AI Safety Guidelines: 10 Essential Rules to Protect Data, Finances, and Reputation When Working with LLMs
🇷🇺 HabrJuly 18, 2026

AI Safety Guidelines: 10 Essential Rules to Protect Data, Finances, and Reputation When Working with LLMs

A detailed analysis of emerging AI-related security risks highlights how large language models can autonomously execute attack chains, fall victim to prompt injection, and cause cascading errors in complex workflows. The article examines real-world incidents such as the Anthropic vending machine pricing failure, the Meta Instagram account takeover via overly helpful AI support, and Copilot Studio data leaks through prompt injection. It emphasizes that while attack methods themselves are not revolutionary, AI agents can now scale them at machine speed with autonomous decision-making and recovery capabilities. The piece provides ten concrete safety rules covering financial controls, fact verification, data confidentiality, context pollution prevention, and access limitation. It also stresses that ultimate responsibility always remains with the human operator, not the AI system.

Translated from Russian

Read full article

Latest News

What Makes a Quality Anti-Detect Browser and Why Aurorium Built Its Own Solution
🇷🇺HabrJul 20

What Makes a Quality Anti-Detect Browser and Why Aurorium Built Its Own Solution

Aurorium explains the current state of the anti-detect browser market and why most existing tools fall short for professional use. The company highlights that true anti-detect browsers must modify browser fingerprints at the kernel level rather than relying on JavaScript injections. It details how solutions like incognito mode, virtual machines, and browser extensions fail to provide proper isolation and spoofing. Aurorium emphasizes its own approach of modifying Blink and V8 engines directly in C++ to create consistent, undetectable profiles. The article also covers legitimate use cases including QA testing, OSINT research, SEO monitoring, and secure web scraping. Advanced fingerprinting techniques such as Canvas and WebGL noise injection are explained alongside methods to detect superficial spoofing attempts.

Translated from Russian

LG Monitors Automatically Install McAfee App via Windows Update Without User Consent
🇷🇺AntiMalwareJul 20

LG Monitors Automatically Install McAfee App via Windows Update Without User Consent

Home users of Microsoft Windows have discovered that certain LG monitors automatically install companion software upon connection to a PC, followed by prompts to try a trial version of McAfee antivirus. The installation occurs through the standard Windows driver and software delivery mechanism without providing a clear, separate confirmation dialog. The LG Monitor App Installer requests broad access to system resources, raising concerns even though the application itself is not classified as malicious. YouTube channel Gamers Nexus identified the behavior across both new monitors and models released approximately three years ago, including units previously used in office environments. Manufacturers commonly supply utilities for display calibration, firmware updates, and monitor management, yet the process becomes problematic when it serves as an entry point for optional software and advertising. Users are advised to review installed applications and remove unnecessary LG utilities, while organizations should monitor automatic software deployment after connecting peripherals. Neither LG nor Microsoft has commented on the issue at the time of publication.

Translated from Russian

Google Quietly Rolls Out Android Developer Verifier App to Curb APK Sideloading Fraud
🇷🇺AntiMalwareJul 20

Google Quietly Rolls Out Android Developer Verifier App to Curb APK Sideloading Fraud

Android users are discovering a new system application called Android Developer Verifier with the package identifier com.google.android.verifier that Google installs automatically through system updates without any separate consent prompt. The service prepares devices for upcoming restrictions on installing APK files from unknown sources by checking whether an app is registered to a verified developer who has passed identity verification and supplied legal information to Google. This verification does not guarantee an application is safe but allows Google to associate it with a specific individual or company, helping combat social-engineering scams in which fraudsters pressure victims into disabling protections and installing malicious APKs. To install software from an unverified developer, users will need to enable developer mode, confirm they are not under duress, reboot the device, wait 24 hours, and re-authenticate with PIN or biometrics. The new requirements begin on 30 September in Brazil, Indonesia, Singapore, and Thailand, with worldwide expansion planned for 2027 and later. While the app can currently be removed, it is unclear whether future updates will restore it, and advanced users retain the option to sideload via ADB, which bypasses the new checks entirely.

