In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing.
The post In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street appeared first on SecurityWeek.
Real emails, hijacked payments: Two H1 2026 attack chains
North Carolina Ports confirms cyberattack disrupting operations
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,
Growing Up The Hard Way
For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral.
Then,
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.
Vishing Extortion Group UNC6671 Rebrands After Making Millions
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.
The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek.
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
“The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning
