IT Security Newsletter - 7/24/2026
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
A Russian state-sponsored threat group has been stealing sensitive data from governments and commercial organizations since July 2025 via a novel exploit in popular Linux-based enterprise software, U.S. authorities and cyber officials from more than a dozen other countries warned in a joint cybersecurity advisory Thursday. Laundry Bear's most recent espionage campaign involves the exploitation of a zero-day vulnerability in Zimbra Collaboration Suite that wasn't patched until November 2025. READ MORE...
OpenAI-Hugging Face attack doesn't mean agents are evil - unless you tell them to be
Open AI's admission this week that its agents escaped the sandbox and autonomously hacked model repository Hugging Face has spawned more apocalyptic warnings of agents gone bad than we can count. Thankfully, Renato Marinho, chief research officer at Morphus Labs and a SANS Technology Institute instructor, brought some sanity to the discussion. "It is tempting to read this as 'AI can now hack autonomously, the sky is falling,'" Marinho said in a Thursday blog. "Resist that." READ MORE...
Australian energy provider Origin says data breach exposes client data
Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers' personally identifiable information (PII). The company has 4.8 million customers and is currently investigating how many of them have been impacted to inform them of the risk via individual notifications. Origin Energy is Australia's largest energy retailer, providing electricity, natural gas, and broadband internet services to millions of clients across the country. READ MORE...
Researchers replace downloaded macOS apps with evil twins, Apple shrugs
Apple macOS apps that have been downloaded from the internet and run at least once can be swapped with malicious versions, a pair of researchers say, calling into question the thoroughness of the company's "Gatekeeper" defenses. As Apple explains, "When a user downloads and opens an app, a plug-in, or an installer package from outside the App Store, Gatekeeper verifies that the software is from an identified developer, is notarized by Apple to be free of known malicious content." READ MORE...
Beyond the Play Store: How Android threats really spread
You probably think of your phone's security the way you think of your front door: as long as you're downloading apps from the Play Store, you're safe. And for the most part, that's true. Google reviews apps before they're published. But some apps reach your phone without ever passing through the Play Store. Take Albiriox, a banking Trojan-as-a-service discovered late last year. It's an Android Remote Access Trojan (RAT) built for on-device fraud. READ MORE...
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. The campaign has been attributed to a threat cluster tracked as UAC-0099, which primarily targets organizations in Ukraine and has previously been linked to providing initial access for attacks carried out by APT44, also known as Sandworm. READ MORE...
AI arms race in line for a reckoning after OpenAI hacking incident
OpenAI chief executive Sam Altman earlier this month endorsed the characterization of its latest model as a rottweiler "who will grab the problem by the throat and not let go until it is done." The San Francisco AI lab discovered this week that its GPT-Sol 5.6 model escaped company controls and carried out a major hack. Staff involved in testing and security at OpenAI were unsurprised but completely "freaked out" by the incident. READ MORE...
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
A popular Vatican website and mobile app has been leaking hundreds of thousands of users' names and email addresses. "Click to Pray" is the Vatican's official prayer app. Users can sign up for access to daily prayers, and a steady stream of papal content on their phones or computers. It's available on iOS and Android, and via a Web browser. According to its website, Click to Pray is used in more or less every country on the planet. READ MORE...
The automotive software vulnerabilities hiding in your dashboard
Pop the hood on a new car and you won't find much you can fix with a wrench. What you'll find is software, and a lot of it. The screen in the dash probably runs Android or a flavor of Linux. The system watching the road for you might run QNX or VxWorks, the same kind of code that flies aircraft and runs factory floors. Carmakers spent the last decade making this switch, and it bought them app stores, wireless updates, and quicker release cycles. READ MORE...
Bruce Schneier: Why AI Needs a "Genie Coefficient"
Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what you ask an AI to do and the unspoken assumptions about how you want the AI to do it. We propose a new metric: the Genie coefficient. There's often a gap between one person's request and another's understanding. Most of the time, we bridge it using general knowledge. READ MORE...
- ...in 1911, American archeologist Hiram Bingham re-discovers the lost Incan citadel of Machu Picchu in the Peruvian mountains.
- ...in 1943, WWII's Operation Gomorrah begins, with UK and American bombers raiding Hamburg over the course of four months.
- ...in 1958, US Vice President Richard Nixon and Soviet Premier Nikita Khrushchev have their famous "Kitchen Debate" at the American National Exhibition in Moscow.
- ...in 1969, Apollo 11 splashes down safely in the Pacific Ocean. Two years later, Mission Commander Neil Armstrong becomes a professor at the University of Cincinnati.







