw stems from a heap-based buffer overflow that occurs during the processing of XZ chunked data. The issue was detailed by Trend Micro's Zero Day Initiative on July 15, but a fix was already released on June 25 with version 26.02 of 7-Zip. Users of 7-Zip should update to this latest version to protect themselves from potential exploitation. The vulnerability poses a serious risk, as it can run code in the context of the current process, making it a significant concern for anyone using the software.

Jul 20, 2026

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

The Hacker News

A Russian-speaking hacker, operating under the name 'bandcampro', has taken control of a botnet consisting of eight computers from dental clinics. This individual utilized Google's open-source Gemini CLI AI to assist in various malicious activities, including cracking passwords and managing the botnet. The analysis of 200 session logs from Gemini CLI between March and April 2026 reveals how the hacker integrated AI into their operations. This incident raises concerns about the increasing use of AI tools by cybercriminals, which can enhance their capabilities and make detection more challenging. Dental clinics, which may have less robust cybersecurity measures, are particularly vulnerable to such targeted attacks.

Jul 20, 2026

More alerts are making your team slower, and an outcome-based SOC fixes that

Help Net Security

Thom Langford, CTO of Rapid7, discusses how an overload of security alerts can hinder a Security Operations Center's (SOC) response time. He emphasizes that modern attackers often use stolen credentials and familiar tools, such as PowerShell, rather than custom malware, making it harder for SOC teams to distinguish genuine threats from noise. In one alarming case, attackers were able to call a help desk, reset a privileged cloud account, and expose thousands of passwords in just three minutes. This rapid access underscores the urgency of improving response strategies, as ransomware groups can deploy their payloads in under three hours. Langford advocates for an outcome-based SOC approach to streamline alerts and enhance overall security effectiveness.

Jul 20, 2026