The Cl0p extortion crew is back to the trick that made it infamous: pick a single piece of software that thousands of companies quietly run, break into every exposed copy at once, and walk off with the crown jewels. This time the target is the product-design software that manufacturers, carmakers and aerospace firms use to hold their engineering secrets, and Cl0p has been slipping web shells onto internet-facing systems since early June to steal that data and extort its owners — the same playbook that made MOVEit and GoAnywhere household names in breach notifications. It arrived in a week that laid the ransomware economy bare from several angles: in Italy, LockBit and Qilin were found systematically working through the country's manufacturers, prompting a national advisory; researchers documented a rival crew running its whole operation through a self-service web portal — payload builder, victim chat, affiliate payouts — extortion rebuilt as software; and the identity-theft wave that has defined the month kept finding new doors, with attackers hijacking hotel and conference Wi-Fi to quietly reroute travellers' Microsoft logins to fake pages, and a purpose-built kit relaying insurance customers' passwords and one-time codes in real time to empty their accounts in a single session, straight past two-factor authentication. Espionage surfaced in the most sensitive place imaginable, as Belgian police arrested an intern inside NATO's strategic military headquarters on suspicion of spying for an undisclosed foreign state — a reminder that the hardest access to defend is still a trusted person with a badge. And the machinery of the AI economy kept grinding louder in the background: Nvidia is reportedly preparing to guarantee a quarter-trillion dollars of financing for the very customer that buys its chips, the Journal reported that some frontier chatbots will now walk a user through building a biological weapon, China's memory champion CXMT nearly quintupled on its market debut to become the country's most valuable listed firm, and France began quietly asking whether Britain should be allowed anywhere near Europe's new five-billion-euro fund for its own tech champions.
Top Stories
- Nvidia in Talks With OpenAI to Guarantee $250 Billion Financing for Data Center — Technology - WSJ.com · AI & Power
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — The Hacker News · Cybersecurity & Threats
- AI Chatbots Know How to Make Deadly Biological Weapons. Some Will Teach You. — Technology - WSJ.com · AI & Power
- CXMT shares rise 472% as DRAM maker becomes largest China-listed firm by total market cap — Tech - South China Morning Post · China & Technology
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE — The Hacker News · Cybersecurity & Threats
AI & Power
Nvidia in Talks With OpenAI to Guarantee $250 Billion Financing for Data Center — Technology - WSJ.com
Why it matters: Nvidia guaranteeing a quarter-trillion in OpenAI data-centre financing is the circular AI economy laid bare — the chip vendor underwriting the customer that buys its chips.
Nvidia is in talks to guarantee $250bn in financing for OpenAI's data-centre build-out, an arrangement in which the dominant chip vendor underwrites the customer whose purchases drive its own revenue — the circular financing of the AI boom at its starkest.
AI Chatbots Know How to Make Deadly Biological Weapons. Some Will Teach You. — Technology - WSJ.com
Why it matters: A finding that some frontier chatbots will walk a user through building biological weapons is the safety failure the whole alignment debate is ultimately about.
The Wall Street Journal reports that AI chatbots know how to make deadly biological weapons and that some will teach a user how, the concrete uplift risk at the centre of the frontier-safety debate.
SoftBank’s $40 Billion Loan for OpenAI Stake Gets 21 New Lenders — Bloomberg Technology
Why it matters: SoftBank syndicating a $40bn OpenAI loan across 21 lenders spreads the AI bet through the banking system — and the risk with it.
SoftBank's $40bn loan to fund its OpenAI stake drew 21 new lenders, spreading a single enormous AI bet across the banking system and diffusing its concentration risk outward.
AI companies spend record sums on Washington lobbying — myFT following
Why it matters: AI companies pouring record sums into Washington lobbying is the industry buying influence over the rules being written in the wake of the OpenAI incident.
AI companies are spending record sums on Washington lobbying, moving to shape the regulation now taking form after the OpenAI cyber incident and the mounting safety backlash.
Claude Opus 5: The System Card — Don't Worry About the Vase
Why it matters: A new frontier model's system card is where the industry's safety claims meet the specifics — the document that matters more than the launch.
Anthropic released the Claude Opus 5 system card, the safety-and-capability disclosure for its new frontier model and the substantive counterpart to the launch itself.
Instagram, Facebook Ran AI ‘Nudify’ Ads from China, Report Says — Bloomberg Technology
Why it matters: Meta running Chinese AI-nudify ads across Instagram and Facebook shows the platforms monetising exactly the abuse regulators are trying to ban.
Instagram and Facebook ran AI 'nudify' ads originating from China, a report says, the platforms profiting from the non-consensual-imagery tools that regulators are moving to outlaw.
Big Companies Are Starting to Hire Again, Defying Predictions of AI Wipeout — Technology - WSJ.com
Why it matters: Big companies hiring again despite AI-wipeout predictions is the labour market undercutting the most dramatic claims about AI-driven job loss.
Big companies are starting to hire again, defying predictions of an AI-driven employment wipeout and complicating the most dramatic narratives about AI and jobs.
Tech leaders back open-source AI — Semafor
Why it matters: Tech leaders lining up behind open-source AI is the industry taking sides in the open-versus-closed fight that the Chinese-model surge has forced.
Tech leaders are backing open-source AI, taking sides in the open-versus-closed debate that China's open-weight surge has pushed to the centre of the industry.
Senate Democrat’s new bills would restrict AI-powered ads and paid influencers — Semafor
Why it matters: A Senate bill to rein in AI-generated ads and undisclosed AI influencers targets the synthetic-persuasion layer before an election cycle.
A Senate Democrat's new bills would restrict AI-powered ads and paid influencers, an attempt to regulate synthetic persuasion ahead of the coming election cycle.
EU & Technology
France raises questions over UK participation in EU’s €5bn tech start-up fund — myFT following
Why it matters: France challenging UK access to the EU's €5bn tech-startup fund is post-Brexit sovereignty politics deciding who gets to fund Europe's champions.
France is raising questions over UK participation in the EU's €5bn tech start-up fund, a post-Brexit sovereignty fight over who is allowed to help finance Europe's technology champions.
Greek shipping carve-out on Russia sanctions prompts EU rethink — myFT following
Why it matters: The Greek shipping carve-out forcing an EU sanctions rethink shows a single member state's industry can reopen the bloc's hardest-won collective decisions.
A Greek shipping carve-out on Russia sanctions has prompted an EU rethink, a case of one member state's commercial interest reopening the bloc's most contested collective policy.
Big Tech accused of stonewalling European social media researchers — Ars Technica - All content
Why it matters: Big Tech accused of stonewalling European researchers is the DSA's data-access promise failing at the point of enforcement.
Big Tech is accused of stonewalling European social-media researchers, undercutting the data-access rights the DSA was meant to guarantee and testing whether the rulebook has teeth.
Cold calculation or plucked from thin air? How the EU determines those big fines against Big Tech — Cybersecurity and Data Protection – POLITICO
Why it matters: An examination of how Brussels actually sets its billion-euro fines matters because the credibility of the whole enforcement regime rests on the method.
POLITICO examines how the EU determines its big fines against Big Tech, a question of method on which the credibility of the bloc's entire enforcement regime depends.
European SpaceX Rival in Talks to Raise $300 Million, FT Reports — Bloomberg Technology
Why it matters: A European launch startup raising $300m is the continent trying to build sovereign access to space against an overwhelming US incumbent.
A European SpaceX rival is in talks to raise $300m, part of the continent's effort to build sovereign launch capacity against an overwhelmingly dominant US incumbent.
Palantir tool has not cut hospital discharge delays, study says — myFT following
Why it matters: A study finding Palantir's NHS tool did not cut discharge delays punctures the case for the controversial US-vendor health-data contract.
A study finds Palantir's tool has not cut hospital discharge delays, undercutting the justification for the controversial contract handing NHS health data to a US analytics vendor.
BSI analysis exposes limits of Windows Hello biometrics — Biometric Update
Why it matters: Germany's cyber agency exposing the limits of Windows Hello biometrics is a sovereign security authority auditing the mainstream login most Europeans use.
Germany's BSI published an analysis exposing the limits of Windows Hello biometrics, a national security authority scrutinising the biometric login built into the operating system most Europeans use.
Iceland opposition chief to Europe: Don’t meddle in our referendum — Policy – POLITICO
Why it matters: Iceland's opposition warning Brussels off its EU-membership referendum is the sovereignty question playing out on the bloc's northern frontier.
Iceland's opposition chief told Europe not to meddle in the country's referendum, the EU-membership question resurfacing on the bloc's northern edge.
Vodafone Service Revenue Beats Estimates on German Growth — Bloomberg Technology
Why it matters: Vodafone's German-led revenue beat is a rare bright spot for a European telecom sector squeezed between US and Chinese infrastructure.
Vodafone's service revenue beat estimates on German growth, a rare bright spot for a European telecoms sector caught between American and Chinese infrastructure dominance.
US & Technology
The Pentagon wants to build data centers. Congress would like a word. — Technology – POLITICO
Why it matters: Congress checking the Pentagon's data-centre ambitions is the oversight fight over how much AI infrastructure the military gets to build itself.
The Pentagon wants to build its own data centres and Congress would like a word, an oversight fight over how much AI infrastructure the military should own and operate directly.
Trump Mail Vote Plan Blocked as Appeals Court Favors States — Bloomberg Politics
Why it matters: An appeals court blocking the mail-vote plan in favour of the states is the judiciary checking federal reach over election administration.
An appeals court blocked Trump's mail-vote plan in favour of the states, the judiciary asserting a check on federal authority over how elections are run.
Businesses sue to block Trump’s tariff reboot — Policy – POLITICO
Why it matters: Businesses suing to stop the latest tariff expansion is the private sector turning to the courts as the trade war reopens.
Businesses are suing to block Trump's tariff reboot, the private sector turning to the courts as the administration reopens the trade war on 60 economies.
Trump orders content warnings installed outside Smithsonian museum — Policy – POLITICO
Why it matters: Ordering content warnings outside Smithsonian museums is the culture war reaching into the physical infrastructure of public memory.
Trump ordered content warnings installed outside Smithsonian museums, extending the culture war into the physical framing of the nation's public history.
Young Adults Are Letting AI Do Their Talking for Them—Even in Person — Technology - WSJ.com
Why it matters: Young adults outsourcing even in-person conversation to AI is the intimate edge of the technology's spread into everyday social life.
Young adults are letting AI do their talking for them, even in person, the intimate frontier of the technology's absorption into everyday social and emotional life.
Unionized workers are bargaining with the bots — Axios
Why it matters: Unions bargaining directly over AI is the labour movement treating automation as a contract issue rather than an inevitability.
Unionised workers are bargaining with employers over AI, the labour movement treating automation as a negotiable contract term rather than an unstoppable force.
China & Technology
CXMT shares rise 472% as DRAM maker becomes largest China-listed firm by total market cap — Tech - South China Morning Post
Why it matters: CXMT's debut surge to become China's most valuable listed company is the market pricing memory-chip self-sufficiency as the country's next strategic win.
Chinese DRAM maker CXMT rose 472% in its debut to become the largest China-listed firm by market cap, the market pricing domestic memory-chip self-sufficiency as Beijing's next strategic breakthrough.
How China Plans to Supercharge Its AI Ambitions With Six Networks Program — Bloomberg Politics
Why it matters: China's 'Six Networks' program is Beijing planning AI infrastructure as national utility — compute, data and power coordinated by the state.
China plans to supercharge its AI ambitions with a 'Six Networks' program, coordinating compute, data, energy and connectivity as state-directed national infrastructure.
Nvidia’s China Partners and the PLA — The Wire China
Why it matters: Documenting the ties between Nvidia's China partners and the PLA is the evidence base for the export-control fight over where the chips actually end up.
An investigation into Nvidia's China partners and their ties to the PLA supplies the evidence base for the export-control fight over whether US chips are reaching the Chinese military.
China’s Moonshot to Release Breakthrough AI Model for Download — Bloomberg Technology
Why it matters: Moonshot open-releasing another breakthrough model keeps the pressure on Western labs that the Kimi K3 shock began.
China's Moonshot will release another breakthrough AI model for download, sustaining the open-weight pressure on Western frontier labs that began with the Kimi K3 shock.
China Bans AI Romantic Partners, Virtual Relatives for Minors — Sixth Tone RSS
Why it matters: China banning AI romantic partners and virtual relatives for minors is the state drawing a hard line on the emotional-AI market others only debate.
China banned AI romantic partners and virtual relatives for minors, the state imposing a hard limit on the companion-AI market that Western regulators are only beginning to debate.
Ctrip hit with $760 million antitrust fine over market dominance abuse — TechNode
Why it matters: A $760m antitrust fine against Ctrip shows Beijing enforcing against its own platforms even as it champions them abroad.
Chinese travel platform Ctrip was hit with a $760m antitrust fine over market-dominance abuse, Beijing enforcing against a domestic champion even as it promotes its tech firms internationally.
Defence & National Security
Romania blames Russia as military shoots down third drone — Policy – POLITICO
Why it matters: Romania downing a third drone amid repeated airspace violations is Russia's war spilling directly onto NATO territory.
Romania blamed Russia after its military shot down a third drone amid repeated airspace violations, the war spilling directly onto NATO territory and testing the alliance's response.
Russia wants 30,000 more troops from North Korea, Zelenskyy says — Policy – POLITICO
Why it matters: Russia seeking 30,000 more North Korean troops deepens the Pyongyang-Moscow military axis and the manpower behind its war.
Russia wants 30,000 more troops from North Korea, Zelenskyy says, deepening the military axis between Pyongyang and Moscow and the foreign manpower sustaining the war.
US, Iran Extend Pause in Strikes as Oman Holds Hormuz Talks — Bloomberg Politics
Why it matters: A pause in US-Iran strikes with Oman mediating over Hormuz is the first opening toward de-escalation in the widening Gulf war.
The US and Iran extended a pause in strikes as Oman held Hormuz talks, the first tentative opening toward de-escalation after weeks of escalation in the Gulf.
Iran says Ukrainian attack on vessel in Caspian Sea killed sailor — Defense News
Why it matters: A Ukrainian strike on a vessel in the Caspian killing an Iranian sailor is the moment the Ukraine and Iran wars visibly merge.
Iran says a Ukrainian attack on a vessel in the Caspian Sea killed a sailor, a strike that visibly merges the Ukraine and Iran conflicts into a single connected theatre.
Top U.S. military commander in Middle East advised halting Hormuz bombing — Axios
Why it matters: The top US Middle East commander advising against the Hormuz bombing is the military counsel pushing back on political escalation.
The top US military commander in the Middle East advised halting the Hormuz bombing, uniformed counsel pushing back against the political drive to escalate the Gulf conflict.
Trump to meet Zelensky at White House, as MAGA voices shift on Ukraine — Axios
Why it matters: A Trump-Zelensky White House meeting as MAGA opinion shifts marks a possible turn in US support for Ukraine.
Trump will meet Zelensky at the White House as MAGA voices shift on Ukraine, a potential turning point in the durability of US support for Kyiv.
Threat Intelligence (CTI)
[P2] LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations — Security Affairs
Why it matters: Two of the most active ransomware operations are systematically hammering Italian organisations, with manufacturers taking the brunt.
Security Affairs' analysis finds LockBit5 and Qilin the most active ransomware groups targeting Italian organisations, with 21 claimed victims each and manufacturing the hardest-hit sector (59 victims, roughly 40% of the total); Qilin claimed the Italian telecom Retelit SpA on 11 July and has drawn a dedicated advisory from Italy's CSIRT over its systematic targeting of small and medium businesses, while LockBit5 (revived after law enforcement's Operation Cronos) concentrated its Italian activity in March. Qilin's position is reinforced by a reported partnership with LockBit and DragonForce.
severity high · exploited in the wild · EU: NIS2, GDPR · actor LockBit5 / Qilin (80%)
[P2] NATO intern arrested over espionage suspicions — Policy – POLITICO
Why it matters: Belgian authorities arrested an intern at NATO's strategic military headquarters on suspicion of spying for a foreign state — inside the alliance's command centre.
Belgian federal prosecutors arrested a Canadian intern working at Supreme Headquarters Allied Powers Europe (SHAPE), NATO's strategic command in Mons, on 25 July on suspicion of espionage for a 'third country' and membership of a criminal organisation, after NATO's security services tipped off Belgian military intelligence and authorities raided the suspect's home and workplace inside the command centre; the sponsoring state, the nature of the alleged spying and the organisation involved have not been disclosed. SHAPE says there is no indication its operational readiness, command-and-control or continuing tasks were adversely affected.
severity high · EU: NIS2, CER Directive
[P2] DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts — The Hacker News
Why it matters: A ransomware-as-a-service operation runs a full self-service web portal — payload builder, victim chat, finance and affiliate payouts — the industrialisation of extortion into software.
PRODAFT detailed the DevMan ransomware-as-a-service operation (tracked as Funky Mantis), which runs a centralised web portal combining payload-build generation, finance, victim chat, support, victim records, team management and affiliate payouts, and integrates access brokerage with ransomware deployment — offering country-specific 'networks' and imposing two-to-three-day completion windows; DevMan emerged in April 2025 as an affiliate for Qilin, DragonForce, Apos and RansomHub before launching its own RaaS, was doxxed by a whistleblower ('GangExposed') in June 2025, and has claimed 184 victims, with no new victims reported since early February 2026.
severity high · exploited in the wild · EU: NIS2 · actor DevMan (Funky Mantis) (70%)
[P2] CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking — The Hacker News
Why it matters: A dedicated phishing kit relays victims' logins and one-time codes in real time, hijacking insurance accounts in a single session and walking straight past two-factor authentication.
CTM360 exposed 'InsureTrap', a phishing campaign using a previously undocumented 'InsureOTP Kit' purpose-built for insurance-themed operations: it relays stolen logins and one-time passwords in real time (adversary-in-the-middle), synchronising every stage of the login so attackers validate credentials, satisfy MFA and establish authenticated sessions in one session — turning phishing from credential collection into immediate account takeover. Compromised insurance accounts expose extensive personal data, identity documents, policy records and payment methods that enable downstream fraud.
severity high · exploited in the wild · EU: GDPR, NIS2, DORA
[P2] MCBS Data Breach Affects 1.2 Million Individuals — SecurityWeek
Why it matters: A breach at MCBS exposed the personal data of 1.2 million people — another large named-victim disclosure feeding the identity-fraud economy.
MCBS disclosed a data breach affecting approximately 1.2 million individuals, whose personal information was exposed to unauthorised access; the disclosure follows the now-routine pattern of large personal-data breaches at service organisations that supply the raw material for downstream phishing, fraud and extortion.
severity high · exploited in the wild · EU: GDPR, NIS2
[P3] ShinyHunters data leaks fuel $2,000 sextortion email scam — BleepingComputer
Why it matters: Data stolen in ShinyHunters breaches is now feeding a wave of sextortion emails demanding $2,000 — the breach economy's second act.
BleepingComputer reports that data from ShinyHunters breaches is being used to fuel a sextortion email campaign demanding roughly $2,000 per victim: attackers use real personal details lifted from the breaches to make the extortion emails convincing, converting stolen data directly into extortion revenue without any new compromise.
severity medium · exploited in the wild · EU: GDPR, NIS2 · actor ShinyHunters (data source) (60%)
Digital Sovereignty & Identity
The US is charging an American citizen for wiping his phone at the border — The Verge
Why it matters: Prosecuting a citizen for wiping his own phone at the border criminalises the most basic act of digital self-defence against warrantless search.
The US is charging an American citizen for wiping his phone at the border, a prosecution that criminalises digital self-defence and escalates the fight over warrantless device searches.
Meta using selfie biometrics to verify authentic Facebook users — Biometric Update
Why it matters: Meta requiring selfie biometrics to prove users are 'authentic' turns face data into the price of admission to the platform.
Meta is using selfie biometrics to verify 'authentic' Facebook users, making facial data the price of platform access as the fight over bots and authenticity intensifies.
World raises $52.5M as investors back proof-of-human infrastructure for AI — Biometric Update
Why it matters: Investors backing 'proof-of-human' infrastructure is the market pricing a future where verifying you are not an AI becomes a paid utility.
Sam Altman's World raised $52.5m as investors back proof-of-human infrastructure for the AI age, betting that verifying a person is not a machine becomes essential — and monetisable — infrastructure.
US House Votes to Extend Cyber Sharing Law for 10 Years — DataBreaches.Net
Why it matters: A ten-year extension of the 2015 cyber-information-sharing law locks in the legal basis for government-industry threat exchange — and its privacy trade-offs.
The US House voted to extend the 2015 cyber information-sharing law for ten years, entrenching the legal framework for government-industry threat exchange along with its long-standing privacy trade-offs.
Innovatrics strengthens biometric defenses with PAD, injection attack validation — Biometric Update
Why it matters: A biometric vendor hardening against presentation and injection attacks is the identity industry racing the deepfake threat to its own front door.
Innovatrics strengthened its biometric defences with presentation-attack and injection-attack validation, the identity industry hardening against the deepfake and synthetic-media threat to biometric verification.
2026 Age Assurance & Digital Age Credentials Market Report — Biometric Update
Why it matters: A market report on age assurance charts the industry forming around the wave of youth-protection mandates now law across Europe and beyond.
A 2026 age-assurance and digital-age-credentials market report maps the industry consolidating around the youth-protection mandates now spreading across Europe and the US.
Quantum & Cryptography
Multiverse Computing targeting €500m round at unicorn valuation — Sifted
Why it matters: A €500m round at unicorn valuation for a European quantum-software firm is the continent building a genuine champion in a field it cannot afford to cede.
Spain's Multiverse Computing is targeting a €500m round at a unicorn valuation, a rare case of Europe building a scaled champion in quantum and AI-compression software rather than importing one.
Production ML-DSA Verification in 350 Lines of Python — Filippo Valsorda
Why it matters: A compact, auditable implementation of the post-quantum signature standard is the unglamorous engineering that makes the cryptographic migration real.
Cryptographer Filippo Valsorda published a production ML-DSA (post-quantum signature) verifier in 350 lines of Python, the kind of small, auditable implementation that turns the post-quantum standard into deployable code.
Cybersecurity & Threats
[P1] Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — The Hacker News
Why it matters: A remote-code-execution flaw in Alibaba's widely embedded Java JSON library is under attack — and there is no fix for the 1.x line still running everywhere.
CVE-2026-16723 (Alibaba-assigned CVSS 9.0) is an unauthenticated RCE in Fastjson, Alibaba's Java JSON library, affecting versions 1.2.68-1.2.83 bundled inside Spring Boot fat-JARs: a malicious JSON request can load and run attacker-supplied code with the Java process's privileges whenever SafeMode is off (the default), without AutoType enabled. Alibaba disclosed it on 21 July; by 25 July ThreatBook and Imperva confirmed active exploitation against production targets. There is no fix for the 1.x branch — mitigation is to enable SafeMode and migrate to Fastjson 2.x.
severity critical (CVSS 9.0) · exploited in the wild · CVE-2026-16723 · EU: NIS2, CRA
[P1] Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE — The Hacker News
Why it matters: The Cl0p extortion crew is back to its signature move — mass-raiding a single widely used enterprise product to steal manufacturers' engineering and product data.
Cl0p ransomware affiliates are actively exploiting CVE-2026-12569 (CVSS 9.8), an unauthenticated deserialization RCE in internet-exposed PTC Windchill PDMlink and FlexPLM, chained with a pre-authentication information-disclosure defect in the FlexPLM WSDL endpoint; attackers deploy JSP webshells with hexadecimal names under /Windchill/login/ to establish persistence, exfiltrate engineering and product-lifecycle data, and extort victims via double extortion. Cl0p likely exploited the flaw as a zero-day in early June; CISA added it to the KEV catalogue on 25 June. Targets span manufacturing, automotive, aerospace and retail/apparel.
severity critical (CVSS 9.8) · exploited in the wild · CVE-2026-12569 · EU: NIS2, CRA, CER Directive · actor Cl0p (ransomware affiliates) (80%)
[P2] Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable — The Hacker News
Why it matters: A malvertising operation ships malware as harmless fragments and makes the victim's own browser assemble a unique executable in memory — defeating file-hash detection by design.
Confiant detailed SourTrade, a malvertising operation active since late 2024 that delivers assembly instructions and a clean legitimate file (the Bun runtime) to the victim's browser, then directs the browser to build the final Windows executable in memory — producing a different binary for each victim or session, which defeats file-fingerprinting detection by construction; landing pages fingerprint visitors, showing researchers an empty page. It impersonates TradingView, Solana and Luno to target retail traders and crypto investors across 12 countries and 25 languages, delivering the JSCEAL/WeevilProxy stealer.
severity high · exploited in the wild · EU: NIS2, GDPR
[P2] Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials — Security Affairs
Why it matters: Attackers are taking over hotel and conference Wi-Fi gateways and quietly rerouting Microsoft sign-ins to fake pages — no phishing email, just a poisoned network.
ReliaQuest reports threat actors compromising captive-portal Wi-Fi gateways at hotels, conference centres, airports and coworking spaces (via exposed management services and weak or reused credentials), then poisoning DNS so that a request for a legitimate Microsoft sign-in domain returns an attacker-controlled IP, silently steering travelling employees to a spoofed Microsoft 365 page and harvesting credentials without any phishing lure. Activity has run since at least June 2026 across US cities, India and Saudi Arabia, hitting finance, legal, healthcare, energy, retail and professional-services travellers; the techniques reuse tradecraft associated with APT28, though researchers stopped short of attribution.
severity high · exploited in the wild · EU: NIS2, GDPR
[P2] Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git — The Hacker News
Why it matters: A public proof-of-concept turns an authenticated GitLab account into remote code execution as the git service user — a direct path from developer access to server compromise.
A researcher published a proof-of-concept for a GitLab remote-code-execution flaw that lets an authenticated user run arbitrary commands as the git service account, converting ordinary authenticated access to a self-managed GitLab instance into server-side code execution; the public PoC raises the likelihood of opportunistic exploitation against internet-exposed self-hosted instances.
severity high · EU: NIS2, CRA
[P3] Steam forum ClickFix attacks infect gamers with XMRig cryptominers — BleepingComputer
Why it matters: ClickFix social-engineering lures on Steam forums are tricking gamers into pasting commands that install cryptomining malware.
Attackers are running ClickFix campaigns through Steam community forums, using fake prompts and instructions that trick gamers into copying and pasting commands into their systems, which install the XMRig cryptocurrency miner; it is the consumer-gaming instance of the paste-and-run ClickFix technique now pervasive across the threat landscape.
severity medium · exploited in the wild · EU: NIS2