ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th)

On Monday, July 13th, a new wave of malicious activity was spotted targeting organizations worldwide, leveraging a previously unknown vulnerability in an open-source web application framework. The ISC Stormcast, a daily podcast and newsletter from SANS Institute, broke the news, warning that the exploitation is already underway. The vulnerable software, called “Appletalk”, is used by … Read more

OpenAI temporarily relaxes GPT-5.6 Sol usage limits

OpenAI Temporarily Lifts Usage Limits on Powerful GPT-5.6 Sol Model, Giving Users a Breathing Room In a move that has provided much-needed relief to developers and professionals who rely heavily on its flagship language model, OpenAI has announced that it is temporarily lifting the usage limits on its powerful GPT-5.6 Sol model. The change comes … Read more

RedHook Android malware now uses Wireless ADB for shell access

A New Variant of RedHook Malware Exploits Wireless ADB to Gain Shell Access on Android Devices Researchers at Group-IB have uncovered a novel way that the RedHook Android malware is gaining shell-level privileges on mobile devices. The latest version of this malicious software takes advantage of the Android Wireless Debugging (Wireless ADB) mechanism, allowing it … Read more

RedHook Android malware now uses Wireless ADB for shell access

A New Twist on Android Malware: RedHook Exploits Wireless ADB for Shell Access Researchers at Group-IB have uncovered a fresh version of the RedHook Android malware that leverages the Android Wireless Debugging (Wireless ADB) mechanism to gain shell-level privileges without requiring a computer connection. This development marks a significant escalation in the capabilities of this … Read more

Ghost Accounts Abuse GitHub API in Mass Recon Campaign

Threat actors have been using a clever tactic to systematically gather sensitive information about organizations and their users through the GitHub API, according to a recent report from Datadog. This reconnaissance campaign has been ongoing for several months, with multiple overlapping campaigns leveraging “ghost accounts” – dormant user accounts that were registered years ago but … Read more

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

A new wave of sophisticated cyber attacks has been uncovered, targeting government agencies and organizations worldwide through a surprising vector: the Balochistan Police Portal in Pakistan. In what is being described as a multi-group espionage campaign, hackers have exploited vulnerabilities in this online platform to gain access to sensitive information, compromise systems, and launch further … Read more

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

A new and concerning threat has emerged on the npm package registry, one of the largest repositories of open-source code used in software development worldwide. A compromised version of Jscrambler’s 8.14.0 library was released, secretly installing a Rust-based infostealer malware during installation. The affected package, labeled as “jscrambler”, appears to be a legitimate library designed … Read more

Ghost Accounts Abuse GitHub API in Mass Recon Campaign

Threat actors have been systematically scanning and mapping GitHub organizations, repositories, and user accounts using a network of dormant “ghost” accounts. The abuse of GitHub’s API has been ongoing for several months, with multiple overlapping campaigns using leaked credentials and automated scanners to gather information. The activity, discovered by cybersecurity firm Datadog, involves exploiting publicly … Read more