News

Cybersecurity News & Audit Summaries

Page 3 of 27 — 790 updates. Back to latest · By industry · National audits

Instant audit

Run a free scan at audit.emailmenow.com, then unlock the full technical report with remediation plan and compliance evidence for $99.

Run free audit
Lookalike archive-tool download lure turning a home PC into a residential proxy node
Cybersecurity Alert
July 29, 2026 by EmailMeNow IT Consulting

Fake 7-Zip Site Distributes Installer That Turns PCs Into Proxy Nodes

7zip.com impersonates 7-zip.org and ships a trojanized installer that enrolls PCs as residential proxy nodes. Of 16 registered lookalikes we scanned, several (7zip.org, 7-zip.com, 7-zip.net) are brand-owned mirrors/forwards — the lure still scores 29% vs 36% for the project; none at the 100% ideal.

NewsMalwareProxywareTyposquattingSoftware Supply Chain7-ZipCybersquatCybersecurity
Read Update
Connected car beside an admin dashboard showing remote unlock and location history risk
Cybersecurity Alert
July 29, 2026 by EmailMeNow IT Consulting

Subaru STARLINK Admin Portal Let Attackers Track and Control Cars With License Plate Data

Sam Curry and Shubham Shah showed Subaru’s STARLINK admin portal allowed account takeover and remote unlock/start plus a year of ~5 m location history. UH West Oahu summarizes the patch-in-24-hours case. Domain audits (ideal 100%): subaru.com 59%, mysubaru.com 28%; none at 100%.

NewsAuto DealersConnected CarsSubaruTelematicsAccount TakeoverCybersecurity
Read Update
Multi-source breach data week of July 26, 2026
Cybersecurity Alert
July 26, 2026 by EmailMeNow IT Consulting

Breach Data Week of July 26, 2026: Texas, HIBP, SEC & HHS Updates

Multi-source breach data week of July 26, 2026: Texas OAG, HHS OCR, SEC Form 8-K, HIBP, and state AG trackers. Texas YTD reports +10 (342 → 352). 13 companies/entities from source roundups.

CybersecurityData BreachTexasHave I Been PwnedHHS OCRSECForm 8-K
Read Update
Hotel lobby traveler laptop showing a fake Microsoft 365 login on public Wi-Fi
Cybersecurity Alert
July 26, 2026 by EmailMeNow IT Consulting

Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts — We Rated Top 10 U.S. Chains

ReliaQuest: hotel Wi-Fi DNS poisoning steals Microsoft 365 logins since June 2026. Full-tunnel VPN guide covers Proton VPN, Cloudflare WARP/Zero Trust, Tailscale, Zscaler, and corporate options. Top 10 U.S. hotel audits (100% ideal): marriott.com 70% leads; choicehotels.com 43%.

NewsMicrosoft 365HospitalityWi-FiDNSPhishingTravel SecurityCybersecurity
Read Update
Digital audit dashboard showing cybersecurity scores of major Texas law firms
Cybersecurity Alert
July 26, 2026 by EmailMeNow IT Consulting

Texas Bar Associations & Law Firms - August 2026 Cyber Monthly

August 2026 Texas bar associations cyber briefing: peer incidents, domain-audit takeaways (ideal 100%), MFA notes, one IT security tip, and free member self-check links. Published on the last Sunday of the prior month.

Law FirmsBar AssociationEmail SecurityTexasSB 2610Monthly
Read Update
Digital audit dashboard with a Texas map highlighting chamber of commerce cybersecurity posture
Cybersecurity Alert
July 26, 2026 by EmailMeNow IT Consulting

Texas Chambers of Commerce - August 2026 Cyber Monthly

August 2026 Texas chambers cyber briefing: peer incidents, domain-audit takeaways (ideal 100%), MFA notes, one IT security tip, and free member self-check links. Published on the last Sunday of the prior month.

Chambers of CommerceSmall BusinessBECEmail SecurityTexasMonthly
Read Update
Digital audit dashboard showing cybersecurity scores of major Texas credit unions
Cybersecurity Alert
July 26, 2026 by EmailMeNow IT Consulting

Texas Credit Unions - August 2026 Cyber Monthly

August 2026 Texas credit unions cyber briefing: peer incidents, domain-audit takeaways (ideal 100%), MFA notes, one IT security tip, and free member self-check links. Published on the last Sunday of the prior month.

Credit UnionFinancialGLBAMFAEmail SecurityTexasMonthly
Read Update
Municipal finance desk with a suspicious ACH payment email and lookalike domain warning
Cybersecurity Alert
July 25, 2026 by EmailMeNow IT Consulting

Surfside Beach Lost $545K to Email Scam — Municipal Coverage Gaps and NRD Defenses

Surfside Beach lost $545,598.30 via ACH on March 13, 2026 after both lookalike domains registered March 9. As of Jul 25, neither the town nor Wildcat has neutralized the squats — both still have live MX. Audits: vendor squat 47%, town squat 43% — none at the 100% ideal.

NewsBusiness Email CompromiseMunicipalCyber InsuranceNewly Registered DomainsTyposquattingMicrosoft 365Google WorkspaceSouth CarolinaCybersecurity
Read Update
Smartphone showing a suspicious party invitation page demanding an email password
Cybersecurity Alert
July 25, 2026 by EmailMeNow IT Consulting

BBB Warns of 'You're Invited' Phishing Scam Targeting Houstonians With Fake E-Vites

BBB and FTC warn that fake Evite, Paperless Post, and Punchbowl 'You're Invited' messages steal email passwords and one-time codes. Houston-area coverage is amplifying the alert. Audits (100% ideal): paperlesspost.com 76%, evite.com 75%, ftc.gov 72%, punchbowl.com 52%.

NewsPhishingTexasHoustonConsumer AlertCybersecurity
Read Update
Loyalty app on a phone showing an account lock and password reset after credential stuffing
Cybersecurity Alert
July 24, 2026 by EmailMeNow IT Consulting

Chick-fil-A One Accounts Hijacked With Stolen Passwords From Other Sites

Attackers stuffed third-party stolen passwords into Chick-fil-A One from June 17–19, 2026. Notices cite 2,182 Texans. Audits (100% ideal): chick-fil-a.com 42%, chickfila.com 28% — neither near ideal.

NewsCredential StuffingAccount TakeoverPassword ReuseRetailTexasCybersecurity
Read Update
Mac desktop with a fake CrashReporter utility and suspicious password prompt
Cybersecurity Alert
July 24, 2026 by EmailMeNow IT Consulting

CrashStealer Poses as Apple CrashReporter to Steal Mac Passwords and Crypto

Jamf documents CrashStealer: a C++ macOS infostealer disguised as CrashReporter that steals Keychain, browsers, ~80 crypto wallets, and 14 password managers via a notarized Werkbit dropper. Audits (100% ideal): cloudflare.com 88%, bitwarden.com 78%.

NewsmacOSMalwareInfostealerPassword TheftCryptocurrencyCybersecurity
Read Update
Person on an iPhone FaceTime call pressured about a fake bank security alert
Cybersecurity Alert
July 24, 2026 by EmailMeNow IT Consulting

Warning: Scammers Are Using FaceTime to Empty Bank Accounts

Cybercriminals combine FaceTime social engineering with unpatched iPhones to steal banking credentials and drain accounts. Apple asks users to report fake bank FaceTime calls. Audits (100% ideal): cloudflare.com 88%, malwarebytes.com 72%, apple.com 70%.

NewsSocial EngineeringFaceTimeBanking FraudiOSPhishingCybersecurity
Read Update
WordPress admin dashboard with a critical remote code execution security alert
Cybersecurity Alert
July 23, 2026 by EmailMeNow IT Consulting

wp2shell: Critical WordPress Core Flaws Enable Unauthenticated RCE — Patch Now

CVE-2026-63030 and CVE-2026-60137 (wp2shell) enable unauthenticated WordPress RCE. Checks of NASA, TechCrunch, and Rolling Stone show patched Core; White House and NYT hide versions. Audits (100% ideal): cloudflare.com 88%, nytimes.com 76%, nasa.gov 65%.

NewsWordPressVulnerability DisclosureRCECybersecurityPatch Now
Read Update
Mac desktop frozen by malware with a fake password prompt filling the screen
Cybersecurity Alert
July 22, 2026 by EmailMeNow IT Consulting

ClickLock Stealer Freezes Mac Screens Until Victims Enter Their Password

Group-IB documents ClickLock Stealer: a ClickFix macOS campaign that kills apps until you type your login password, then steals Keychain, browsers, crypto wallets, and leaves a GSocket backdoor. Domain audits (ideal 100%): cloudflare.com 88%, malwarebytes.com 72%, apple.com 70%.

NewsmacOSMalwarePhishingClickFixPassword TheftCybersecurity
Read Update
Multi-source breach data week of July 19, 2026
Cybersecurity Alert
July 19, 2026 by EmailMeNow IT Consulting

Breach Data Week of July 19, 2026: Texas, HIBP, SEC & HHS Updates

Multi-source breach data week of July 19, 2026: Texas OAG, HHS OCR, SEC Form 8-K, HIBP, and state AG trackers. Texas YTD reports +15 (327 → 342). 16 companies/entities from source roundups.

CybersecurityData BreachTexasHave I Been PwnedHHS OCRSECForm 8-K
Read Update
Password vault under phishing attack from fake policy emails and a deceptive compliance portal
Cybersecurity Alert
July 19, 2026 by EmailMeNow IT Consulting

Phishing Campaign Hits LastPass and Bitwarden Users With Fake Security Policy Emails

LastPass warned July 13, 2026 of lookalike-domain phishing (lastpassnewsletter.com / lastpasscompliance.com) impersonating DocuSign. A parallel Bitwarden lure uses bitwardennewsletter.com. Neither vault vendor was breached. Audits: bitwarden.com 78%, docusign.com 72%, lastpass.com 66% — all below the 100% ideal, with lastpass.com at 15% transport.

NewsPhishingLastPassBitwardenPassword ManagersCybersecurity
Read Update
SEC Form 8-K Item 1.05 cybersecurity disclosure screen for year-to-date 2026 filings
Cybersecurity Alert
July 19, 2026 by EmailMeNow IT Consulting

SEC Form 8-K Item 1.05 Cyber Disclosures YTD 2026: 14 Issuers Through July 19

EmailMeNow’s SEC EDGAR tracker finds 14 Item 1.05 cybersecurity issuer families YTD through July 19, 2026 (18 filings / 31 cyber-related 8-Ks). Domain audits of filers: Stryker 76% leads; none reach the 100% ideal; most score 15% transport.

NewsCybersecurityData BreachSECForm 8-KPublic Companies
Read Update
Ranked cybersecurity scoreboard comparing password manager domain security toward a 100 percent ideal
Cybersecurity Alert
July 19, 2026 by EmailMeNow IT Consulting

Password Manager Domain Security Audit 2026: Proton, LastPass, Bitwarden & Peers

Independent EmailMeNow audits of seven major password-manager domains find scores from 86% (Dashlane) to 65% (Keeper) — none reach the 100% ideal. Proton.me leads transport at 100%; LastPass sits at 66% with 15% transport amid 2026 phishing waves.

NewsPassword ManagersEmail SecurityLastPassBitwardenProtonCybersecurity
Read Update
Dairy production line darkened by cyber-alert lighting after a ransomware disruption
Cybersecurity Alert
July 18, 2026 by EmailMeNow IT Consulting

Fairlife Halts U.S. Milk Production After Ransomware Hits Production Systems

Coca-Cola disclosed a July 16, 2026 Fairlife ransomware event that suspended U.S. dairy production while Canada continued. Product safety unaffected; scope still unknown. Audits: fairlife.com 78%, coca-cola.com 69%, coca-colacompany.com 63% — all below the 100% ideal, with 15% transport on each.

NewsRansomwareData BreachFood and BeverageCoca-ColaFairlifeCybersecurity
Read Update
Illustration of a connected robot vacuum linked to a cloud broker with a broken lock warning
Cybersecurity Alert
July 17, 2026 by EmailMeNow IT Consulting

Shark Robot Vacuums Exposed by Unpatched AWS IoT Flaw Affecting Millions

Researcher tokay0 disclosed an unpatched SharkNinja AWS IoT Core certificate-scoping flaw (Jul 13, 2026) enabling cross-device RCE, cameras, maps, and plaintext Wi-Fi keys. ~1.52M devices seen in one region; ~44% respond to command probes. Audits: irobot.com 68%, ecovacs.com 62%, roborock.com 61%, sharkninja.com 54%, sharkclean.com 46% — none at the 100% ideal.

NewsIoTVulnerabilitySmart HomeCybersecurity
Read Update