Translated from Russian

Protecting Your Credit History: How to Check for Unauthorized Microloans and Set Up Self-Bans in Russia
🇷🇺SecuritylabJul 20

Protecting Your Credit History: How to Check for Unauthorized Microloans and Set Up Self-Bans in Russia

Russians often discover fraudulent loans taken out in their name only when banks reject their applications, revealing unknown debts in their credit reports. The article explains how to obtain a list of credit bureaus via Gosuslugi or the Central Bank of Russia, download free reports twice a year from each BKI, and thoroughly review contracts, applications, and creditor inquiries rather than focusing solely on credit scores. It details the new self-ban mechanism available from March 2025 on Gosuslugi and September 2025 via MFC, which blocks remote lending while allowing exceptions for mortgages and education loans. Practical advice covers pre-travel preparations, immediate actions after losing documents or phones, and the step-by-step process of disputing fraudulent entries with creditors, police, and the Central Bank. The guide also includes a table of common red flags and a checklist of ongoing security habits to prevent identity theft and financial fraud.

Translated from Russian

Securing CI/CD in Open Source Projects: Cilium’s Final Guide to Credentials, Verification, and Remaining Gaps
🇷🇺HabrJul 20

Securing CI/CD in Open Source Projects: Cilium’s Final Guide to Credentials, Verification, and Remaining Gaps

VK Cloud has published the third and final part of its translated Cilium series on protecting the software supply chain in open source projects. The article details how Cilium isolates CI and production credentials using separate GitHub environments, enforces keyless signing with Sigstore Cosign and SBOM attestations, and applies strict release controls that prevent compromised workflows from reaching production images. It also covers the team’s ongoing security operations, additional hardening measures such as immutable tags and mandatory DCO sign-offs, and a gap analysis against OpenSSF Scorecard and SLSA standards. The post examines GitHub’s 2026 Actions security roadmap and explains how planned platform features like dependency blocking, scoped secrets, and native egress firewalls align with Cilium’s existing controls. The piece concludes by emphasizing defense-in-depth and the importance of openly sharing supply-chain security practices across the open source community.

Translated from Russian

Walk In, You've Been Recognized: The Evolution of Identification Technologies in Modern Access Control Systems
🇷🇺HabrJul 20

Walk In, You've Been Recognized: The Evolution of Identification Technologies in Modern Access Control Systems

PERCo has expanded its PERCo-Web access control system with new BLE-enabled readers, companion mobile apps, and a joint facial recognition solution developed with the CRТ group. The update provides an opportunity to examine how identification methods in physical access control have developed without any single technology fully displacing the others. Traditional proximity and MIFARE cards remain the foundation, while QR codes, NFC, BLE, and biometrics each occupy specific niches based on convenience, security, and regulatory requirements. Russian Federal Law 572-FZ has fundamentally changed facial biometrics deployment by mandating use of the Unified Biometric System (EBS) or accredited commercial systems (KBS) for authentication. The article explains the technical workflow from reader to controller, the cryptographic protections of modern cards, the contactless advantages of BLE, and the privacy and compliance considerations that now make facial recognition a 'technology of trust' rather than simple convenience.

Translated from Russian

Hugging Face Confirms Production Infrastructure Breach by Autonomous AI Agent via Malicious Dataset
🇪🇸HispasecJul 20

Hugging Face Confirms Production Infrastructure Breach by Autonomous AI Agent via Malicious Dataset

Hugging Face has disclosed a sophisticated intrusion into its production environment that began with a malicious dataset and was executed by an autonomous AI agent. The attacker gained code execution in the dataset processing pipeline through a remote code execution loader and template injection, then escalated privileges and moved laterally across internal clusters over a weekend. Limited internal datasets and service credentials were accessed, but the company found no evidence of tampering with public models, Spaces, container images, or published packages. Forensic analysis processed over 17,000 attacker events using LLM-based agents, and the investigation ultimately relied on an open-weight model after commercial LLMs refused to handle real attack artifacts. Hugging Face responded by closing the initial execution paths, rebuilding compromised nodes, rotating all credentials and tokens, and tightening cluster admission controls. Users are strongly advised to immediately rotate Hugging Face access tokens, audit secrets in CI/CD pipelines and repositories, and apply least-privilege principles.

