12 years of God's undeniable faithfulness. Promises fulfilled. Destinies aligned. Lives elevated. The testimony continues!
Join us at the *Phaneroo Grounds, NAGURU and regional celebration centers* on the *8th of August 2026* as we celebrate the *12th anniversary* of Phaneroo Ministries International.
*Entrance is Free | Gates Open at 10AM*.
*#PhanerooAt12 🎉*
*#Bring20*
🛑 One visit to a malicious webpage could have been enough to expose your #WhatsApp Web chats.
CVE-2026-48294 in Adobe Acrobat’s Chrome extension could read messages, contact names, chat previews, and profile data without malware, stolen credentials, or session cookies.
76% of employees now use AI at work. Most of those tools were never reviewed by security.
When approval takes six weeks and a workaround takes six minutes, AI use moves out of sight.
Windmill servers are under active attack.
Experts say attackers are exploiting CVE-2026-29059 to read arbitrary server files without logging in. On some systems, the same flaw can lead to superadmin access and code execution.
Around 79% of attacks are malware-free, CrowdStrike estimates.
Endpoint alerts alone can miss credential theft and lateral movement across identity and cloud systems. AI cannot connect what the SOC never captured.
🛑 MFA didn’t stop Kratos.
The phishing kit stole Microsoft 365 session cookies, letting attackers enter accounts without another MFA check. Police took 200+ servers offline and arrested the alleged operator in Indonesia.
But about 1,800 customers may still have the code.
One extra “t” hid a package built to rig live betting results.
Newtonsoftt.Json[.]Net worked as a normal JSON library for most users, but targeted Digitain’s FG-Crash backend when the right conditions were present.
⚠️ An attacker does not need the reviewer’s broader Azure DevOps permissions.
In tests, one hidden PR comment steered the reviewer’s AI coding agent into other projects and leaked data the attacker could not access directly.
🔥 OpenAI says its own AI models broke out of a sandbox, exploited a zero-day, and targeted Hugging Face’s production infrastructure to cheat a security benchmark.
The incident showed how long-running models can learn and work around approval-system blind spots.
Chick-fil-A has announced that they've been hit by a data breach, caused by a series of "credential stuffing" attacks.
Credential stuffing is a type of cyber attack where hackers use stolen login credentials from one website to try and access accounts on other websites
Police have taken down the main operation of Kratos, a large-scale phishing scam that targeted people worldwide. They've also caught the person behind it in Indonesia.
The authorities worked together with their counterparts in Germany to dismantle the platform's infrastructure.
A massive campaign known as "FakeGit" is spreading malware through thousands of compromised GitHub repositories.
Here are the details:
* 7,600 GitHub repositories have been hijacked to spread malicious code.
* These repos have accumulated over 14 million downloads so far.
Critical Vulnerability Found in SharePoint;
A severe flaw, known as CVE-2026-50522, has been discovered in Microsoft's SharePoint platform. This vulnerability allows hackers to gain remote code execution (RCE) and steal machine keys. As a result, attackers can maintain access.
🛑 Invisible text on a web page was enough to hijack AWS's Kiro AI coding tool.
Ask it to summarize a page, and hidden instructions make Kiro rewrite its own config and run attacker code. The approval prompt did nothing.
Apple’s Hide My Email exposed the real address it was designed to hide.
A flaw caused users’ personal email addresses to appear in mail logs when messages sent to an alias were rejected as spam.
Apple fixed it on July 3, more than a year after disclosure.
🚨 Attackers are exploiting Palo Alto Networks PAN-OS flaw CVE-2026-0257 to deploy Qilin ransomware.
Some intrusions ended in rapid encryption. Others escalated to credential theft, data exfiltration, and double extortion.
Anubis Ransomware Gang Claims Responsibility for Coca-Cola's Fairlife Attack
The Anubis ransomware gang has taken credit for the cyberattack on Coca-Cola's Fairlife dairy subsidiary. They're now threatening to release allegedly stolen corporate data unless a ransom is paid.
Hackers are taking advantage of two critical vulnerabilities in WordPress, known as wp2shell (CVE-2026-63030 and CVE-2026-60137), to install malicious web tools called "webshells" on affected servers.
These webshells allow hackers to gain persistent access to the server.