8news

Tech • AI • Robotics

VIDEO
ENFR
TodayShortsTop StoriesYour topicFor youTopicsAll videosYT channelsArchivesSearchFavorites

Cybersecurity Updates July 25, 2026: Fastjson Exploits, Cl0p Attacks, and Android NFC Surge

CybersecSaturday, July 25, 2026

50 articles analyzed by AI / 54 total

Key points

Audio player
0:00 / 0:00
  • Over 700,000 global users of the Vatican’s 'Click to Pray' app have been exposed to data leaks from a security flaw persisting for more than six months without a patch as of July 2026, highlighting critical risks in widely used mobile applications.[Tom's Hardware]
  • Critical remote code execution vulnerabilities in widely-used software libraries such as Fastjson 1.x remain unpatched while being actively exploited, putting countless Spring Boot applications at immediate risk globally with no current mitigation.[The Hacker News RSS][The Hacker News RSS]
  • The rise of AI-powered cyberattacks has democratized hacking capabilities, with cybercriminals and even novices leveraging AI tools like ChatGPT and Claude for exploiting vulnerabilities and unauthorized system access, significantly expanding the cyber threat landscape over the past two years.[LinkedIn]
  • A popular Chrome extension 'Planet Search' with 2 million installs was found diverting user queries to a hijacker network, demonstrating risks associated with malicious browser extensions and their potential for large-scale user privacy breaches.[Reddit /r/netsec]
  • The Cl0p ransomware group has intensified attacks exploiting unauthenticated remote code execution flaws in enterprise software platforms like PTC Windchill and FlexPLM to conduct data extortion and ransomware campaigns, reflecting ongoing targeted ransomware operations.[The Hacker News RSS]
  • Phishing attacks in the insurance sector have evolved into more sophisticated real-time account hijacking schemes, where attackers gain immediate control over victim accounts instead of merely stealing credentials, signaling a troubling escalation in cybercrime tactics.[The Hacker News RSS]
  • The DevMan ransomware-as-a-service platform has enhanced its operational capabilities with a centralized portal enabling affiliates to create ransomware payloads, manage victims, and automate payouts, showcasing an advanced and professionalized ransomware ecosystem.[The Hacker News RSS]
  • Cobalt’s launch of an autonomous pentesting tool offers continuous offensive security testing embedded within modern development cycles, aiming to improve the speed and effectiveness of vulnerability identification and mitigation in software environments.[Cybersecurity Insiders]
  • Android NFC cyberattacks have surged by 188%, revealing significant security weaknesses in contactless communication and payment technologies that could affect millions of users, emphasizing an urgent need for improved NFC security measures.[Escudo Digital]
Explain this

Relevant articles

Two years ago, most people did not believe AI-based attacks would become a real threat. Today, a complete beginner with no cybersecurity knowledge can use ChatGPT or Claude to exploit vulnerabilities and gain unauthorised access to systems, and that ch - LinkedIn

8/10

AI tools like ChatGPT and Claude are increasingly used by cybercriminals, even those without cybersecurity experience, to exploit vulnerabilities and gain unauthorized access to systems. This trend has significantly expanded the cyber threat landscape over the past two years.

LinkedIn · 7/25/2026, 11:30:04 AM

Go deeper

This day's Daily Podcast — Top 24h, all topics