Medical Computer Business Services disclosed that a 2025 intrusion affects 1,261,464 individuals across multiple healthcare organizations. Potentially stolen data includes Social Security numbers, insurance details, medical information, payment data and emails, while the PEAR ransomware group claims 3 TB of exfiltrated files. Healthcare providers and partners should prepare for targeted phishing, identity fraud and downstream notification obligations.
root@news:~/news$ ls -lah news/
GitHub now applies a default three-day cooldown to Dependabot version updates, while PyPI blocks maintainers from adding new files to releases older than 14 days. The controls reduce exposure to newly published malicious packages and poisoned trusted releases, but do not replace lockfiles, scoped tokens or installation-script restrictions in CI pipelines.
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and
Rockwell Automation fixed four high-severity memory corruption vulnerabilities in Arena Simulation 17.00.00 and earlier. Malicious project files can trigger out-of-bounds writes and execute code in the current user's context, creating a practical phishing or supply-chain path into engineering environments. Organizations using Arena should upgrade to 17.00.01 and restrict untrusted simulation files.
Cisco Talos identified a Rust-based RAT that launches Chrome or Edge and controls it through the Chrome DevTools Protocol. Command-and-control traffic then leaves through legitimate browser processes using Cloudflare-hosted infrastructure, Google STUN and Twilio TURN over WebRTC.
Origin Energy confirmed that customer records were accessed and disclosed without authorization. Potentially affected fields include names, addresses, dates of birth, phone numbers, account information and partial credit-card or bank-account digits.
Check Point confirmed in-the-wild exploitation of a SmartConsole login flaw that can let an unauthenticated remote attacker obtain an application token and authenticate with full administrative privileges. The exposed control plane can be used to modify security policies and management configuration.