Domingo 26 Julio 2026 16:08:57 GMT+02:00

Netcrook

InicioManifiesto
Noticias
Techcrook
Geocrook
WikicrookEquipoAppContactoLogin
EnglishItaliano

North America


When a Simulation File Becomes a Loader: Rockwell’s Arena Fix Exposes a Quiet Industrial Risk

Rockwell has patched code-execution flaws in Arena Simulation, and the case shows how trusted engineering files can turn workstation software into an entry point.

GitLab Notebook Diffs Become an RCE Trigger in a New Authenticated-User PoC

Published: 25 July 2026 12:06Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: DEBUGSAGE

A published proof-of-concept shows how a normal project account, two crafted Jupyter notebooks, and a diff request can turn a review feature into command execution as the Git service user.

ChatGPT Went Dark Worldwide, and the Real Risk Is Dependency

Published: 25 July 2026 12:02Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: TRUSTBREAKER

A global outage is not a breach, but it is a reminder that centralized AI services can become single points of failure for work, automation, and support.

When the Screen Lies: Industrial Controllers Turned Into a Cover Story

A revised federal warning points to a dangerous OT pattern: internet-exposed PLCs and tampered HMI displays can leave operators watching a system that no longer reflects reality.

Google’s New Threat-Actor Naming System Turns Labels into a Security Control

Published: 25 July 2026 10:01Category: Cyber Intelligence & Threat TrendsGeo: North America / USAAuthor: PHANTOMINTEGRITY

GTIG’s shift to one cryptonym framework is less about branding than about keeping attribution consistent as separate security teams are folded into a single intelligence unit.

New Ransomware Listing Leaves 503 GB Figure Unproven

Published: 25 July 2026 08:07Category: Ransomware & ExtortionGeo: North America / USAAuthor: LOGICFALCON

A victim entry linked to Securotrop names Advantage Sintered Metals, but the status and size field remain unverified as evidence of any breach.

Control Rooms Under Pressure: A PLC Advisory Puts OT Integrity in the Crosshairs

Published: 25 July 2026 08:06Category: Industrial Cybersecurity & Critical InfrastructureGeo: North America / USAAuthor: NETAEGIS

A revised federal advisory on PLC targeting highlights a danger that matters more than theft alone: when attackers can tamper with logic and the operator view, trust in the industrial process itself starts to erode.

Trusted Labels, Hidden Payloads: How a Fake Logistics Email Became a Malware Delivery Trap

Published: 25 July 2026 08:04Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A phishing run dressed up as shipping notices and tax-audit mail shows how attackers can turn everyday business trust into a credential-theft pipeline.

Google Unifies Its Threat Labels, Exposing the Cost of Confusing Names

Published: 25 July 2026 08:02Category: Cyber Intelligence & Threat TrendsGeo: North America / USAAuthor: GHOSTCOMPLY

A new cryptonym-based naming system is meant to reduce split-brain attribution across Google’s threat-intelligence teams, and that matters more than it sounds.

Named, Tagged, Unverified: The Ransomware Claim Around Jiva Health

Published: 25 July 2026 02:04Category: Ransomware & ExtortionGeo: North America / USAAuthor: LOGICFALCON

A posted claim links Jiva Health to the unsafe group and a specific hash, but the available record does not confirm a breach, data theft, or operational impact.

Unsafe Listing Names Jiva Health as a New Victim

Published: 25 July 2026 02:04Category: Ransomware & ExtortionGeo: North America / USAAuthor: NEBULASCOUT

A ransomware bulletin has put Jiva Health into an extortion-style listing and attached a revenue figure of 9 million, but the post does not verify breach scope or technical impact.

Bing’s Image Pipeline Faced a High-Privilege SVG Trap

Published: 24 July 2026 19:17Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: DEBUGSAGE

A crafted image file reportedly pushed Microsoft’s Bing processing workers into SYSTEM or root context, highlighting how media pipelines can become command-execution surfaces when untrusted content is handled too freely.

The Phishing Link That Could Have Turned an AI Workspace Into a Rogue Operator

Published: 24 July 2026 19:14Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A reported flaw in ChatGPT Workspace Agents shows how one click can become an agent-launch event, not just a browser detour.

The Quiet Bill That Can Sink an AI Rollout

Published: 24 July 2026 19:12Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

When coding agents are metered by tokens instead of seats, the real risk is often not model failure but runaway consumption that finance teams cannot see soon enough.

Inbox Security Gets Another Capital Injection as AI Tools Chase the Next Phish

Published: 24 July 2026 19:10Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

AegisAI has raised $36 million, lifting its total funding to $49 million, in a round aimed at AI-powered email security and backed by Battery Ventures, Accel, and Foundation Capital.

Pear Claim Targets a Roofing Brand, but the Evidence Stops at the Post

Published: 24 July 2026 19:00Category: Ransomware & ExtortionGeo: North America / USAAuthor: LOGICFALCON

A ransomware claim tied to Metropolitan-Construction-Systems and metropolitanroof.com has appeared, but the technical fallout remains unverified.

Extortion Post Puts a New York Roofing Firm Into Pear’s Orbit

Published: 24 July 2026 19:00Category: Ransomware & ExtortionGeo: North America / USAAuthor: NEBULASCOUT

A new victim entry linked to Pear names Metropolitan Construction Systems, but the available material does not establish whether the listing reflects a verified intrusion, data theft, or only an extortion-site claim.

Azure Automation’s Quiet Default That Could Have Collapsed Tenant Boundaries

Published: 24 July 2026 18:55Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Microsoft corrected a public-by-default configuration and code flaws in a cloud automation service that may have created a cross-tenant identity risk, without any confirmed exploitation in the available material.

Black Hat’s July 31 Clock Is Ticking for Security Teams

Published: 24 July 2026 18:53Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

The event’s return to Las Vegas is confirmed, but the real takeaway is planning: deadlines, travel, and briefing schedules can shape how defenders prepare for the months ahead.

Engineering Files Become the Prize in a Claimed Cl0p Exploitation Run

Published: 24 July 2026 18:53Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A reported flaw in PTC Windchill and FlexPLM has raised concern for internet-facing PLM systems, but the full technical path and real-world impact remain unconfirmed.