<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 7/30/2026

SHARE

Top News

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. Email security company Proofpoint spotted the activity a week ago targeting various organizations, including government entities in the U.S. and Europe, and companies in the telecommunications, financial, hospitality, and aerospace sectors. READ MORE...

Breaches

Semiconductor Firm Analog Devices Discloses Data Breach

Semiconductor company Analog Devices, Inc. (NASDAQ: ADI) has disclosed a data breach stemming from a hacker attack detected last month. Analog Devices is a Massachusetts-based company with roughly 24,000 employees and $12 billion in annual revenue that designs and manufactures analog, mixed-signal, and digital signal processing chips used across industrial, automotive, and communications equipment. Analog Devices said it detected unauthorized access to certain systems on June 23. READ MORE...

Hacking

North Korea's elite hackers turned on their own government - and got caught

For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme. But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead. And, it doesn't sound as if it has ended that well for them. READ MORE...


Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems

Security researchers at Tenable suspect the Iran-linked faux hacktivist outfit CyberAv3ngers was behind the cyberattack that disrupted more than 30 Minnesota water facilities. Neither state-level nor federal officials have made any claims regarding attribution for the attacks, however, Tenable reckons the operational pattern is consistent with the crew's previous raids, noting the timing relative to recent government warnings. READ MORE...

Malware

Tengu botnet reboots Linux devices to survive removal

A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a machine-learning system the company uses to identify malware families that do not match known signatures. Researchers first observed the dropper reaching their honeypots through Telnet credential brute-force attacks. READ MORE...


OpenAI's Rogue Model Claims More Victims Beyond Hugging Face

Following the recent incident in which cutting-edge OpenAI models went rogue during a security benchmark and breached popular AI model store Hugging Face, OpenAI has revealed that more organizations were compromised in this incident than initially disclosed. OpenAI detailed a security incident last week in which a combination of OpenAI agents based on GPT-5.6 Sol and "an even more capable pre-release model" broke containment during a sandboxed security evaluation. READ MORE...

Exploits/Vulnerabilities

Hidden prompt turns Microsoft Copilot into an AI worm

A security researcher has demonstrated how Microsoft Copilot for Word can be tricked into spreading a self-propagating prompt-injection "AI worm." The attack silently alters documents and embeds its own hidden instructions into newly created files, allowing it to spread through normal document-sharing workflows without macros or traditional malware. The technique allows an attacker to hide a JSON-formatted prompt as white text on a white background inside a Word document. READ MORE...


Cisco Secure FMC Zero-Day Exploited in the Wild

Cisco on Wednesday announced patches for an actively exploited zero-day vulnerability affecting its Secure Firewall Management Center (FMC) product. The security hole, tracked as CVE-2026-20316, has been described as a static credential issue. Specifically, an attacker can leverage default credentials for a low-privilege user account to log into vulnerable devices and access sensitive data. Cisco assigned a 'high severity' rating to the vulnerability. READ MORE...


A little-known npm package was North Korea's warm-up act for the axios hack

Amazon's security researchers say a hacking group tied to North Korea targeted small, little-noticed software packages more than a year before it struck one of the internet's most widely used programming tools. The company's threat intelligence team said Wednesday at a media roundtable at its Arlington, Va., offices that the same group linked to the recent compromise of the open-source axios software library also planted malicious code in a package called typo-crypto in March 2025. READ MORE...

Science & Culture

Bruce Schneier: Should You Use AI for a Task? Here's a Simple Way to Decide

I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And it will come as no surprise to you that my students regularly use AI to complete their writing assignments. Doing so is a waste of their tuition money. But if their entire career is going to include AI writing assistants, why shouldn't they embrace their future? The best way I've found to explain the dilemma comes from the AI researcher Daniel Meissler: it's the difference between work and the gym. READ MORE...

On This Date

  • ...in 1932, Walt Disney releases his first cartoon in color -- "Flowers and Trees".
  • ...in 1947, actor and former politician Arnold Schwarzenegger is born in Thal, Austria.
  • ...in 1961, actor Laurence Fishburne ("The Matrix", "Apocalypse Now") is born in Augusta, GA.
  • ...in 1965, President Lyndon B. Johnson signs the Social Security Act of 1965, establishing Medicare and Medicaid.