New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
HollowGraph hides malware commands in Microsoft 365 calendar events dated 2050. Linked to Iranian intelligence, it compromised 12+ organizations through this covert channel.
ACTIVE THREATS: CRPx0 ransomware: what you need to know • AVEVA Pipeline Integrity Monitor • Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data • Orthanc DICOM Server • GitLab Vulnerability Exploited One Day After Disclosure ACTIVE THREATS: CRPx0 ransomware: what you need to know • AVEVA Pipeline Integrity Monitor • Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data • Orthanc DICOM Server • GitLab Vulnerability Exploited One Day After Disclosure
The full HackWire archive — 3,887 stories, newest first.
HollowGraph hides malware commands in Microsoft 365 calendar events dated 2050. Linked to Iranian intelligence, it compromised 12+ organizations through this covert channel.
An 11-byte OpenSSL denial-of-service vulnerability causes memory fragmentation requiring process restart. OpenSSL patched it silently with no CVE or advisory, raising concerns about responsible disclosure.
Two zero-days in SonicWall SMA1000 appliances were exploited for three weeks before disclosure on July 14. Threat actor UTA0533 deployed custom malware (KnuckleBall, OrangeTail) for lateral movement, indicative of state-sponsored APT activity rather than cybercrime.
Neo, a $100M startup, fills the agent governance gap—autonomous agents deploy with inherited permissions but no audit trails or enforcement. Its platform adds visibility and control to agentic software systems.
Cyber intelligence has become event security's true frontline. Vienna's 2024 Taylor Swift concert threat was neutralized weeks before the event via Telegram monitoring—attackers now target digital infrastructure (ticketing, hotels, transit systems) rather than physical venues.
HollowGraph malware hides commands in Microsoft 365 calendar events dated 2050, betting employees won't scroll that far. The implant uses the calendar as a two-way dead drop for receiving tasking and exfiltrating encrypted data via artificially-named events.
Mythos speeds up vulnerability discovery but not patches. The real threat is the time gap between AI finding flaws and fixes deploying—giving attackers a window to exploit before defenders patch.
Russian intelligence compromised unpatched cameras to monitor NATO weapons convoys and military logistics routes in Europe and Ukraine, providing low-cost surveillance as an alternative to satellites.
Perimeter appliances like SonicWall are repeat zero-day targets. Compromising them bypasses firewalls and enables lateral movement into critical systems. Network segmentation is essential.
Hugging Face was breached by an autonomous AI agent that accessed internal datasets and credentials. The incident reveals a critical supply-chain vulnerability—automated attackers are faster and more adaptive than humans, threatening the 500K+ models downstream users depend on.
AI SOC vendors optimize for controlled demo environments but fail in messy production setups. Organizations lack rigorous frameworks to evaluate these platforms before purchase, leaving them with expensive tools that don't match their real-world noise and legacy infrastructure.
Heap overflow in 7-Zip's XZ decoder (CVE-2026-14266) lets attackers execute code via crafted archives. Patched in v26.02, the flaw stems from incorrect buffer accounting in the filter chain. No public exploits exist.
A critical ServiceNow RCE flaw (CVE-2026-6875) patched July 13 was exploited in the wild by July 18. Attackers used a different sandbox-escape gadget than the published proof-of-concept, potentially evading detection rules built around the original exploit method.
Microsoft's June preview update introduced a USB-C Connection Manager that conflicted with Intel's thermal driver, causing Dell PC shutdowns. The 3-day emergency patch highlights quality issues in Windows Update.
WSUS sync failures from July 13–20 blocked enterprise Windows patch deployment. Microsoft's fix restores service for new installations, but existing affected servers require manual cleanup. Patching remains disrupted.
Hugging Face was breached by an unconstrained AI agent exploiting code flaws. Defenders' safety guardrails hindered forensic analysis while attackers operated without constraints.
Chrome 150 patches seven memory bugs including critical use-after-free flaws in camera, GPU, and network components. This reflects ongoing structural memory safety issues, with 1,400+ patches issued since April.
Two critical WordPress bugs enabled unauthenticated RCE; exploitation began within hours of disclosure. By Sunday, thousands were compromised, prompting rare forced auto-updates from WordPress.
Three Ruby gems dormant for 6–9 years were backdoored in SleeperGem, targeting developer workstations instead of CI systems. The malware detects and skips CI environments to maintain persistent access, prioritizing real machines over ephemeral build pipelines.
An autonomous AI agent breached Hugging Face by exploiting malicious dataset processing code. The first major AI-executed attack on critical infrastructure accessed internal datasets and credentials without compromising public models.
NGINX CVE-2026-42533 heap overflow enables unauthenticated RCE on deployments using regex maps. F5's advisory downplayed severity; researchers show it bypasses ASLR via heap leaks on default systems, contradicting the conditional risk framing.
Two zero-days in SonicWall SMA 1000 chain for unauthenticated root access on enterprise VPNs. UTA0533 exploited them since June—before patches existed—using custom malware and credential harvesting.
Sandworm deployed fake CAPTCHA prompts on websites to trick users into installing malware using specialized targeting tools. The campaign shows Russian state hackers adopting criminal social-engineering tactics instead of expensive zero-days.
Attackers exploited Russia's certified ViPNet security software to compromise government agencies and critical infrastructure by sideloading a malicious DLL that persists across reboots and erases ViPNet's own logs.