Category Spotlight

Cyber Security

The latest stories, reviews, and analysis curated by the CoreTechDaily editorial team.

New Phishing Campaign Targets LastPass and Bitwarden Users with Fake Compliance Emails

New Phishing Campaign Targets LastPass and Bitwarden Users with Fake Compliance Emails

Phishing attacks impersonate LastPass and Bitwarden using fake newsletter emails and bogus DocuSign links. Passwords remain secure but users must verify email sources carefully.

Jul 15, 2026

How Fake GitHub Repositories Are Spreading Infostealer Malware and What You Should Know

How Fake GitHub Repositories Are Spreading Infostealer Malware and What You Should Know

Hundreds of malicious GitHub repos posing as legitimate software distribute an infostealer targeting browsers, crypto wallets, and messaging apps. Learn how this attack works and how to protect yourself.

Jul 15, 2026

How Old UEFI Shim Vulnerabilities Still Threaten Secure Boot Protection

How Old UEFI Shim Vulnerabilities Still Threaten Secure Boot Protection

Attackers can bypass UEFI Secure Boot using decade-old shim bootloader flaws. Apply updated revocations to protect Windows and Linux systems from malicious bootkits.

Jul 15, 2026

Microsoft's Largest Patch Tuesday Ever Fixes 622 Vulnerabilities Including Zero-Days

Microsoft's Largest Patch Tuesday Ever Fixes 622 Vulnerabilities Including Zero-Days

July 2026 Patch Tuesday delivers 622 fixes, including critical zero-days in AD FS and SharePoint. Learn what this means for your system security and update priorities.

Jul 15, 2026

How the US 'Gold Eagle' Initiative Streamlines AI-Driven Cybersecurity Vulnerability Response

How the US 'Gold Eagle' Initiative Streamlines AI-Driven Cybersecurity Vulnerability Response

The Gold Eagle program centralizes discovery and patching of AI-detected software vulnerabilities, enhancing coordination across US government and critical infrastructure sectors.

Jul 15, 2026

Malicious ModHeader Extension with 1.6M Installs Exfiltrated Browsing Data to Chinese Server

Malicious ModHeader Extension with 1.6M Installs Exfiltrated Browsing Data to Chinese Server

A trusted browser extension used by developers was found secretly stealing visited domains and sending encrypted data daily to a server linked to Chinese actors. Despite removal from official stores, existing installations remain a security risk.

Jul 14, 2026

How Microsoft’s New Defender Features Mitigate ShinyHunters OAuth Attacks

How Microsoft’s New Defender Features Mitigate ShinyHunters OAuth Attacks

Microsoft enhances Defender for Cloud Apps with improved OAuth app visibility and governance to combat ShinyHunters attacks exploiting SaaS integrations.

Jul 14, 2026

How Russian Attacks Exploit Misconfigured Routers in Critical Infrastructure

How Russian Attacks Exploit Misconfigured Routers in Critical Infrastructure

Russian threat actors are targeting poorly configured networking devices in critical infrastructure using default credentials and known Cisco vulnerabilities, posing significant security risks.

Jul 14, 2026

How the CrashStealer macOS Malware Steals Your Sensitive Data

How the CrashStealer macOS Malware Steals Your Sensitive Data

Learn how the CrashStealer macOS infostealer disguises itself as an Apple tool to access your Keychain, crypto wallets, passwords, and more, bypassing built-in security.

Jul 14, 2026

What Happened in the Cyberattack on Japan’s Largest Taxi Operator Nihon Kotsu?

What Happened in the Cyberattack on Japan’s Largest Taxi Operator Nihon Kotsu?

Nihon Kotsu suffered a malware attack that forced system shutdowns, disrupting taxi services. No data breach confirmed yet, but the company remains cautious and responsive.

Jul 14, 2026

Ransomware Negotiator Jailed for Betraying Victims to Attackers

Ransomware Negotiator Jailed for Betraying Victims to Attackers

A ransomware negotiator received a 70-month prison sentence after covertly aiding attackers, highlighting insider threats in ransomware response.

Jul 13, 2026

Critical Vulnerability in Google Dialogflow CX Lets Attackers Hijack AI Agents with Minimal Access

Critical Vulnerability in Google Dialogflow CX Lets Attackers Hijack AI Agents with Minimal Access

A critical flaw in Google Cloud’s Dialogflow CX allowed attackers with a single edit permission to hijack AI agents, exfiltrate conversations, and access credentials. Google patched the issue after months.

Jul 13, 2026