Translated from Spanish

Ransomware Attack Hits Coca-Cola Subsidiary Fairlife, Temporarily Halting US Production Systems
🇵🇹BoletimSecJul 20

Ransomware Attack Hits Coca-Cola Subsidiary Fairlife, Temporarily Halting US Production Systems

Fairlife, a company owned by Coca-Cola, temporarily suspended production operations in the United States after detecting unauthorized access to parts of its systems in a ransomware incident. The breach, publicly disclosed by Coca-Cola on July 16, 2026, affected environments directly linked to industrial production, prompting an immediate shutdown while investigations and recovery efforts continue. Fairlife manufactures milk, protein beverages, and other dairy products sold across the North American market, making the incident potentially disruptive to product availability, logistics, and internal processes. The company activated its incident response and business continuity protocols and engaged external cybersecurity specialists and consultants to assist with containment, investigation, and system restoration. No information has yet been released regarding data exfiltration, file encryption, or ransom demands, and the full scope of the attack remains under assessment. Coca-Cola has notified law enforcement authorities about the incident, while operations at Fairlife facilities in Canada were confirmed to be unaffected.

Translated from Portuguese

OpenSSL Patches HollowByte Vulnerability That Enables Denial-of-Service Attacks on TLS Connections with Just 11 Bytes
🇵🇹BoletimSecJul 20

OpenSSL Patches HollowByte Vulnerability That Enables Denial-of-Service Attacks on TLS Connections with Just 11 Bytes

OpenSSL has released fixes for a vulnerability dubbed HollowByte that allows denial-of-service attacks against servers using unpatched versions of the library. The flaw can be triggered by a malicious TLS request as small as 11 bytes and was addressed without a CVE or formal security advisory because it was classified as a hardening improvement. Researchers from Okta warn that the operational impact can be significant on internet-facing servers, as the issue occurs during the initial TLS handshake when vulnerable OpenSSL versions reserve memory based on the client-declared size before verifying actual data delivery. Attackers can open connections, claim they will send a large message, and then deliver only a tiny portion, leaving the server waiting indefinitely with reserved memory. In tests with NGINX, low-memory servers could be completely taken down while more powerful machines suffered substantial capacity loss without triggering abnormal traffic volumes. The patches are included in OpenSSL versions 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, and administrators are advised to update packages, restart affected services, and monitor for unusual memory growth.

Translated from Portuguese

🇷🇺

From Russian sources

Translated from Russian

View all (113) →
VK WorkSpace Adds Guest Access Without Accounts, Password Protection, Polls, and File Uploads Up to 30 MB
🇷🇺AntiMalwareJul 20

VK WorkSpace Adds Guest Access Without Accounts, Password Protection, Polls, and File Uploads Up to 30 MB

VK Tech has updated the cloud version of its VK WorkSpace Board to allow external participants such as clients, contractors, and other guests to join collaborative boards without creating an account. Access can be protected by a password set by the owner, who can also assign specific permissions including view-only, commenting, or full editing rights while restricting guests from creating new boards or viewing version history. Domain administrators can enforce mandatory password protection across all boards that permit guest access. Additional features include built-in polls with automatic result counting, support for uploading files up to 30 MB that are scanned by antivirus software, a mini-map for navigating large projects, and export options in SVG, PNG, JPG, PDF, and CSV formats. The service also received an English-language interface, addressing key use cases involving external collaboration as highlighted by VK Tech executive Petr Shcheglov.

Russian Users Report Widespread App Store Outages as Roskomnadzor Denies Any Role in Restricting Access
🇷🇺AntiMalwareJul 20

Russian Users Report Widespread App Store Outages as Roskomnadzor Denies Any Role in Restricting Access

Russian users began experiencing technical problems with the App Store starting early in the day, with the monitoring service Sboy.rf receiving 251 complaints about instability and failed downloads. The majority of reports originated from Moscow, accounting for 20 percent of cases, followed by Saint Petersburg at 13 percent and several other regions including Udmurtia, Kursk, Rostov, Bryansk oblasts and Stavropol Krai each contributing 5 percent. Affected users described inconsistent behavior of the App Store application itself along with difficulties downloading games and other software, where the Get button would appear but actual downloads would succeed only sporadically. In response to the growing number of reports, Roskomnadzor quickly issued a brief statement clarifying that it is not imposing any restrictions on access to the App Store. The exact cause of the disruptions remains unknown, Apple has not provided any official comment, and the scale of the incident is considered limited since only several hundred users have reported issues and not everyone is affected. Standard troubleshooting steps such as verifying internet connectivity, restarting the App Store application, and waiting for service restoration have been recommended to users.

New Russian Translations of Leading Cybersecurity Books on Ethical Hacking, Reverse Engineering, Malware Analysis, and Privacy Released
🇷🇺HabrJul 20

New Russian Translations of Leading Cybersecurity Books on Ethical Hacking, Reverse Engineering, Malware Analysis, and Privacy Released

A popular Russian library project has published fresh translations of more than a dozen top-tier English-language books covering ethical web hacking, bug bounty hunting, network protocol attacks, binary reverse engineering, malware analysis, fuzzing, and privacy protection. The updates continue the long-running “Materials on Hacking in Russian” series, with all books made freely available through the Hackbooks platform. Titles include Web Hacking 101, Real-World Bug Hunting, the official Nmap guide, Attacking Network Protocols, a comprehensive beginner’s reverse engineering textbook, and specialized works on binary format analysis, obfuscation techniques, Windows security internals, Practical Malware Analysis, Evasive Malware, and The Fuzzing Book. Additional volumes address the history of state surveillance, Crypto Wars, and the societal implications of mass data collection. Each book entry features detailed descriptions, practical examples, and direct links to the corresponding Hackbooks cards, enabling Russian-speaking researchers and students to study advanced information security topics without language barriers.

VPN Services Stabilize in Russia? Expert Warns Users Not to Relax as New Blocks May Be Coming
🇷🇺AntiMalwareJul 20

VPN Services Stabilize in Russia? Expert Warns Users Not to Relax as New Blocks May Be Coming

Russian users have recently noticed that personal VPN services and anonymizers are operating more stably after months of aggressive disruptions. Technical director Sergey Shcherbakov of the company Stakhanovets explains that the current improvement is likely only a temporary pause while deep packet inspection systems recalibrate. Earlier this year, DPI equipment was blocking traffic based on crude digital fingerprints of protocols such as OpenVPN and WireGuard, causing widespread collateral damage and connection drops. Operators are now believed to be collecting detailed data on ports, reconnection patterns, and obfuscation techniques to build more precise filters. Shcherbakov predicts the next wave of restrictions will arrive by late summer or early autumn, possibly shifting from outright blocks to throttling speeds during peak hours and delaying large file transfers. Meanwhile, users have adapted by maintaining multiple VPN clients, switching protocols and ports, and enabling obfuscation when needed.

Natalia Kasperskaya Advises Against Mass Biometric Rollout in Russia Citing High Costs, Reliability Issues and Deepfake Threats
🇷🇺AntiMalwareJul 20

Natalia Kasperskaya Advises Against Mass Biometric Rollout in Russia Citing High Costs, Reliability Issues and Deepfake Threats

Natalia Kasperskaya, president of InfoWatch and chair of the Domestic Software association, has warned that widespread deployment of biometric authentication across Russia would be both prohibitively expensive and insufficiently reliable. She argued that systems such as face recognition, which rely on creating detailed digital models from tens of thousands of points, require enormous computing power and data storage when scaled nationally. Kasperskaya highlighted practical limitations including poor camera quality, inadequate lighting and low-resolution source images that can prevent accurate recognition, especially on older smartphones. A growing concern she raised is the rapid improvement of deepfakes, which are becoming increasingly difficult for both humans and systems to distinguish from genuine images, thereby opening new avenues for fraud. She recommended using biometrics only in limited, high-value scenarios as a supplementary verification method rather than a universal replacement for other authentication techniques. The remarks come as Russia already operates the Unified Biometric System that enables access to Gosuslugi, electronic signatures, eSIM issuance and certain banking services.

Mimolet Dating App Shows Strong Data Protection Practices in Photo Handling, Moderation, and Infrastructure Review
🇷🇺HabrJul 19

Mimolet Dating App Shows Strong Data Protection Practices in Photo Handling, Moderation, and Infrastructure Review

A detailed technical review of the Russian dating service Mimolet reveals several well-implemented security and privacy measures across its photo upload pipeline, content moderation systems, and infrastructure choices. The app processes every uploaded image by validating its actual content rather than file extension, strips EXIF metadata, resizes it, and stores only the cleaned version. Public images undergo pre-publication checks using two AI models plus an additional verification pass before they appear in group chats or profiles. Complaints and blocks are available to all users without requiring a subscription, and moderator decisions are logged for accountability. The core API and database run in Russia while media files are stored in a domestic S3-compatible object storage, and the main AI features operate on dedicated GPU infrastructure managed by the team. The review highlights two areas needing improvement: clearer data retention timelines and a dedicated, trackable appeals process for blocked accounts.

🇨🇳

From Chinese sources

Translated from Chinese

View all (10) →
Houlang Security Research Institute Releases 2026 Cybersecurity Industry Map Highlighting AI-Driven Structural Transformation in China
🇨🇳嘶吼Jul 18

Houlang Security Research Institute Releases 2026 Cybersecurity Industry Map Highlighting AI-Driven Structural Transformation in China

The Houlang Security Industry Research Institute has officially published its 2026 Cybersecurity Industry Map following a multi-month survey that collected over 400 valid responses from representative Chinese security companies. The report details how AI-enabled industrial-scale attacks have moved from theory to practice, with large language models powering automated phishing, deepfake fraud, and multi-extortion ransomware that combines encryption with data theft. On the defensive side, AI is enabling real-time threat blocking, large-scale zero-trust deployments, privacy-preserving computation, and preparations for quantum-safe migration. The study observes a fundamental market shift from scale-based competition to value-based competition, where specialized vendors focused on vertical scenarios are gaining ground against broad-line vendors. Three irreversible trends are identified: AI integration as a survival requirement, movement from “large and comprehensive” to “specialized and refined” strategies, and continued strong growth in China’s cybersecurity sector driven by digital transformation and geopolitical factors.

CACTER Upgrades PhishSim Anti-Phishing Simulation System to Help Enterprises Reduce Phishing Risks in Four Easy Steps
🇨🇳嘶吼Jul 18

CACTER Upgrades PhishSim Anti-Phishing Simulation System to Help Enterprises Reduce Phishing Risks in Four Easy Steps

CACTER has released an updated version of its PhishSim anti-phishing drill system designed to replace traditional theoretical training with realistic, immersive phishing simulations. The platform can replicate common attack vectors including fake links, malicious attachments, and disguised QR codes while impersonating legitimate senders and official domains to mimic both APT and spear-phishing campaigns. Organizations using the system have reportedly lowered their average employee click rate from 23.88% to 4.16% through regular, customized exercises. Key features include a continuously updated template library tailored to specific industries and business scenarios, automated visual reports that rank departments and classify employee risk levels, and actionable remediation recommendations. The entire workflow is completed in just four steps—selecting templates, grouping employees, launching drills, and reviewing reports—allowing companies to run ongoing training without dedicated security specialists. The solution emphasizes measurable results and a closed-loop process of simulation, analysis, and improvement to strengthen email security posture.

OpenAI GPT-RED and Fudan AgentCyberRange Usher in the Era of AI Self-Play Cybersecurity
🇨🇳安全客Jul 17

OpenAI GPT-RED and Fudan AgentCyberRange Usher in the Era of AI Self-Play Cybersecurity

In July 2026, three major milestones signaled a shift from human-led to AI-driven security testing: OpenAI released GPT-RED, an automated red-team model trained via self-play reinforcement learning; Fudan University open-sourced AgentCyberRange, the first realistic cyber-range benchmark for AI agents; and the UK AISI quantified that frontier AI cyber-attack capabilities are doubling every four months. GPT-RED demonstrated 6.5× higher indirect prompt-injection success than human experts and discovered the previously unknown “Fake Chain-of-Thought” attack that bypasses reasoning models. AgentCyberRange evaluated six leading AI systems across 110 vulnerabilities in 15 real applications and 156-host enterprise ranges, with GPT-5.5 leading in both web exploitation and post-exploitation tasks. AISI’s multi-step scenarios showed models progressing from 1.7 to fully solving 32-step enterprise attacks within 18 months. Together the developments illustrate an accelerating “AI versus AI” paradigm in which stronger attack models generate better defensive training data, yet also highlight persistent gaps in OPSEC, deep vulnerability reach, and the high compute barriers to replicating such systems.

Bankrupt After Just Six Weeks of Production Shutdown: How a Cyber Attack Killed a 37-Year-Old German Textile Manufacturer and Exposed the Cruel Reality of Modern Cyber Threats
🇨🇳安全客Jul 14

Bankrupt After Just Six Weeks of Production Shutdown: How a Cyber Attack Killed a 37-Year-Old German Textile Manufacturer and Exposed the Cruel Reality of Modern Cyber Threats

A 37-year-old German textile processing company, ZEGO Textilveredelungszentrum, has filed for insolvency after a cyber attack halted its production lines for nearly six weeks, demonstrating that business interruption alone can destroy even well-established manufacturing firms without any data theft or ransom demands. The firm, based in Bavaria and serving automotive, workwear, and technical textiles industries, suffered the attack on March 29, 2026, leading to irrecoverable financial losses despite eventual system recovery. Managing Director Johannes Zenglein described the decision as one of the most difficult in the company's history, noting that the prolonged downtime caused severe cash flow disruption, lost orders, and customer attrition. The incident highlights a growing trend where cyber attacks on industrial systems lead directly to bankruptcy, as seen in prior cases like the 158-year-old British transport company Knights of Old and a German mobile phone repair firm. Key lessons include the critical need for robust business continuity plans, quantified downtime cost assessments, and supply chain resilience evaluations beyond traditional security measures. Unlike typical ransomware events, this attack required no encryption or extortion to achieve devastating results, underscoring that operational resilience is now a matter of corporate survival.

Ghostcommit Attack: Malicious Prompts Hidden in PNG Images Hijack AI Coding Agents to Steal .env Secrets
🇨🇳安全客Jul 13

Ghostcommit Attack: Malicious Prompts Hidden in PNG Images Hijack AI Coding Agents to Steal .env Secrets

A novel supply-chain attack called Ghostcommit allows attackers to embed prompt-injection instructions inside PNG images, bypassing AI-powered code review tools and tricking coding agents into leaking sensitive .env configuration files and API keys. Researchers from the ASSET Research Group demonstrated that direct plaintext instructions are immediately flagged by tools such as Cursor and CodeRabbit, but splitting the payload across an AGENTS.md file and a seemingly innocuous image evades detection. The attack remains dormant until a developer later asks the agent to perform normal development tasks, at which point the agent reads the image, extracts the .env contents byte-by-byte, and outputs them as a long tuple of ASCII numbers. Testing across 11 tool-model combinations revealed that success depends primarily on the runtime framework rather than the underlying LLM, with Cursor and Antigravity leaking secrets while Claude Code successfully blocked the attack in most cases. The team also released an open-source multimodal defense prototype based on Gemma 4 that runs on a single 4 GB GPU and achieved near-perfect detection rates on both known and unknown attack samples.

Phase II of National 100-City FDE Frontier Deployment Engineer Onboarding Program Officially Launches
🇨🇳安全客Jul 12

Phase II of National 100-City FDE Frontier Deployment Engineer Onboarding Program Officially Launches

The second phase of the nationwide "Hundred Cities On-the-Job Plan" for FDE Frontier Deployment Engineers has been announced, expanding opportunities across China. The initiative targets experienced engineers specializing in advanced deployment technologies and aims to place professionals in key urban centers. Building on the success of the first phase, this new round seeks to strengthen technical capabilities in critical infrastructure and cybersecurity domains. Participants will receive structured onboarding, training, and direct placement support in multiple cities. The program underscores growing demand for specialized deployment expertise amid rapid digital transformation.

🇵🇹

From Portuguese sources

Translated from Portuguese

View all (4) →
Zero-Day Vulnerability CVE-2026-15682 in AnyDesk Enables Denial-of-Service Attacks on Affected Systems
🇵🇹BoletimSecJul 18

Zero-Day Vulnerability CVE-2026-15682 in AnyDesk Enables Denial-of-Service Attacks on Affected Systems

A newly disclosed zero-day vulnerability in AnyDesk, tracked as CVE-2026-15682, allows attackers to trigger denial-of-service conditions on systems running the popular remote access tool. The flaw centers on a support information transmission feature that can be abused through Windows file system redirection mechanisms. An attacker with limited local access can manipulate these redirections to crash either the AnyDesk application or the underlying operating system. Because AnyDesk is widely deployed by support teams, managed service providers, and internal IT departments, the vulnerability poses a significant risk to remote assistance workflows and incident response operations. Until an official patch is released, organizations are advised to restrict code execution privileges, monitor for anomalous file system redirection activity, and apply updates as soon as they become available.

Cybercriminals Actively Exploiting Critical Zero-Day Vulnerabilities in SonicWall SMA1000 Appliances
🇵🇹BoletimSecJul 18

Cybercriminals Actively Exploiting Critical Zero-Day Vulnerabilities in SonicWall SMA1000 Appliances

Cybercriminals are actively exploiting a critical zero-day vulnerability in SonicWall SMA1000 appliances used for corporate remote access. The attack chain combines two flaws that together enable unauthenticated access to internal services and local privilege escalation, ultimately allowing remote code execution with maximum privileges on affected devices. The most severe issue, CVE-2026-15409, carries a maximum CVSS score of 10.0 and permits attackers to reach internal appliance services without authentication, while CVE-2026-15410 facilitates local privilege escalation. Impacted models include the SMA1000 Series 6210, 7210, and 8200v running firmware versions 12.4.3-03434 and 12.5.0-02800. SonicWall has confirmed that its SSL VPN firewalls and the SMA 100 product line remain unaffected. Compromised appliances have already been observed serving as stealthy entry points into corporate networks, where attackers harvested credentials, session data, and multi-factor authentication seeds before pivoting into Active Directory environments. Administrators are urged to apply the emergency patches that upgrade devices to firmware versions 12.4.3-03453, 12.5.0-02835, or later.

🇪🇸

From Spanish sources

Translated from Spanish

View all (3) →
Eleven Old Microsoft-Signed UEFI Shims Enable Bypass of Secure Boot on Linux Systems Still Trusting Microsoft Corporation UEFI CA 2011
🇪🇸HispasecJul 18

Eleven Old Microsoft-Signed UEFI Shims Enable Bypass of Secure Boot on Linux Systems Still Trusting Microsoft Corporation UEFI CA 2011

Eleven legacy UEFI shim bootloaders signed by Microsoft, all version 0.9 or earlier, can be abused to bypass UEFI Secure Boot on systems whose firmware still trusts the Microsoft Corporation UEFI CA 2011 certificate. Attackers who manage to place one of these vulnerable shims in the boot path can execute arbitrary code before the operating system loads, enabling bootkits, persistence, and kernel-level compromise with minimal visibility to traditional EDR tools. The issue stems not from a new kernel bug but from the continued validity of old, correctly signed binaries that have not yet been revoked in the DBX database. Microsoft has already issued DBX revocation updates, yet administrators must first upgrade shim, GRUB, and other boot components to modern versions that support SBAT before applying the revocations to avoid bricking systems. Affected implementations include Red Hat Enterprise Linux 7.2, CentOS 7.2, Oracle Linux 7.2, openSUSE, baramundi Management Suite up to 2024R1, WipeDrive 8.0.0–8.1.3, PC Doctor Service Center, and Abitti 1. The problem is tracked under CVE-2026-8863 and CVE-2026-10797, with public references available from The Hacker News, CERT/CC VU#616257, NIST NVD, and Help Net Security.

SonicWall Issues Emergency Hotfixes After Detecting Active Exploitation of Two Zero-Day Vulnerabilities in SMA1000 Appliances
🇪🇸HispasecJul 18

SonicWall Issues Emergency Hotfixes After Detecting Active Exploitation of Two Zero-Day Vulnerabilities in SMA1000 Appliances

SonicWall has confirmed active exploitation of two zero-day vulnerabilities in its SMA1000 series appliances, prompting the immediate release of hotfixes and a strict compliance deadline for U.S. federal agencies. The first flaw, CVE-2026-15409, carries a critical CVSS score of 10.0 and allows unauthenticated server-side request forgery (SSRF) through the Appliance Work Place interface, enabling attackers to force the device to make unauthorized requests to internal services. The second vulnerability, CVE-2026-15410, rated CVSS 7.2, permits authenticated code injection via the Appliance Management Console, allowing administrators to execute operating system commands. Affected models include SMA6210, SMA7210, and SMA8200v running specific vulnerable platform versions such as 12.4.3-03245 through 12.5.0-02800. CISA has added both CVEs to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch or decommission impacted systems by July 17, 2026. Indicators of compromise and recommended response actions, including log analysis and potential appliance reimaging, have been published to help organizations detect and mitigate potential intrusions.

🇯🇵

From Japanese sources

Translated from Japanese

View all (2) →
CISA Adds Three Exploited Vulnerabilities in FortiSandbox and SharePoint to KEV Catalog
🇯🇵Security NEXTJul 18

CISA Adds Three Exploited Vulnerabilities in FortiSandbox and SharePoint to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026. Two of the flaws affect Fortinet’s FortiSandbox malware analysis product and involve OS command injection issues that can be triggered via specially crafted HTTP requests without requiring authentication. The third vulnerability impacts Microsoft SharePoint and stems from unsafe deserialization of untrusted data, potentially allowing remote code execution over the network. CISA’s action follows public advisories released by the vendors in April and June 2026. The agency is urging organizations to apply available patches and mitigations immediately to reduce the risk of compromise.

CISA Urges Immediate Patching as Multiple SharePoint Server Vulnerabilities Confirmed Exploited
🇯🇵Security NEXTJul 18

CISA Urges Immediate Patching as Multiple SharePoint Server Vulnerabilities Confirmed Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory after confirming active exploitation of multiple vulnerabilities in Microsoft SharePoint Server. Four specific CVEs have been added to the Known Exploited Vulnerabilities (KEV) catalog, with one additional flaw flagged by Microsoft as high-risk even without confirmed exploitation. Successful attacks can lead to remote code execution, theft of Internet Information Services (IIS) machine keys, establishment of persistent access, and deployment of malware. CISA recommends applying the latest Microsoft patches immediately, verifying successful installation, enabling the Antimalware Scan Interface (AMSI), and strengthening monitoring through Microsoft Defender Antivirus. Organizations are also advised to avoid direct internet exposure of SharePoint servers and to implement Layer 7 reverse proxies with enhanced logging to reduce the attack surface.