Off the Wire
What’s New
New and updated since 20 July 2026. The latest stories filed to the Digest, newest first.
New since last issue
54 stories- CISOs Feel the Heat Over AI Risk20 Jul
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 205020 Jul
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More20 Jul
- Hugging Face warns an autonomous AI agent hacked its network20 Jul
- Mythos Didn't Break Your Security Program. Your Exposure Window Could.20 Jul
- Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust20 Jul
- Software provider to more than 2,000 US hospitals says hackers stole employee and customer data20 Jul
- Microsoft confirms Windows Server Update Services sync delays20 Jul
- [NEU] [hoch] Extreme Networks ExtremeXOS: Mehrere Schwachstellen20 Jul
- [NEU] [hoch] Grafana: Schwachstelle ermöglicht Manipulation von Dateien20 Jul
- [NEU] [hoch] IBM Langflow Desktop OSS: Mehrere Schwachstellen20 Jul
- Critical ServiceNow code execution flaw now exploited in attacks20 Jul
- [NEU] [UNGEPATCHT] [mittel] Keycloak: Mehrere Schwachstellen20 Jul
- [UPDATE] [hoch] Composer: Mehrere Schwachstellen ermöglichen Codeausführung20 Jul
- [NEU] [mittel] IBM WebSphere Application Server: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen20 Jul
- [UPDATE] [hoch] Mozilla Firefox und Firefox ESR: Mehrere Schwachstellen20 Jul
- [NEU] [mittel] Microsoft Windows: Mehrere Schwachstellen20 Jul
- [UPDATE] [mittel] Cpython: Mehrere Schwachstellen20 Jul
- [UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellen20 Jul
- [UPDATE] [hoch] Shibboleth Service Provider: Schwachstelle ermöglicht SQL Injection20 Jul
- Is That Really My X-Ray? Measuring Internet-Exposed DICOM Services in the Presence of Deception20 Jul
- Characterizing Phishing Pages by JavaScript Capabilities20 Jul
- Jailbreak Foundry: From Papers to Runnable Attacks for Reproducible Benchmarking20 Jul
- Hidden in Thought: Transferable Chain-of-Thought Artifacts Induce Harmful Behavior20 Jul
- Poison to Detect: Detection of Targeted Overfitting in Federated Learning20 Jul
- Converging Safety and Security: IO-Link Wireless and OPC UA over 5G under prEN 5074220 Jul
- Intentional Electromagnetic Interference Attacks on Facial Recognition20 Jul
- Coercion and Deception in AI-to-AI Management: An Agentic Benchmark of Unprompted Escalation20 Jul
- DoSQ: A Cross-Layer Denial of Service Quality Attack by Exploiting Side Channels in 5G NR20 Jul
- Code-Poisoning Property Inference Attacks20 Jul
- Vogls: a Fast Interactive Full-timing Simulator for Pre-silicon Power Side-Channel Analysis20 Jul
- Central Bank Digital Currencies: Where is the Privacy, Technology, and Anonymity?20 Jul
- Beyond Detection: Agentic Attack Synthesis and Simulation for Smart Contracts20 Jul
- AI Watermark Evidence Fails Forensic Readiness: An Empirical Evaluation20 Jul
- CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages20 Jul
- DICOMHawk: A Cyber Deception Framework for Medical Imaging Infrastructure20 Jul
- Ciphertext- and Polynomial-Level Optimization for Fully Homomorphic Encryption20 Jul
- Natural Backdoor Attacks on Speech Recognition Models20 Jul
- Latent Fusion Jailbreak: Blending Harmful and Harmless Representations to Elicit Unsafe LLM Outputs20 Jul
- Improving Network Anomaly Detection via Choquet-Integral-Based Feature Aggregation20 Jul
- VeriX-Anon: A Multi-Layered Framework for Mathematically Verifiable Outsourced Target-Driven Data Anonymization20 Jul
- Refusal is Not Safety! Benchmarking Latent Safety Risks of LLM-Driven Content Humorization20 Jul
- Do Agents Dream of False Memories? Black-box Visual Attacks on Long-term Memory in Multimodal AI Agents20 Jul
- FLINT: Fingerprinting Federated Learning Architectures from 5G PHY-Layer Side Channels20 Jul
- Hide and Seek in Embedding Space: Geometry-based Steganography and Detection in Large Language Models20 Jul
- From Neural Intent to Cryptographic Authorization: Governing Agentic Workflows20 Jul
- Autonomous AI Intrusions Are Here: Lessons from the Hugging Face Compromise20 Jul
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution19 Jul
- Security incident disclosure – July 202619 Jul