lithos Twitter
Lithos Header
Last Updated
Age in hrs 
1
2
3
5
8
13
21
34
55

 Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw  - Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Disclosure lists vBulletin...

 Ransomware Groups Increasingly Deploy EDR Kill Techniques  - Halcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight against

 Hacker who targeted over 500 Snapchat accounts sentenced to over 6 years in prison  - Svara used two-factor authentication to lock victims out of their Snapchat accounts.

 GitHub, PyPI add time-absed defenses against supply chain attacks  - GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.

 An Open and Competitive AI Ecosystem  - AI leadership depends on innovation, competition and choice. Michael Dell shares his perspective on the role of open-weight AI models, the importance of a competitive AI…

 Microsoft Xbox outage leaves players locked out of their own games  - Players lose access to purchased games, accounts, and the Microsoft Store as restoration timeline remains unknown.

 Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update  - Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management ( RMM ) tools. "The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that...

 MY TAKE: Big Tech is funding the AI race by cutting the skilled employees it needs to win it  - Big Tech isn’t buying the AI future with profits. It’s buying it with payroll.

 Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available  - Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723 , the...

 Ernst & Young data breach claimed by ShinyHunters extortion gang  - The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack.

 Russian Hackers Steal Emails Via Zimbra Exploit  - Russian state-linked hacking group Laundry Bear targeted previously unknown exploit to steal emails from corporate servers, say authorities

 Steam forum ClickFix attacks infect gamers with XMRig cryptominers  - Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers.

 ShinyHunters data leaks fuel $2,000 sextortion email scam  - Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin.