Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack

2026-07-17T01:24:16Zb2d22efcd94f395a895fdb04cc2592dc2d94fb3e82b1d8e36fcb9be1ce068dc0
active-exploitagent-data-injectionai-securityaptbackdoorcredential-theftcritical-vulnerabilityidentityiotiot-botnetjwtmacos-infostealermalwarenpm-compromisepatchesphishingprivilege-escalationprompt-injectionransomwareratremote-code-executionresearch-poCsupply-chainzero-day

What happened

This feed aggregates multiple high-impact security stories: several actively exploited and high‑severity vulnerabilities (Zoom CVE-2026-53412 — CVSS 9.8; SonicWall SMA 1000 zero-day CVE-2026-15409 — CVSS 10.0; SAP NetWeaver CVE-2026-44747 — CVSS 9.9; Firefox CVE-2026-15718 and CVE-2026-15719 with public exploit code) and Microsoft’s unusually large Patch Tuesday (622 fixes, including two zero-days under active attack). New and evolving malware/campaigns were reported — TELEPUZ, ClickLock macOS stealer, OkoBot seed-phrase theft, LabubaRAT, TuxBot v3 Evolution, PhantomEnigma site‑hijacks, and an

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
b2d22efcd94f395a895fdb04cc2592dc2d94fb3e82b1d8e36fcb9be1ce068dc0
Enrichment time
2026-07-17T01:24:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.