A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.OpenSSL Fixes HollowByte Memory Exhaustion BugDaxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s NetworkU.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalogErnst & Young (EY) Investigates Data Breach Involving Third-Party Support TicketsA cyberattack hit Nichirei, one of Japan’s largest food companiesNew Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RATU.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalogTwo Scattered Spider Members Sentenced to Prison Over £29 Million TfL CyberattackTuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and AllClaude Code and DeepSeek Powered Chinese Cyber Espionage CampaignZoom Fixes CVE-2026-53412, a Critical Account Takeover BugUS and allied Governments’ Recommendations: Securing Network Devices Against Russian APT GroupsChaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows SystemsAsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly DownloadsU.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalogSonicWall warns of active exploitation of two SMA 1000 zero-daysPatch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one monthU.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware LossesAttacker Used AI to Build Custom PowerShell Recon MalwareMalware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily SuspendedCrashStealer: New macOS Infostealer Uses Signed Apps to Evade GatekeeperLidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data BreachU.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalogEU Targets FSB-Linked Hackers in New Sanctions Over Cyber SabotageDutch Nationals Suspected in Odido Hack That Exposed Six Million CustomersAustralia Alerts Organizations to Ongoing CMS Exploitation AttacksRyuk Ransomware Member Pleads Guilty Over Attacks on U.S. OrganizationsProgress Told ShareFile Customers to Pull the Plug on Their Servers. Here’s What We Know.International Press – NewsletterCybercrimeArmenian National Extradited to the United States Pleads Guilty to Ransomware Extortion Conspiracy Investigation into Odido hack points to possible involvement of the Dutch German firm files for insolvency, blames cybercrims who shut down production for 6 weeksJapan’s largest taxi operator shuts systems after cyberattackInside Forg365: A Telegram-Distributed Sneaky 2FA-Style PhaaS Targeting Microsoft 365 Two sentenced for hacking Transport for London in UK’s biggest ever cyber crime case Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong ManMalwareCrashStealer: C++ macOS infostealer posing as crash reporterLucide Proxy: Turning Student Web Proxies into DDoS Bots AsyncAPI npm organization compromised, 2M weekly downloads affected TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era HackingLarge-scale exploitation campaign targeting website content management systems (CMS) Analyzing AI-Augmented Network Enumeration LegacyHive public disclosure Claude for-Chrome Extension-BypassSame Subject, Wrong User: A Cross-Issuer Account Takeover in n8n wp2shell: Pre Authentication RCE in WordPress Core OpenSSL HollowByte: A DoS Hiding in 11 Bytes wp2shell: Pre Authentication RCE in WordPress Core Intelligence and Information Warfare EU targets Russian intelligence officers accused of running a yearslong cyberspying campaign NSA revives ‘Tailored Access Operations’ name for elite hacking unit UK and EU strike Russian cyber networks with new sanctions Improve Router Hygiene to Protect Against Russian State-Sponsored TargetingNATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says Suspected Chinese Operators Use Claude Code and DeepSeek to Target Government and Financial Systems Across Four Countries Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New BackdoorNew North Korean campaign uses fake coding interviews to steal developer credentialsCybersecurityxAI Grok CLI Uploads Full Repos and Secrets, Opt-Out Ignored Satya Nadella’s ‘Reverse Information Paradox’ post draws reactions from AI leadersBabeLLM: A unified taxonomy for NLP-based LLM cybersecurity applications Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans The July 2026 Security Update Review A Puerto Rico Government Agency Exposed 1 Million Social Security Numbers AI Data Centers Are Being Built Faster Than They Can Be SecuredCyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei Ernst & Young discloses data breach after support system hack Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, newsletter)