The hacker who humiliated spyware makers and was never caught

Lorenzo Franceschi-Bicchierai
, 25/07/2026 | Source : IT-Sentinel - Actualités Cybersécurité

An awe-inspiring hacktivist who hacked two controversial government spyware makers may be the most prolific hacker to have never gotten caught. What do we know about Phineas Fisher?

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and

Australian energy provider Origin Energy disclosed a data breach impacting customer data

Pierluigi Paganini
, 25/07/2026 | Source : IT-Sentinel - Actualités Cybersécurité

Origin Energy confirmed a data breach after a hacker claimed to have stolen data from 2 million customers and threatened to leak it. Origin Energy disclosed a cyberattack that exposed customer data after a hacker claimed to have stolen records belonging to 2 million customers and threatened to publish them. An alleged hacker calling themselves “John Doe” claimed responsibility for the Origin Energy breach, saying they accessed the company’s customer systems and stole customers’ personal data. “Most are loyal, long-term customers,” reads an email sent by the hacker to Australian media outlet 7News.  “Despite my outreach to their board members, security teams, and customer care departments, Origin hasn’t made a public announcement about the breach or responded to negotiate next steps. “They’ve shown no interest in resolving it before the data goes public.”  Source 7News The claim prompted an urgent investigation by the Australian energy provider. The Australian energy provider said unauthorized access affected some customer information and is still investigating the incident to determine how many people were impacted. “Origin can confirm there has been unauthorised access and disclosure of some customers’ data. We are working to understand the total number of impacted customers, and we will contact any customers where we can confirm they have been affected.” reads the update on data security incident published by the company on July 23. “For affected customers, impacted data may include name, address, date of birth, contact phone number and account information, as well as the last four digits of a credit card, or the last three digits of a bank account. Incomplete credit card or bank account information cannot be used to make purchases or access accounts.” Origin Energy is one of Australia’s largest integrated energy companies, with approximately 4.8 million customers. Headquartered in Sydney, it operates across the electricity and natural gas sectors. The firm is investigating the security breach with the help of external cybersecurity experts. The company said the attacker may have stolen customers’ names, addresses, dates of birth, phone numbers, account details, and partial payment card or bank account numbers. The energy firm is notifying affected customers and has informed Australian law enforcement, cyber, and privacy authorities, including the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner. Origin Energy pointed out that its operations have not been impacted. The “John Doe” gave Origin 14 days to respond and threatened to release the stolen data if the company does not reach an agreement. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, newsletter)

Malicious sites use JavaScript to build malware in browser memory

Bill Toulas
, 25/07/2026 | Source : IT-Sentinel - Actualités Cybersécurité

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. [...]

1,500 curl authors

Daniel Stenberg
, 25/07/2026 | Source : IT-Sentinel - Actualités Cybersécurité

It takes a village to make curl. A rather big village. I have not been a solo maintainer of curl for a long time and I don’t even do half of the commits anymore Since today, the curl git repository holds the accumulated efforts from 1,500 separate and named individuals. Only 4.5 years since we passed 1,000. Yay for us! Author 1,500 turned out to be Sameeh Jubran who authored this. Number of commit authors in the curl project

ShinyHunters data leaks fuel $2,000 sextortion email scam

Lawrence Abrams
, 25/07/2026 | Source : IT-Sentinel - Actualités Cybersécurité

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. [...]

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires

ConfigoMatic : le configurateur de PC sur mesure 100% compatible

Florian BURNEL
, 25/07/2026 | Source : IT-Sentinel - Actualités Cybersécurité

Découvrez le ConfigoMatic, le configurateur PC de TopAchat pour concevoir un PC gamer sur mesure 100% compatible, à monter soi-même ou pas : à vous de choisir. Le post ConfigoMatic : le configurateur de PC sur mesure 100% compatible a été publié sur IT-Connect.

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

Lily Hay Newman, Dhruv Mehrotra
, 25/07/2026 | Source : IT-Sentinel - Actualités Cybersécurité

Plus: Russian hackers are trying to steal US nuclear scientists’ emails, the State Department bans known scammers from entering the United States, and more.

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling