HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel

Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The … Continue reading HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches

Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging… Continue reading Italy fines WINDTRE €1.7 million over security flaws behind two data breaches

A forensic tool for backdoored code completions in AI assistants

Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some of that code ca… Continue reading A forensic tool for backdoored code completions in AI assistants

Two new high severity WordPress vulnerabilities, patch immediately!

The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, … Continue reading Two new high severity WordPress vulnerabilities, patch immediately!

Ransomware attack halts Coca-Cola’s Fairlife US milk production

A ransomware attack has stopped milk production at Fairlife, the Coca-Cola dairy brand known for its high-protein milk, protein shakes, and nutrition drinks. Coca-Cola disclosed the incident on July 16, 2026, in a Form 8-K filed with the U.S. Securitie… Continue reading Ransomware attack halts Coca-Cola’s Fairlife US milk production

The script, not the voice, is what makes AI voice phishing work

The call comes in at 4:40 on a Friday. The voice belongs to a senior manager, or sounds close enough, and she needs a password reset before a flight. She is polite, she is in a hurry, and she has the last four of the badge number. Researchers at Harvar… Continue reading The script, not the voice, is what makes AI voice phishing work

Scattered Spider members jailed over Transport for London hack that cost £29 million

Two members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters and cost t… Continue reading Scattered Spider members jailed over Transport for London hack that cost £29 million