Waqas
5479 posts
I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests
Anthropic found Claude accessed systems at three real businesses after a testing error gave its AI models live internet access during cybersecurity evaluations.
July 31, 2026
Wordfence Finds Critical Backdoor in ARVE WordPress Plugin
A backdoored ARVE WordPress Plugin release could grant attackers administrator access with one token, but WordPress.org blocked automatic distribution to WordPress sites.
July 31, 2026
Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover
Cybersecurity researchers at Wiz found CosmosEscape in Azure's Gremlin API, exposing a master key that could access any Cosmos DB account. Microsoft fixed it, with no customer impact found.
July 30, 2026
LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach
LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people.
July 30, 2026
CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.
July 29, 2026
22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking
Researchers found 24,650 public BMC interfaces leaking IPMI password hashes, exposing servers to offline password cracking through a decades-old protocol flaw.
July 29, 2026
ShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 Leak
EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data.
July 28, 2026
Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations
July 28, 2026
Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation
Certighost allowed a low-privilege domain user obtain a valid Domain Controller certificate through AD CS. Microsoft patched the issue in the July security updates.
July 27, 2026
Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens.
July 27, 2026