A week in security (July 6 – July 12)
Last week on Malwarebytes Labs: This new Windows malware can take over your PC and wipe it clean How mule betting scams recruit ordinary people…
Last week on Malwarebytes Labs: This new Windows malware can take over your PC and wipe it clean How mule betting scams recruit ordinary people…
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The…
Supply chain management has induced headaches at enterprises struggling with geopolitical challenges, sustainability mandates, and the sheer volume and velocity of decisions they must take…
The investigation into the Odido cyberattack has uncovered possible involvement of Dutch nationals, according to Dutch police, as authorities continue to investigate the ShinyHunters ransomware-linked…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities (KEV) catalog after reports confirmed active zero-day attacks targeting the iCagenda and Balbooa extensions for Joomla. Both…
Federal government staff largely turned down “gifts” from nine of the largest IT vendors in the year to March 2026, an analysis by the Digital…
Threat actors have been exploiting critical vulnerabilities in the Balbooa Forms and iCagenda Joomla extensions that allow unauthenticated attackers to achieve remote code execution (RCE).…
Australia Alerts Organizations to Ongoing CMS Exploitation Attacks Pierluigi Paganini July 13, 2026 Australia warns of a global campaign exploiting CMS flaws to deploy webshells…
That workflow requires more than a model. It requires corporate data, secure infrastructure, feedback loops, security engineers, data scientists, and AI specialists who can work…
AI is changing the way organizations build, ship, and interact with software. And with it comes a new security reality. As more teams adopt generative…
A newly disclosed unauthenticated remote code execution vulnerability in Motorola MR2600 Wi-Fi routers allows attackers on the local network to upload and install a malicious…
Operation Capsule Vault began with spear-phishing emails sent on June 22, 2026, posing as notices distributing materials from a legitimate academic event. The lures referenced…