
Hosted by Johannes Ullrich · EN

When the "Autonomous Attacker" Is Your Own AI Modelhttps://isc.sans.edu/diary/When%20the%20%22Autonomous%20Attacker%22%20Is%20Your%20Own%20AI%20Model/33180 Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbrahttps://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204ahttps://cert.gov.ua/article/6318634https://cybersecuritynews.com/hackers-abuse-notepad-plugins/ Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channelhttps://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

Rondo Meets Geoserverhttps://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176 Oracle July Patch Updatehttps://www.oracle.com/security-alerts/cpujul2026.html OpenAI and Hugging Face partner to address security incident during model evaluationhttps://openai.com/index/hugging-face-model-evaluation-security-incident/ Checkpoint July 2026 Security Advisory (CVE-2026-16232)https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

Captive Portal Detectionhttps://isc.sans.edu/diary/Captive%20Portal%20Detection/33172 Critical SolarWinds Serv-U Updatehttps://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm Zimbra Update with Critical Security Fixeshttps://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/ Apple Fixed Hide My E-Mail Leakhttps://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

WordPress Exploitation Underway (CVE-2026-63030)https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168 HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channelshttps://www.group-ib.com/blog/hollowgraph-microsoft-365/ Gitea Vulnerablity CVE-2026-58443https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2 My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

Scans for Hikvision Intelligent Security APIhttps://isc.sans.edu/diary/Scans%20for%20Hikvision%20Intelligent%20Security%20API/33164 LG Monitor Spywarehttps://www.techradar.com/televisions/lgs-gaming-monitors-and-tvs-are-facing-a-user-revolt https://www.youtube.com/watch?v=Q9uefFYe6bM Huggingface Hackhttps://huggingface.co/blog/security-incident-july-2026 Wordpress Core RCEhttps://wp2shell.com

German Federal Information Security Office Analyzes Windows Hello for Businesshttps://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.htmlhttps://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Windows_dissected/AP1_Windows-Hello-for-Business.pdf?__blob=publicationFile&v=7 NGINX Vulnerabilityhttps://my.f5.com/manage/s/article/K000162097 7-Zip XZ Decompression CVE-2026-14266https://www.zerodayinitiative.com/advisories/ZDI-26-444/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

DShield SIEM Updatehttps://isc.sans.edu/diary/Recent%20DShield%20SIEM%20Update/33156 Microsoft Patch Tuesday vs. Dell Intel Innovation Platform Framework (IPF) drivershttps://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875 Zoom Account Takeover Patchhttps://www.zoom.com/en/trust/security-bulletin/zsb-26014/ Forgotten UEFI shims undermining Secure Boothttps://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Herehttps://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202026%20-%20The%20AI%20Acopolypse%20is%20Here%20/33154 LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerabilityhttps://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive Progress confirms ShareFile zero-day flaw behind Storage Zone shutdownhttps://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/ xAI/Grok Exfiltrating Data and Secretshttps://cereblab.com My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

Someone Is Scanning for Your MCP Servers and AI Assistant Credentialshttps://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150 Improve Router Hygiene to Protect Against Russian State-Sponsored Targetinghttps://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a OAuth Client ID Spoofinghttps://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854https://www.veeam.com/kb4869 My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

Progress Sharefile Emergency Shutdown Noticehttps://status.sharefile.comhttps://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/ U-Boot Vulnerabilitieshttps://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification Nightmare Eclipse Releases Next Microsoft Defender Exploithttps://blog.projectnightcrawler.dev/posts/2026-07-09-some-interesting-findings-in-windows-defender/ Cisco Increases Patch Cadencehttps://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich