Sunday, July 19, 2026
Headline Clips: BLEEPING COMPUTER
Hackers abuse ViPNet software to target Russian govt agencies
Bill Toulas
- July 19, 2026
- 10:23 AM
- 0

An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies.
Dubbed HelloNet, the campaign has been active since at least May, deploying a malicious payload that acts as a proxy and loader for additional malware.
According to Kaspersky researchers, HelloNet has impacted organizations in the government, energy, transport, education, and logistics sectors.
Kaspersky has tentatively attributed the campaign to an unidentified Chinese-speaking advanced persistent threat (APT) group.
However, the researchers stressed that the evidence is weak, relying primarily on an unused string referencing the Chinese website sina.com and a malware download mirror hosted by the University of Science and Technology of China.
As a result, they assign the attribution low confidence and do not rule out the possibility of a false flag operation.
The cybersecurity firm recommends thorough monitoring of systems running ViPNet software, particularly traffic passing through ports 5003, 5060 (HelloProxy), and 443 (HelloBackdoor).
-
Get pro-level edits with little effort—this Luminar Neo deal is $80
For a limited time, you can get the Award-Winning Luminar Neo photo editor Lifetime Bundle for a one-time $79.99 (MSRP $332), which saves you $252 while skipping another recurring subscription.
- BleepingComputer Deals
- July 19, 2026
- 08:10 AM
0
-
Shadow AI Is Everywhere. Here's How to Find and Secure It.

Shadow AI is quietly spreading across SaaS environments as employees adopt new AI tools without IT oversight. Nudge Security explains how security teams can discover AI apps, monitor usage, and govern risky AI activity.
- Nudge Security Sponsorship
-
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.
- Lawrence Abrams
- July 18, 2026
- 03:32 PM
3
-
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately.
- Lawrence Abrams
- July 18, 2026
- 01:22 PM
0
-
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.
- Bill Toulas
- July 18, 2026
- 10:17 AM
1
-
The Future of Age Verification: Your Face Never Leaves Your Device
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting compliance.
-
This $79.99 Mac app replaces a whole stack of PDF tools
If you use a Mac, chances are you've opened a PDF only to realize you need to edit text, sign a form, merge files, or convert a document—and suddenly you're searching for another app. PDF Expert Premium is designed to eliminate that cycle.
- BleepingComputer Deals
- July 18, 2026
- 08:12 AM
0
-
Abbott probes two cyber incidents amid extortion claims
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data.
- Lawrence Abrams
- July 17, 2026
- 04:45 PM
0
-
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes.
- Bill Toulas
- July 17, 2026
- 01:56 PM
0
-
Ernst & Young discloses data breach after support system hack
Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel.
- Bill Toulas
- July 17, 2026
- 10:55 AM
3
-
Inside the Search for "Clean" Residential Proxies for Carding
Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection.
-
Learn networking, cybersecurity & cloud skills from home for just $50
This Complete 2026 CompTIA Certification Training Bundle helps you build meaningful technical skills. And for a limited time, you can get lifetime access for $49.99, down from $199, saving $149 while unlocking seven comprehensive training courses covering the certifications employers most often ask for.
- BleepingComputer Deals
- July 17, 2026
- 07:12 AM
0
-
New Windows LegacyHive zero-day gives hackers admin privileges
A security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems.
- Sergiu Gatlan
- July 17, 2026
- 07:05 AM
1
-
Windows Server 2022 reach end of mainstream support in 90 days
Microsoft announced that Windows Server 2022 will reach the mainstream end date in October 2026, but will switch to extended support and continue receiving security updates for five more years.
- Sergiu Gatlan
- July 17, 2026
- 05:10 AM
0
-
US charges two over laundering $43 million from investment fraud
U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams.
- Sergiu Gatlan
- July 17, 2026
- 04:13 AM
0
-
CISA urges immediate action on actively exploited Fortinet flaws
CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform.
- Sergiu Gatlan
- July 17, 2026
- 03:03 AM
0
-
New ClickLock macOS malware traps users into revealing login password
A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password.
- Bill Toulas
- July 16, 2026
- 05:52 PM
0
-
Coca-Cola says Fairlife ransomware attack halts US dairy production
The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States.
Politicians will want you to believe that wildfires are another country's problem, but the whole world is currently burning. 🌎🔥
As much as nationalists want you to believe that each border is a separate universe in itself, the truth is that the entire planet is interconnected.
-
Flash News: Ukraine Intercepts Russian Kh-59 Cruise Missile Using US VAMPIRE Air Defense System Mounted on Boat. Ukrainian forces have made ...
-
A nor’easter is about to hit the Northeast in May. That’s very unusual.
